Internet Is At Greater Risk Due To 2nd Severe Bug, Which Was Patched

Internet is at greater risk due to 2nd severe bug, which was patched

New Delhi, Dec 15 : As the Internet faces one of the most serious vulnerabilities in recent years putting millions of devices at hacking risk, attackers are now making thousands of attempts to exploit a second vulnerability involving a Java logging system called ‘Apache log4j2’.

 Internet Is At Greater Risk Due To 2nd Severe Bug, Which Was Patched-TeluguStop.com

The description of the new vulnerability, titled ‘CVE 2021-45046’, says the fix to address the earlier security bug (CVE-2021-44228) in ‘Apache Log4j 2.15.0’ was “incomplete in certain non-default configurations”.

“It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations.

“This could allow attackers.to craft malicious input data using a JNDI Lookup pattern resulting in a denial of service (DOS) attack,” the CVE description read.

Several popular services, including Apple iCloud, Amazon, Twitter, Cloudflare and Minecraft, are vulnerable to the ‘ubiquitous’ zero-day exploit.

Apache has now released a new security patch to address the second bug.

‘Apache Log4j’ is used in many forms of enterprise and open-source software, including cloud platforms, web applications and email services.

It is the most popular java logging library with over 400,000 downloads from its GitHub project.It is used by a vast number of companies worldwide, enabling logging in a wide set of popular applications.

“Exploiting this vulnerability is simple and allows threat actors to control java-based web servers and launch remote code execution attacks,” cyber security researchers at Check Point had said in a blog post.Another cyber security company Sophos said that it is already detecting malicious cryptominer operations attempting to leverage the vulnerability, and there are credible reports from other sources that several automated botnets (such as Mirai, Tsunami, and Kinsing) have begun to exploit it as well.

At present, most of the attacks focus on the use of cryptocurrency mining at the expense of the victims.However, under the auspices of the noise, more advanced attackers may act aggressively against quality targets.

Researchers at Microsoft have also warned about attacks attempting to take advantage of ‘Log4j’ vulnerabilities, including a range of crypto-mining malware.
na/vd

Internet faces greater risk as 2nd serious bug found, patch released

Check Point cyber security researchers stated in a blog that exploiting this vulnerability allows for threat actors to take control of java-based web servers, launch remote code execution attacks and more,” they wrote.
Sophos, another cyber security firm, stated that they are already finding malicious cryptominer operations trying to exploit the vulnerability.There are also credible reports that other automated botnets, such as Mirai and Tsunami have started to exploit it.

Currently, the majority of attacks are focused on cryptocurrency mining to the detriment of victims.But, advanced attackers could act aggressively on quality targets, while the noise may lead to more sophisticated attacks.

Microsoft researchers have warned of attacks that could exploit the ‘Log4j” vulnerabilities.This includes a variety of crypto-mining malware.

#greater #severe #patched #Delhi #Delhi #New Delhi #Apple #Amazon #Microsoft #Twitter #Cloud # Java #Cloudflare #GitHub #ICloud

.

Disclaimer : TeluguStop.com Editorial Team not involved in creation of this article & holds no responsibility for its content..This Article is Provided by IANS, Please contact IANS if any issues in Article .


Follow Us on Facebook Follow Us on WhatsApp Follow Us on Twitter