Connect with us

Telecom

Sophos Detects How Cyberattackers Are Exploiting Apache Log4Shell Vulnerability to Exploit Unpatched Systems

Published

on

Kindly share this post

Following the reporting of the Apache Log4Shell vulnerability, Sophos has provided new threat intelligence on how cyberattackers are already exploiting or attempting to exploit unpatched systems.

The threat intelligence as detailed in the SophosLabs Uncut report, Log4Shell Hell: Anatomy of an Exploit Outbreak, shows that Sophos is seeing a rapid uptick in attacks exploiting or attempting to exploit this vulnerability, with hundreds of thousands of attempts detected so far.

The report also indicated that Cryptomining botnets are among the earliest “attack” adopters; botnets focus on Linux server platforms, which are particularly exposed to this vulnerability.

Sophos has also seen attempts to extract information from services, including Amazon Web Services keys and other private data.

The company said it observed that attempts to exploit network services start by probing for different types.

Advertisement

Around 90 percent of the probes Sophos detected were focused on the Lightweight Directory Access Protocol (LDAP.) A smaller number of probes targeted Java’s Remote Interface (RMI,) but Sophos researchers noted that there seem to be a larger variety of unique RMI-related attempts

Sophos said it expects adversaries to intensify and diversify their attack methods and motivations in the coming days and weeks, including the possibility of leveraging for ransomware.

According to Sean Gallagher, senior threat researcher at Sophos, in the SophosLabs Uncut report issued on Dec. 9, Sophos has detected hundreds of thousands of attempts to remotely execute code using the Log4Shell vulnerability.

“Initially, these were Proof-of-Concept (PoC) exploit tests by security researchers and potential attackers, among others, as well as many online scans for the vulnerability. This was quickly followed by attempts to install coin miners, including the Kinsing miner botnet.

“The most recent intelligence suggest attackers are trying to exploit the vulnerability to expose the keys used by Amazon Web Service accounts.

Advertisement

“There are also signs of attackers trying to exploit the vulnerability to install remote access tools in victim networks, possibly Cobalt Strike, a key tool in many ransomware attacks.

“The Log4Shell vulnerability presents a different kind of challenge for defenders. Many software vulnerabilities are limited to a specific product or platform, such as the ProxyLogon and ProxyShell vulnerabilities in Microsoft Exchange. Once defenders know what software is vulnerable, they can check for and patch it.

“However, Log4Shell is a library that is used by many products. It can therefore be present in the darkest corners of an organization’s infrastructure, for example any software developed in-house. Finding all systems that are vulnerable because of Log4Shell should be a priority for IT security.

“Sophos expects the speed with which attackers are harnessing and using the vulnerability will only intensify and diversify over the coming days and weeks. Once an attacker has secured access to a network, then any infection can follow.

“Therefore, alongside the software update already released by Apache in Log4j 2.15.0, IT security teams need to do a thorough review of activity on the network to spot and remove any traces of intruders, even if it just looks like nuisance commodity malware”, Gallagher added,

Advertisement

New and additional information on how Log4Shell works is also available in the Sophos Naked Security article, Log4Shell Explained – How it Works, Why You Need to Know, and How to Fix It, by Paul Ducklin.

According to Paul Ducklin, principal research scientist at Sophos: “Technologies including IPS, WAF and intelligent network filtering are all helping to bring this global vulnerability under control.

“But the staggering number of different ways that the Log4Shell ‘trigger text’ can be encoded, the huge number of different places in your network traffic that these strings can appear, and the wide variety of servers and services that could be affected are collectively conspiring against all of us.

“The very best response is perfectly clear: patch or mitigate your own systems right now. Our article provides practical advice that explains how the vulnerability works, why it works, what it can do, and how to fix it.”

Sophos threat intelligence experts are continuing to monitor Log4Shell.

Advertisement

Kindly share this post

Ugo Onwuaso is an ICT enthusiast. He believes technology should be used for general good. He holds a Master of Public Administration (MPA) degree from the Lagos state University. Dear Reader, Your support matters. But we believe that technology makes life more exciting and helps improve the lives of people around Nigeria and indeed the world. That is why, we have devoted our energy to independent reportage of technology and finance and how they affect lives. Our incisive and analytical view of how technology news affects the daily life help individuals and organizations make up their minds. Quality journalism costs money. Today, we're asking that you support us to do more. Kindly support our effort to deliver technology and finance journalism to everyone in the world. Donate as little as N1,000. Bank transfers can be made to: UBA Plc 1017156876 Communication Week Media Ltd

Telecom

NCC Asks Telcos to Make Budgetary Provisions for Cybersecurity

Published

on

Kindly share this post

Nigerian Communications Commission (NCC) has directed telecommunications operators to make dedicated budgetary provisions for cybersecurity as part of efforts to strengthen the resilience of Nigeria’s communications infrastructure against the growing wave of cyber threats.

NCC Asks Telcos to Make Budgetary Provisions for Cybersecurity

 

The directive forms part of the Commission’s Cyber Resilience Framework for the Nigerian Communications Sector (CRF-NCS), which introduces new governance, risk management and operational requirements aimed at safeguarding the country’s critical telecommunications infrastructure from increasingly sophisticated cyberattacks.

Under the framework, all licensed telecom operators are expected to establish formal cybersecurity governance structures, dedicate adequate financial resources to cyber resilience programmes, and integrate cybersecurity into their enterprise-wide risk management processes.

The Commission said operators must ensure cybersecurity investments are no longer treated as optional operational expenses but as strategic business priorities necessary to protect network infrastructure, customer information and the country’s digital economy.

Advertisement

According to the NCC, licensees are expected to allocate sufficient budgets to support cyber risk assessments, security technologies, staff training, incident response capabilities, continuous monitoring and compliance with regulatory requirements.

The framework also requires operators to designate senior executives responsible for cybersecurity oversight.

At the same time, boards of directors are expected to provide strategic direction and ensure adequate funding for cyber resilience initiatives.

Speaking on the need for a stronger cybersecurity regime during the unveiling of the framework, Abraham Oshadami, executive commissioner, Technical Services, NCC,  said, “Given the increasing digitalisation of services, the rapid growth of data exchange, and the sophisticated nature of modern cyber threats, the need for a robust, adaptive and inclusive cybersecurity framework has become more urgent.”

He added, “Both state and non-state actors are targeting essential sectors—including ours—through coordinated cyber and physical attacks. These attacks frequently target control systems and data integrity, underscoring the critical risks posed to operational technology (OT), especially in our sector.”

Advertisement

“As cyber threats evolve, they endanger not only system performance but also human safety, amplifying the severity and consequences of disruptions to vital communications infrastructure. Cybersecurity now encompasses human safety and must address the real risk to people’s lives when a system is attacked or compromised.”

The Commission further stated that operators are required to develop comprehensive cybersecurity implementation plans, conduct periodic risk assessments, establish business continuity and disaster recovery procedures, and regularly test their cyber defence capabilities.

In addition, the framework makes cyber incident reporting compulsory. Licensees must inform the NCC’s CSIRT of any major cybersecurity breach within four hours of discovery, and provide a thorough post-incident analysis after mitigation is complete.

 

Advertisement

Kindly share this post
Continue Reading

Telecom

Glo Leads Internet Growth Figures in Nigeria for May

Published

on

Kindly share this post

Digital solution provider, Globacom has recorded the highest Internet subscriber growth among Nigeria’s major telecom companies for the month of May.

Data from the Nigerian Communications Commission, NCC, Nigeria’s total Internet users increased to 157 million in May, up from 154.3 million in April. That is a growth of 2.67 million users in one month.

Globacom led the market by adding about 1.2 million new Internet subscribers. This means Glo was responsible for almost half of all new Internet users in May.

The company’s subscriber base grew from 15.5 million in April to 16.8 million in May. Airtel came second with 1.07 million new users, moving from 54.8 million to 55.8 million. MTN added 382,894 users to reach 83.5 million.

T2 Mobile, formerly 9mobile, recorded no growth for the second month in a row. Its subscriber base remained at 802,534. This is despite its roaming agreement with MTN, which was approved almost a year ago to help T2 customers use MTN’s network in areas with poor coverage.

Advertisement

Industry experts say Glo’s strong growth is due to its ongoing network upgrade. Since last year, the company has been building new base stations, expanding its fibre network, and adding thousands of new 4G sites across cities and rural areas.

The upgrades have improved voice and data quality for customers, while Globacom remain committed to providing better network experience and affordable Internet services to more Nigerians.

Kindly share this post
Continue Reading

Telecom

MTN Paid 600Bn in Taxes in H1 2026 – Kadri, MTN CFO

Published

on

Kindly share this post

MTN Nigeria’s half-year 2026 performance reflects more than revenue growth, highlighting the wider economic activity generated through tax payments, infrastructure investment and shareholder returns.

MTN Paid 600 Billion in Taxes in H1 2026 - Kadri, MTN CFO

Kadri, MTN CFO

Beyond its financial results, the telecommunications operator said it continues to channel substantial resources into expanding network infrastructure, meeting statutory obligations and delivering value across its stakeholder ecosystem.

The company disclosed that it paid more than ₦600 billion in taxes, customs duties, regulatory levies and other statutory obligations over the past year.

It also invested over ₦1.6 trillion in capital expenditure since January 2025 to expand network capacity and improve service quality, while declaring an interim dividend of ₦26 per share for shareholders.

Speaking on Arise News’ Global Business Report, MTN Nigeria’s Chief Financial Officer, Modupe Kadri, explained that the company’s earnings are shared across several stakeholders before returns reach investors. “For every one naira of revenue, about 24 kobo becomes profit.

“The government receives over ₦600 billion through taxes and levies, operating costs account for a significant portion of our revenue, and every participant within the ecosystem benefits from the value we create,” he said.

Advertisement

According to the Nigerian Communications Commission (NCC), telecommunications remains one of the largest contributors to Nigeria’s Gross Domestic Product, supporting digital financial services, education, healthcare, commerce and public services. Continued investment by operators has also been identified as critical to expanding broadband access and improving digital inclusion across the country.

Kadri noted that shareholder returns remain an important part of MTN’s capital allocation strategy, but stressed that they represent only one aspect of the company’s broader economic contribution.

“Even when we declare dividends, the government still receives withholding tax, while we continue investing heavily in our network because sustaining quality service requires ongoing capital commitment,” he said.

Kindly share this post
Continue Reading

Trending