Log4Shell is still an exploited vulnerability

It seems a long time ago that the Log4Shell vulnerability was discovered. A vulnerability that had far reaching consequences as many systems used this framework for their logging functionality.

The US Cybersecurity and Infrastructure Security Agency(CISA) with the United States Coast Guard Cyber Command (CGCYBER) has issued an advisory of exploits associated with Log4Shell and the equally popular VMware Horizon Systems – with a warning to treat all systems as compromised unless checked and patched. The advisory contains technical information to assist sysadmins manage the issue.

Malicious Cyber Actors Continue to Exploit Log4Shell in VMware Horizon Systems | CISA

My advice: Either you or your IT support need to check whether these issues impact your systems. You need to have a master document that details your systems, hardware, software, online, networks, back-ups, suppliers etc – so when cyber security (or operational) issues arise you and your support teams can quickly check if you are affected. From there you can take fast, effective action.

Further Reading

Log4j and Log4Shell posts at Smart Thinking Solutions

Log4Shell – Wikipedia