In case anyone missed all the action today:
Log4Shell’ vulnerability poses critical threat to applications using ‘ubiquitous’ Java logging packa...and here Exploiting JNDI Injections in Java
Have a nice weekend...
@csjohnng Like everyone else, it appears that Alibaba, didn't disclose it to the Chinese Government first, which apparently they were meant to do before it went public!! We can guess what would have happened, if the Chinese Government had been informed and then decided to use it against everyone else.
Unfortunately the North Korean hacking teams are probably making hay while they can and using for their own nefarious purposes too.
Best to keep an eye on what is going on, more exploits being created and reported upon even as we liaise.
Lets hope it is a quiet Christmas, but unfortunately, I don't think that will be the case.
And just as predicted Conti and ransomware exploiters are now using it:
Regards
Caute_Cautim