Skip to main content
Log4Shell

Log4Shell

SoftwareWikipedia

Search complete. 14 mentions across 8 episodes found for "Log4Shell".

Sep 16, 2026

Adrienne CulleyHOST
9:37
On the SecFlow side, the confirmed Fengtai compromise included LSAS credential dumping, technique 1003.001, against the government OA environment, plus database access to over 800 accounts.
Adrienne CulleyHOST
9:50
And the exploit chain covered eight named CVEs, Shellshock, Log4Shell, Sprint4Shell, Ghostcat, all amongst them.
Adrienne CulleyHOST
9:58
Vulnerabilities from 2014 Java ecosystem, all still apparently useful against unpatched estates in 2026.
Tova DvorinHOST
10:06
So this is not experimental.
Snehal AntaniGUEST
6:22
And I think I'll end with, I was sick and tired of getting 100,000 vulnerabilities from a bone scanner, most of which weren't even exploitable in my environment.
Snehal AntaniGUEST
6:30
Log4Shell being a great example.
Snehal AntaniGUEST
6:32
Um, just because you got the log for J jar file doesn't mean it's a problem.
Snehal AntaniGUEST
6:35
You could have had an egress rule in place that blocked the outbound RMI call or so on and so forth.
Snehal AntaniGUEST
6:22
And I think I'll end with, I was sick and tired of getting 100,000 vulnerabilities from a bone scanner, most of which weren't even exploitable in my environment.
Snehal AntaniGUEST
6:30
Log4Shell being a great example.
Snehal AntaniGUEST
6:32
Um, just because you got the log for J jar file doesn't mean it's a problem.
Snehal AntaniGUEST
6:35
You could have had an egress rule in place that blocked the outbound RMI call or so on and so forth.
Snehal AntaniGUEST
6:27
...
Snehal AntaniGUEST
6:27
most of which weren't even exploitable in my environment, Log4Shell being a great example.
Snehal AntaniGUEST
6:32
Um, just because you got the Log4j JAR file doesn't mean it's a problem.
Adrian SanabriaHOST
6:35
Right.
Snehal AntaniGUEST
6:27
most of which weren't even exploitable in my environment.
Snehal AntaniGUEST
6:30
Log4Shell being a great example.
Snehal AntaniGUEST
6:32
Um, just because you got the Log4j JAR file doesn't mean it's a problem.
Adrian SanabriaHOST
6:35
Right.
Artificial IntelligenceNARRATOR
0:00
This audio is presented by Hacker Noon, where anyone can learn anything about any technology.
Artificial IntelligenceNARRATOR
0:05
Log4Shell is almost five years old.
Artificial IntelligenceNARRATOR
0:08
Most teams still can't answer, "What's in our software?" By Igbonugo David-Uguchukwu.
Artificial IntelligenceNARRATOR
0:13
Apache disclosed Log4Shell on December nine to ten, twenty twenty-one.
Artificial IntelligenceNARRATOR
0:18
As I write this, that's closing in on five years ago, long enough that it should be ancient history, a war story security teams tell new hires.
Artificial IntelligenceNARRATOR
0:27
It isn't.
Artificial IntelligenceNARRATOR
3:22
Agencies are no longer required to obtain those attestations by default, though they still may request them, and cloud providers can still be asked for a runtime SBOM on request.
Artificial IntelligenceNARRATOR
3:32
What that means in practice, the regulatory floor got softer, not the underlying risk.
Mitch AshleyHOST
26:37
was hard to know that
Tracy RaganGUEST
26:39
Log4Shell was being called, right? And now, considering how many people were using Log4J, just having one bad vulnerability is pretty good, actually.
Tracy RaganGUEST
26:52
I guess
Brad ShimminHOST
26:52
so, right?
Adrienne CulleyHOST
5:42
That's exactly the pattern in the advisory's targeting timeline.
Adrienne CulleyHOST
5:45
Log4Shell in December 2021, ProxyLogon in March 2021, Avanti CSA Zero Days in September 2024, Treft TP in April 2025, and as recently as February this year, Beyond Trust Remote Support, CVE-2026-1731, used against a US state government and water district.
Tova DvorinHOST
6:06
That's the newest CEV in the advisory.
Adrienne CulleyHOST
6:08
It is, and it's a great example and illustration of the model.

We value your privacy

We use cookies to understand how you use our platform and to improve your experience. Click “Accept All” to consent, or “Decline non-essential” to opt out of non-essential cookies. Read our Privacy Policy.