{"id":3278,"date":"2021-12-14T10:10:22","date_gmt":"2021-12-14T15:10:22","guid":{"rendered":"https:\/\/lg-staging.lougcloud.com\/?p=3278"},"modified":"2025-07-24T14:04:25","modified_gmt":"2025-07-24T19:04:25","slug":"apache-log4j-exploit-5-things-to-know","status":"publish","type":"post","link":"https:\/\/lg-staging.lougcloud.com\/?p=3278","title":{"rendered":"Apache Log4j Exploit: 5 Things to Know"},"content":{"rendered":"\n<style type=\"text\/css\" data-created_by=\"avia_inline_auto\" id=\"style-css-av-85bp3-f856194ef33e7bc72ec0d3bf98278fce\">\n.flex_column.av-85bp3-f856194ef33e7bc72ec0d3bf98278fce{\nborder-radius:0px 0px 0px 0px;\npadding:0px 0px 0px 0px;\n}\n<\/style>\n<div  class='flex_column av-85bp3-f856194ef33e7bc72ec0d3bf98278fce av_one_full  avia-builder-el-0  avia-builder-el-no-sibling  first flex_column_div av-zero-column-padding  '     ><p><br \/>\n<section  class='av_textblock_section av-k0pon615-114d01afa1a8988881100bbf49ddc8fc '  ><div class='avia_textblock' ><h1>The Log4j vulnerability affects everything from the cloud to developer tools and security devices. Here&#8217;s what to look for, according to the latest information.<\/h1>\n<\/div><\/section><br \/>\n<section  class='av_textblock_section av-k0pop9td-8497efcd251a401b4e3e5b055a544ee1 '  ><div class='avia_textblock' ><p>A vulnerability in a commonly used logging platform has security experts and officials rushing to patch systems before cybercriminals are able to exploit the flaw. Also known as Log4Shell, the flaw is exposing some of the world&#8217;s most popular applications and services to attack, and the outlook hasn&#8217;t improved since the vulnerability was announced last week. Cybersecurity experts warn this vulnerability will continue to haunt the internet for the next several years.<\/p>\n<p>Here are 5 important things to know about the Log4j vulnerability.<\/p>\n<h2>What is Apache Log4j?<\/h2>\n<p>Log4j is a logging library widely used by developers and programmers to take notes about what\u2019s happening on applications and servers. The vulnerability is also being referred to as \u201dLog4Shell.\u201d The name of the Java logging system where the vulnerability has been found is \u201clog4j2\u201d. The threat is a zero-day vulnerability, meaning hackers are taking advantage of a software security flaw that is either unknown to those who should be securing the issue or a patch or solution is not yet available to correct the vulnerability. The typical catch with zero-day vulnerabilities is the flaws are only known to bad actors, meaning the good guys have no clue about its existence and therefore have no patch to fix it.<\/p>\n<h2>Why is it such a big deal?<\/h2>\n<p>The range of impact is so broad because of the nature of the vulnerability itself. Log4j is used by a very large percentage of the Java programs developed in the last decade for both server and client applications. Java is also one of the top programming languages used by businesses. The bug makes several online systems built on Java vulnerable to zero-day attacks. If the vulnerability is exploited by bad actors, it will allow remote code execution (RCE) and bad actors to download malware via exposed servers. Since the bug affects companies and services that have millions of customers (and their data), it puts a myriad of servers and machines at risk.<\/p>\n<h2>When was it discovered?<\/h2>\n<p>The Log4j flaw first came to light on December 9, 2021.<\/p>\n<h2>What devices and applications are at risk?<\/h2>\n<p>Amazon Web Services, Microsoft, Cisco, Apple iCloud, Google Cloud and IBM have all found that at least some of their services were vulnerable, and these vendors have been rushing to issue fixes and advise customers about how best to proceed. Even widely used apps like Minecraft have been found vulnerable. An extensive list of responses from impacted organizations has been compiled here. The exact extent of the exposure is still coming into view, though.<\/p>\n<h2>How can you protect yourself and your organization?<\/h2>\n<p>The Cybersecurity &amp; Infrastructure Security Agency\u2019s (CISA\u2019s) SA&#8217;s main advice main advice is to identify internet-facing devices running Log4j and upgrade them to version 2.15.0, or to apply the mitigations provided by vendors &#8220;immediately.\u201d But it also recommends setting up alerts for probes or attacks on devices running Log4j.<\/p>\n<p>CISA recommends affected entities:<\/p>\n<p>\u2022 Review Apache\u2019s Log4j Security Vulnerabilities page for additional information.<br \/>\n\u2022 Apply available patches immediately. See CISA&#8217;s upcoming GitHub repository for known affected products and patch information.<br \/>\n\u2022 Prioritize patching, starting with mission critical systems, internet-facing systems and networked servers. Then prioritize patching other affected information technology and operational technology assets.<br \/>\n\u2022 Until patches are applied, set log4j2.formatMsgNoLookups to true by adding -Dlog4j2.formatMsgNoLookups=true to the Java Virtual Machine command for starting your application. Note: this may impact the behavior of a system\u2019s logging if it relies on Lookups for message formatting. Additionally, this mitigation will only work for versions 2.10 and above.<br \/>\n\u2022 CISA\u2019s Binding Operational Directive (BOD) 22-01 directs federal civilian agencies to mitigate CVE-2021-44228 by December 24, 2021, as part of the Known Exploited Vulnerabilities Catalog.<br \/>\n\u2022 Conduct a security review to determine if there is a security concern or compromise. The log files for any services using affected Log4j versions will contain user-controlled strings.<br \/>\n\u2022 Consider reporting compromises immediately to CISA and the FBI.<\/p>\n<\/div><\/section><\/p><\/div>\n","protected":false},"excerpt":{"rendered":"","protected":false},"author":3,"featured_media":3281,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[8],"tags":[71,29],"class_list":["post-3278","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity-news","tag-apache","tag-scams"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.2 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Apache Log4j Exploit: 5 Things to Know - Louisville Geek<\/title>\n<meta name=\"description\" content=\"A serious vulnerability in a commonly used logging platform was found and cybersecurity officials are deeply concerned about the ramifications it will cause. Hundreds of millions of devices are likely affected, and the flaw is exposing some of the world\u2019s most popular applications and services to attack.\" \/>\n<meta name=\"robots\" content=\"noindex, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Apache Log4j Exploit: 5 Things to Know - Louisville Geek\" \/>\n<meta property=\"og:description\" content=\"A serious vulnerability in a commonly used logging platform was found and cybersecurity officials are deeply concerned about the ramifications it will cause. Hundreds of millions of devices are likely affected, and the flaw is exposing some of the world\u2019s most popular applications and services to attack.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/lg-staging.lougcloud.com\/?p=3278\" \/>\n<meta property=\"og:site_name\" content=\"Louisville Geek\" \/>\n<meta property=\"article:published_time\" content=\"2021-12-14T15:10:22+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2025-07-24T19:04:25+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/lg-staging.lougcloud.com\/wp-content\/uploads\/2021\/12\/shutterstock_2010177530.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t<meta property=\"og:image:height\" content=\"628\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Ben Lawrence\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Ben Lawrence\" \/>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Apache Log4j Exploit: 5 Things to Know - Louisville Geek","description":"A serious vulnerability in a commonly used logging platform was found and cybersecurity officials are deeply concerned about the ramifications it will cause. Hundreds of millions of devices are likely affected, and the flaw is exposing some of the world\u2019s most popular applications and services to attack.","robots":{"index":"noindex","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"og_locale":"en_US","og_type":"article","og_title":"Apache Log4j Exploit: 5 Things to Know - Louisville Geek","og_description":"A serious vulnerability in a commonly used logging platform was found and cybersecurity officials are deeply concerned about the ramifications it will cause. Hundreds of millions of devices are likely affected, and the flaw is exposing some of the world\u2019s most popular applications and services to attack.","og_url":"https:\/\/lg-staging.lougcloud.com\/?p=3278","og_site_name":"Louisville Geek","article_published_time":"2021-12-14T15:10:22+00:00","article_modified_time":"2025-07-24T19:04:25+00:00","og_image":[{"width":1200,"height":628,"url":"https:\/\/lg-staging.lougcloud.com\/wp-content\/uploads\/2021\/12\/shutterstock_2010177530.png","type":"image\/png"}],"author":"Ben Lawrence","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Ben Lawrence"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/lg-staging.lougcloud.com\/?p=3278#article","isPartOf":{"@id":"https:\/\/lg-staging.lougcloud.com\/?p=3278"},"author":{"name":"Ben Lawrence","@id":"https:\/\/lg-staging.lougcloud.com\/#\/schema\/person\/1e8874ec46062e6e46fbbba43fc82d56"},"headline":"Apache Log4j Exploit: 5 Things to Know","datePublished":"2021-12-14T15:10:22+00:00","dateModified":"2025-07-24T19:04:25+00:00","mainEntityOfPage":{"@id":"https:\/\/lg-staging.lougcloud.com\/?p=3278"},"wordCount":849,"publisher":{"@id":"https:\/\/lg-staging.lougcloud.com\/#organization"},"image":{"@id":"https:\/\/lg-staging.lougcloud.com\/?p=3278#primaryimage"},"thumbnailUrl":"https:\/\/lg-staging.lougcloud.com\/wp-content\/uploads\/2021\/12\/shutterstock_2010177530.png","keywords":["apache","scams"],"articleSection":["Cybersecurity"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/lg-staging.lougcloud.com\/?p=3278","url":"https:\/\/lg-staging.lougcloud.com\/?p=3278","name":"Apache Log4j Exploit: 5 Things to Know - Louisville Geek","isPartOf":{"@id":"https:\/\/lg-staging.lougcloud.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/lg-staging.lougcloud.com\/?p=3278#primaryimage"},"image":{"@id":"https:\/\/lg-staging.lougcloud.com\/?p=3278#primaryimage"},"thumbnailUrl":"https:\/\/lg-staging.lougcloud.com\/wp-content\/uploads\/2021\/12\/shutterstock_2010177530.png","datePublished":"2021-12-14T15:10:22+00:00","dateModified":"2025-07-24T19:04:25+00:00","description":"A serious vulnerability in a commonly used logging platform was found and cybersecurity officials are deeply concerned about the ramifications it will cause. Hundreds of millions of devices are likely affected, and the flaw is exposing some of the world\u2019s most popular applications and services to attack.","breadcrumb":{"@id":"https:\/\/lg-staging.lougcloud.com\/?p=3278#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/lg-staging.lougcloud.com\/?p=3278"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/lg-staging.lougcloud.com\/?p=3278#primaryimage","url":"https:\/\/lg-staging.lougcloud.com\/wp-content\/uploads\/2021\/12\/shutterstock_2010177530.png","contentUrl":"https:\/\/lg-staging.lougcloud.com\/wp-content\/uploads\/2021\/12\/shutterstock_2010177530.png","width":1200,"height":628},{"@type":"BreadcrumbList","@id":"https:\/\/lg-staging.lougcloud.com\/?p=3278#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/lg-staging.lougcloud.com\/"},{"@type":"ListItem","position":2,"name":"Apache Log4j Exploit: 5 Things to Know"}]},{"@type":"WebSite","@id":"https:\/\/lg-staging.lougcloud.com\/#website","url":"https:\/\/lg-staging.lougcloud.com\/","name":"Louisville Geek","description":"Empowering Local Businesses and National Enterprises with Comprehensive IT Services","publisher":{"@id":"https:\/\/lg-staging.lougcloud.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/lg-staging.lougcloud.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/lg-staging.lougcloud.com\/#organization","name":"Louisville Geek","url":"https:\/\/lg-staging.lougcloud.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/lg-staging.lougcloud.com\/#\/schema\/logo\/image\/","url":"https:\/\/lg-staging.lougcloud.com\/wp-content\/uploads\/2019\/10\/lougeek_full_logo-black-1.png","contentUrl":"https:\/\/lg-staging.lougcloud.com\/wp-content\/uploads\/2019\/10\/lougeek_full_logo-black-1.png","width":1671,"height":506,"caption":"Louisville Geek"},"image":{"@id":"https:\/\/lg-staging.lougcloud.com\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/lg-staging.lougcloud.com\/#\/schema\/person\/1e8874ec46062e6e46fbbba43fc82d56","name":"Ben Lawrence","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/82e4d3ae8ca51a80f9e1c400a5a63cd408dddc6d07c994878451703381610b2e?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/82e4d3ae8ca51a80f9e1c400a5a63cd408dddc6d07c994878451703381610b2e?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/82e4d3ae8ca51a80f9e1c400a5a63cd408dddc6d07c994878451703381610b2e?s=96&d=mm&r=g","caption":"Ben Lawrence"},"description":"Managing Partner at Louisville Geek, an IT services company supporting small and medium-sized businesses. Since joining in 2009, he has helped grow the company while leading its marketing efforts. Based in Louisville, Kentucky, Ben brings more than 15 years of experience in technology services and business leadership. View Ben's LinkedIn","url":"https:\/\/lg-staging.lougcloud.com\/?author=3"}]}},"_links":{"self":[{"href":"https:\/\/lg-staging.lougcloud.com\/index.php?rest_route=\/wp\/v2\/posts\/3278","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/lg-staging.lougcloud.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/lg-staging.lougcloud.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/lg-staging.lougcloud.com\/index.php?rest_route=\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/lg-staging.lougcloud.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=3278"}],"version-history":[{"count":2,"href":"https:\/\/lg-staging.lougcloud.com\/index.php?rest_route=\/wp\/v2\/posts\/3278\/revisions"}],"predecessor-version":[{"id":3282,"href":"https:\/\/lg-staging.lougcloud.com\/index.php?rest_route=\/wp\/v2\/posts\/3278\/revisions\/3282"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/lg-staging.lougcloud.com\/index.php?rest_route=\/wp\/v2\/media\/3281"}],"wp:attachment":[{"href":"https:\/\/lg-staging.lougcloud.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=3278"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/lg-staging.lougcloud.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=3278"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/lg-staging.lougcloud.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=3278"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}