The U.S. Cybersecurity and Infrastructure Security Agency, the FBI and the National Security Agency have issued a joint advisory on the known vulnerabilities in the Apache Log4j software library. The advisory is a response to “active, worldwide exploitation by numerous threat actors” The advisory follows CISA’s emergency directive, issued Friday, overriding the previous deadline of Dec. 24 to patch or mitigate immediately. Israeli security firm Check Point has reported that a known Iranian APT group has been behind attempts to exploit the flaw.”]
Source: https://www.bankinfosecurity.com/cisa-international-partners-issue-joint-log4j-advisory-a-18183