Log4j: Kaspersky registers 30.000 scans for vulnerabilities

Log4j Log4shell

Share post

Although the Apache Foundation released a patch shortly after the discovery of Log4j / Log4Shell, this vulnerability continues to pose a major threat to consumers and businesses. Kaspersky products blocked 30.562 attack attempts in the first three weeks of January.

The vulnerability is extremely attractive to cyber criminals as it is easy to exploit and allows them to take complete control over the victim's system.

Log4j: Kaspersky has already blocked over 150.000 attacks

Since initial reporting, Kaspersky products have detected and blocked 154.098 attempts to scan and attack devices by targeting the Log4Shell vulnerability. Most of the systems attacked were in Russia (13 percent), Brazil (8,97 percent) and the United States (7,36 percent). 3,87 percent of the systems were in Germany, 0,39 percent in Switzerland and 0,29 percent in Austria.

Evgeny Lopatin, security expert at Kaspersky, comments on the situation as follows: “We can see that with Log4Shell there are now fewer scans and attack attempts than in the first few weeks immediately after the discovery. However, attempts to exploit this vulnerability are still being made. Our telemetry shows that cyber criminals continue their extensive mass scanning activities and attempt to exploit the exploit. The vulnerability is used by both advanced threat actors targeting specific organizations and opportunists simply looking for vulnerable systems to attack. We urge everyone who hasn't already done so to install patches and use a strong security solution to protect themselves."

Kaspersky products detect and block attacks via this vulnerability under the following ID:

  • UMIDS: Intrusion.Generic.CVE-2021-44228.
  • PDM: Exploit.Win32.Generic

Kaspersky recommendation for protection

  • Immediately the install latest version of library 2.15.0; this is available on the project page. If the library is used in a third-party product, it should be checked when the software provider will make an update available; this should also be installed immediately.
  • Follow the Apache Log4j project guidelines at https://logging.apache.org/log4j/2.x/security.html.
  • Businesses should use a security solution or service such as Kaspersky Endpoint Detection and Response or Kaspersky Managed Detection and Response Service that can detect and stop attacks in the early stages.
More at Kaspersky.com

 


About Kaspersky

Kaspersky is an international cybersecurity company founded in 1997. Kaspersky's in-depth threat intelligence and security expertise serve as the basis for innovative security solutions and services to protect companies, critical infrastructures, governments and private users worldwide. The company's comprehensive security portfolio includes leading endpoint protection as well as a range of specialized security solutions and services to defend against complex and evolving cyber threats. Kaspersky technologies protect over 400 million users and 250.000 corporate customers. More information about Kaspersky can be found at www.kaspersky.com/


 

Matching articles on the topic

Cybersecurity platform with protection for 5G environments

Cybersecurity specialist Trend Micro unveils its platform-based approach to protecting organizations' ever-expanding attack surface, including securing ➡ Read more

Data manipulation, the underestimated danger

Every year, World Backup Day on March 31st serves as a reminder of the importance of up-to-date and easily accessible backups ➡ Read more

Printers as a security risk

Corporate printer fleets are increasingly becoming a blind spot and pose enormous problems for their efficiency and security. ➡ Read more

The AI ​​Act and its consequences for data protection

With the AI ​​Act, the first law for AI has been approved and gives manufacturers of AI applications between six months and ➡ Read more

Windows operating systems: Almost two million computers at risk

There are no longer any updates for the Windows 7 and 8 operating systems. This means open security gaps and therefore worthwhile and ➡ Read more

AI on Enterprise Storage fights ransomware in real time

NetApp is one of the first to integrate artificial intelligence (AI) and machine learning (ML) directly into primary storage to combat ransomware ➡ Read more

DSPM product suite for Zero Trust Data Security

Data Security Posture Management – ​​DSPM for short – is crucial for companies to ensure cyber resilience against the multitude ➡ Read more

Data encryption: More security on cloud platforms

Online platforms are often the target of cyberattacks, such as Trello recently. 5 tips ensure more effective data encryption in the cloud ➡ Read more