Spring4Shell Flaw Is Now Being Used To Spread This Botnet Malware
Researchers at security firms Trend Micro and Qihoo 360 watched the attacks emerge almost as soon as the bug become public. While Spring4Shell isn’t quite as dire as Log4Shell, most security firms, the US Cybersecurity and Infrastructure Security Agency (CISA), and Microsoft are urging developers to patch it if they’re using Java Development Kit (JDK) from version 9.0 and upwards if the system is also using Spring Framework versions 5....