News & Analysis | No. 311

1 · Daniel Miessler · Dec. 13, 2021, 3:05 p.m.
SECURITY NEWS The log4j (Log4Shell) Situation  What Happened: A 0-day exploit was released for log4j—a Java-based logging utility that’s part of the Apache Logging Services project. It is used by millions of systems worldwide to process logs.  Impact: People are comparing this to Heartbleed, but it’s much worse in a number of ways. While Heartbleed affected all TLS implementations, and this…...