logo

Episode 232: Log4j Won’t Go Away (And What To Do About It.)

ID: 33462247-262c-5678-8011-19955bea3004

STIX ID: report--33462247-262c-5678-8011-19955bea3004

Feed Name: Security Ledger

Threat Score
90/100

Date Published: 2021-12-17

Date Updated: 2026-04-26

Author: Paul Roberts

...
...

This podcast transcript explains the critical Log4j (Log4Shell) remote code execution vulnerability affecting the Log4j Java logging library, its pervasive presence across thousands of software packages and major services (including Minecraft, iCloud, Twitter), evidence of active scanning and exploitation by threat actors, and the resulting large-scale remediation challenge; it emphasizes mitigation steps (patches, disabling unsafe features, WAF rules) and the need for software bills of materials (SBOMs) to manage supply-chain risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.