Log4j
SoftwareWikipedia
43
MENTIONS
22
EPISODES
20
PODCASTS
Search complete. 43 mentions across 22 episodes found for "Log4j".
Sep 19, 2026
Thinking Like a Security Architect with Lester Nichols
L
26:23Lester NicholsGUEST
I mean, how many different supply chain attacks that have we seen in the past few years? And they've only been getting faster.
L
26:34Lester NicholsGUEST
I mean, it started with SolarWinds and went to Log4J.
L
26:37Lester NicholsGUEST
And then you had the...
L
26:40Lester NicholsGUEST
What was it? Seven zip binary attack.
371: MrBeast Bets on Gemini for Survival
J
71:30Jonathan BakerHOST
And I'm doing it more for bugs rather than security, but it's definitely a good spin on it, which is WAF rule automation and things along those lines that can start to put in the WAF rules in place until you have time to fix your code base or something like that.
J
71:45Jonathan BakerHOST
So I'm imagining something like Log4J again out there where Log4J went out, it would tell you what's being attacked and you would press a button that does it.
J
71:54Jonathan BakerHOST
Now, all the cloud vendor, all the vendors when log4j came out all just had WAF rules available
R
72:01Ryan LucasHOST
yeah added the WAF rule classification yeah where you just now it's checkbox
Holy Mythos, Batman! — CVEs, Incidents & Platform Security | CF Weekly 88
D
34:28DavidGUEST
If you need an update within a day, 24, 48 hours, we've proven in the past.
D
34:34DavidGUEST
When Log4J came out, we had a command line mitigation for the environment variable within hours.
D
34:40DavidGUEST
It's like, here's how you mitigate it.
D
34:42DavidGUEST
And then we had a patch within a day.
Episode 113 - The EU Cyber Resilience Act Countdown: Why U.S. Companies Can't Afford to Look Away
M
11:23Mark LambertGUEST
So you get a signal that tells you you've got an active exploit, you have 24 hours to get your ducks in a row and get that information out, right? So you need accelerated automation, you need signals that tell you this information, you need to be able to correlate the information, you need to be able to understand the blast radius, how many versions of your product are impacted, what products are intended.
M
11:50Mark LambertGUEST
And just think back to Log4j, that wasn't a million years ago, right? So, you know, Log4j, people are still scrambling to try and fix the problem, but finding the problem took days.
M
12:02Mark LambertGUEST
Now you've got to actually understand the blast radius in 24 hours.
M
12:05Mark LambertGUEST
Now there is a second day, or second time, should I say, which is 72 hours.
Safely exploiting vulnerabilities at scale, TVs attack privacy, and the news. - Snehal Antani - ESW #476
A
7:24Adrian SanabriaHOST
I was just talking about that earlier today with somebody.
A
7:27Adrian SanabriaHOST
It was kind of shocking to me how few breaches we had come out of Log4J, given that everybody had it in their environment, right? So very interesting.
A
7:36Adrian SanabriaHOST
And I think a lot of it was that people had decent egress rules for their server environment.
A
7:41Adrian SanabriaHOST
So that outbound call to pull down the next stage of the attack payload didn't succeed.
Safely exploiting vulnerabilities at scale, TVs attack privacy, and the news. - Snehal Antani - ESW #476
A
7:24Adrian SanabriaHOST
I was just talking about that earlier today with somebody.
A
7:27Adrian SanabriaHOST
It was kind of shocking to me how few breaches we had come out of Log4J, given that everybody had it in their environment, right? So very interesting.
A
7:36Adrian SanabriaHOST
And I think a lot of it was that people had decent egress rules for their server environment.
A
7:41Adrian SanabriaHOST
So that outbound call to pull down the next stage of the attack payload didn't succeed.
Safely exploiting vulnerabilities at scale, TVs attack privacy, and the news. - Snehal Antani - ESW #476
S
6:30Snehal AntaniGUEST
Log4Shell being a great example.
S
6:32Snehal AntaniGUEST
Um, just because you got the Log4j JAR file doesn't mean it's a problem.
A
6:35Adrian SanabriaHOST
Right.
S
6:35Snehal AntaniGUEST
You could have had a egress rule in place that blocked the outbound RMI call or so on and so forth.
A
7:56Adrian SanabriaHOST
Mm-hmm
S
7:56Snehal AntaniGUEST
...
S
7:56Snehal AntaniGUEST
some bean counter with some spreadsheet said, "No, no, no, you've got these JAR files over here." Even though you put in that egress rule, they still had to burn their time.
A
8:04Adrian SanabriaHOST
Yeah.
Log4Shell Is Almost Five Years Old. Most Teams Still Can't Answer "What's In Our Software?"
A
1:03Artificial IntelligenceNARRATOR
And the hardest part for most organizations wasn't applying the fix once they knew where it was needed.
A
1:08Artificial IntelligenceNARRATOR
It was figuring out where it was needed because Log4j wasn't something teams had installed on purpose.
A
1:14Artificial IntelligenceNARRATOR
It was buried three, four, five dependencies deep, pulled in transitively by some other library nobody remembered choosing.
A
1:22Artificial IntelligenceNARRATOR
That's the thesis of this piece.
A
4:13Artificial IntelligenceNARRATOR
They're targeting a dependency or the pipeline that builds and signs your code, which you trust by default.
A
4:19Artificial IntelligenceNARRATOR
Log4Shell is the first pattern, a vulnerability in a component so widely embedded that almost nobody who was exposed had made a direct conscious decision to use it.
A
4:29Artificial IntelligenceNARRATOR
Log4j is a logging library, the kind of dependency that ships inside other dependencies, inside vendor products, inside your own code, often without anyone on a given team knowing it's there.
A
4:40Artificial IntelligenceNARRATOR
That's precisely why an inventory after-the-fact response took so long.
The Real Reason SpaceX Paid $60B for Cursor
P
0:20Papani OkaiGUEST
Yeah, you can say you're not gonna hire any engineers, but you're not gonna be able to scale because people are gonna burn the hell out, right?
M
0:27Martin ReynoldsHOST
Where exactly are the seniors for 2030 coming from? And I mentioned the Log4j, and, uh-
P
0:34Papani OkaiGUEST
Everybody was like, "What the hell?" And it just screwed up everybody.
P
0:39Papani OkaiGUEST
[laughs]
38 MINS LATER
M
38:15Martin ReynoldsHOST
[laughs]
P
38:15Papani OkaiGUEST
But that was the whole point of dependency management.
P
38:18Papani OkaiGUEST
That's why we use Maven, right? It's like, you know, I want this function, give it to me so I can move on, right? And, you know, it's funny, was it three years ago we had the Log4j issue? And look at what it did [laughs] to a whole industry, whole companies.
P
38:31Papani OkaiGUEST
Log, Log4j.
“Electronic Prescriptions Can Help Mitigate VAT Impact on Insurers” by Bruno Valera, CEO, Medikit (AA2589)
L
3:48Lorena RuizNARRATOR
The AI slop era ends.
L
3:51Lorena RuizNARRATOR
Early adopters who chased safety over safety and plastered over their tech stacks with mismanaged commoditized AI will face public embarrassment akin to the Log4j fallout.
L
4:04Lorena RuizNARRATOR
Twenty twenty-six will be the year the shortcuts get exposed.
L
4:09Lorena RuizNARRATOR
Trust and innovation finally converge.
12 more episodes mention Log4j.
Create an account to see the whole feed, search across every transcript, and follow the entities you care about.