From zdnet.com
![](https://www.zdnet.com/a/img/resize/7967c35572c0e3c8ae19ffdfcbbe691e4d648170/2022/01/06/303cf815-4713-44b1-a898-31b9630d1d75/shutterstock-2091644743.jpg?width=770&height=578&fit=crop&auto=webp)
Initial access broker group, Prophet Spider, has been found exploiting the Log4J vulnerability in VMware Horizon, according to a new report from researchers with BlackBerry Research & Intelligence and Incident Response teams.
Even though VMware released a patch in December and has published extensive guidance on how to mitigate the issue, many implementations remain unpatched.