Log4j's Log4Shell Vulnerability: One Year Later, It's Still Lurking
Despite mitigation, one of the worst bugs in internet history is still prevalent—and being exploited.
Stay updated with breaking news from Dan Lorenc. Get real-time updates on events, politics, business, and more. Visit us for reliable news and exclusive interviews.
Despite mitigation, one of the worst bugs in internet history is still prevalent—and being exploited.
Here's a comprehensive look at some of the lesser-known, but no less serious, types of software supply chain attacks.
The vulnerability in OpenSSL that forced the project's leaders to issue a security patch on Tuesday isn't as bad as initially feared, with the hole's severity shifted from "critical" to "high." Still, experts say infosec leaders need to take it seriously. OpenSSL 3.07 fixes a buffer overrun vulnerability in version 3.0 that can be triggered
With so much unknown about what developers and systems rely on to be productive — and what those tools and code bases rely on in turn — it’s time to get serious about securing the software supply chain.
With so much unknown about what your developers and systems rely on to be productive — and what those tools and code bases rely on in turn — it’s time to get serious about securing your software supply chain.