Log4j 2.17 adoption is leveling off without fully replacing 2.16. I wonder if this is because people (potentially incorrectly) assume 2.16 is good enough? IMO 2.17 is the proper, complete fix that eliminates all the hard to disprove side attacks. Upgrade!
https://t.co/Qb77wx4doy
Heads up: We see a lot of scanning against the #log4j vulnerability and decided to publish a blog post with some guidance:
https://t.co/dtEXfY1G16
Please patch now!
"I just wonder what all of this says about us," @JoyAnnReid says. "I think it raises real questions about what America is at the end of the day and whether what Trump is more like what the American character is than people ever, ever wanted to admit." https://t.co/VGXgk6DsCa