
Security researchers have observed attackers exploiting the Spring4Shell Java-related flaw to install malware on target systems. While Spring4Shell isn't quite as dire as Log4Shell, most security firms, the US Cybersecurity and Infrastructure Security Agency (CISA), and Microsoft are urging developers to patch it if they're using Java Development Kit (JDK) from version 9.0 and upwards if the system is also using Spring Framework versions 5.3.0 to 5.3.17, 5.2.0 to 5.2.19, and earlier versions.
Link: Spring4Shell flaw is now being used to spread this botnet malware
via http://www.zdnet.com
No comments:
Post a Comment