The Apache Log4j logging library is a free Java tool that is used by many programs to log information. It was recently discovered that it has a zero-day security vulnerability that is easy to exploit. An attacker could cause the tool to log a specific message that can take over the entire host system. The new vulnerability has been identified and tracked as CVE-2021-44228 .
Read more: HIPAA compliant email: The definitive guide
Since log4j is commonly used, it could cause widespread damage. Hackers can use the zero-day vulnerability to take over devices and services that are running software like iCloud or Twitter.
Unfortunately, hackers had an entire week's headstart to exploiting the vulnerability before it was publicly disclosed. Recent reports show that hackers are already targeting Windows users and attempting to install Khonsari ransomware and a remote access Trojan called Orcus.
"We are taking urgent action to drive mitigation of this vulnerability and detect any associated threat activity," said Jen Easterly, Director of the Cybersecurity and Infrastructure Security Agency (CISA) in a statement . "To be clear, this vulnerability poses a severe risk. We will only minimize potential impacts through collaborative efforts between government and the private sector."