Hackers used the Log4Shell vulnerability to install hidden miners
The experts have identified attacks aimed at devices running Linux
13.12.2021 - 12:20
329
1 min
0
.
What’s new? The experts from Netlab 360 reported a critical vulnerability in Apache Log4j, a Java-based logging library. The attackers used it to install the malware and hidden miners.
Information on the Netlab 360 blog
What is the danger of a critical vulnerability? Log4Shell or LogJam is a Remote Code Execution class vulnerability. If the attackers manage to exploit it on one of the servers, they will be able to execute the arbitrary code and take full control of the system. The hackers took advantage of the situation to launch the Kinsing crypto miners and organize large-scale DDoS attacks. .
What are the experts saying? The Apache Foundation recommends that all developers upgrade the library to version 2.15.0, or if this is not possible, use one of the methods described on the Apache Log4j Security Vulnerabilities page. The experts added:
“At the moment, there have been no instances of exploitation of vulnerabilities by ransomware or APT-groups, however, the fact of the deployment of Cobalt Strike beacons indicates the forthcoming malicious campaigns.”
Useful material?
Market
According to the preliminary plan, the free coin giveaway will take place in January 2025
Dec 27, 2024
Market
The fund’s issuer will be Donald Trump associate Vivek Ramaswamy’s Strive company
Dec 27, 2024
Market
Digital assets have made it easier to conduct transactions in the face of sanctions
Dec 25, 2024
Mining
The restrictions are designed to maintain the balance of energy consumption, taking into account the demands of the industry
Dec 24, 2024
Market
Due to supply shortages, the asset’s pre-market exchange rate was climbing above $1000
Dec 16, 2024
Incidents
Reports about the hacking of the exchange with calls to withdraw assets began to spread on December 13
Dec 13, 2024