New zero-day exploit for Log4j Java library is an enterprise nightmare
ALPHV BlackCat – This year’s most sophisticated ransomware
Volvo Cars discloses security breach leading to R&D data theft
Massive attack against 1.6 million WordPress sites underway
Microsoft: These are the building blocks of QBot malware attacks
Amazon explains the cause behind Tuesday’s massive AWS outage
Want to become a networking expert? Try this $69 Cisco course bundle
Researchers release ‘vaccine’ for critical Log4Shell vulnerability
Qualys BrowserCheck
STOPDecrypter
AuroraDecrypter
FilesLockerDecrypter
AdwCleaner
ComboFix
RKill
Junkware Removal Tool
How to remove the PBlock+ adware browser extension
Remove the Toksearches.xyz Search Redirect
Remove the Smashapps.net Search Redirect
Remove the Smashappsearch.com Search Redirect
Remove Security Tool and SecurityTool (Uninstall Guide)
How to remove Antivirus 2009 (Uninstall Instructions)
How to Remove WinFixer / Virtumonde / Msevents / Trojan.vundo
How to remove Google Redirects or the TDSS, TDL3, or Alureon rootkit using TDSSKiller
Locky Ransomware Information, Help Guide, and FAQ
CryptoLocker Ransomware Information Guide and FAQ
CryptorBit and HowDecrypt Information Guide and FAQ
CryptoDefense and How_Decrypt Ransomware Information Guide and FAQ
How to make the Start menu full screen in Windows 10
How to install the Microsoft Visual C++ 2015 Runtime
How to open an elevated PowerShell Admin prompt in Windows 10
How to Translate a Web Page in Google Chrome
How to start Windows in Safe Mode
How to remove a Trojan, Virus, Worm, or other Malware
How to show hidden files in Windows 7
How to see hidden files in Windows
eLearning
IT Certification Courses
Gear + Gadgets
Security
Minecraft rushes out patch for critical Log4j vulnerability
Swedish video game developer Mojang Studios has released an emergency Minecraft security update to address a critical bug in the Apache Log4j Java logging library used by the game’s Java Edition client and multiplayer servers.
The vulnerability is fixed with the release of Minecraft: Java Edition 1.18.1, which is now rolling out to all customers.
“This release fixes a critical security issue for multiplayer servers, changes how the world fog works to make more of the world visible, and fixes a couple of other bugs,” the company said today.
“If you are running a multiplayer server, we highly encourage you to upgrade to this version as soon as possible.”
To upgrade to the patched version, those using Mojang’s official game client are advised to close all running game and Minecraft Launcher instances and restart the Launcher to install the patch automatically.
Gamers who use modified Minecraft clients and third-party launchers should reach out to their third-party providers for a security update.
Those hosting their own Minecraft: Java Edition servers will have to go through different steps depending on the version they’re using, as outlined here.
Player safety is the top priority for us. Unfortunately, earlier today we identified a security vulnerability in Minecraft: Java Edition.

The issue is patched, but please follow these steps to secure your game client and/or servers. Please RT to amplify.https://t.co/4Ji8nsvpHf
The bug, now tracked as CVE-2021-44228 and dubbed Log4Shell or LogJam, is a remote code execution (RCE) flaw found in the ubiquitous Apache Log4j Java-based logging library and reported by Alibaba Cloud’s security team.
It impacts default configurations of multiple Apache frameworks, including Apache Struts2, Apache Solr, Apache Druid, and Apache Flink, used by countless enterprise software products from Apple, Amazon, Cloudflare, Twitter, Steam, and others.
Attackers are already mass scanning the Internet [12] for vulnerable systems, and, according to a CERT NZ security advisory, they are also actively exploiting it in the wild.
This was also confirmed by Coalition Director Of Engineering – Security Tiago Henriques and security expert Kevin Beaumont.
Apache has already released Log4j 2.15.0 to address this maximum severity vulnerability. CVE-2021-44228 can also be mitigated in previous releases (2.10 and later) by setting system property “log4j2.formatMsgNoLookups” to “true” or removing the JndiLookup class from the classpath.
Security company Lunasec underscored the severity of CVE-2021-44228 attacks earlier today, saying that “many, many services are vulnerable to this exploit. Cloud services like Steam, Apple iCloud, and apps like Minecraft have already been found to be vulnerable.”
“Anybody using Apache Struts is likely vulnerable. We’ve seen similar vulnerabilities exploited before in breaches like the 2017 Equifax data breach,” they added.
Researchers release ‘vaccine’ for critical Log4Shell vulnerability
New zero-day exploit for Log4j Java library is an enterprise nightmare
SonicWall ‘strongly urges’ customers to patch critical SMA 100 bugs
Mediatek eavesdropping bug impacts 30% of all Android smartphones
Microsoft: New security updates trigger Windows Server auth issues
Not a member yet? Register Now
New zero-day exploit for Log4j Java library is an enterprise nightmare
Massive attack against 1.6 million WordPress sites underway
To receive periodic updates and news from BleepingComputer, please use the form below.
Terms of Use Privacy PolicyEthics Statement
Copyright @ 2003 – 2021 Bleeping Computer® LLC – All Rights Reserved
Not a member yet? Register Now
Read our posting guidelinese to learn what content is prohibited.

source

You May Also Like

Tor’s main site blocked in Russia as censorship widens

Emotet now drops Cobalt Strike, fast forwards ransomware attacksSonicWall ‘strongly urges’ customers…

New Dell BIOS updates cause laptops and desktops not to boot

Russian hackers made millions by stealing SEC earning reportsThreat actors steal $80…

Dell driver fix still allows Windows Kernel-level attacks

Attackers can get root by crashing Ubuntu’s AccountsServiceAttackers can get root by…

Six million Sky routers exposed to takeover attacks for 17 months

US regulators order banks to report cyberattacks within 36 hoursHackers deploy Linux…