
Transitive Dependencies — The Hidden Vulnerability Risk Most Teams Miss
Transitive dependencies security is one of the most misunderstood parts of modern software supply...
Tag archive

Transitive dependencies security is one of the most misunderstood parts of modern software supply...

Equifax did not suffer a $1.4 billion security disaster because attackers used an unknown zero-day....

Log4Shell 2026 is not a historical cleanup task. It is still a live security problem. Years after...
Remember December 2021? The collective panic when Log4Shell dropped and suddenly every engineering...
A version of Azure DevOps Server with a reasonably recent, secure, and supported version of Elastic...
Except if you lived in a cave or a desert island for more than 2 months, you should have eared about ...

Last December, Log4Shell shortened the nights of many people in the JVM world. Worse, using the...

It seems surreal seeing log4j, a logging utility in the news and all over the internet. How is it...

The Log4j vulnerability tracked as CVE-2021-44228 (also known as Log4Shell) allows an attacker to...
![Serious flaw in Java log4j has been discovered, affecting large number of devices. [weekly tech news]](https://media2.dev.to/dynamic/image/width=1000,height=420,fit=cover,gravity=auto,format=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F2nyozq69jz9qroef370n.png)
On December 9th, a zero-day vulnerability in log4j, a widely used Java logging library, was...