HomeSecurityDutch cybersecurity agency warns of lingering Log4j risks

Dutch cybersecurity agency warns of lingering Log4j risks

In a warning issued on Thursday, the Dutch National Cyber Security Centre (NCSC) says that organisations should continue to be aware of the risks associated with Log4j attacks and remain vigilant for ongoing threats.

See also: State-sponsored hackers attack Log4j via new PowerShell backdoor

Log4j

Although the echo of recent incidents linked to the exploitation of Log4Shell was not “very bad” because many organisations have acted quickly to mitigate these critical vulnerabilities, the NCSC says that threat actors are likely still planning to breach new targets.

Log4j vulnerabilities (including Log4Shell) are a very attractive attack vector both for financially motivated intruders and for state‑supported attackers, given that the open‑source Apache Log4j logging library is used in a wide range of systems from dozens of vendors.

See also: Aquatic Panda team infiltrated an academic institution via Log4j

Log4Shell can be exploited remotely on servers that are exposed to local access or internet access to allow attackers to move laterally through a network until they reach sensitive internal systems.

After its disclosure, many threat actors began developing Log4Shell exploits, including hacking groups linked to governments in China, Iran, North Korea, and Turkey, and they have access to brokers used by ransomware gangs.

Log4j

Log4j is still under active exploitation

The NCSC warning is timely, as multiple alerts about ongoing Log4j exploitation worldwide have been issued by governmental and private organizations worldwide.

For example, a report published by Microsoft on Wednesday reports attempts by unknown threat actors to spread Log4j attacks to an organization's internal LDAP servers by exploiting a SolarWinds Serv-U zero-day.

However, the attacks failed because the Windows domain controllers targeted in the incident were not vulnerable to Log4j exploits.

See also: CISA: Apache Log4j scanner released to detect vulnerable apps

A week earlier, Microsoft warned of a Chinese threat actor referred to as DEV-0401 using Log4Shell exploits on VMware Horizon servers exposed to the Internet to deploy the Night Sky ransomware.

Microsoft's reports had preceded another notice issued by the United Kingdom's National Health Service (NHS) on January 5 regarding attackers targeting VMware Horizon systems with Log4Shell exploits.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS