← Back to feed
Vulnerabilities & PatchesEmerging1 sourceJan 4, 2022 · 23:18via Embrace The Red (AI agent security)

Log4Shell and Request Forgery Attacks

Brief

The last weeks of 2021 got quite interesting for security professionals and software engineers.

Apache’s log4j library and its now prominent Java Naming and Directory Interface support , which enables easy remote code execution, made the news across the industry.

What makes Log4Shell scary is the widespread adoption of the Log4j library amongst Java applications, and the ease of remote exploitation.

A dangerous combination.

Patches got released, bypasses were discovered more patches were released and so forth.

Read more on Embrace The Red (AI agent security)