Log4Shell - Vulnerability

Threat entity extracted from intelligence sources

Frequency
22
occurrences
First Seen
November 8, 2025
Last Seen
July 3, 2026

Log4Shell is a vulnerability tracked across 20 threat clusters and 22 intelligence report mentions on ThreatCluster. First observed November 8, 2025; most recent activity July 3, 2026.

Related Threat Clusters

  • FortiWeb WAF Vulnerability Enables Full Admin Control Exploitation

    A critical vulnerability in FortiWeb Web Application Firewall (WAF) has been actively exploited, allowing attackers to gain full administrative access to affected systems. Organizations using FortiWeb are at risk of…

    100 articles · Updated November 15, 2025
  • Operation Escaneo Targets Latin American Critical Infrastructure

    Operation Escaneo is a coordinated cyberattack attributed to the MexicanMafia group, targeting critical infrastructure across Latin America, primarily Mexico. The campaign, which spanned from 2025 to 2026, utilized…

    4 articles · Updated June 18, 2026
  • Sandworm Targets Critical Infrastructure with Aggressive OT Attacks

    The Russian state-sponsored group Sandworm has intensified its cyber operations against industrial and critical infrastructure, utilizing pre-compromised operational technology (OT) environments instead of zero-day…

    5 articles · Updated May 14, 2026
  • SAP Patch Day Addresses Critical Vulnerabilities

    On March 10, 2026, SAP released 15 security notes, including two critical vulnerabilities that could allow remote code execution and system compromise. Administrators are urged to apply the patches promptly to protect…

    10 articles · Updated March 10, 2026
  • Aikido Acquires Root to Combat Supply Chain Vulnerabilities

    On June 30, 2026, Aikido Security announced its acquisition of Root, a startup specializing in automated vulnerability remediation for open-source software. This acquisition aims to enhance supply chain security as…

    9 articles · Updated June 30, 2026
  • New CVSS 10.0 Vulnerability CVE-2026-29000 Discovered

    A new CVSS 10.0 vulnerability, CVE-2026-29000, was published on March 4, 2026, allowing attackers to bypass authentication in the pac4j-jwt library, enabling impersonation of any user, including administrators. This…

    2 articles · Updated March 6, 2026
  • Mini Shai-Hulud Supply Chain Attack Targets SAP npm Packages

    A new supply chain attack, dubbed 'Mini Shai-Hulud', has compromised multiple npm packages related to SAP's Cloud Application Programming Model (CAP). This attack involves injecting malicious preinstall scripts into…

    697 articles · Updated April 29, 2026
  • Urgent Mitigation Needed for Multiple Cyber Vulnerabilities in UK Organizations

    The NCSC has issued an urgent advisory for UK organizations to address critical vulnerabilities affecting F5 BIG-IP Access Policy Manager, Citrix NetScaler ADC, and Citrix NetScaler Gateway. These vulnerabilities…

    2 articles · Updated April 15, 2026
  • Critical React Flaw CVE-2025-55182 Exposes Major Security Risks

    A maximum-severity vulnerability in the React JavaScript library, tracked as CVE-2025-55182, allows unauthenticated remote code execution on affected instances. Security researchers report that 39 percent of cloud…

    47 articles · Updated December 3, 2025
  • Anthropic Launches Cyber Jailbreak Severity Framework for Fable 5 Safeguards

    Anthropic has redeployed its AI model, Claude Fable 5, after a temporary suspension due to a jailbreak vulnerability. The US Commerce Department had enforced export controls after Amazon researchers discovered a method…

    12 articles · Updated July 3, 2026

Recent Intelligence Reports

  • Anthropic Proposes Cross — Letsdatascience · July 3, 2026
  • Aikido buys Israel's Root to patch open source with AI — Thenextweb · July 1, 2026
  • Aikido acquires Root to secure the supply chain — Aikido.Dev · June 30, 2026
  • Aikido Acquires Root to Defend Open Source From AI-Powered Attacks — Uk.Finance.Yahoo · June 30, 2026
  • LATAM Infrastructure Hit by Fortinet and Ivanti Exploits — Infosecurity-Magazine · June 18, 2026
  • Sandworm Activity In Industrial Environments What The Data Reveals — www.nozominetworks.com · May 14, 2026
  • Sandworm uses pre-compromised OT environments instead of zero — Industrialcyber.Co · May 14, 2026
  • Some trackers — zerodayclock.com · April 22, 2026

CVSS v3.1 Breakdown