How Can You Leave Log4J in 2021?The Hacker News·Jan 11, 20:29 UTC · Jan 11, 2022Vulnerability in the wild57
New Local Attack Vector Expands the Attack Surface of Log4j VulnerabilityThe Hacker News·Dec 20, 05:03 UTC · Dec 20, 2021Vulnerability in the wildCVE-2021-45105CVE-2021-45046CVE-2021-44228+1 CVEs60
The Log4j saga: New vulnerabilities and attack vectors discoveredHelp Net Security·Dec 20, 00:00 UTC · Dec 20, 2021VulnerabilityCVE-2021-44228CVE-2021-45046CVE-2021-45105+1 CVEs47
Answering Log4ShellKaspersky Securelist·Dec 21, 10:55 UTC · Dec 21, 2021Vulnerability in the wildCVE-2021-44228CVE-2021-45046CVE-2021-4510560
Apache Log4j 2.17.1 fixes remote code execution flaw (CVE-2021Security Affairs·Dec 29, 14:34 UTC · Dec 29, 2021VulnerabilityCVE-2021-44832CVE-2021-44228CVE-2021-45046+2 CVEs47
While attackers begin exploiting a second Log4j flaw, a third one emergesSecurity Affairs·Dec 18, 14:00 UTC · Dec 18, 2021RansomwareCVE-2021-45046CVE-2021-4422860
HackDHS program accepts reports of Log4jSecurity Affairs·Dec 23, 10:04 UTC · Dec 23, 2021Exploit / PoC in the wildCVE-2021-44228CVE-2021-4504660
How the Pentagon enlisted ethical hackers amid the Log4j crisisThe Record·Jan 17, 00:00 UTC · Jan 17, 2023Vulnerability42
Hackers Begin Exploiting Second Log4j Vulnerability as a Third Flaw EmergesThe Hacker News·Dec 17, 05:54 UTC · Dec 17, 2021VulnerabilityCVE-2021-45046CVE-2021-4422847
Hackers using Log4j bug to profit from victim IP addresses through ‘proxyjacking’ schemeThe Record·Apr 5, 04:44 UTC · Apr 5, 2023Vulnerability42
Pay attention to Log4j attacks, Dutch National Cybersecurity Centre warnsSecurity Affairs·Jan 22, 20:34 UTC · Jan 22, 2022RansomwareCVE-2021-44228CVE-2021-45046CVE-2021-4104+1 CVEs60
CISA Releases Free Scanner to Spot Log4j ExposureInfosecurity Magazine·Dec 23, 09:21 UTC · Dec 23, 2021AdvisoryCVE-2021-44228CVE-2021-4504647
Google: More than 35,000 Java packages impacted by Log4j vulnerabilitiesThe Record·Jan 18, 00:00 UTC · Jan 18, 2023VulnerabilityCVE-2021-44228CVE-2021-4504647
Local governments allegedly targeted with Iranian ‘Drokbk’ malware through Log4j vulnerabilityThe Record·Jan 9, 00:00 UTC · Jan 9, 2023VulnerabilityCVE-2021-44228CVE-2021-4504647
Threat actors continue to exploit Log4j flaws, Microsoft WarnsSecurity Affairs·Jan 5, 10:46 UTC · Jan 5, 2022Threat actor in the wildCVE-2021-45046CVE-2021-45105CVE-2021-4104+2 CVEs60
New Log4j Patch Released to Fix DoS FlawInfosecurity Magazine·Dec 20, 10:43 UTC · Dec 20, 2021VulnerabilityCVE-2021-4422847
Microsoft Warns of Continued Attacks Exploiting Apache Log4j VulnerabilitiesThe Hacker News·Jan 5, 05:13 UTC · Jan 5, 2022Vulnerability in the wildCVE-2021-45046CVE-2021-45105CVE-2021-4104+1 CVEs60
Operation Blacksmith: Lazarus exploits Log4j flaws to deploy DLang malwareSecurity Affairs·Dec 12, 15:31 UTC · Dec 12, 2023MalwareCVE-2021-4422847
Iran-linked TunnelVision APT is actively exploiting the Log4j vulnerabilitySecurity Affairs·Feb 18, 15:21 UTC · Feb 18, 2022VulnerabilityCVE-2018-1337947
Suspected Chinese hackers use Log4j flaw to deploy Night Sky ransomware, Microsoft warnsCyberScoop·Jan 11, 15:36 UTC · Jan 11, 2022Ransomware57
CISA, FBI and NSA Publish Joint Advisory and Scanner for Log4j VulnerabilitiesThe Hacker News·Dec 29, 03:34 UTC · Dec 29, 2021VulnerabilityCVE-2021-45046CVE-2021-45105CVE-2021-44228+2 CVEs47
Apache Issues 3rd Patch to Fix New HighThe Hacker News·Dec 20, 05:02 UTC · Dec 20, 2021Vulnerability in the wildCVE-2021-45105CVE-2021-45046CVE-2021-4422860
Two Linux botnets already exploit Log4Shell flaw in Log4jSecurity Affairs·Dec 13, 07:36 UTC · Dec 13, 2021Malware42
AWS's Log4Shell Hot Patch Vulnerable to Container Escape and Privilege EscalationPalo Alto Unit 42·Jun 5, 22:41 UTC · Jun 5, 2024VulnerabilityCVE-2021-3100CVE-2021-3101CVE-2022-0070+2 CVEs47
North Korean hackers using Log4J vulnerability in global campaignThe Record·Dec 11, 20:36 UTC · Dec 11, 2023VulnerabilityCVE-2021-4422847
Threat Report: High Tech Industry targeted the most with 46% of attack traffic tagged by NLXThe Hacker News·Sep 29, 01:42 UTC · Sep 29, 2023Ransomware57
Microsoft: Nation-state Iranian hackers exploit Log4Shell against IsraelThe Record·Jan 11, 00:00 UTC · Jan 11, 2023Threat actor57
U.S. state legislature, Middle Eastern gov’t targeted by espionage group through Log4jThe Record·Jan 9, 00:00 UTC · Jan 9, 2023Threat actorCVE-2021-44228CVE-2021-4510560
Suspected Iranian APT accessed federal server via Log4j vulnerabilityThe Record·Dec 21, 00:00 UTC · Dec 21, 2022Vulnerability42
Log4Shell exploitation: Which applications may be targeted next?Help Net Security·Apr 5, 00:00 UTC · Apr 5, 2022RansomwareCVE-2022-22965CVE-2021-44228160
B1txor20 Linux botnet use DNS Tunnel and Log4J exploitSecurity Affairs·Mar 17, 11:18 UTC · Mar 17, 2022Malware42
From Log4j to IIS, China’s Hackers Turn Legacy Bugs into Global Espionage ToolsThe Hacker News·Nov 22, 06:13 UTC · Nov 22, 2025Threat actorCVE-2022-26134CVE-2021-44228CVE-2017-9805+2 CVEs60
Five Eyes issue joint advisory for defending against Log4ShellThe Record·Jan 4, 00:00 UTC · Jan 4, 2023Advisory42
New "B1txor20" Linux Botnet Uses DNS Tunnel and Exploits Log4J FlawThe Hacker News·Mar 15, 00:00 UTC · Mar 15, 2022Malware42
Iranian Hackers Targeting VMware Horizon Log4j Flaws to Deploy RansomwareThe Hacker News·Feb 18, 07:40 UTC · Feb 18, 2022RansomwareCVE-2018-1337960
Alibaba Suffers Government Crackdown Over Log4jInfosecurity Magazine·Dec 23, 10:05 UTC · Dec 23, 2021Vulnerability42
Most attackers lose interest in Log4ShellThe Record·Jan 17, 00:00 UTC · Jan 17, 2023Exploit / PoC in the wildCVE-2021-4422860
Google backs Senate bill on securing open source softwareThe Record·Jan 4, 00:00 UTC · Jan 4, 2023Policy & legal42
Log4Shell Still Being Exploited to Hack VMWare Servers to Exfiltrate Sensitive DataThe Hacker News·Jun 24, 07:37 UTC · Jun 24, 2022VulnerabilityCVE-2021-44228CVE-2022-2295447
Quebec shuts down thousands of sites as disclosure of the Log4Shell flawSecurity Affairs·Dec 12, 20:27 UTC · Dec 12, 2021Exploit / PoCCVE-2021-4422860