Log4j hearing: 'open source is not the problem'
Cisco, Palo Alto, Apache executives look at Log4j vulnerability responses, and the likelihood of future issues.
Stay updated with breaking news from Brad Arkin. Get real-time updates on events, politics, business, and more. Visit us for reliable news and exclusive interviews.
Cisco, Palo Alto, Apache executives look at Log4j vulnerability responses, and the likelihood of future issues.
Open source software underpins the nation’s digital infrastructure, Apache President David Nalley told senators. But efforts to keep it safe and patched need a boost — and the federal government can help.
Cisco, Palo Alto, Apache execs look at Log4j vulnerability responses, and the likelihood of future issues.
Apache Software Foundation president David Nalley said that the log4j bug was resilient to automated tools and seven years of contributors auditing the code, because the problem more stemmed from the software ecosystem: the complex interaction of multiple systems combined with Java code dating back to the 1990s.
Cybersecurity experts struggled Tuesday to answer lawmakers' basic questions about the danger of a flaw in the open-source logging platform Apache Log4J that could plague computer network defenders for years to come.