Kevin Beaumont · @GossiTheDog
25893 followers · 1190 posts · Server cyberplace.social

If you see this report and think it is talking about , it isn't - the incident MSTIC are talking about here happened in February.

Also, patch . microsoft.com/en-us/security/b

#capita #log4shell

Last updated 2 years ago

ITSEC News · @itsecbot
1119 followers · 33137 posts · Server schleuss.online

Log4Shell, a critical vulnerability discovered in December 2021 and officially tracked as CVE-2021-44228, has had a long-lasting impact, prompting enterprises to adopt software composition analysis and secure supply chain management practices. Despite receiving patches and widespread attention, it remains a common cause for security breaches a year later. csoonline.com/article/3684108/ -44228

#log4shell #cve2021 #softwarecompositionanalysis #securesupplychainmanagement

Last updated 3 years ago

Matthias Stürmer · @maemst
621 followers · 163 posts · Server swiss.social

Heute gehen die Präsentationen der @unibern Studierenden der Vorlesung weiter: Auf der Agenda stehen faire Notebooks (?), , Social Crediting System in China, Open Source Forks und viele weitere Themen. Hier live ab 9:15h oder später als Aufzeichnung: bbb.ch-open.ch/b/mat-dxn-qli-s - Übersicht aller Präsentationen:
digitale-nachhaltigkeit.unibe.

#digitalenachhaltigkeit #log4shell

Last updated 3 years ago

INNOQ · @innoq
387 followers · 62 posts · Server innoq.social

🎄Heute vor genau einem Jahr haben wir im Adventskalender von berichtet… Doch wie hat sich die Situation seither entwickelt? innoq.com/de/podcast/023-secur

#log4shell

Last updated 3 years ago

Nic Wise · @fastchicken
162 followers · 148 posts · Server mastodon.nz
Ian Barker · @iandbarker
22 followers · 32 posts · Server newsie.social
jessehouwing :verified: · @jessehouwing
30 followers · 16 posts · Server hachyderm.io

In case you're still on 2020 or older (Team Foundation Server), and want your Search feature to be truly secure, start planning your upgrade to Azure DevOps Server 2022 now and bring the embedded Elastic Search to 7.17.5.

jessehouwing.net/azure-devops-

#azuredevopsserver #log4j #log4shell #devops #azure #tfs

Last updated 3 years ago

gesualdo :redhat: · @gesualdo
51 followers · 256 posts · Server mastodon.uno

@ Csirt_it

: proseguono le attività di sfruttamento delle note vulnerabilità, presenti nei prodotti che implementano la libreria , tramite l’utilizzo del motore di scripting

t.co/HEtQxwQkcC

#NASH #javascript #log4j #log4shell

Last updated 3 years ago

MrsYisWhy · @chubirka
4 followers · 26 posts · Server hachyderm.io

HackRead: An Iranian APT group accessed the domain controller of a US Federal agency by exploiting the vulnerability, CISA has revealed.

Details: hackread.com/log4shell-iran-ha

#log4shell #security #vulnerability #log4j #iran #cybersecurity

Last updated 3 years ago

ITSEC News · @itsecbot
856 followers · 32559 posts · Server schleuss.online

Dangerous hole in Apache Commons Text – like Log4Shell all over again - Third time unlucky. Time to put your patching boots on again... nakedsecurity.sophos.com/2022/ -2022-42889

#log4j #apache #log4shell #vulnerability #cve #apachecommonstext #stringinterpolation

Last updated 3 years ago

Gonçalo Valério · @dethos
295 followers · 1159 posts · Server s.ovalerio.net
ITSEC News · @itsecbot
856 followers · 32559 posts · Server schleuss.online

8 months on, US says Log4Shell will be around for “a decade or longer” - When it comes to cybersecurity, ask not what everyone else can do for you... nakedsecurity.sophos.com/2022/ .txt

#dhs #csrb #log4j #malware #log4shell #security #vulnerability

Last updated 3 years ago

· @redfrog
2604 followers · 57205 posts · Server mamot.fr

The "hotpatch" released by Web Services (AWS) in response to the vulnerabilities could be used for container escape and privilege escalation, allowing an attacker to take control of the underlying host.

Read details: thehackernews.com/2022/04/amaz

#hacking #infosec #log4shell #amazon

Last updated 3 years ago

hellosct1@mamot.fr · @hellosct1
151 followers · 1090 posts · Server mamot.fr

Vous pensez avoir échappé à la faille , ---> ERREUR… j’en ai parlé cette semaine dans ma présentation

#log4j #log4shell #devsecops #cybersecurity #cybersécurité

Last updated 4 years ago

ITSEC News · @itsecbot
856 followers · 32557 posts · Server schleuss.online
Olivier Duquesne aka DaffyDuke · @daffyduke
485 followers · 37712 posts · Server mamot.fr

RT @newsoft
A Rennes, il y a désormais une rue consacrée à la faille 😉

#trolldi #log4shell

Last updated 4 years ago

ITSEC News · @itsecbot
856 followers · 32557 posts · Server schleuss.online

FTC threatens “legal action” over unpatched Log4j and other vulns - Remember the Equifax breach? Remember the $700m penalty? In case you'd forgotten, here's ... nakedsecurity.sophos.com/2022/ &order

#ftc #log4j #equifax #privacy #patching #dataloss #log4shell #law #vulnerability

Last updated 4 years ago

Jan Korbel 🇨🇿 🏴‍☠️ · @jackc
170 followers · 1960 posts · Server kompost.cz

#security #log4shell

Last updated 4 years ago