Log4j RCE Alert Debated, LockBit Targets U.S. Bank, Minimus Shuts Down
An Apache Log4j 2 vulnerability sparked concern this week after reports surfaced of a critical remote code execution flaw, but the project's developers pushed back, labeling the issue a "known security non-finding." While they confirmed RCE was theoretically possible under specific circumstances, maintainers warned that volunteer bandwidth is better spent on issues with real-world impact. The episode revives memories of Log4Shell, the catastrophic Log4j bug that compromised countless enterprise systems and remains a benchmark for supply-chain risk.
U.S. Bancorp is responding to LockBit ransomware claims that allegedly involved stolen bank data, but says the incident traces back to a fourth-party provider outside its own environment. The bank reports no evidence of compromise to its systems, networks, or data repositories, even as LockBit threatened to publish the allegedly stolen material. Separately, hardened container image provider Minimus is shutting down less than a month after appearing at Black Hat, citing an untenable business climate despite a $51 million raise in 2025. Echo quickly announced it had acquired the company and its technology.
New research underscores the scale of exposed cloud credentials. Truffle Security identified more than 700 still-active corporate AWS keys with full account control among 10,616 keys exposed between 2022 and 2026. Intruder, meanwhile, scanned 3.5 million hosts and uncovered 28,000 exposed Git repositories containing over 400 AWS keys, 107 Stripe keys, 123 OpenAI keys, 80 Telegram tokens, and 17 GitHub PATs, several still valid. Zimperium reported 30 mobile malware families actively targeting more than 800 banking and fintech apps across 44 EMEA countries, with attackers increasingly using AI for localized lures and overlays. Researchers and end users alike can review their own exposure using a password strength checker and an email breach checker to see whether credentials have surfaced in public leaks. Troy Hunt also confirmed that a substantial portion of data tied to the Carhartt breach turned out to be fabricated, a reminder that stolen-data dumps often contain padding designed to inflate impact claims.
Mitigation guidance from each story is consistent: patch Log4j promptly despite the disputed severity rating, scrutinize fourth-party provider relationships against ransomware extortion attempts, rotate any long-lived cloud API keys, and audit Git repositories for hardcoded secrets. Organizations running internet-facing services should also run a SSL/TLS checker to confirm encryption configurations have not drifted from policy.