#Log4j

Apache - The ASFTheASF@fosstodon.org
2026-03-12

What did Log4Shell teach us about securing open source?

Join the ORC WG on Monday to explore the lessons from Log4Shell and what a CRA-ready Log4j looks like.

📆 March 16 at 12 pm EDT
➕ Add to your calendar: buff.ly/GZ8m6Gv

#CRA #CyberResilience #opensource #ORCWG #log4j #CRAMondays

AllAboutSecurityallaboutsecurity
2026-03-11

SAP Patch Day März 2026: Zwei HotNews-Lücken in Log4j und NetWeaver geschlossen

Im Fokus stehen eine seit Jahren bekannte Log4j-Komponente und eine Deserialisierungslücke im NetWeaver Enterprise Portal.

all-about-security.de/sap-patc

Apache - The ASFTheASF@fosstodon.org
2026-03-10

Log4Shell revealed just how deeply open source runs through the global software supply chain—and how hard it can be to respond when a critical dependency fails.

Join the ORC WG for the next #CRAMondays to explore the lessons from Log4Shell and what it takes to build a CRA-ready Log4j.

📆 March 16 at 12 pm EDT
➕ Add to your calendar: bit.ly/3PuQozy

#CRA #CyberResilience #opensource #ORCWG #log4j

2026-03-07

I'm afraid the deprecation of the Security Manager just added several lines to that risk, all linked to running untrusted code....
#JEP411 #Log4J #Log4Shell #Security #securitymanager
foojay.io/today/running-untrus

Dirk Schnelle-Walkadsw@mastodontech.de
2026-02-27

Projects like Log4j are seeing a flood of low-quality, likely AI-generated security reports that overwhelm maintainers with noise. After high volumes since Dec 2025, only a tiny fraction are real issues and reviewing them strains volunteer time.

Code generation by #AI is not bad per se, but you should still know what you are doing.

share.google/5NzOQ0fhog8X2xbfw #OpenSource #Security #Log4j #OSS #AIspam #aicodewriting #codegeneration #vibecoding

𝗣𝗠𝗝 ⚫pmj@social.pmj.rocks
2026-01-26

weil jeder mit nem claude abo denkt er sei jetzt plötzlich security researcher und die bug bounty programme diverser opensource projekte mit slop flutet, stellen jetzt cURL und log4j ihre ein!

die welt ein bisschen unsicherer machen - dank KI! 😠
#cURL #log4j #KI #BugBounty #CyberSecurity #foss #opensource

2026-01-23

You know that meme about "all modern digital infrastructure"? I found it in real life! #log4j #allModern #IT #infrastructure

2026-01-15

@grobmeier Good logging is the A and O of a good program. Only with logging you can comprehend what was going on in case of unexpectable behaviour. And #log4j is the best tool to do it. It was inveented for #java and due to its superb concept (distinction of loggers, appenders, levels, layout, etc.) it was ported to all other known languages.

Christian Grobmeiergrobmeier
2026-01-15

My book Logging is the deal of the day!

manning.com/books/java-logging

If you consider it, today is a good day!

2025-12-14

4 years already since the Log4J incident. That was not a fun time, but this meme made me laugh again this morning. 😆

#SysAdmin #Log4J #Meme

A 6 frame meme. 

Frame 1 - A person sleeping in the dark.
Frame 2 - The person’s brain wide awake saying “Log4J on your toaster”
Frame 3 - The person still laying and seemingly relaxed saying “That’s not a thing”
Frame 4 - The person still relaxed with eyes closed
Frame 5 - The person eyes closed but now with a frown.
Frame 6 - The person now awake, frowning, face lit up by their phone and assumed to be looking up Log4J on their toaster.

People. Why you gotta do me like this? Even knowing CICD pipes for versions of software that was retired years ago are still chugging along (oh yeah, I know about that one!!) this is an nsane number.

infosecurity-magazine.com/news

#log4j #cicd

Alexander Thurowalexthurow@mstdn.social
2025-11-15
René Moser (resmo) レネresmo@mstdn.social
2025-11-11

#Techflix recommandation: "The Untold Story of Log4j and #Log4Shell | Christian Grobmeier | GitHub" #youtube #log4j #ApacheSoftwareFoundation

Many, many ❤️ to @grobmeier it takes a lot of courage to talk about your failures (no one is error prove!)

(I must laught when his kid asked for help playing minecraft during the incident. Turned out, minecraft suffered about log4j as well)

youtube.com/embed/t74ClffSUW0

Nicolas Fränkel 🇪🇺🇺🇦🇬🇪frankel@mastodon.top
2025-10-31
Christian Grobmeiergrobmeier
2025-10-25

RE: ohai.social/@senficon/11541721

is popular.
funding is necessary.
Thanks to the @sovtechfund, which did so much for us after Log4shell!

jeffluszczjeffluszcz
2025-10-20

(repost from GitHub blog) The internet was on fire. 🔥
One small library affecting billions of systems.
Log4Shell was the biggest security vulnerability of all time.

Now, Log4J maintainer, Christian Grobmeier tells us what it felt like inside the flames .

github.blog/open-source/inside

a person sitting in a chair with the text "The phone call no developer wants to receive" and "imagine you find out". There is a white column in the background and a window with green foliage visible through it. The man is wearing sneakers black pants and a light blue or white button down long sleeve shirt. He is wearing glasses and looking toward the left.
Christian Grobmeiergrobmeier
2025-10-20

I never imagined GitHub would ask me to speak about Log4Shell.
But it happened.

GitHub asked me to share the story as I lived it, for the benefit of all maintainers and users of open source. How could I say no?

I hope it helps build a more secure future.

No more Log4Shell.

github.blog/open-source/inside

JAVAPROjavapro
2025-09-26

could have failed many times. But it survived. Not because of money, but because of people. An honest look behind the scenes — from the first line of code to the project’s greatest crisis.

Read Christian Grobmeier’s new piece: javapro.io/2025/06/10/the-long

@theasf

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst