Critical Java flaw “Log4J” used to deliver malware, crypto miners

[ad_1]

AppleInsider is supported by its audience and can earn commission as an Amazon Associate and Affiliate Partner on qualifying purchases. These affiliate partnerships do not influence our editorial content.

A critical flaw in a commonly used Java library is exploited by malicious actors to distribute malware, while security researchers search for vulnerable servers.

The flaw and a proof of concept exploit were made public on Friday, wreaking havoc on companies that use the popular Java Log4j platform. The companies involved included Amazon, Apple, Steam, Minecraft and many more.

According to Bleeping Computer, the threat actors used the vulnerability to provide crypto-mining, botnet and penetration tools that could be used to deploy ransomware to affected systems.

There is currently no public data to suggest that ransomware gangs used the Log4k exploit, but the deployment of the aforementioned penetration tools suggests such attacks could be “imminent,” reported Bleeping Computer.

Additionally, threat actors and security researchers use the exploit to find vulnerable servers and steal information from them. From there, scanners can determine if a server can be used for additional attacks, research purposes, or bug bounty rewards.

The flaw exists in the Java Log4j logging platform, which is used for web server access and application logs. Once exploited, the vulnerability could allow a remote attacker to execute code or take control of a vulnerable server.

Since Log4j is used in thousands of corporate websites and applications, security researchers are concerned that it could lead to large-scale malware attacks and deployments.

Apache quickly patched its systems to mitigate the vulnerability.

Who is at risk and how to protect yourself

Although the vulnerability appears to be taking its toll on Friday, the effects are mostly felt in the corporate sector. In other words, it is not up to end users to defend themselves against the vulnerability.

Engineers working on the programming subreddit have suggested that big tech companies like Amazon have been working to fix the issue since Thursday night. AppleInsider has learned that the week continued throughout the weekend at Amazon and others, and that some companies are still implementing fixes and workarounds.

Sources

1/ https://Google.com/

2/ https://appleinsider.com/articles/21/12/13/critical-log4j-java-flaw-being-used-to-deliver-malware-crypto-miners

The mention sources can contact us to remove/changing this article

[ad_2]

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Posts