Sploitus New Exploits Target PowerShell and Log4j Vulnerabilities
Article Content
- •Stracciatella exploit disables PowerShell security features for script execution.
- •LogJackFix addresses the critical Log4j CVE-2021-44228 vulnerability.
- •Both exploits were released in late September 2026, highlighting ongoing security threats.
Two new exploits have emerged, targeting PowerShell and the Log4j vulnerability CVE-2021-44228. The Stracciatella exploit allows execution of PowerShell scripts with disabled security features, potentially affecting systems using PowerShell in unprotected environments. Meanwhile, the LogJackFix exploit addresses the Log4j vulnerability, which has been exploited in the wild since its discovery. The Stracciatella exploit is designed for advanced adversarial simulations, while LogJackFix aims to protect Minecraft clients from remote code execution risks. Both tools highlight ongoing concerns regarding the security of widely used software frameworks. The Stracciatella exploit was published on September 29, 2026, while LogJackFix was released a day earlier on September 28, 2026. Security professionals are urged to assess their environments for these vulnerabilities and implement necessary mitigations.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track CVE-2021-44228 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
China-Linked QTFY Group Targets Critical Infrastructure with Advanced Exploits The Joint Cybersecurity Advisory JCSA-20260826-01, released on August 26, 2026, details ongoing activities by the China-linked hacking group QTFY, attributed to Nanjing Xinjiuwei Network Technology Co. Active since 2018, QTFY employs platforms like QScan and QTRouter to exploit vulnerabilities in critical…