A Reported Log4j RCE Is More Complicated Than It Looks
From the source: Sonatype BlogTL;DR A recently circulated Log4j finding demonstrates a reproducible bypass of a defense-in-depth deserialization control involving FilteredObjectInputStream. Sonatype does not currently consider this a clear-cut Log4j vulnerability. Apache explicitly warns that deserializing untrusted data is unsafe and treats these filters as hardening measures rather than complete security boundaries.…
Read the full story on Sonatype BlogHave you worked with this?
The story is what was announced. Nobody has discussed it yet, so if it touches your team, a short post about what you’ve seen helps the next reader.
More from Sonatype
Recent updates from Sonatype, so you can tell whether this is a one-off or part of a pattern.
The New Engineering Problem: Managing What AI Decides to Import
AI makes it faster to turn an idea into working software. A developer describes a feature, integration, or service and receives an implementation in minutes. Coding agents go further by editing files, running tests, troubleshooting failures, and preparing changes for review.
Sonatype Is Now Awardable on the Platform One Solutions MarketPlace
Software delivery across th e Department of War (DoW) dep ends on speed, but growing use of open source, third-party components, and AI-assisted development makes the software supply chain harder to control. DoW teams need to identify and address risk early without introducing manual gates that slow mission delivery.
Why Are OSS Attackers Always After CI/CD Credentials?
CI/CD credentials are a prime target of malicious open source packages because of the sheer authority those credentials carry. Depending on their privileges, they can provide access to source code, build systems, package registries, cloud infrastructure, and production delivery.
More in DevOps & Platform Engineering
What other companies in DevOps & Platform Engineering are doing. The category page shows who’s active, side by side.
Secure AI agents with HashiCorp Boundary
Enable AI agents to securely access your resources while operating within enterprise identity, access, and audit controls.
Terraform provider for Google Cloud 8.0 now generally available
The Terraform provider for Google Cloud 8.0 builds on expanded infrastructure discovery workflows, modernizes provider defaults, removes support for retired Google Cloud services, and improves consistency between Terraform configurations and Google Cloud APIs.
External Interfaces: Build Your Own UI on Top of Port's Catalog
External Interfaces let you build standalone apps on Port's catalog, where users log in with Port and keep their own permissions.
Resolve AI Alternatives: How to Choose Your Incident AI Layer
What does Resolve AI do? It runs AI agents that investigate production incidents. A buyer's guide to its features, limits, pricing, and alternatives.
