15/12/2021
Dear All,
Please be aware that on December 9, 2021, a new critical 0-day vulnerability impacting multiple versions of the popular Apache Log4j 2 logging library was publicly disclosed. Versions of the library said to be affected are versions 2.0-beta 9 to 2.14.1. Once exploited, this vulnerability could potentially result in Remote Code Ex*****on (RCE) by logging a certain string on affected installations. This specific vulnerability, also known as CVE-2021-44228, is being commonly referred to as "Log4Shell" in various blogs and reports.
Please be assured that together with our partners, we are conducting a detailed investigation across our own platforms to determine vulnerable versions of Log4J needing remediation or mitigation. For more information and details on protection, investigation and preventative rules, filters & detection, please see do not hesitate to write us.
We are continuing to monitor all our environments for active threats or compromises, and we will provide regular updates as and when relevant.
Kind regards,
Your Intellinks Cyber Monitoring Team