The Night Sky ransomware gang has started to exploit the critical CVE-2021-44228 vulnerability in the Log4j logging library, also known as Log4Shell. Microsoft published a warning about a new campaign from a China-based actor it tracks as DEV-0401. The threat actor is targeting vulnerable machines exposed on the public web from domains that impersonate legitimate companies, some of them in the technology and cybersecurity sectors. Microsoft’s warning comes on the heels of another alert from UK’s National Health Service on January 5.”]