Log4Shell
TIL about the breakdown of the Log4Shell shared library.
Innerworkings
Tom Kellermann, a member of President Obama's Commission on Cyber Security
Affected commercial services
The Log4Shell vulnerability's disclosure received strong reactions from cybersecurity experts.
Cybersecurity company Tenable stated
Quote
Log4j is foundational software. This 20+ year-old Java logging library quietly powers system events in applications worldwide, like user logins and calculation results. But this small piece of software had quietly become a dependency in thousands of projects across the Java ecosystem.
Opinion & reaction
Analysis
Open Source programming is a thankless job
Be nice to Open Source programmers
Don't be a dick!
Be nice to programmers
Give them Love
Z
#Log4Shell #TIL #programming #data #Java #exploit #ZeroDay #technology #Enterprise #networking #OpenSource #POSIX #BSD #freeBSD #ghostBSD #openBSD #Linux #win64 #mac #history #reading
Sources:
#Log4Shell didn’t break #Java — it revealed it. @spoole167 shows how decades of “it still works” thinking left the Java #SupplyChain exposed & why maintenance is now a legal obligation.
See what regulators expect from Java teams: https://javapro.io/2026/01/08/the-myth-of-stability-javas-software-supply-chain-after-log4shell/
🔍 CVE-2021-44228 (Log4Shell)
Three years later, Log4Shell is still being scanned for on the internet every single day.
Why?
Legacy Java apps
Forgotten containers
Vendors who never backported fixes
👉 Breakdown & mitigation:
https://cvedatabase.com/cve/CVE-2021-44228
#CVE #Log4Shell #CyberSecurity
Who is responsible for your #Java dependencies when upstream disappears? @spoole167 traces how #Log4Shell exposed the reality of #OpenSource maintenance and why SBOMs, CRA & NIS2 changed the rules.
Learn what “responsibility” means now: https://javapro.io/2026/01/08/the-myth-of-stability-javas-software-supply-chain-after-log4shell/
Still calling unmaintained #Java libraries “stable”? After #Log4Shell, that myth collapsed. @spoole167 explains why Java’s software #SupplyChain is fragile & why regulation now forces real accountability.
Understand what changed (and why it matters): https://javapro.io/2026/01/08/the-myth-of-stability-javas-software-supply-chain-after-log4shell/
For my fellow Log4j victims celebrating 4 years #log4shell PTSD: CVE-2025-68161
"The Socket Appender in Apache Log4j Core versions 2.0-beta9 through 2.25.2 does not perform TLS hostname verification of the peer certificate, even when the verifyHostName configuration attribute or the log4j2.sslVerifyHostName system property is set to true."
https://logging.apache.org/security.html#CVE-2025-68161
(It's not that terrible. Seeing the string "log4j" just makes me twitch. :-)