Skip to main content
Log4j

Log4j

SoftwareWikipedia

Search complete. 43 mentions across 22 episodes found for "Log4j".

Sep 19, 2026

Lester NicholsGUEST
26:23
I mean, how many different supply chain attacks that have we seen in the past few years? And they've only been getting faster.
Lester NicholsGUEST
26:34
I mean, it started with SolarWinds and went to Log4J.
Lester NicholsGUEST
26:37
And then you had the...
Lester NicholsGUEST
26:40
What was it? Seven zip binary attack.
Jonathan BakerHOST
71:30
And I'm doing it more for bugs rather than security, but it's definitely a good spin on it, which is WAF rule automation and things along those lines that can start to put in the WAF rules in place until you have time to fix your code base or something like that.
Jonathan BakerHOST
71:45
So I'm imagining something like Log4J again out there where Log4J went out, it would tell you what's being attacked and you would press a button that does it.
Jonathan BakerHOST
71:54
Now, all the cloud vendor, all the vendors when log4j came out all just had WAF rules available
Ryan LucasHOST
72:01
yeah added the WAF rule classification yeah where you just now it's checkbox
DavidGUEST
34:28
If you need an update within a day, 24, 48 hours, we've proven in the past.
DavidGUEST
34:34
When Log4J came out, we had a command line mitigation for the environment variable within hours.
DavidGUEST
34:40
It's like, here's how you mitigate it.
DavidGUEST
34:42
And then we had a patch within a day.
Mark LambertGUEST
11:23
So you get a signal that tells you you've got an active exploit, you have 24 hours to get your ducks in a row and get that information out, right? So you need accelerated automation, you need signals that tell you this information, you need to be able to correlate the information, you need to be able to understand the blast radius, how many versions of your product are impacted, what products are intended.
Mark LambertGUEST
11:50
And just think back to Log4j, that wasn't a million years ago, right? So, you know, Log4j, people are still scrambling to try and fix the problem, but finding the problem took days.
Mark LambertGUEST
12:02
Now you've got to actually understand the blast radius in 24 hours.
Mark LambertGUEST
12:05
Now there is a second day, or second time, should I say, which is 72 hours.
Adrian SanabriaHOST
7:24
I was just talking about that earlier today with somebody.
Adrian SanabriaHOST
7:27
It was kind of shocking to me how few breaches we had come out of Log4J, given that everybody had it in their environment, right? So very interesting.
Adrian SanabriaHOST
7:36
And I think a lot of it was that people had decent egress rules for their server environment.
Adrian SanabriaHOST
7:41
So that outbound call to pull down the next stage of the attack payload didn't succeed.
Adrian SanabriaHOST
7:24
I was just talking about that earlier today with somebody.
Adrian SanabriaHOST
7:27
It was kind of shocking to me how few breaches we had come out of Log4J, given that everybody had it in their environment, right? So very interesting.
Adrian SanabriaHOST
7:36
And I think a lot of it was that people had decent egress rules for their server environment.
Adrian SanabriaHOST
7:41
So that outbound call to pull down the next stage of the attack payload didn't succeed.
Snehal AntaniGUEST
6:30
Log4Shell being a great example.
Snehal AntaniGUEST
6:32
Um, just because you got the Log4j JAR file doesn't mean it's a problem.
Adrian SanabriaHOST
6:35
Right.
Snehal AntaniGUEST
6:35
You could have had a egress rule in place that blocked the outbound RMI call or so on and so forth.
Adrian SanabriaHOST
7:56
Mm-hmm
Snehal AntaniGUEST
7:56
...
Snehal AntaniGUEST
7:56
some bean counter with some spreadsheet said, "No, no, no, you've got these JAR files over here." Even though you put in that egress rule, they still had to burn their time.
Adrian SanabriaHOST
8:04
Yeah.
Artificial IntelligenceNARRATOR
1:03
And the hardest part for most organizations wasn't applying the fix once they knew where it was needed.
Artificial IntelligenceNARRATOR
1:08
It was figuring out where it was needed because Log4j wasn't something teams had installed on purpose.
Artificial IntelligenceNARRATOR
1:14
It was buried three, four, five dependencies deep, pulled in transitively by some other library nobody remembered choosing.
Artificial IntelligenceNARRATOR
1:22
That's the thesis of this piece.
Artificial IntelligenceNARRATOR
4:13
They're targeting a dependency or the pipeline that builds and signs your code, which you trust by default.
Artificial IntelligenceNARRATOR
4:19
Log4Shell is the first pattern, a vulnerability in a component so widely embedded that almost nobody who was exposed had made a direct conscious decision to use it.
Artificial IntelligenceNARRATOR
4:29
Log4j is a logging library, the kind of dependency that ships inside other dependencies, inside vendor products, inside your own code, often without anyone on a given team knowing it's there.
Artificial IntelligenceNARRATOR
4:40
That's precisely why an inventory after-the-fact response took so long.
Papani OkaiGUEST
0:20
Yeah, you can say you're not gonna hire any engineers, but you're not gonna be able to scale because people are gonna burn the hell out, right?
Martin ReynoldsHOST
0:27
Where exactly are the seniors for 2030 coming from? And I mentioned the Log4j, and, uh-
Papani OkaiGUEST
0:34
Everybody was like, "What the hell?" And it just screwed up everybody.
Papani OkaiGUEST
0:39
[laughs]

38 MINS LATER

Martin ReynoldsHOST
38:15
[laughs]
Papani OkaiGUEST
38:15
But that was the whole point of dependency management.
Papani OkaiGUEST
38:18
That's why we use Maven, right? It's like, you know, I want this function, give it to me so I can move on, right? And, you know, it's funny, was it three years ago we had the Log4j issue? And look at what it did [laughs] to a whole industry, whole companies.
Papani OkaiGUEST
38:31
Log, Log4j.
Lorena RuizNARRATOR
3:48
The AI slop era ends.
Lorena RuizNARRATOR
3:51
Early adopters who chased safety over safety and plastered over their tech stacks with mismanaged commoditized AI will face public embarrassment akin to the Log4j fallout.
Lorena RuizNARRATOR
4:04
Twenty twenty-six will be the year the shortcuts get exposed.
Lorena RuizNARRATOR
4:09
Trust and innovation finally converge.

12 more episodes mention Log4j.

Create an account to see the whole feed, search across every transcript, and follow the entities you care about.

We value your privacy

We use cookies to understand how you use our platform and to improve your experience. Click “Accept All” to consent, or “Decline non-essential” to opt out of non-essential cookies. Read our Privacy Policy.