Cybersecurity experts have identified a security flaw in Log4j, a Java library for logging error messages in applications, which could allow hackers unfettered access to corporate computer systems. This discovery has prompted urgent warnings from both America’s Cybersecurity and Infrastructure Security Agency and the UK’s National Cyber Security Center. According to NCSC, an application is vulnerable “if it consumes untrusted user input and passes this to a vulnerable version of the Log4j logging library.”
What You Can Do
Identify internet-facing devices running Log4j and upgrade them to version 2.15.0, or apply the mitigations provided by vendors ASAP. Also, set up alerts for probes or attacks on devices running Log4j. Vendors with popular products known to be still vulnerable include […]