Cybersecurity training institute invites world to help Santa defeat cyber-villains
Hackers Target India’s Prime Minister
Prime Minister Modi’s Twitter account hacked to spread fake Bitcoin message
Log4j CVE-2021-44228
We are fairly confident that we are not vulnerable to the Log4J bug, but we will be releasing an update soon with an updated version of Log4J. Stay tuned.
EDIT: Please download 5.1.4-b2090 for the log4j update as well as a few other libraries.
Ex-NFL Star Gets Three Years for #COVID19 Fraud
Joshua Bellamy falsified information about his company
“Sadistic” Online Extortionist Jailed for 32 Years
Birmingham man forced some victims to the point of suicide
“Worst-Case Scenario” Log4j Exploits Travel the Globe
Log4j vulnerability affects huge sweep of applications and vendors
CVE-2021-44228 – Patching is Recommended for Evolving Zero Day Vulnerability in Apache Log4j that allows remote code execution (RCE)
Akamai has been monitoring the rapidly evolving developments of CVE-2021-44228. We have been working closely with our customers and internal application teams to mitigate the risks posed by the threat of unauthorized remote code execution. This inclu…
CVE-2021-44228 – Zero Day Vulnerability in Apache Log4j that allows remote code execution (RCE)
See how Akamai helped open-source logging library Log4j fight against a critical unauthenticated remote code execution (RCE) vulnerability and reduce customer exposure.
modsecurity rule to filter CVE-2021-44228/LogJam/Log4Shell [update]
As a fast workaround, a friend of mine made a modsecurity rule to filter CVE-2021-44228/LogJam/Log4Shell, which he allowed me to share with you. SecRule \ ARGS|REQUEST_HEADERS|REQUEST_URI|REQUEST_BODY|REQUEST_COOKIES|REQUEST_LINE|QUERY_STRING “jndi:ldap:” \ “phase:1, \ id:751001, \ t:none, \ deny, \ status:403, \ log, \ auditlog, \ msg:’Block: CVE-2021-44228 – deny pattern \”jndi:ldap:\”‘, \ severity:’5’, \ rev:1, \ tag:’no_ar'” New […]
The post modsecurity rule to filter CVE-2021-44228/LogJam/Log4Shell [update] first appeared on Robert Penz Blog.
Cyber-Attack on Hellmann Worldwide Logistics
German logistics firm unable to rule out data leakages or unauthorized use of data