2026-08-27 10:04:37
A good explanation of yesterday’s finding in #Log4J regarding deserializing untrusted data. Remote Code Execution needs preconditions, it’s not a new problem, and it typically cannot be exploited.
“What made the news in this issue is that it was nearly deleted before anyone had triaged it. Let me remind you the first rule of security response: brew some good ☕ .”
