Federal Criminal Record investigation
Log4Shell Ubiquitous Remote Code Execution Crisis (CVE-2021-44228)

Universal zero-day vulnerability in Apache Log4j (Log4Shell) where arbitrary JNDI lookup strings (${jndi:ldap://...}) processed by logger components permitted unauthenticated remote code execution, triggering mass scanning and exploitation across billions of enterprise cloud servers by nation-state actors and ransomware syndicates worldwide.

Loss Amount $3.0B
Techniques 2 Mapped
Threat Actor Individual