Last week, if you're not yet aware, a vulnerability was found in Log4j, an open-source logging library commonly used by apps and services across the internet. If left unfixed, attackers can break into systems, steal passwords and logins, extract data, and infect networks with malicious software. This library is being used in all kinds of enterprise and open-source software. In short, its something major that could take down huge portions of the internet and other connected networks and devices.
Log4j is used worldwide across software applications and online services, and the vulnerability requires very little expertise to exploit. This makes Log4shell potentially the most severe computer vulnerability in years. This issue could allow hackers to take control of any Java-based web servers and launch remote-code execution attacks, which could give them control of the computer servers. That could open up a host of security-compromising possibilities.
Patches were deployed quickly, however more vulnerabilities have since been found and so, even if you think you've responded to this already, the chances are there are more fixes to come, and more vulnerabilities discovered. Microsoft stated on Tuesday that international hacking groups have already been exploiting the vulnerabilities and that can only mean Ransomware attacks down the line.
So the upshot is that you need to consider how this affects you and your estate. If you're a Simplify IT customer you will or already have received an alert asking you to get in touch so we can take action. If you're not a Simplify IT customer, now is a very good time to begin.
Part of Simplify Technology Group Ltd