Skip to content
GeekWire
  • HOME
  • NEWS
    • CERT
    • EXPLOITS
    • NCSC
    • NVD
    • SECURELIST
    • US-CERT
  • BLOG
    • Books
    • OSINT
    • Pentest
    • Privacy
  • GHDB
  • CHDB
  • OSINT
  • ARCHIVE
  • ABOUT
    • Privacy Policy
    • Terms of Use
    • External Links
    • Sitemap
GeekWire
GeekWire
  • HOME
  • NEWS
    • CERT
    • EXPLOITS
    • NCSC
    • NVD
    • SECURELIST
    • US-CERT
  • BLOG
    • Books
    • OSINT
    • Pentest
    • Privacy
  • GHDB
  • CHDB
  • OSINT
  • ARCHIVE
  • ABOUT
    • Privacy Policy
    • Terms of Use
    • External Links
    • Sitemap

Log4j

Log4j flaw: Thousands of applications are still vulnerable, warn security researchers

28 April 2022

Months on from a critical zero-day vulnerability being disclosed in the widely-used Java logging library Apache Log4j, a significant number …

Tags IT, Log4j, News

Remote execution holes in Log4j, Exchange and Confluence lead Five Eyes 2021 exploited CVE list

28 April 2022

During 2021, the top 15 vulnerabilities that were exploited — as observed by the US Cybersecurity and Infrastructure Security Agency, US …

Tags Confluence, CVE, Exchanges, Log4j, Remote

Log4j Attack Surface Remains Massive

27 April 2022

Four months after the Log4Shell vulnerability was disclosed, most affected open source components remain unpatched, and companies continue …

Tags Attack Surface, IT, Log4j, Massive, News

Amazon’s Hotpatch for Log4j Flaw Found Vulnerable to Privilege Escalation Bug

21 April 2022

The “hotpatch” released by Amazon Web Services (AWS) in response to the Log4Shell vulnerabilities could be leveraged for container escape …

Tags Bug, Flaws, Found, Log4j, Vulnerable

Vulnerabilities that kept security leaders busy in Q1 2022

21 April 2022

In this video for Help Net Security, Yotam Perkal, VP of Research at Rezilion, talks about the most critical vulnerabilities published …

Tags Log4j, Q1, Security Pro, Spring4Shell, Vulnerability

Just Because You Don’t Use Log4j or Spring Beans Doesn’t Mean Your Application is Unaffected

20 April 2022

The Spring Framework vulnerability – made public on March 29, 2021 – was caused by unforeseen access to Tomcat’s ClassLoader as a …

Tags Application, Beans, Just, Log4j, Mean

AWS’s Log4j patches blew holes in its own security

20 April 2022

Amazon Web Services has updated its Log4j security patches after it was discovered the original fixes made customer deployments vulnerable …

Tags IT, Log4j, News

The Log4j Issue: Do You Know What is in Your Software?

19 April 2022

This article explores the importance of knowing and documenting the usage of different components in your software. log4j is an open source …

Tags Cyber Threats, Hacking, Issues, Log4j, Softwares

Log4Shell exploitation: Which applications may be targeted next?

5 April 2022

Spring4Shell (CVE-2022-22965) has dominated the information security news these last six days, but Log4Shell (CVE-2021-44228) continues to …

Tags IT, Log4j, Log4Shell, Mandiant, Randori

Log4j Attacks Continue Unabated Against VMware Horizon Servers

30 March 2022

VMware Horizon servers — which many organizations are using to enable secure anywhere, anytime access to enterprise apps for remote …

Tags Attacks, Cloud, Log4j, Servers, VMware Horizon

30% of Apache Log4j Security Holes Remain Unpatched

23 March 2022

According to cloud security company Qualys, only 70% has been patched. “30% of Log4j instances remain vulnerable to exploitation.” This …

Tags Apache, Apache Software Foundation, IT, Log4j, Open Source Software

Darktrace AI Stops Cyberattack Exploiting Log4j Vulnerability at Global Financial Services Provider

23 March 2022

CAMBRIDGE, UK, March 23, 2022 /PRNewswire/ — Darktrace, a global leader in cyber security AI, today announced that a global provider of …

Tags AI, Cyber Attack, Darktrace, Global, Log4j

Shifting Log4j Discovery Right

22 March 2022

You hear a lot about shifting your application security (AppSec) left – in other words, shifting AppSec to the beginning of the software …

Tags Discovery, IT, Log4j, Security Pro, Security Trends

Well done patching Log4j. Now, are you ready for the next zero day disaster?

22 March 2022

If you breathed a sigh of relief after dealing with the Log4j vulnerability last year, here’s some bad news. There are further equally …

Tags IT, Log4j, News, Now
Post navigation
Older posts
Page1 Page2 … Page15 Next →
Cookie-Free

NVD

  • CVE-2022-29662 – CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via …26 May 2022
  • CVE-2022-29687 – CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerabili …26 May 2022
  • CVE-2022-29663 – CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via …26 May 2022
  • CVE-2022-29688 – CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerabili …26 May 2022
  • CVE-2021-42692 – There is a stack-overflow vulnerability in tinytoml v0.4 that can cause a crash or DoS. …26 May 2022
  • CVE-2022-29664 – CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via …26 May 2022

EXPLOITS

  • qdPM 9.1 – Remote Code Execution (RCE) (Authenticated) (v2)26 May 2022
  • m1k1o’s Blog v.10 – Remote Code Execution (RCE) (Authenticated)23 May 2022
  • OpenCart v3.x Newsletter Module – Blind SQLi23 May 2022
  • Showdoc 2.10.3 – Stored Cross-Site Scripting (XSS)17 May 2022
  • SolarView Compact 6.0 – OS Command Injection17 May 2022
  • T-Soft E-Commerce 4 – SQLi (Authenticated)17 May 2022

SECURELIST

  • Managed detection and response in 202126 May 2022
  • The Verizon 2022 DBIR25 May 2022
  • What’s wrong with automotive mobile apps?25 May 2022
  • ISaPWN – research on the security of ISaGRAF Runtime23 May 2022
  • Evaluation of cyber activities and the threat landscape in Ukraine17 May 2022
  • HTML attachments in phishing e-mails16 May 2022

Information Cyber Network Enterprise Security News

Copyright © 2022 GeekWire | Cookie-Free | Privacy Policy | We are not responsible for the content of external sites.

GeekWire Information Cyber Network Enterprise Security News

Next Page »