Skip to content

Contrast Marketing

Subscribe Now
    Topics
    Expression language and deserialization attacks on the rise in lead-up to Log4j vulnerability

    Expression language and deserialization attacks on the rise in lead-up to Log4j vulnerability

    It’s been a couple of weeks since the first public disclosure of the Log4j vulnerability. A lot has happened - perhaps..

    Three Reasons Why Contrast SCA Is Best Suited for Log4Shell Rapid Response

    Three Reasons Why Contrast SCA Is Best Suited for Log4Shell Rapid Response

    With Log4j being such a ubiquitous library embedded in tens of millions applications across the Java ecosystem, it’s..

    [Upgrade to 2.17] Updated Guidance on Addressing Log4J CVEs

    [Upgrade to 2.17] Updated Guidance on Addressing Log4J CVEs

    The Apache Software Foundation provided another update to log4j (version 2.17.0) to address a new CVE-2021-45105 on..

    Log4Shell By The Numbers

    Log4Shell By The Numbers

    We monitor many thousands of applications with Contrast Assess (IAST), Contrast SCA, and Contrast Protect (RASP) so we..

    Updated Guidance on Addressing Log4J CVEs

    Updated Guidance on Addressing Log4J CVEs

    The information below is no longer current against the evolving security landscape. See [updated guidance] again on..

    Instantly Inoculate Your Servers Against Log4J With New Open Source Tool

    Instantly Inoculate Your Servers Against Log4J With New Open Source Tool

    Contrast is releasing SafeLog4j, a free and open-source, general purpose tool that can detect/verify vulnerable log4j..

    WAF, RASP and Log4Shell

    WAF, RASP and Log4Shell

    Log4Shell has done an excellent job of making the case for Runtime Application Self-Protection (RASP). Here’s the quick..

    Scaling to Scala

    Scaling to Scala

    Scala developers ship quickly, using the power of a scalable language as their ideas move from concept to prototype and..

    0-Day Detection of Log4j2 Exploit Vulnerability

    0-Day Detection of Log4j2 Exploit Vulnerability

    The world’s most used logging framework was just hit by the Log4j2 exploit, but DevSecOps teams can quickly identify..