Zum Hauptinhalt springen
tsecurity.de LIVE
Echtzeit-Radar & Feeds
Alle RSS Feeds
👥 Community & Social
Sichere ProgrammierungMCP Is an Adapter Layer, So Version the API First(20.09.2026 um 00:11 Uhr)
Sichere ProgrammierungAI Didn’t Build My Backend for Me. I Used It as My Copilot.(20.09.2026 um 00:17 Uhr)
Sichere ProgrammierungWe Reinvented OOP by Making a Sandwich (Before Writing Any Code)(20.09.2026 um 00:28 Uhr)
Sichere ProgrammierungYour Inertia SSR server is down and your site still returns 200(20.09.2026 um 00:29 Uhr)
Sichere ProgrammierungStop Your CSS Layout From Breaking: Understand `box-sizing(20.09.2026 um 00:45 Uhr)
Sichere ProgrammierungWhy your order system and your payment provider disagree(20.09.2026 um 00:56 Uhr)
Sichere ProgrammierungMCP Is an Adapter Layer, So Version the API First(20.09.2026 um 00:11 Uhr)
Sichere ProgrammierungAI Didn’t Build My Backend for Me. I Used It as My Copilot.(20.09.2026 um 00:17 Uhr)
Sichere ProgrammierungWe Reinvented OOP by Making a Sandwich (Before Writing Any Code)(20.09.2026 um 00:28 Uhr)
Sichere ProgrammierungYour Inertia SSR server is down and your site still returns 200(20.09.2026 um 00:29 Uhr)
Sichere ProgrammierungStop Your CSS Layout From Breaking: Understand `box-sizing(20.09.2026 um 00:45 Uhr)
Sichere ProgrammierungWhy your order system and your payment provider disagree(20.09.2026 um 00:56 Uhr)
Intelligence View
⚡ tsecurity.de Intelligence

Improving OSS-Fuzz and Jazzer to catch Log4Shell

The discovery of the Log4Shell vulnerability has set the internet on fire. Similar to shellshock and heartbleed, Log4Shell is just the latest catastrophic vulnerability in software that runs the internet. Our mission as the Google Open Source Security Team is to secure the open source libraries the world depends on, such as Log4j. One of our capabilities in this space is OSS-Fuzz, a free fuzzing service that is used by over 500 critical open source projects and has found more than 7,000 vulnerabilities in its lifetime.

We want to empower open source developers to secure their code on their own. Over the next year we will work on better automated detection of non-memory corruption vulnerabilities such as Log4Shell. We have started this work by partnering with the security company Code Intelligence to provide continuous fuzzing for Log4j, as part of OSS-Fuzz. Also as part of this partnership, Code-Intelligence improved their Jazzer fuzzing engine to make it capable of detecting remote JNDI lookups. We have awarded Code Intelligence $25,000 for this effort and will continue to work with them on securing the open source ecosystem.
Vulnerabilities like Log4Shell are an eye-opener for the industry in terms of new attack vectors. With OSS-Fuzz and Jazzer, we can now detect this class of vulnerability so that they can be fixed before they become a problem in production code.

Over the past year we have made a number of investments to strengthen the security of critical open source projects, and recently announced our $10 billion commitment to cybersecurity defense including $100 million to support third-party foundations that manage open source security priorities and help fix vulnerabilities.

We appreciate the maintainers, security engineers and incident responders that are working to mitigate Log4j and make our internet ecosystem safer.

Check out our documentation to get started using OSS-Fuzz.
Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten Improving OSS-Fuzz and Jazzer to catch Log4Shell

Thematisch verwandte Begriffe: Improving, OSSFuzz, Jazzer, catch · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Zum Aktualisieren ziehen
ZERO-DAY CVE-2026-93987 | rclone versions 1.56.0 through 1.75.0 contain a path traversal vulnerabi…
Advisory →
TTS Reader • tsecurity.de Voice
tsecurity.de Icon
tsecurity.de App
Offline-Lesen, Eilmeldungen & 0ms Ladezeit

Installiere tsecurity.de direkt auf deinen Home-Bildschirm für das ultimative Vollbild-Magazinerlebnis ohne Browser-Leisten.

Nächster Beitrag
Themen-Radar & Intelligence Matrix
Echtzeit-Taxonomie nach Angriffsvektoren & Plattformen
Community Radar & Live Chat
Sentinel Bot online • Live-Stream
Dein Cluster: Security Explorer
Match:
lädt…
Verbindung zum Community-Stream wird aufgebaut...
Bearbeitungsmodus — Senden überschreibt deine Nachricht
Community-Puls — was gerade passiert
lädt…
Aktivitäten deiner Analysten
lädt…
Neues Thema oder Eilmeldung einreichen

Reiche interessante Links, Zero-Days oder Debatten ein. Die Community entscheidet per Upvote über die Veröffentlichung.

Heiß diskutierte Einreichungen
🔖 Gespeicherte Artikel
📂 Keine gespeicherten Artikel vorhanden.
Zurück Ziehen Vor
Links: vorheriger Artikel Rechts: nächster Artikel unten: schließen
News NIS-2 Frühwarnung Tier-1 Intel ⏱️ 3 Min vor 10 Min
Artikeldaten werden geladen...

Zurück: vorheriger Vor: nächster
↗ Original-Quelle
Social Reaktionen Deine Reaktion zählt
Einstufung & Relevanz-Poll 0 Stimmen
In sozialen Netzwerken teilen 1-Klick