The Log4Shell Vulnerability – How We Are Protecting You
The latest zero day is a big one. Recently announced, CVE-2021-44228 (dubbed Log4Shell) defines the vulnerability identified in Java's logging package "log4j". This CVE is rated the maximum 10 out of 10. The log4j logging package is built into a significant amount of software, including Apple, Apache, iCloud, Steam, Tesla, Minecraft, and many others. TL;DR: Critical Path Security has been working non-stop to stay ahead of this threat. Our Threat Intelligence feeds have been updated and rolled out to include detections for these attacks. We worked hand in hand with our trusted cyber-security partners to combine our Threat Intelligence with vulnerability identification mechanisms to provide overwhelming support to our customers against this attack. Additionally, our world-class researchers, responders, and analysts have been working around the clock since the notification. The team has continually rolled out additional detections and have worked closely with our customers and partners to respond to attacks.…