Tootfinder

Opt-in global Mastodon full text search. Join the index!

@johl@mastodon.xyz
2026-08-27 10:04:37

A good explanation of yesterday’s finding in #Log4J regarding deserializing untrusted data. Remote Code Execution needs preconditions, it’s not a new problem, and it typically cannot be exploited.
“What made the news in this issue is that it was nearly deleted before anyone had triaged it. Let me remind you the first rule of security response: brew some good ☕ .”

@TobiasFrech@ijug.social
2026-08-26 18:20:37

RE: #Log4j strictly for local file l…

@hacksilon@infosec.exchange
2026-08-27 05:46:47

RE: #RCE in #Log4J is nowhere near as easily exploited as the original. It has a lot of preconditions. Sonatype has a good writeup: sonatype.com/blog/a-reported-l