Threat actors have revived an old and relatively inactive ransomware family known as TellYouThePass. Ransomware was dropped on old Windows systems using exploits abusing the flaw tracked as CVE-2021-44228 and known as Log4Shell. The attacks target a critical remote code execution bug in the Apache Log4j library. CISA ordered Federal Civilian Executive Branch agencies today to patch their systems against the flaw within the next six days, until December 23, until the deadline is December 24.”]

