Connect with us

News

Log4j Vulnerably To Wreak Havoc On The Internet For Years To Come

Because of how widespread Log4j is, experts estimate that it may take years to hunt down all vulnerable instances and patch them.

Published

on

log4j vulnerability to wreak havoc on the internet for years to come

As if one pandemic wasn’t enough, there’s now also a cyber-pandemic whose scale is increasing at an exponential rate. The cause of this digital pandemic is a zero-day vulnerability in Java-based logging utility called Log4j. This open-source software allows software developers to log data within their applications, and it has been widely used since its release in 2001.

The vulnerability was disclosed on December 9 by the Alibaba Cloud Security Team, which named it Log4Shell (CVE-2021-44228). Two days later, cybersecurity company Tenable described it as “the single biggest, most critical vulnerability of the last decade”.

Since then, the vulnerability has affected many major tech players, including Amazon Web Services, Adobe, Broadcom, Cisco, Docker, F-Secure, IBM, Juniper Networks, Oracle, Red Hat, Siemens, SolarWinds, Sophos, Ubiquiti, Zoho, and others.

“It’s ubiquitous” said Chris Eng, chief research officer at cybersecurity firm Veracode, in an interview for CNN Business. Even if you’re a developer who doesn’t use Log4j directly, you might still be running the vulnerable code because one of the open-source libraries you use depends on Log4j”.

In addition to affecting large swaths of the global IT infrastructure, the Log4Shell vulnerability is also extremely severe because it involves arbitrary code execution. In other words, it makes it possible for attackers to make the vulnerable system do anything they want.

That’s why the Cybersecurity and Infrastructure Security Agency (CISA), the Canadian Centre for Cyber Security (CCCS), and Germany’s Bundesamt für Sicherheit in der Informationstechnik (BSI) have all called on organizations to take on immediate action and install the available fixes, which were released three days before the vulnerability was published.

Also Read: How To Enable WhatsApp Disappearing Messages For All Chats

Still, attackers have already successfully exploited the vulnerability to steal sensitive data, extract system credentials, install backdoors, and run crypto miners. Some of the largest botnets in the world are now scanning for the vulnerability, and almost half of all corporate networks have already been probed.

Because of how widespread Log4j is, experts estimate that it may take years to hunt down all vulnerable instances and patch them. Until that happens, cybercriminals will be on a hunt as well, ready to exploit them.

Advertisement

📢 Get Exclusive Monthly Articles, Updates & Tech Tips Right In Your Inbox!

JOIN 23K+ SUBSCRIBERS

Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

News

Visa’s Return To Syria Starts With A Test And A Bank In Lebanon

Foreign visitors will be the first users to benefit, but whether Syria’s own banks and cardholders follow is still an open question.

Published

on

visa's return to syria starts with a test and a bank in lebanon

Visa is returning to Syria. Its first live international card transaction in the country was a test rather than a launch, and the milestone event ran through a Lebanese bank.

The acquirer (the bank on the merchant’s side of a card payment) was Fransabank Lebanon, with Paymera as the other named partner. Nadim Moujaes, who heads a Fransabank Group subsidiary, describes the test as both the culmination of “longstanding efforts to link Syria back to international payment networks” and “the first step in a larger path”.

“We are excited to have successfully tested live transactions today as we plan to enable international visitors to use their Visa cards while in Syria,” says Leila Serhan, Visa’s senior vice president and group country manager for the North Africa, Levant and Pakistan region. Although a significant first step, that plan doesn’t come with a hard date for when a visitor’s card will work normally.

Mohammed Safwat Raslan, governor of the Central Bank of Syria, says the test paves the way for international card acceptance in Syria and that maintaining strong compliance, risk management and operational controls will remain essential. Serhan likewise stresses that Visa has worked within applicable legal, regulatory and compliance requirements. For a test transaction, it seems there was a great deal of attention paid to the rules, with the entire operation being carefully managed.

Also Read: Lebanon’s 5G Era Begins With 150 Stations And A $1M Budget

The test is the latest step in a sequence that began in December 2025, when Visa announced a strategic roadmap to support Syria’s integration into the global digital economy. In February 2026 it hosted its first industry gathering of banks, ecosystem partners and policymakers in Damascus and, the same month, signed an agreement with Syria’s Ministry of Communications and Information Technology in San Francisco.

Michel Kattouah, Paymera’s CEO, called the test “the return of international card acceptance,” but while that’s positive news, there’s no word yet on when a Syrian bank will issue a Visa card to a Syrian customer.

Continue Reading

#Trending