Universal zero-day vulnerability in Apache Log4j (Log4Shell) where arbitrary JNDI lookup strings (${jndi:ldap://...}) processed by logger components permitted unauthenticated remote code execution, triggering mass scanning and exploitation across billions of enterprise cloud servers by nation-state actors and ransomware syndicates worldwide.