The Impact Of Log4j Since Its Disclosure | Steps Businesses Can Take To Maintain Software Supply Chain Security | Part 1 Of 2 | An Imperva Brand Story With Gabi Stapel episode artwork

EPISODE · Feb 16, 2023 · 23 MIN

The Impact Of Log4j Since Its Disclosure | Steps Businesses Can Take To Maintain Software Supply Chain Security | Part 1 Of 2 | An Imperva Brand Story With Gabi Stapel

from Redefining CyberSecurity · host Sean Martin, ITSPmagazine, Marco Ciappelli, Gabi Stapel

The December 2021 log4j vulnerability was a major event in the cybersecurity world. When it was released and exposed to the internet, it caused an explosion in attacks with five and a half million attacks per day and up to 25,000 sites attacked per hour. The vulnerability affects any system running that version of Java lookup and could be at risk, even if it is only exposed internally to insiders. The attackers initially used scanning and checking to see which sites were vulnerable, and then it was automated. Attack tools were created to make it easier for attackers to reach as many targets as possible. Public awareness campaigns have been effective, but vulnerabilities can reappear due to the prevalence of the software. 72% of organizations still had some level of vulnerability to log4j as of October 2022.As captured in this episode, remediation is not a one-and-done solution, as seen with Log4j, where organizations would fix the problem, and then it would come right back due to the prevalence of the software and how deep it went. The importance of API security is emphasized since 15% of the numbers were coming from APIs. The need to check and document new things added to the system is crucial to maintain proper documentation and be up on remediation. In short, software supply chain security is critical.Note: This story contains promotional content. Learn more.Guest: Gabi Stapel, Content Manager @ Imperva Threat Research [@Imperva]On LinkedIn | https://www.linkedin.com/in/gabriella-stapel/On Twitter | https://twitter.com/GabiStapelResourcesLearn more about Imperva and their offering: https://itspm.ag/imperva277117988Blog: Log4j: One Year LaterSolution page: Stopping software supply chain attacksLearning center: Supply Chain AttackLearning center: Zero-day (0day) exploitNational Telecommunications and Information Administration: Software Bill of MaterialsNational Telecommunications and Information Administration: Vulnerability-Exploitability eXchangeAre you interested in telling your story?https://www.itspmagazine.com/telling-your-story

Episode metadata supplied by the publisher feed · Published Feb 16, 2023

Embed this episode

When Log4j was disclosed, it was quickly hyped up with some even saying the internet was on fire. Did Log4j live up to that hype or cause as much damage as expected?Join us for a conversation to get a view into the overall impact of Log4j and what the research team at Imperva has seen and monitored since the disclosure of Log4j, including any noticeable trends/key findings in Imperva’s research.

Distinct summary based on available episode metadata or transcript content.

Ready to play

The Impact Of Log4j Since Its Disclosure | Steps Businesses Can Take To Maintain Software Supply Chain Security | Part 1 Of 2 | An Imperva Brand Story With Gabi Stapel

0:00 23:17

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

IT Trendsetters SynerComm During each episode, our team is joined by a relevant industry expert to gain insight into new IT trends and learn about important IT and cybersecurity concepts. Our goal is to give you the advice your need to safeguard your network and digital assets. The AI-Powered Lawyer River Braun Welcome to The AI-Powered Lawyer, where host River Braun takes you on a journey into the heart of the AI revolution in law. This isn't about traditional legal practice; it's about exploring cutting-edge technology that's transforming the way we work. Each episode dives into the tools, trends, and techniques redefining what it means to be a lawyer in the age of AI. Subscribe and join us as we redefine law...together! IT Jobs's Podcast IT Jobs Two Cisco CCIEs discussing topics related to getting and IT Job or hiring for an IT Job. Focus on both Network Engineering, Cloud, Development, and CyberSecurity and as much reality as can be brought. The Cyber Sleuth Show Cyber Social Hub Step into the world of digital forensics, mobile forensics, OSINT, and cybersecurity with The Cyber Sleuth Show! Hosted by Kevin DeLong, this podcast dives deep into the ever-evolving landscape of digital investigations, featuring expert guests, cutting-edge tools, real-world case insights, and, of course, the occasional terrible dad joke.From law enforcement investigators and forensic analysts to OSINT specialists and cybersecurity pros, we uncover the latest trends, techniques, and challenges in the field—giving you the knowledge you need to find the truth behind digital incidents.🔍 Stay ahead of the curve. Stay informed. Stay sleuthing.📢 Join the community! Connect with fellow digital investigators for FREE at CyberSocialHub.com.🎥 Prefer video? Watch the podcast on YouTube: @CyberSocialHub.🚀 Subscribe now and sharpen your investigative skills!

Frequently Asked Questions

How long is this episode of Redefining CyberSecurity?

This episode is 23 minutes long.

When was this Redefining CyberSecurity episode published?

This episode was published on February 16, 2023.

Can I download this Redefining CyberSecurity episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!