Zero Day Room
Live
Vulnerabilities

Log4j RCE Scare Dismissed by Developers

Apache Log4j developers have described a recently reported critical remote code execution vulnerability as a 'known security non-finding', calming

Apache Log4j developers have described a recently reported critical remote code execution vulnerability as a 'known...

Apache Log4j developers have calmed fears over a reported critical remote code execution vulnerability, describing the issue as a "known security non-finding". The developers confirmed its potential for remote code execution but pointed out the specific circumstances required for exploitation, noting that volunteers' limited time could be spent on more useful things.

This alert follows the serious impact of the historic Log4Shell flaw. The news was part of a broader set of developments reported by SecurityWeek.

Critical Vulnerability Exploited

In other incident news, the Akira ransomware group took credit for an attack on Paylogix. Attackers stole files from its network over several days in November, exposing Social Security numbers, financial and health insurance information, medical data, passport numbers and taxpayer IDs. At least 67,789 people across South Carolina, New Hampshire and Vermont have been reported affected.

Separately, hackers accessed personal data belonging to about 8.7 million customers of Manchester Airports Group. The compromised data included email addresses, phone numbers, vehicle registrations and postcodes. The attackers demanded a ransom, but MAG refused to pay. Airport operations were not affected.

Vendor Security Advisories

U.S. Bancorp responded to ransomware claims involving its name, stating they stem from a potential incident at a fourth-party provider outside the bank's environment. The bank says there is currently no evidence its systems, networks or data repositories were compromised, although the LockBit gang has threatened to publish allegedly stolen data.

Hardened container image provider Minimus is winding down operations after raising $51 million in 2025, citing the business and investment climate. The shutdown comes less than a month after the company appeared at the Black Hat conference. Shortly after the announcement, Echo said it acquired the company and its technology.

Credential Leak Research

New research highlights the scale of exposed credentials. A Truffle Security study found over 700 still-active corporate AWS keys that granted full control over accounts during a review of 10,616 AWS keys exposed between 2022 and 2026.

Intruder's separate scan of 3.5 million active hosts found 28,000 exposed Git repositories, uncovering more than 400 AWS keys, 107 Stripe keys, 123 OpenAI keys, 80 Telegram tokens and 17 GitHub PATs. Some credentials were still active and could provide access to cloud environments and private source code.

Credential TypeCount Found
AWS Keys400+
Stripe Keys107
OpenAI Keys123
Telegram Tokens80
GitHub PATs17

Mobile banking malware is also widening its reach. Zimperium found 30 mobile malware families actively targeting more than 800 banking and fintech apps across 44 EMEA countries. Attackers are increasingly using AI across the attack chain.

Policy and Exposure Updates

The US Treasury sanctioned Iranian cyber actors tied to the MOIS, accusing them of compromising critical infrastructure and conducting financially motivated cyber theft. Keyvan Fayyaz Ghareh Blagh, Saber Shahbazi Balujeh and Mohammad Reza Kadkhoda’i were named for carrying out compromises and data theft.

Leaked Bauman University records reveal a long-running program that trained roughly 250 career and reserve students for Russian military intelligence and cyber operations. Graduates have been linked to units associated with the Russian threat groups APT28 and Sandworm.

In breach analysis, Troy Hunt found that a large portion of data attributed to an alleged Carhartt breach was actually synthetic benchmark data mixed with genuine customer information. His analysis suggests roughly half of the 24.8 million email addresses were junk records, meaning the original breach claims significantly overstated the amount of real customer data involved.

Related coverage

More from Vulnerabilities