It’s not like the four — count ’em, four — https://thenewstack.io/log4shell-we-are-in-so-much-trouble/ vulnerabilities aren’t more than just trouble in and of themselves. Now, the U.S. https://www.ftc.gov/ has issued a warning that it will https://www.ftc.gov/news-events/blogs/techftc/2022/01/ftc-warns-companies-remediate-log4j-security-vulnerability security problems. Specifically, if the https://nvd.nist.gov/vuln/detail/CVE-2021-44228 security hole leads to a “loss or breach of personal information, financial loss, and other irreversible harms,” the FTC may take legal action against your company.

They simply did a crappy job of maintaining their software and got caught out by a nasty, but patched, security bug.

With Log4j companies really can say they didn’t know that the problem existed until it was too late.

Related Articles