About one in six organizations worldwide affected by the zero-day Spring4Shell vulnerability have already been targeted by threat actors, according to statistics from a cybersecurity firm.

See also: Cash App data breach: Millions of customers affected
The exploitation attempts occurred in the first four days after the disclosure of the serious remote code execution (RCE) flaw, tracked as CVE-2022-22965, and the associated exploit code.
According to Check Point, which compiled the report based on its telemetry data, 37,000 Spring4Shell attacks were detected last weekend alone.

The industry most affected appears to be software vendors, representing 28% of the total, likely due to them being prime candidates for supply chain attacks.
In the first 4 days after the vulnerability was released, 16% of organizations worldwide were affected by exploitation attempts. In terms of the most targeted region, Check Point ranks Europe first with 20%.
See also: US: $34 million in crypto seized from the Dark Web
This suggests that the malicious attempt to exploit existing RCE opportunities against vulnerable systems is ongoing and threat actors appear to be shifting to Spring4Shell while still being able to take advantage of unpatched systems.
Signs of exploit in the US
North America accounts for 11% of Spring4Shell attacks detected by Check Point, and confirmations of active exploitation in the US also come from other entities.
Yesterday, the US Cybersecurity and Infrastructure Security Agency (CISA) added four vulnerabilities to its list of flaws known to be used in real attacks, one of which is Spring4Shell.
More specifically, the service has seen evidence of attacks targeting VMware products, for which the company released security updates and advisories yesterday.
Microsoft has published guidance for detecting and protecting against Spring4Shell attacks and noted that it is already monitoring exploitation attempts.

Protect yourself from Spring4Shell attacks
CVE-2022-22965 affects Spring MVC and Spring WebFlux applications running on JDK 9+, so all Java Spring deployments should be considered as potential attack vectors.
The vendor has released Spring Framework versions 5.3.18 and 5.2.2, as well as Spring Boot 2.5.12, which successfully address the RCE issue. Therefore, there is a strong recommendation to upgrade to these versions or later.
See also: GitHub: Automatically blocks commits containing API keys
Additionally, system administrators should be aware of the remote code execution flaws CVE-2022-22963 and CVE-2022-22947 in Spring Cloud mode and Spring Cloud gateway. Proof-of-concept exploits for these flaws are already available to the public.
Information source: bleepingcomputer.com
