The attack campaigns appear to be exploiting CVE-2021-21974 for which a patch has been available since February 23, 2021. Systems running ESXi versions 7.0, 6.7 and 6.5 are currently being targeted and pose the greatest threat.
The OpenSSL V3 Vulnerabilities project announced details of vulnerabilities that exist in versions of the OpenSSL software versions earlier than version 3.0.7. They have released OpenSSL Version 3.0.7 to address these security vulnerabilities. BigFix can address and speed vulnerability remediation.
BigFix has remediation and mitigation fixlets available and has already published these for all the supported Linux Operating Systems. For more information, read this blog.
CISA has created a list of known vulnerabilities or KEV to safeguard federal infrastructure from cyber attacks. Know more about Exploited Vulnerabilities
Google Chrome and Microsoft Edge are forcing both companies to push emergency updates to address this critical issue. For more information, read this blog.
Apache Log4j has been embedded in hundreds of Internet services and products from companies worldwide, including Apple, Amazon, etc. Read to know more.