#Log4J

JAVAPROjavapro
2025-06-13

Would YOU patch a global CVE… unpaid… over your vacation? That’s what the team did. But the full story goes way deeper — punk roots, fights, near-abandonment & one massive comeback.

Read Christian Grobmeier’s story: javapro.io/2025/06/10/the-long

@theasf

JAVAPROjavapro
2025-06-10

How did a tiny Java logging lib bring the internet to its knees? How did unpaid devs patch it in the middle of global panic? And what’s next for ? Christian Grobmeier takes you inside one of ’s wildest stories.

Read it now → javapro.io/2025/06/10/the-long

JAVAPROjavapro
2025-05-29

Von „an/aus“ zu Hierarchien. Von Punk zu @theasf. Von SEMPER zu SourceForge. war nie nur ein Tool – es war Revolution, Rebellion, Rettung. Christian Grobmeier nimmt dich mit durch 30 Jahre Code und Chaos.

Lies seine Story, lass sie wirken & teile: javapro.io/de/die-lange-geschi

JAVAPROjavapro
2025-05-26

Ein Logging-Framework. Ein Bug, der das Internet erschüttert! Ein paar Freiwillige, die es retteten! Die wahre Geschichte von Log4j ist dramatischer als jeder Thriller.

Christian Grobmeier verrät, warum überlebte & was das für bedeutet: javapro.io/de/die-lange-geschi

just a💧in my 🍺Gboeer@det.social
2025-05-25

Gerade hab ich die Folge "Das wichtigste Hobby der Welt" vom Wild Wild Web Podcast gehört. Ein sehr passender Titel, denn es geht um die bekannte Tatsache, dass große Teile der weltweiten IT Infrastruktur auf der Arbeit von ein paar Dutzend #opensource Entwicklern beruht, die den Code fast immer in ihrer Freizeit pflegen. Zuletzt ist das mit dem #log4j Vorfall mal wieder in den Fokus geraten, von dessen Maintainern hier auch jemand zu Wort kommt. Anhören lohnt sich

ardaudiothek.de/episode/wild-w

Christian Grobmeiergrobmeier
2025-02-24

It feels good when something is finished, and I just finished the article for the new Javapro magazine. It's about the history of . Proud of it. Needed a lot of chocolate. Not from though, but :)

Nicolas Fränkel 🇺🇦🇬🇪frankel@mastodon.top
2025-02-19
2025-01-29

Log4ts — библиотека, которой не должно быть

В этой статье я хочу рассказать о моей библиотеке, которой не должно существовать. Почему её не должно существовать? Потому что функциональность логирования, по моему глубокому убеждению, должна быть в числе первых включена в любой новый язык. А разработчики старых языков тоже должны об этом подумать и включить логирование, если это ещё не сделано, в ближайший релиз. Библиотека Log4ts вдохновлена идеями Log4J и обеспечивает логирование в программах, написанных на TypeScript. Далее в этой статье я расскажу о том, как её установить, использовать и конфигурировать. А в конце я опишу коротенько другие мои библиотеки, которые тоже не должны были бы существовать.

habr.com/ru/articles/877698/

#logging #logs #log4j #angular #nodejs

2025-01-23

How pray tell is this a good move??

Department of Homeland Security (DHS) disbands all memberships of advisory committees including the Cyber Safety Review Board (CSRB). thehackernews.com/2025/01/trum #Hackers #CyberSecurity #cybercrime #DHS #CSRB #Log4j #SaltTyphoon #security

Hacker Image
Christian Grobmeiergrobmeier
2025-01-06

Spent the past year working with @pkarwasz on . What started as patches turned into deep dives into , VEX, and securing supply chains.

In 2025, we’re building a small -based tool to help devs write more secure software. No big funding—just two folks in the trenches trying to get it right.

Let’s talk if your company’s digging into SBOM or . We’re happy to share insights or lend a hand!

Christian Grobmeiergrobmeier
2024-12-16

You can call yourself a senior programmer when you have at least one in your
life, told yourself: "I should have logged this."

Christian Grobmeiergrobmeier
2024-12-13
Andreas Scherbaumascherbaum
2024-11-24

Today, 3 years ago, the (in)famous vulnerability was made public.

This was an arbitrary code execution in the popular logging framework , the issue was there since 2013. This vulnerability received a CVSS severity rating of 10, the highest possible.

Hope you all updated your billions of devices running Java out there already!

Christian Grobmeiergrobmeier
2024-11-08

Excited and honored to speak at the User Group this November! I’ll dive into the story behind and , explore the impacts on the open-source ecosystem, and discuss lessons learned since. Looking forward!
java-users.jp/post/night202411/

Japan Java Usergroup Logo
Christian Grobmeiergrobmeier
2024-11-05

I'm getting my hands dirty with for a talk about , , and in Tokyo. This time, I will only travel light with my @tuxedocomputers laptop, so I started creating my presentations in an open format (as I should have done before).

Benjamin Carr, Ph.D. 👨🏻‍💻🧬BenjaminHCCarr@hachyderm.io
2024-11-04

How to make #opensource #software more secure
The #xz attack, which followed other well-known cybersecurity incidents involving open source software like #Heartbleed, #Shellshock, and #Log4j, was another stark reminder that open source software, given how widespread it is, can pose significant #security risks.  
techcrunch.com/2024/11/01/how- #itsec

Christian Grobmeiergrobmeier
2024-10-10

released its new report saying that 13% of downloads are still vulnerable. It does not mean you are a target, but you should double-check and update when possible.


sonatype.com/en/press-releases

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst