Skip to content
GeekWire
  • HOME
  • NEWS
    • CERT
    • EXPLOITS
    • NCSC
    • NVD
    • SECURELIST
    • US-CERT
  • BLOG
    • Books
    • OSINT
    • Pentest
    • Privacy
  • GHDB
  • CHDB
  • OSINT
  • LABS
  • ARCHIVE
  • ABOUT
    • Privacy Policy
    • Terms of Use
    • External Links
    • Sitemap
GeekWire
GeekWire
  • HOME
  • NEWS
    • CERT
    • EXPLOITS
    • NCSC
    • NVD
    • SECURELIST
    • US-CERT
  • BLOG
    • Books
    • OSINT
    • Pentest
    • Privacy
  • GHDB
  • CHDB
  • OSINT
  • LABS
  • ARCHIVE
  • ABOUT
    • Privacy Policy
    • Terms of Use
    • External Links
    • Sitemap

Log4Shell

Log4Shell Still Has Sting In The Tail

28 December 2022

The December holiday plans of IT workers were thrown into disarray last year after the disclosure of a major bug in the widely-used Log4j …

Tags IT, Log4j, Log4Shell, Sting, Tail

Log4Shell remains a big threat and a common cause for security breaches

28 December 2022

The Log4Shell critical vulnerability that impacted millions of enterprise applications remains a common cause for security breaches a year …

Tags IT, Log4Shell, News

Log4j’s Log4Shell Vulnerability: One Year Later, It’s Still Lurking

10 December 2022

Many critical vulnerabilities get discovered every year that are of high urgency to address, but Log4Shell was unusual because it was so …

Tags Log4Shell, One, Security Pro, Vulnerability, Year

Researchers Uncover New Drokbk Malware that Uses GitHub as a Dead Drop Resolver

9 December 2022

The subgroup of an Iranian nation-state group known as Nemesis Kitten has been attributed as behind a previously undocumented custom …

Tags Dead, Drop, Iranian Hackers, Log4Shell, Malware

Log4Shell Lives!

6 December 2022

It has been about a year since the security hole at the heart of the open source Java logging library Apache Log4j was revealed. The …

Tags IT, Log4Shell, News, Open Source, Open Source Software

Week in review: Log4Shell lingers, NIS2 directive adopted, LastPass breached (again)

4 December 2022

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: The top 200 most common passwords in …

Tags IT, LastPass, Log4Shell, News, Week

One Year After Log4Shell, Most Firms Are Still Exposed to Attack

1 December 2022

Though there have been fewer than expected publicly reported attacks involving the vulnerability, nearly three-quarters of organizations …

Tags After, Attacks, Exposed, Log4Shell, One

A year later, Log4Shell still lingers

1 December 2022

72% of organizations remain vulnerable to the Log4Shell vulnerability as of October 1, 2022, Tenable‘s latest telemetry study has …

Tags IT, Log4j, Log4Shell, News, Tenable

Iranian Hackers Compromised a U.S. Federal Agency’s Network Using Log4Shell Exploit

17 November 2022

Iranian government-sponsored threat actors have been blamed for compromising a U.S. federal agency by taking advantage of the Log4Shell …

Tags CISA, Federal, Iranian Hackers, IT, Log4Shell

Hackers Started Exploiting Critical “Text4Shell” Apache Commons Text Vulnerability

21 October 2022

WordPress security company Wordfence on Thursday said it started detecting exploitation attempts targeting the newly disclosed flaw in …

Tags Apache, Critical, Cyber Threats, Hacking, Log4Shell

Apache Commons Text Flaw Not a Repeat of Log4Shell

21 October 2022

A freshly fixed flaw (CVE-2022-42889) in the Apache Commons Text library has been getting attention from security researchers these last …

Tags Apache, Apache Software Foundation, Flaws, IT, Log4Shell

Presentation: Securing Java Applications in the Age of Log4Shell

20 October 2022

Transcript Maple: My name is Simon …

Tags Age, Application, Development, IT, Log4Shell

Apache Commons Text flaw is not a repeat of Log4Shell (CVE-2022-42889)

19 October 2022

A freshly fixed vulnerability (CVE-2022-42889) in the Apache Commons Text library has been getting attention from security researchers …

Tags Apache, Apache Commons, Apache Software Foundation, Log4Shell, Texts

Dangerous hole in Apache Commons Text – like Log4Shell all over again

18 October 2022

Java programmers love string interpolation features. If you’re not a coder, you’re probably confused by the word “interpolation” …

Tags Apache, Apache Commons, Log4j, Log4Shell, Texts
Older posts
Page1 Page2 … Page6 Next →
Cookie-Free

NVD

  • CVE-2023-1753 – Weak Password Requirements in GitHub repository thorsten/phpmyfaq prior to 3.1.12. …31 March 2023
  • CVE-2023-1747 – A vulnerability has been found in IBOS up to 4.5.4 and classified as critical. Affected by …31 March 2023
  • CVE-2023-1754 – Improper Input Validation in GitHub repository thorsten/phpmyfaq prior to 3.1.12. …31 March 2023
  • CVE-2023-28727 – Panasonic AiSEG2 versions 2.00J through 2.93A allows adjacent attackers bypass authenticat …31 March 2023
  • CVE-2023-1759 – Cross-site Scripting (XSS) – Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.12 …31 March 2023
  • CVE-2023-1760 – Cross-site Scripting (XSS) – Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.12 …31 March 2023

EXPLOITS

  • Judging Management System v1.0 – Remote Code Execution (RCE)31 March 2023
  • Bludit 3-14-1 Plugin ‘UploadPlugin’ – Remote Code Execution (RCE) (Authenticated)31 March 2023
  • rconfig 3.9.7 – Sql Injection (Authenticated)31 March 2023
  • Spitfire CMS 1.0.475 – PHP Object Injection31 March 2023
  • Senayan Library Management System v9.0.0 – SQL Injection31 March 2023
  • EQ Enterprise management system v2.2.0 – SQL Injection31 March 2023

SECURELIST

  • Selecting the right MSSP: Guidelines for making an objective decision30 March 2023
  • Financial cyberthreats in 202229 March 2023
  • Copy-paste heist or clipboard-injector attacks on cryptousers28 March 2023
  • How scammers employ IPFS for email phishing27 March 2023
  • Understanding metrics to measure SOC effectiveness24 March 2023
  • Developing an incident response playbook23 March 2023
Copyright © 2023 GeekWire | Cookie-Free | Privacy Policy | We are not responsible for the content of external sites.
Next Page »