roydan
Elite Member
- Dec 17, 2013
- 5,618
- 14,572
Just got this email from Wordfence, you should act fast if it concerns you:
I'm taking the unusual step of sending out a quick email alert about a very bad Java vulnerability in log4j. PHP and WordPress are our wheelhouse at Wordfence, but this is so bad, that I'm sending this alert with resources to help our Java friends lock things down fast.
Hopefully, you've all seen this vulnerability in the news already, but in case not, I'm going to link to a collection of resources rather than writing a blog post, because others have already covered this story. If you are developing or running any Java-based web applications, you need to move fast to fix this. It's bad and will have a wide impact.
Move fast, use the links above to get up to speed, and secure your Java applications. This is Javageddon folks. Best of luck.
I'm taking the unusual step of sending out a quick email alert about a very bad Java vulnerability in log4j. PHP and WordPress are our wheelhouse at Wordfence, but this is so bad, that I'm sending this alert with resources to help our Java friends lock things down fast.
Hopefully, you've all seen this vulnerability in the news already, but in case not, I'm going to link to a collection of resources rather than writing a blog post, because others have already covered this story. If you are developing or running any Java-based web applications, you need to move fast to fix this. It's bad and will have a wide impact.
- The vulnerability is officially designated as CVE-2021-44228
- The Apache foundation has released a fix.
- Ars Technica: Zero-day in ubiquitous Log4j tool poses a grave threat to the Internet
- ZDNet: Security warning: New zero-day in the Log4j Java library is already being exploited
- A thread by Marcus Hutchins
- A disorganized list of vulnerable stuff already found.
- A proof of concept, if you're a researcher.
Move fast, use the links above to get up to speed, and secure your Java applications. This is Javageddon folks. Best of luck.