Log4Shell: How It’s Exploited and Mitigating DamageRecorded Future·Jun 27, 00:00 UTC · Jun 27, 2025Exploit / PoC in the wildCVE-2021-4422860
Log4Shell attacks began two weeks ago, Cisco and Cloudflare sayThe Record·Jan 18, 00:00 UTC · Jan 18, 2023Ransomware in the wild60
Cynet Log4Shell Webinar: A Thorough - And ClearThe Hacker News·Feb 4, 08:34 UTC · Feb 4, 2022Vulnerability in the wild60
Log4Shell: A new fix, details of active attacks, and risk mitigation recommendationsHelp Net Security·Dec 15, 00:00 UTC · Dec 15, 2021Ransomware in the wildCVE-2021-44228CVE-2021-4504660
US CISA orders federal agencies to fix Log4Shell by December 24thSecurity Affairs·Dec 14, 15:54 UTC · Dec 14, 2021Exploit / PoC in the wildCVE-2021-4422860
Iranian hackers use Log4Shell to mine crypto on federal computer systemCyberScoop·Nov 16, 23:37 UTC · Nov 16, 2022Ransomware in the wild60
Open-source software holds the key to solving Log4Shell-like problemsHelp Net Security·Dec 22, 00:00 UTC · Dec 22, 2021Exploit / PoC in the wild60
CISA, Five Eyes issue guidance meant to slow Log4Shell attacksCyberScoop·Dec 22, 17:03 UTC · Dec 22, 2021Ransomware in the wild60
Week in review: Log4Shell updates, Kronos ransomware attack, unused identities threatHelp Net Security·Dec 19, 00:00 UTC · Dec 19, 2021Ransomware in the wildCVE-2021-44228CVE-2021-4389060
CISA adds Log4Shell flaw to the Known Exploited Vulnerabilities CatalogSecurity Affairs·Dec 13, 13:44 UTC · Dec 13, 2021Exploit / PoC in the wildCVE-2021-44228CVE-2021-44515CVE-2021-44168+10 CVEs60
Log4Shell was in the wild at least nine days before public disclosureSecurity Affairs·Dec 13, 09:47 UTC · Dec 13, 2021Exploit / PoC in the wildCVE-2021-22448CVE-2021-4422860
Log4Shell, ProxyLogon and Atlassian bug top CISA\'s list of routinely exploited vulnerabilities in 2021The Record·Jan 12, 00:00 UTC · Jan 12, 2023Vulnerability in the wildCVE-2020-1472CVE-2018-13379CVE-2019-11510+3 CVEs60
CISA's new JCDC worked as intended, witnesses say at Senate hearing on Log4Shell bugCyberScoop·Feb 8, 18:22 UTC · Feb 8, 2022Exploit / PoC in the wild60
Log4Shell update: Attack surface, attacks in the wild, mitigation and remediationHelp Net Security·Dec 13, 00:00 UTC · Dec 13, 2021Ransomware in the wildCVE-2021-44228160
Week in review: Log4Shell lingers, NIS2 directive adopted, LastPass breached (again)Help Net Security·Dec 4, 00:00 UTC · Dec 4, 2022Data breach in the wildCVE-2021-3558760
Google Cloud offers good news and bad news on Log4Shell, other issuesCyberScoop·Feb 15, 17:25 UTC · Feb 15, 2022Exploit / PoC in the wild60
Microsoft Patch Tuesday, December 2021 EditionKrebs on Security·Dec 15, 00:00 UTC · Dec 15, 2021Vulnerability in the wildCVE-2021-43890CVE-2021-43905CVE-2021-43883+1 CVEs60
North Korean hacking ops continue to exploit Log4ShellCyberScoop·Dec 11, 13:00 UTC · Dec 11, 2023Ransomware in the wild60
Iran-linked threat actors compromise US Federal NetworkSecurity Affairs·Nov 17, 07:58 UTC · Nov 17, 2022Threat actor in the wildCVE-2021-4422860
Apache Log4j Vulnerability — Log4Shell — Widely Under Active AttackThe Hacker News·Dec 15, 00:00 UTC · Dec 15, 2021Vulnerability in the wildCVE-2021-26084CVE-2021-4422860
Second Log4j Vulnerability (CVE-2021The Hacker News·Dec 18, 13:56 UTC · Dec 18, 2021Vulnerability in the wildCVE-2021-45046CVE-2021-4422860
Contrast CVE Shield aims to protect applications while security teams deploy patchesHelp Net Security·Jul 29, 00:00 UTC · Jul 29, 2026Vulnerability in the wildCVE-2021-44228160
NHS Warns of Hackers Targeting Log4j Flaws in VMware HorizonThe Hacker News·Jan 8, 07:04 UTC · Jan 8, 2022Ransomware in the wildCVE-2021-4422860
Apache releases the third patch to address a new Log4j flawSecurity Affairs·Dec 18, 15:20 UTC · Dec 18, 2021Vulnerability in the wildCVE-2021-45046CVE-2021-44228CVE-2021-4510560
Hackers Exploit Log4j Vulnerability to Infect Computers with Khonsari RansomwareThe Hacker News·Dec 15, 00:00 UTC · Dec 15, 2021Ransomware in the wildCVE-2021-4422860
Top 12 vulnerabilities list highlights troubling reality: many organizations still aren't patchingCyberScoop·Aug 3, 19:44 UTC · Aug 3, 2023Vulnerability in the wild60
China suspends deal with Alibaba for not sharing Log4j 0The Hacker News·Dec 23, 15:13 UTC · Dec 23, 2021Vulnerability in the wildCVE-2021-4422860
Attacks pinned to critical React2Shell defect surge, surpass 50 confirmed victimsCyberScoop·Dec 11, 17:17 UTC · Dec 11, 2025Ransomware in the wildCVE-2025-5518260
2021 Vulnerability LandscapeRecorded Future·Jul 28, 00:00 UTC · Jul 28, 2025Vulnerability in the wildCVE-2021-4422860
5 Ways to Take Your Vulnerability Management Program to the Next LevelRecorded Future·Jun 27, 00:00 UTC · Jun 27, 2025Vulnerability in the wildCVE-2022-0847CVE-2022-138860
Java security: If you ain’t cheatin,’ you ain’t tryin’CyberScoop·Feb 19, 11:00 UTC · Feb 19, 2025Exploit / PoC in the wildCVE-2021-4422860
CISA adds Spring4Shell to list of exploited vulnerabilitiesHelp Net Security·Jan 10, 14:38 UTC · Jan 10, 2025Vulnerability in the wildCVE-2022-22965CVE-2021-4422860
How new and old security threats keep persistingHelp Net Security·Mar 8, 00:00 UTC · Mar 8, 2024Ransomware in the wild60
White House releases report on securing openCyberScoop·Jan 30, 21:09 UTC · Jan 30, 2024Exploit / PoC in the wild60
Week in review: Apache Struts vulnerability exploit attempt, EOL Sophos firewalls get hotfixHelp Net Security·Dec 17, 00:00 UTC · Dec 17, 2023Vulnerability in the wildCVE-2022-3236CVE-2023-50164CVE-2021-44228+1 CVEs60
Congress looks to expand CISA's role, adding responsibilities for satellites and open source softwareCyberScoop·May 17, 21:21 UTC · May 17, 2023Policy & legal in the wild60
Hackers Started Exploiting Critical "Text4Shell" Apache Commons Text VulnerabilityThe Hacker News·Oct 24, 05:48 UTC · Oct 24, 2022Vulnerability in the wildCVE-2022-42889CVE-2022-3398060
Threat Source newsletter (July 21, 2022) — No topic is safe from being targeted by fake news and disinformationCisco Talos·Jul 21, 18:00 UTC · Jul 21, 2022Ransomware in the wildCVE-2022-2204760
Metasploit 6.2.0 comes with 138 new modules, 148 enhancements and featuresHelp Net Security·Jun 13, 00:00 UTC · Jun 13, 2022Exploit / PoC in the wildCVE-2021-44228CVE-2022-1388CVE-2022-22954+3 CVEs60
Amazon's Hotpatch for Log4j Flaw Found Vulnerable to Privilege Escalation BugThe Hacker News·Apr 23, 05:41 UTC · Apr 23, 2022Vulnerability in the wildCVE-2021-3100CVE-2021-3101CVE-2022-0070+1 CVEs60