Critical Cyber Vulnerability Revealed by Chinese Company
(www.bleepingcomputer.com)
π EYES ON! π
You're viewing a single comment thread. View all comments, or full comment thread.
Comments (16)
sorted by:
CCP likely only allowed them to report it because they weren't the ones that found or created the exploit and they knew one of their nation state competitors was using it.
My theory is that the Amazon Web Services (AWS) outages over the last couple of days are related. The log manager is present in a LOT of SaaS and cloud products.
Alibaba reported it, which is basically chinese amazon (they have an alibaba cloud even)
I think you're spot on, if its not Chinese tradecraft, they were allowed to expose it.
Valid.
The specific systems are email systems using log4j for extended logging metrics. Itβs common and major providers are hit heavily. We had to patch it where I am as an updated vector from Apache apparently has been slow to deploy ( from what I heard they said Monday )