Log4Shell: The most critical Java vulnerability in a decade. Unauthenticated RCE via JNDI injection in Apache Log4j2. Patch to 2.17.1+ immediately. Mass-exploited within hours of disclosure by nation-states and ransomware groups worldwide.
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled.
Supernova subscribers receive AI-triaged CVE alerts the moment they're published — before the PoC drops.
Start Supernova — $99/mo →