Skip to content
website logo

Primary Menu
  • Home
  • My Bibles
  • My Music
  • RESOURCES
  • LINKS
  • Software
  • LinkTree
  • About Me
  • Home
  • 2021
  • December
  • 14
  • The Log4Shell 0-day exploit, how bad is it really?

The Log4Shell 0-day exploit, how bad is it really?

Mike December 14, 2021

Share this:

  • Share on Facebook (Opens in new window) Facebook
  • Share on Threads (Opens in new window) Threads
  • Share on X (Opens in new window) X
  • Print (Opens in new window) Print
  • Email a link to a friend (Opens in new window) Email
  • More
  • Share on WhatsApp (Opens in new window) WhatsApp
  • Share on Telegram (Opens in new window) Telegram
  • Share on Reddit (Opens in new window) Reddit
  • Share on Bluesky (Opens in new window) Bluesky
  • Share on Tumblr (Opens in new window) Tumblr
  • Share on Pinterest (Opens in new window) Pinterest
  • Share on Mastodon (Opens in new window) Mastodon

Log4Shell is the name given to a critical zero-day vulnerability that surfaced last Thursday when it was exploited in the wild in remote-code compromises against Minecraft servers. The source of the vulnerability was Log4J, a logging utility used by thousands if not millions of apps, including those used inside just about every enterprise on the planet. The Minecraft servers were the proverbial canary in the coal mine.

In the four days since, it’s clear Log4Shell is every bit as grave a threat as claimed, with the list of cloud services affected reading like a who’s who of the biggest names on the Internet. Threat analysts and researchers are still assessing the damage so far and the outlook over the next weeks and months.

What’s Log4J and what makes Log4Shell such a big deal?
Log4J is an open source Java-based logging tool available from Apache. It has the ability to perform network lookups using the Java Naming and Directory Interface to obtain services from the Lightweight Directory Access Protocol. The end result: Log4j will interpret a log message as a URL, go and fetch it, and even execute any executable payload it contains with the full privileges of the main program. Exploits are triggered inside text using the ${} syntax, allowing them to be included in browser user agents or other commonly logged attributes.

The vulnerability, tracked as CVE-2021-44228, has a severity rating of 10 out of 10. The zero-day had been exploited at least nine days before it surfaced.

Researchers at Cisco’s Talos security team said they observed exploits beginning December 2.

What has happened since Log4Shell surfaced last Thursday?
Almost immediately, security firm Greynoise detected active scanning attempting to identify vulnerable servers. Researchers report seeing this critical and easy-to-exploit vulnerability being used to install crypto-mining malware, bolster Linux botnets, and exfiltrate configurations, environmental variables, and other potentially sensitive data from vulnerable servers.

What’s the prognosis?
In a best-case scenario, major brokerages, banks, and merchants will invest huge sums in overtime costs to pay large numbers of already overworked IT employees to mop up this mess during the holidays. You don’t want to think about the worst-case scenario, other than to remember the 2017 breach of Equifax and the resulting compromise of 143 million US consumers’ data that followed when that company failed to patch against a similarly devastating vulnerability.

Like this:

Like Loading…

Post navigation

Previous: Diners leave $4,400 tip, then server is fired by Arkansas restaurant
Next: ‘So Easy I Was Cruising’: Teammate Says Penn’s Trans Swimmer Boasted After Destroying Competition

Related Stories

kevin mitnick 2

One of my GenX Heroes: Kevin Mitnick

Mike July 31, 2026
microprocessor early 3

The Microprocessor turns 55, Thanks in large part to 3 Intel Engineers

Mike November 16, 2025
linus torvaldes

Linux, Linus and the personal OS that never really caught on

Mike August 25, 2025
Log in

Abortion Anglican bible business california Christ christian Christmas church church of england cofe college football Coronavirus covid covid-19 dogs episcopal church Florida food football fsu god hurricane Israel Jesus john macarthur lawsuit los angeles Music nfl orlando pets Politics pope recipe religion roman catholic salvation sbc seminoles target acquired Thanksgiving trans unemployment Weather

  • New Updates to SingHymnal.com
  • Podcast: How to Find Joy Even If Happiness Doesn’t Come Naturally (Andrew Wilson)
  • Our Motive for Obeying God Shouldn’t Be Gratitude
  • Introducing ‘The Sing! Hymnal,’ Lyrics & Liturgies and Personal Edition
  • How Do You Deal with the Grief Sin Produces?
  • Psalms 50 (Secret)
  • 1 Corinthians 13 (Family)
  • Ezekiel 11 (Secret)
  • 2 Samuel 2 (Family)
  • Hosea 14:8 - Morning Devotional for Sep. 8th
  • Mark 2:4 - Morning Devotional for Sep. 7th
  • Philippians 2:15 - Morning Devotional for Sep. 6th
  • Psalms 120:5 - Morning Devotional for Sep. 5th
  • Mark 1:41 - Morning Devotional for Sep. 4th
  • Ephesians 1:19, 20 - Evening Devotional for Sep. 8th
  • Jeremiah 49:23 - Evening Devotional for Sep. 7th
  • Galatians 5:18 - Evening Devotional for Sep. 6th
  • Job 38:16 - Evening Devotional for Sep. 5th
  • Leviticus 19:36 - Evening Devotional for Sep. 4th

RECENT:

  • Pure Gold! Warren Buffet learning how to open a fortune cookie.
  • Edina Lutheran church recites ‘sparkle creed,’ professes belief in ‘non-binary god’
  • Wisconsin Cathedral Installs First Transgender Dean in Episcopal History.
  • Why Anglicans Worship the Way They Do
  • St. Paul’s Cathedral Under Scrutiny for Concert Partnership with Nightclub Fabric

December 2021
M T W T F S S
 12345
6789101112
13141516171819
20212223242526
2728293031  
« Nov   Jan »
Copyright 2026 © All rights reserved. | MoreNews by AF themes.
%d