This on-demand webinar explains how an SBOM-powered approach helps go from discovering a new vuln to creating a remediation list in minutes. https://go.anchore.com/rapid-incident-response-with-sboms/ #SBOM
This on-demand webinar explains how an SBOM-powered approach helps go from discovering a new vuln to creating a remediation list in minutes. https://go.anchore.com/rapid-incident-response-with-sboms/ #SBOM
テスラの pool-ntp.tesla.com をめぐる Assetnote のスキャニングにより、NTPプールの参加サーバーへ多数の攻撃トラフィックが集中していることが発覚。攻撃はSSRFやLog4Shellなど多様な脆弱性を狙い、Host Referer に Tesla 関連以外の第三者ドメインも混ざっており、着信元は AWS の複数IP(主に 54.165.75.96、35.168.63.24、52.44.200.251)である。投稿者は tesla へ通知済みで、今後も被害は続く可能性があると報告している。
テスラの pool-ntp.tesla.com をめぐる Assetnote のスキャニングにより、NTPプールの参加サーバーへ多数の攻撃トラフィックが集中していることが発覚。攻撃はSSRFやLog4Shellなど多様な脆弱性を狙い、Host Referer に Tesla 関連以外の第三者ドメインも混ざっており、着信元は AWS の複数IP(主に 54.165.75.96、35.168.63.24、52.44.200.251)である。投稿者は tesla へ通知済みで、今後も被害は続く可能性があると報告している。
https://malwareintel.es/blog/vulnerabilidades/?utm_source=bluesky&utm_medium=social&utm_campaign=infografia-sept
https://malwareintel.es/blog/vulnerabilidades/?utm_source=bluesky&utm_medium=social&utm_campaign=infografia-sept
Log4Shell exposed a hard truth: without an SBOM, teams may not know what's actually in their software.
#hackernews #news
Log4Shell exposed a hard truth: without an SBOM, teams may not know what's actually in their software.
#hackernews #news
Minecraft Honeypot for Log4j exploit. CVE-2021-44228 Log4Shell LogJam
#go
Minecraft Honeypot for Log4j exploit. CVE-2021-44228 Log4Shell LogJam
#go
A new potential remote code execution vulnerability in Apache Log4J 2 has been reported, with proofs-of-concept now circulating. Given Log4J's notorious history with the Log4Shell vulnerability, this discovery is being taken seriously, and the IFIN team is
A new potential remote code execution vulnerability in Apache Log4J 2 has been reported, with proofs-of-concept now circulating. Given Log4J's notorious history with the Log4Shell vulnerability, this discovery is being taken seriously, and the IFIN team is
Two answers fit this physics. Ship continuously in public: Chrome ships two security releases a week, the kernel defers fixes at most seven days. And put protocol layer mitigations live while the real fix lands. Cloudflare did that for Log4shell in 2021.
Two answers fit this physics. Ship continuously in public: Chrome ships two security releases a week, the kernel defers fixes at most seven days. And put protocol layer mitigations live while the real fix lands. Cloudflare did that for Log4shell in 2021.
#Cybersecurity #InfoSec #CVE #Vulnerability #Security #CyberAttack #Exploit #Malware #Ransomware
x.com/RFGroenewoud...
x.com/RFGroenewoud...
Our public At The Edge one-pager is attached. Customers get the full weekly brief.
🔗 www.greynoise.io/resources/at...
Our public At The Edge one-pager is attached. Customers get the full weekly brief.
🔗 www.greynoise.io/resources/at...
Roughly three fifths of the traffic carrying the Log4Shell exploitation tag came from one commercial vulnerability management service, so a […]
[Original post on infosec.exchange]
Roughly three fifths of the traffic carrying the Log4Shell exploitation tag came from one commercial vulnerability management service, so a […]
[Original post on infosec.exchange]
www.cyberkendra.com/2026/08/log4...
#infosec #apache #log4j
www.cyberkendra.com/2026/08/log4...
#infosec #apache #log4j
#Log4j #RCE #CyberSecurity #Deserialization #Infosec
#Log4j #RCE #CyberSecurity #Deserialization #Infosec
That CVE is still in mods from 2021.
AI assistants might generate new mods with the same vulnerable dependency.
That CVE is still in mods from 2021.
AI assistants might generate new mods with the same vulnerable dependency.
Minecraft Honeypot for Log4j exploit. CVE-2021-44228 Log4Shell LogJam
#go
Minecraft Honeypot for Log4j exploit. CVE-2021-44228 Log4Shell LogJam
#go
Eine SBOM ist ein Inventar, keine Verteidigung. Sie zu erzeugen hätte Log4Shell nicht gestoppt. Was schon: kontinuierliche CVE-Korrelation, signierte Provenance und VEX gegen den Lärm. Ein praktisc…
#sbom #softwaresupplychain #log4j
Eine SBOM ist ein Inventar, keine Verteidigung. Sie zu erzeugen hätte Log4Shell nicht gestoppt. Was schon: kontinuierliche CVE-Korrelation, signierte Provenance und VEX gegen den Lärm. Ein praktisc…
#sbom #softwaresupplychain #log4j