Best podcast episodes on Log4Shell
In December 2021, CISA and its partners began responding to active, widespread exploitation of Log4Shell (CVE-2021-44228), a critical remote code execution flaw in Apache's Log4j logging library, versions 2.0-beta9 to 2.14.1. Because Log4j is built into a wide range of consumer, enterprise, and operational technology products, CISA issued an emergency directive on December 17, 2021 ordering federal agencies to mitigate it.
Sources: cisa.gov, logging.apache.org
8 episodes from 8 shows. Dates and lengths are from each show's own feed.
- 01
Log4j vulnerability (noun) [Word Notes]
· 9 min · Beginner
Nine minutes on what Log4j is and why one logging library caused so much damage.
- 02
Talkin’ About Infosec News: The Floor is Java, 12/15/2021
· 64 min · Practitioner
A Black Hills feature recorded in the first days: how the exploit works, mitigations, and finding it on hosts.
- 03
· 34 min · Practitioner
Recorded the week of disclosure, it lays out every gap defenders faced from the open source side.
- 04
Log4j RCE coming to a service near you and uBlock CSS Injection [Bounty]
· 68 min · Expert
The exploit-level view from vulnerability researchers, for listeners who want the JNDI mechanics.
- 05
A digital vaccine for Log4Shell [ML BSide]
· 19 min · Practitioner
A short side episode on the community vaccine released to blunt exploitation while patches rolled out.
- 06
What Log4Shell has taught us. [CyberWire-X]
· 31 min · Practitioner
Two months on: what Log4Shell taught defenders about the fragile software supply chain.
- 07
Adkins and Alperovitch Talk About the Cyber Safety Review Board and Log4j
· 51 min · Practitioner
Cyber Safety Review Board leaders discuss the board's first report, which focused on Log4j.
- 08
Cloud Security Podcast by Google
Next 2022 Log4j Reflections, Software Dependencies and Open Source Security
· 27 min · Expert
Why Log4j was an ecosystem-wide problem, and whether other language ecosystems are any safer.