当前位置:网站首页>The "nuclear bomb level" log4j vulnerability is still widespread and has a continuing impact
The "nuclear bomb level" log4j vulnerability is still widespread and has a continuing impact
2022-07-26 16:13:00 【Program ape DD_】

Produce :OSCHINA, edit : Boiled water without sugar
source :https://www.oschina.net/news/203874/log4j-the-pain-just-keeps-going-and-going
Log4j “ Nuclear grade ” Loophole Log4Shell May affect the world forever .
Department of homeland security (DHS) Network Security Review Committee (CSRB) Recently released for last year Log4Shell Vulnerability Investigation Report :
https://www.cisa.gov/sites/default/files/publications/CSRB-Report-on-Log4-July-11-2022_508.pdf
CSRB This year 2 The month is only by DHS Established institution , Responsibility is to investigate major network security incidents , And provide a report containing recommendations to improve National Cybersecurity .CSRB The first incident investigated was last year Log4j Explosive “ Nuclear grade ” Loophole .

According to the report , Although there is no indication that due to Log4j Vulnerabilities and major network attacks , But it will still be “ Be used in the next few years ”. Deputy Secretary of Homeland Security Rob Silvers Also said :“Log4j Vulnerability is one of the most serious software vulnerabilities in history .”
CSRB The board mentioned , It's amazing ,Log4j The degree of vulnerability utilization is lower than experts' expectation . They also said , At present, there is no significant... For key infrastructure systems Log4j attack , But there are some cyber attacks that are not mentioned in the report .
The board said , Future attacks are likely to be largely due to Log4j Often embedded in other software , Due to indirect dependence, it is difficult for enterprises to find running in their systems . They lighten Log4j The impact of vulnerabilities and the overall improvement of network security put forward some suggestions , This includes advising universities and community colleges to make cybersecurity training an integral part of their computer science degree and certification programs .
according to sonatype Statistical data (https://www.sonatype.com/resources/log4j-vulnerability-resource-center), stay Maven Central On , Vulnerable every working day Log4j There are still more than 100,000 Number of downloads per time .

Finally, ask : Yours Log4j Has the vulnerability been fixed ? Let's talk in the message area
We have created a high-quality technical exchange group , With good people , I will be excellent myself , hurriedly Click Add group , Enjoy growing up together . in addition , If you want to change jobs recently , Years ago, I spent 2 A wave of large factory classics were collected in a week , Those who are ready to change jobs after the festival can Click here to get !
Recommended reading
Sentinel vs Hystrix Current limiting comparison , How to choose ?
Spring Batch processing framework in family bucket , Really strong !
··································
Hello , I'm a procedural ape DD,10 Old driver developed in 、 Alibaba cloud MVP、 Tencent cloud TVP、 I have published books and started a business 、 State-owned enterprises 4 In the Internet 6 year . From ordinary developers to architects 、 Then to the partner . Come all the way , My deepest feeling is that I must keep learning and pay attention to the frontier . As long as you can hold on , Think more 、 Don't complain 、 Do it frequently , It's easy to overtake on a curve ! therefore , Don't ask me what I'm doing now, whether it's in time . If you are optimistic about one thing , It must be persistence to see hope , Instead of sticking to it when you see hope . believe me , Just stick to it , You must be better than now ! If you don't have any direction , You can pay attention to me first , Some cutting-edge information is often shared here , Help you accumulate the capital to overtake on the curve .
边栏推荐
- 理解卷积神经网络中的权值共享
- 初识OpenGL (4)链接着色器
- German EMG electric actuator eb800-60ii
- 山西阳泉一煤矿发生致1人死亡安全事故,被责令停产整顿
- Bugku login1
- Development and implementation of campus epidemic prevention and control management system based on SSM
- 潘多拉 IOT 开发板学习(RT-Thread)—— 实验17 ESP8266 实验(学习笔记)
- 基于SSM实现个性化健康饮食推荐系统
- 中金财富炒股安全吗 手续费最便宜的证券公司
- hawe螺旋插装式单向阀RK4
猜你喜欢

SQL statement -- single line comment and multi line comment

This article explains in detail the discovery and processing of bigkey and hotkey in redis

潘多拉 IOT 开发板学习(RT-Thread)—— 实验17 ESP8266 实验(学习笔记)

马斯克被曝绿了谷歌创始人:导致挚友二婚破裂,曾下跪求原谅

【物理模拟】最简单的shape matching的原理与实践

Google Earth Engine——MERRA-2 M2T1NXSLV:1980-至今全球压力、温度、风等数据集

bucher齿轮泵QX81-400R301

我们被一个 kong 的性能 bug 折腾了一个通宵

DELTA控制器RMC200

【ARM学习(9) arm 编译器了解学习(armcc/armclang)】
随机推荐
Google Earth engine - merra-2 m2t1nxaer: aerosol daily data set from 1980 to 2022
Specific practice cases of "card note taking method" in Siyuan
SAP ABAP Netweaver 容器化的一些前沿性研究工作分享
CAD进阶练习题(一)
御神楽的学习记录之SoC FPGA的第一个工程-Hello World
Development daily summary (11): file upload function improvement: Chinese character detection and text content processing
初识OpenGL (3)片段着色器(Fragment Shader)
Jmeter快速上手之接口测试
[RCTF2015]EasySQL
Robot hand eye calibration ax=xb (eye to hand and eye in hand) and plane nine point calibration
2022 what is your sense of security? Volvo asked in the middle of the year
First knowledge of OpenGL (2) compilation shaders
[physical simulation] the principle and practice of the simplest shape matching
Bucher gear pump qx81-400r301
Is it safe for Guoyuan futures to open an account online? What is the account opening process?
ZABBIX 6.2.0 deployment
Operating system migration practice: deploying MySQL database on openeuler
My brother created his own AI anti procrastination system, and he was "blinded" when playing with his mobile phone | reddit was hot
Mapwithstate of spark streaming state flow
想让照片中的云飘起来?视频编辑服务一键动效3步就能实现