LOG4SHELL WILL HAVE A LASTING RIPPLE EFFECT S
ecurity teams must stay vigilant in the days and weeks ahead because state-sponsored actors such as China and Iran and other bad actors are lurking, just waiting to exploit Log4j to launch broader attacks. What’s the big deal, some may ask? Log4j operates as an open-source Java logging library that’s widely used in a range of software applications and services around the world. The vulnerability in Log4j can allow threat actors the opportunity to take control of any Java-based, internetfacing server and engage in remote code execution (RCE) attacks. The problem with Log4j is how the Java Naming and Directory Interface (JNDI) can “lookup” commands and how they are
17
VOL 22
ISSUE 2
CEO GLOBAL MAGAZINE.COM