Research Two years on, 1 in 4 apps still vulnerable to Log4Shell Lack of awareness still blamed for patching apathy despite it being among most infamous bugs of all time
Software US government extends software security deadline because vendors aren't ready This from the Administration that made infosec a priority
Security T-Mobile US suffers second data theft within months Also, Capita's buckets are leaking, ransomware attackers deliver demands via emergency alert, and this week's critical vulns
Software SBOMs should be a security staple in the software supply chain Know the ingredients before mixing the code. Oh and pay open source maintainers for goodness' sake...
Security Open source software has its perks, but supply chain risks can't be ignored While app development is faster and easier, security is still a concern
CSO Miscreants sure do love ransacking cloud networks, more so than before Thanks for putting all your data in one basket
Security Iranian cyberspies exploited Log4j to break into a US govt network It's the gift to cybercriminals that keeps on giving
Research China's infosec researchers obeyed Beijing and stopped reporting vulns ... or did they? Report finds increase in anonymous vuln reports
Security Time from vulnerability disclosures to exploits is shrinking Palo Alto Networks Unit 42 incident response team warns of patch speedups
Patches Homeland Security warns: Expect Log4j risks for 'a decade or longer' Great, another thing that's gone endemic
Security That critical vulnerability might not be the first you should patch Startup Rezilion suggests enterprises should change prioritization strategies
CSO Software patching must work like car safety recalls, says US cyber boss Adds infosec regulation coming to more industries but with a light touch, more collaboration
Patches AWS's Log4j patches blew holes in its own security Remote code exec is so 2014. Have this container escape and privilege escalation, instead
Security VMware Horizon platform pummeled by Log4j-fueled attacks Miscreants deployed cryptominers, backdoors since late December, Sophos says
Security Triton malware still a threat to energy sector, FBI warns Plus: Ransomware gangster sentenced, Dell patches more Log4j bugs, and cartoon apes gone bad
Security Satellite comms networks on alert after US govt warning Plus: Security teams burning out, more Conti leaks analysis, and Log4j still plagues enterprises
Security Linux botnet exploits Log4j flaw to hijack Arm, x86 systems On a plus side, their code's not very good
Virtualization VMware fixes vSphere release it pulled, sorts out Log4j while it's at it Driver drama is done, new dev practices should prevent repeats, says Virtzilla
Security Sophos: Log4Shell would have been a catastrophe without the Y2K-esque mobilisation of engineers Anti-malware biz weighs in on one of the worst security flaws of recent times
Software Open source isn't the security problem – misusing it is Security is a process, not a product
Security Four million outdated Log4j downloads were served from Apache Maven Central alone despite vuln publicity blitz It's not as though folks haven't been warned about this
Security You better have patched those Log4j holes or we'll see what a judge has to say – FTC Apply fixes responsibly in a timely manner or face the wrath of Lina Khan
Security Alibaba Cloud slapped by Chinese ministry for mishandling Log4j Beijing's not saying what cloudy contender did wrong
Security Belgian defence ministry admits attackers accessed its computer network by exploiting Log4j vulnerability Perpetrators' ID unknown, however
Columnists Log4j and Omicron: Brothers in harm, mothers of invention That which does not kill us can still ruin our Christmas
Security Bad things come in threes: Apache reveals another Log4J bug Third major fix in ten days is an infinite recursion flaw rated 7.5/10
Science Mars helicopter mission (which Apache says is powered byLog4j) overcomes separate network glitch to confirm new flight record Ingenuity clocks up 30 minutes flying in the Martian skies
Security As CISA tells US govt agencies to squash Log4j bug by Dec 24, fingers start pointing at China, Iran, others Microsoft says cyber-spies linked to Beijing, Tehran are getting busy with security flaw along with world + dog
Applications CompSci boffins claim they can recreate missing lines in log files 'Event imputation' draws on lots of other sources to fill in gaps
Security Apache takes off, nukes insecure feature at the heart of Log4j from orbit with v2.16 Now open-source logging library's JNDI disabled entirely by default, message lookups removed
Software Log4j doesn't just blow a hole in your servers, it's reopening that can of worms: Is Big Biz exploiting open source? Would more money have prevented this security flaw? Would the cash be useful in other ways anyway?
Security Log4j RCE latest: In case you hadn't noticed, this is Really Very Bad, exploited in the wild, needs urgent patching This might be the bug that deserves the website, logo and book deal
Security Log4j RCE: Emergency patch issued to plug critical auth-free code execution hole in widely used logging utility Prepare to have a very busy weekend of mitigating and patching