A year ago, a zero-day vulnerability shook the cybersecurity world. Almost 12 months later, it seems we still haven't learned our lesson.
The zero-day bug, also known as CVE-2021-44228, was discovered in Apache Log4j, which is a Java-based logging utility. The role of the Log4j Java library is to record information that helps applications run smoothly, determine what is happening, and aid in the debugging process when errors occur. The zero-day allowed hackers to remotely gain access and take control of machines and servers.
See also: Microsoft fixes zero-day that introduces malware via ISO files

a huge concern , as Log4j was and remains integrated into a huge range of applications, services, and software tools written in Java.
The huge range of applications was also the reason for the high risk of this zero-day vulnerability. Thus, NIST (National Institute of Standards and Technology) gave Log4j a score of 10 on the CVSS (Common Vulnerability Scoring System), making it extremely serious.
It didn't take more than a few hours for hackers to exploit the situation. Jen Easterly, director of the CISA (Cybersecurity and Infrastructure Security Agency), described this zero-day vulnerability as perhaps the most serious she has ever seen in her career , as millions of users were affected.
Security updates and mitigations were released quickly, but a year after the initial disclosure, Log4j still poses a threat because many organizations and their vendors have yet to implement the updates.
See also: New CryWiper malware appears to be ransomware

Hacking groups , ransomware groups, and nation-state - sponsored cyber-espionage operations have been actively targeting Log4j vulnerabilities and continue to do so. Last month, the FBI and CISA advised organizations that if they haven’t patched the Log4J vulnerabilities, they should assume their network has been compromised and act accordingly. This means organizations can’t just ignore the vulnerabilities and hope for the best. Fixing the problems is certainly a challenge , but ensuring network security is absolutely essential . Source: zdnet.com
