Posts

Stellar Cyber: Log4j Vulnerability and Exploitation Detection

Image
  1. Introduction In the past several days, a serious Log4j vulnerability ( CVE-2021-44228 ,  CVE-2021-45046 ) has nearly led to a perfect storm in the Internet world. As a widely used Java logging utility with an easily exploitable vulnerability, Log4j has no doubt made IT professionals and companies nervous and many questions have been raised – What is this vulnerability? How can I know if our system is vulnerable? Has my IT infrastructure already been breached? What can I do to prevent future attacks leveraging this vulnerability? At  Stellar Cyber , we have been closely monitoring the situation, and we are here to provide our takeaways and advice to our current and prospective customers and partners as they navigate through the uncertainties brought by this Log4j vulnerability. 2. Impact and Mitigation According to  CVE-2021-44228 , any Apache Log4j2 prior to v2.15.0 is affected by the vulnerability due to an unchecked string interpolation with  Java Naming ...

XDR will converge from different directions: XDR, Open XDR, Native XDR, Hybrid XDR -> XDR

Image
  2022 Predictions By Aimei Wei Initial definitions of  XDR  envisioned  eXtended Detection and Response  – a single platform that unified  detection and response  across the entire security  kill chain . According to Rik Turner, who coined the  XDR acronym ,  XDR  is  “a single, stand-alone solution that offers integrated threat detection and response capabilities.”   To meet Omdia’s criteria to be classified as a  “comprehensive”   XDR solution , a product must offer  threat detection  and response functionality across endpoints, networks and cloud computing environments. Gartner’s definition is similar in that it points to features such as alert and incident correlation, built-in automation, multiple streams of telemetry, multiple forms of detections (built in detections), and multiple methods of response. However, Gartner requires  XDR  to be achieved through consolidating multiple proprie...

When Doing Nothing is Too Expensive

Image
  Resource strapped companies trying to put together a comprehensive  cybersecurity  defense in today’s environment have three key challenges: there’s not enough time, there aren’t enough people, and there isn’t enough money. Most companies look at their monthly spend on  security tools , training and headcount and the typical reaction (after the groaning) is to stand pat, limping along with barely adequate security. In extreme cases, they actually want to reduce the security budget because at least that will ease one of their three challenges.  But when you look at monthly spend and weigh it against the risk of doing nothing in an age when cyberattacks are more numerous and complex every week, it puts you in a real bind about what to do. Doing nothing means you put your entire business in danger because a serious attack can take you out of business. So, you can either continue to watch your analysts drown in a sea of largely meaningless alerts, or you can choos...