Authorities warned that the Apache Log4j flaw was being exploited at scale as defenders struggled to identify the vulnerable library across widely used applications and services. The issue affected many popular products, exploitation attempts rose sharply, and domestic organizations were also targeted. Administrators were urged to update affected Log4j deployments immediately, with guidance pointing to version 2.17.0, while noting that remediation was slowed by the difficulty of locating the component, validating fixes, and rolling out updates.
A separate alert said a critical zero-day in SAP NetWeaver Visual Composer Framework 7.xx allowed arbitrary code execution on SAP application servers and could lead to full server compromise and lateral movement. The vulnerable component was described as trivial to exploit when exposed to the internet, and officials said attacks in Finland had begun weeks before public disclosure. Organizations were told to apply SAP’s fixes at once, inspect systems for compromise by reviewing server files and HTTP requests to the metadatauploader endpoint, and treat any internet-exposed server that was not promptly patched and investigated as potentially compromised.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
On 2025-04-30, Traficom published an alert about a critical actively exploited zero-day in SAP NetWeaver Visual Composer Framework 7.xx. It urged organizations to patch immediately, investigate exposed systems for compromise, and presume unpatched internet-exposed servers may be compromised.
Finland’s National Cyber Security Centre said it is aware of exploitation of the SAP NetWeaver Visual Composer vulnerability in Finland, with the first attacks occurring in mid-March 2025. The flaw can enable arbitrary code execution and full server compromise when the vulnerable component is exposed to the network.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
kyberturvallisuuskeskus.fi
Open sourcekyberturvallisuuskeskus.fi
Open sourcekyberturvallisuuskeskus.fi
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.