Remote code execution vulnerability in Java-based logging utility Log4j was first reported Dec. 9, after allegedly being detected by Alibaba’s cloud security unit. It immediately put security teams on high alert heading into the holiday season. Apache Software Foundation continues to push out semi-regular updates for the logging library to address another, less-severe RCE vulnerability – CVE-2021-44832 – disclosed last week by the firm Checkmarx. An incident reporting bill fell off the annual defense spending bill in December after lawmakers failed to come to a consensus.”]
Source: https://www.bankinfosecurity.com/sen-gary-peters-revisits-incident-reporting-legislation-a-18272

