Hackers used the Log4Shell vulnerability to install hidden miners
The experts have identified attacks aimed at devices running Linux
13.12.2021 - 12:20
321
1 min
0
.
What’s new? The experts from Netlab 360 reported a critical vulnerability in Apache Log4j, a Java-based logging library. The attackers used it to install the malware and hidden miners.
Information on the Netlab 360 blog
What is the danger of a critical vulnerability? Log4Shell or LogJam is a Remote Code Execution class vulnerability. If the attackers manage to exploit it on one of the servers, they will be able to execute the arbitrary code and take full control of the system. The hackers took advantage of the situation to launch the Kinsing crypto miners and organize large-scale DDoS attacks. .
What are the experts saying? The Apache Foundation recommends that all developers upgrade the library to version 2.15.0, or if this is not possible, use one of the methods described on the Apache Log4j Security Vulnerabilities page. The experts added:
“At the moment, there have been no instances of exploitation of vulnerabilities by ransomware or APT-groups, however, the fact of the deployment of Cobalt Strike beacons indicates the forthcoming malicious campaigns.”
Useful material?
Market
According to the politician, this will combat widespread corruption by ensuring transparency and accountability of budgetary funds
Nov 26, 2024
Market
Justin Sun invested $30 million in the project
Nov 26, 2024
Technologies
Network fees will be integrated into the cost of swaps
Nov 22, 2024
Market
The company’s unrealized profits from investing in its first cryptocurrency approached $14 billion
Nov 19, 2024
Incidents
The search, the reason for which was not announced, took place a week after the election, the results of which Polymarket users predicted quite accurately
Nov 14, 2024
Market
Analysts point to the growing popularity of the first cryptocurrency as a safe haven asset
Nov 13, 2024