infotechlead
infotechlead

Warning issued on Java-based library known as Log4j

The BSI, Germany’s federal cybersecurity regulator, has issued a red alert warning on a flawed piece of widely-used software as it posed an extremely critical threat to web servers.
Cybersecurity for CSOs
A vulnerability in a Java-based library known as Log4j can be exploited to allow a complete takeover of the affected system, the BSI said in a statement on its website.

“The reason for this assessment is the very wide distribution of the affected product and the associated impact on countless other products. The vulnerability is easily exploitable, and a proof-of-concept is publicly available,” the BSI said.

“The BSI is aware of world- and Germany-wide mass scans as well as attempted compromises. Initial successful compromises are also being publicly reported,” BSI added.

The BSI said that although there was a security update for Log4j all products using it also needed to be adapted, recommending that companies and organizations implemented the measures outlined in the cyber security warning.

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Latest

More like this
Related

Black Friday Shoppers Warned as Over 2,000 Fake Online Stores Target Holiday Buyers

Online shoppers hunting for Black Friday deals are being...

Cybersecurity Burnout Intensifies in 2025 as Rising Threat Activity Pushes Teams to the Breaking Point

Cyber security major Sophos reports that burnout among cybersecurity...

Palo Alto Networks to Acquire Chronosphere for $3.35 bn, Expands AI and Observability Leadership

Palo Alto Networks is set to acquire Chronosphere for...