当前位置:网站首页>The "nuclear bomb level" log4j vulnerability is still widespread and has a continuing impact
The "nuclear bomb level" log4j vulnerability is still widespread and has a continuing impact
2022-07-26 16:13:00 【Program ape DD_】

Produce :OSCHINA, edit : Boiled water without sugar
source :https://www.oschina.net/news/203874/log4j-the-pain-just-keeps-going-and-going
Log4j “ Nuclear grade ” Loophole Log4Shell May affect the world forever .
Department of homeland security (DHS) Network Security Review Committee (CSRB) Recently released for last year Log4Shell Vulnerability Investigation Report :
https://www.cisa.gov/sites/default/files/publications/CSRB-Report-on-Log4-July-11-2022_508.pdf
CSRB This year 2 The month is only by DHS Established institution , Responsibility is to investigate major network security incidents , And provide a report containing recommendations to improve National Cybersecurity .CSRB The first incident investigated was last year Log4j Explosive “ Nuclear grade ” Loophole .

According to the report , Although there is no indication that due to Log4j Vulnerabilities and major network attacks , But it will still be “ Be used in the next few years ”. Deputy Secretary of Homeland Security Rob Silvers Also said :“Log4j Vulnerability is one of the most serious software vulnerabilities in history .”
CSRB The board mentioned , It's amazing ,Log4j The degree of vulnerability utilization is lower than experts' expectation . They also said , At present, there is no significant... For key infrastructure systems Log4j attack , But there are some cyber attacks that are not mentioned in the report .
The board said , Future attacks are likely to be largely due to Log4j Often embedded in other software , Due to indirect dependence, it is difficult for enterprises to find running in their systems . They lighten Log4j The impact of vulnerabilities and the overall improvement of network security put forward some suggestions , This includes advising universities and community colleges to make cybersecurity training an integral part of their computer science degree and certification programs .
according to sonatype Statistical data (https://www.sonatype.com/resources/log4j-vulnerability-resource-center), stay Maven Central On , Vulnerable every working day Log4j There are still more than 100,000 Number of downloads per time .

Finally, ask : Yours Log4j Has the vulnerability been fixed ? Let's talk in the message area
We have created a high-quality technical exchange group , With good people , I will be excellent myself , hurriedly Click Add group , Enjoy growing up together . in addition , If you want to change jobs recently , Years ago, I spent 2 A wave of large factory classics were collected in a week , Those who are ready to change jobs after the festival can Click here to get !
Recommended reading
Sentinel vs Hystrix Current limiting comparison , How to choose ?
Spring Batch processing framework in family bucket , Really strong !
··································
Hello , I'm a procedural ape DD,10 Old driver developed in 、 Alibaba cloud MVP、 Tencent cloud TVP、 I have published books and started a business 、 State-owned enterprises 4 In the Internet 6 year . From ordinary developers to architects 、 Then to the partner . Come all the way , My deepest feeling is that I must keep learning and pay attention to the frontier . As long as you can hold on , Think more 、 Don't complain 、 Do it frequently , It's easy to overtake on a curve ! therefore , Don't ask me what I'm doing now, whether it's in time . If you are optimistic about one thing , It must be persistence to see hope , Instead of sticking to it when you see hope . believe me , Just stick to it , You must be better than now ! If you don't have any direction , You can pay attention to me first , Some cutting-edge information is often shared here , Help you accumulate the capital to overtake on the curve .
边栏推荐
- A coal mine in Yangquan, Shanxi Province, suffered a safety accident that killed one person and was ordered to stop production for rectification
- Google Earth engine - merra-2 m2t1nxaer: aerosol daily data set from 1980 to 2022
- TKE集群节点max-pod是如何配置的
- First knowledge of OpenGL (4) link shader
- 物联网工业级串口转WiFi转网口转以太网模块的选型
- 哪本书才是编程领域的“九阴真经”
- 初识OpenGL (3)片段着色器(Fragment Shader)
- 德国emg电动执行器EB800-60II
- 御神楽的学习记录之SoC FPGA的第一个工程-Hello World
- hawe螺旋插装式单向阀RK4
猜你喜欢
![[ten thousand words long text] Based on LSM tree thought Net 6.0 C # realize kV database (case version)](/img/84/640de0bf779cd45498204909be56d1.png)
[ten thousand words long text] Based on LSM tree thought Net 6.0 C # realize kV database (case version)

Test cases should never be used casually, recording the thinking caused by the exception of a test case

German EMG electric actuator eb800-60ii
FTP protocol

德国emg电动执行器EB800-60II

A comprehensive review of image enhancement technology in deep learning

PAT甲级 1046 Shortest Distance

基于SSM开发实现校园疫情防控管理系统

博途PLC顺序开关机功能块(SCL)

Understand │ XSS attack, SQL injection, CSRF attack, DDoS attack, DNS hijacking
随机推荐
Advanced CAD exercises (I)
This article explains in detail the discovery and processing of bigkey and hotkey in redis
Jointly discuss the opening of public data, and the "digital document scheme" appeared at the digital China Construction Summit
我们被一个 kong 的性能 bug 折腾了一个通宵
[tool sharing] automatic generation of file directory structure tool mddir
Taishan Office Technology Lecture: the zoom ratio of word is slightly different from the display
FTP协议
《硅谷之谜》读后感
Pat grade a 1044 shopping in Mars
I would like to ask you guys, how to specify the character set of MySQL CDC tables? I can't find the corresponding connector parameters on the official website. I read one
换把人体工学椅,缓解久坐写代码的老腰吧~
基于SSM开发实现校园疫情防控管理系统
泰山OFFICE技术讲座:WORD的缩放比例与显示略有差异
Understand │ XSS attack, SQL injection, CSRF attack, DDoS attack, DNS hijacking
2022 test questions and answers for the latest national fire facility operator (senior fire facility operator)
spark-streaming状态流之mapWithState
A coal mine in Yangquan, Shanxi Province, suffered a safety accident that killed one person and was ordered to stop production for rectification
Pat grade a 1046 shortest distance
机器人手眼标定Ax=xB(eye to hand和eye in hand)及平面九点法标定
一款可视化浏览器历史的 Firefox/Chrome 插件