The U.S. Cybersecurity and Infrastructure Security Agency issued an emergency directive on Friday regarding the Log4j vulnerabilities. The directive requires federal civilian departments and agencies to immediately patch their systems or implement appropriate mitigation measures. CISA previously gave agencies until Dec. 24 to patch against log4j exploits via its Known Exploited Vulnerabilities Catalog. The agency has already created a central landing page with technical details and patch information on its site and added a GitHub repository of affected devices and services. Senate leaders also renewed talks on mandatory incident reporting, a provision nixed at the eleventh hour during congressional negotiations on the must-pass defense spending bill.”]
Source: https://www.inforisktoday.com/cisa-to-agencies-patch-log4j-vulnerability-immediately-a-18150

