Vulnerability will remain a "significant" threat for years to come and highlighted the need for more public and private sector support for open source software ecosystem, Cyber Safety Review Board says.
Log4Shell highlighted weaknesses in the software supply chain, especially when it comes to weaknesses in the security of web applications. This article explores the lessons of Log4Shell and how they can influence security strategies moving forward.
A critical exploit in widespread Java library has been found, disrupting much of the internet as server admins scramble to fix it. The vulnerable component, log4j, is used everywhere as an included library, so you will need to check your servers and make sure they’re updated.