Epic Log4Shell 0-Day Vulnerability Puts Top Tech Companies at Risk
The Log4j vulnerability–first reported on last Friday– is turning out to be a cybersecurity nightmare that likely impacts a wide range of products from Apple’s iCloud to Twitter to Microsoft’s Minecraft to Amazon and a number of other enterprise as Tencent, Steam, Twitter, Baidu, DIDI, JD, NetEase, CloudFlare, Tesla, Google, Webex, LinkedIn, etc. LunaSec also notes that simply changing an iPhone’s name was triggering the vulnerability in Apple’s servers. The vulnerability was announced suddenly, as a “zero-day” vulnerability, taking the industry by surprise. The vulnerability, dubbed ‘Log4Shell,’ was rated 10 on a scale of one to 10, the worst possible. Anyone with the exploit can get full access to an unpatched machine. The Log4j software flaw as reported by cybersecurity researchers could allow attackers to have uncontrolled access to computer systems, and even the US government’s cybersecurity agency has issued a warning on the same. LunaSec notes that simply changing an iPhone...