Log4Shell
SoftwareWikipedia
14
MENTIONS
8
EPISODES
7
PODCASTS
Search complete. 14 mentions across 8 episodes found for "Log4Shell".
Sep 16, 2026
Ep. 80 - The AI Harness That Never Checked Its Work: Absence of Evidence Isn't Evidence of Absence
A
9:37Adrienne CulleyHOST
On the SecFlow side, the confirmed Fengtai compromise included LSAS credential dumping, technique 1003.001, against the government OA environment, plus database access to over 800 accounts.
A
9:50Adrienne CulleyHOST
And the exploit chain covered eight named CVEs, Shellshock, Log4Shell, Sprint4Shell, Ghostcat, all amongst them.
A
9:58Adrienne CulleyHOST
Vulnerabilities from 2014 Java ecosystem, all still apparently useful against unpatched estates in 2026.
T
10:06Tova DvorinHOST
So this is not experimental.
Safely exploiting vulnerabilities at scale, TVs attack privacy, and the news. - Snehal Antani - ESW #476
S
6:22Snehal AntaniGUEST
And I think I'll end with, I was sick and tired of getting 100,000 vulnerabilities from a bone scanner, most of which weren't even exploitable in my environment.
S
6:30Snehal AntaniGUEST
Log4Shell being a great example.
S
6:32Snehal AntaniGUEST
Um, just because you got the log for J jar file doesn't mean it's a problem.
S
6:35Snehal AntaniGUEST
You could have had an egress rule in place that blocked the outbound RMI call or so on and so forth.
Safely exploiting vulnerabilities at scale, TVs attack privacy, and the news. - Snehal Antani - ESW #476
S
6:22Snehal AntaniGUEST
And I think I'll end with, I was sick and tired of getting 100,000 vulnerabilities from a bone scanner, most of which weren't even exploitable in my environment.
S
6:30Snehal AntaniGUEST
Log4Shell being a great example.
S
6:32Snehal AntaniGUEST
Um, just because you got the log for J jar file doesn't mean it's a problem.
S
6:35Snehal AntaniGUEST
You could have had an egress rule in place that blocked the outbound RMI call or so on and so forth.
Safely exploiting vulnerabilities at scale, TVs attack privacy, and the news. - Snehal Antani - ESW #476
S
6:27Snehal AntaniGUEST
...
S
6:27Snehal AntaniGUEST
most of which weren't even exploitable in my environment, Log4Shell being a great example.
S
6:32Snehal AntaniGUEST
Um, just because you got the Log4j JAR file doesn't mean it's a problem.
A
6:35Adrian SanabriaHOST
Right.
Safely exploiting vulnerabilities at scale, TVs attack privacy, and the news. - Snehal Antani - ESW #476
S
6:27Snehal AntaniGUEST
most of which weren't even exploitable in my environment.
S
6:30Snehal AntaniGUEST
Log4Shell being a great example.
S
6:32Snehal AntaniGUEST
Um, just because you got the Log4j JAR file doesn't mean it's a problem.
A
6:35Adrian SanabriaHOST
Right.
Log4Shell Is Almost Five Years Old. Most Teams Still Can't Answer "What's In Our Software?"
A
0:00Artificial IntelligenceNARRATOR
This audio is presented by Hacker Noon, where anyone can learn anything about any technology.
A
0:05Artificial IntelligenceNARRATOR
Log4Shell is almost five years old.
A
0:08Artificial IntelligenceNARRATOR
Most teams still can't answer, "What's in our software?" By Igbonugo David-Uguchukwu.
A
0:13Artificial IntelligenceNARRATOR
Apache disclosed Log4Shell on December nine to ten, twenty twenty-one.
A
0:18Artificial IntelligenceNARRATOR
As I write this, that's closing in on five years ago, long enough that it should be ancient history, a war story security teams tell new hires.
A
0:27Artificial IntelligenceNARRATOR
It isn't.
A
3:22Artificial IntelligenceNARRATOR
Agencies are no longer required to obtain those attestations by default, though they still may request them, and cloud providers can still be asked for a runtime SBOM on request.
A
3:32Artificial IntelligenceNARRATOR
What that means in practice, the regulatory floor got softer, not the underlying risk.
Inside the Mind of an Open Source Innovator with Tracy Ragan | Agents of Dev Episode 36
M
26:37Mitch AshleyHOST
was hard to know that
T
26:39Tracy RaganGUEST
Log4Shell was being called, right? And now, considering how many people were using Log4J, just having one bad vulnerability is pretty good, actually.
T
26:52Tracy RaganGUEST
I guess
B
26:52Brad ShimminHOST
so, right?
Ep. 77 - The Scan Factory: Inside China's Industrial Exploitation Business
A
5:42Adrienne CulleyHOST
That's exactly the pattern in the advisory's targeting timeline.
A
5:45Adrienne CulleyHOST
Log4Shell in December 2021, ProxyLogon in March 2021, Avanti CSA Zero Days in September 2024, Treft TP in April 2025, and as recently as February this year, Beyond Trust Remote Support, CVE-2026-1731, used against a US state government and water district.
T
6:06Tova DvorinHOST
That's the newest CEV in the advisory.
A
6:08Adrienne CulleyHOST
It is, and it's a great example and illustration of the model.