#Spring4Shell
Log4Shell - Spring4Shell - The XZ Backdoor

As the software ecosystem grows more complex, are we ready for the next #CyberSecurity crisis?

Discover practical strategies to secure your development lifecycle, whether you're a lean startup or a global enterprise.

🎬 bit.ly/4m1LyGg

#SoftwareSecurity
April 2, 2026 at 12:16 PM
The persistent threat: Why major vulnerabilities like Log4Shell and Spring4Shell remain significant

TL;DR too many folks still did not update from these vulnerable versions which is kinda shocking.

https://buff.ly/3yWfVtQ
The persistent threat: Why major vulnerabilities like Log4Shell and Spring4Shell remain significant | Snyk
Read on to learn about the danger of the continued use of vulnerable Log4j and Spring Framework versions in many projects.
buff.ly
November 27, 2024 at 3:04 PM
E o spring4shell? Que ao compilar código executando com jre 9+ rodando injeção do spring em um tomcat padrão (não embarcado) ao empacotar com war tinha um lance de desvio do classloader do tomcat que permitia RCE, né?
May 13, 2025 at 1:58 AM
Honestly the numbers are insane. Do something about it people, take responsibility 😑
snyk.io/blog/log4she...
The persistent threat: Why major vulnerabilities like Log4Shell and Spring4Shell remain significant | Snyk
Read on to learn about the danger of the continued use of vulnerable Log4j and Spring Framework versions in many projects.
snyk.io
November 16, 2024 at 5:43 PM
Java Crack of the Week #2 is out now! 💻
👉 youtube.com/watch?v=nAPm...

Discover what Spring4Shell (CVE-2022-22965) does and how it works, as well as how to protect Spring apps against this code vulnerability.

Subscribe to our channel and learn more #Java ins and outs!
#Java30withSoftwareMill
Spring4Shell RCE Explained | Java Crack of the Week #2
YouTube video by SoftwareMill
youtube.com
May 28, 2025 at 11:36 AM
Trend Micro analysis of the facts we know so far about Spring Framework Core vulnerability “Spring4Shell” CVE-2022-22965

https://success.trendmicro.com/dcx/s/solution/000290730?language=en_US&sfdcIFrameOrigin=null
SECURITY ALERT: Spring Framework "Spring4Shell" RCE...
success.trendmicro.com
November 17, 2024 at 1:49 PM
In case somebody’s investigating #Spring4Shell vulnerability, Azure Application Gateway WAF policies (OWASP_3.1) are already updated with corresponding rules. Also check
November 14, 2024 at 8:28 AM
Research reveals attackers exploit vulnerabilities 7 days before patches are available, while critical flaw exposure at Day 7 increases. Automation in Risk Ops Centers needed to cut human latency. #RiskMass #ClosedLoop #USA
Analysis of one billion CISA KEV remediation records exposes limits of human-scale security
Qualys research shows attackers weaponize critical vulnerabilities faster than organizations can patch them, with Time-to-Exploit at negative seven days and a rising percentage of critical flaws still open at Day 7. Defenders must move from manual scan-and-report models to autonomous, closed-loop Risk Operations Centers that measure Risk Mass and AWE and automate remediation to remove human latency. #Spring4Shell #CiscoIOSXE #Follina
www.hendryadrian.com
April 10, 2026 at 3:15 PM
【CSIRT向け】FutureVulsを活用した脆弱性対応模擬訓練をやってみた! - ISID テックブログ
<a href="https://tech.isid.co.jp/entry/futurevuls-vulnerability-response-training" class="hover:underline text-blue-600 dark:text-sky-400 no-card-link" target="_blank" rel="noopener" data-link="bsky">tech.isid.co.jp/ent...
【CSIRT向け】FutureVulsを活用した脆弱性対応模擬訓練をやってみた! - ISID テックブログ
こんにちは、Xイノベーション本部 ソフトウェアデザインセンター セキュリティグループの福山です。 今回は、弊社CSIRTチームの一機能として活動している「脆弱性管理チーム」の活動に関する内容となります。 昨今では、Log4shellやSpring4shellなど、影響範囲の広い脆弱性が後を絶ちません。 これらの緊急度の高い脆弱性情報が公開された場合を想定した、情報収集〜現場対応までのCSIRT目線での模擬訓練を、FutureVulsを含めて実施してみましたので紹介したいと思います。 FutureVulsとは FutureVulsを導入した経緯 事前準備 模擬訓練 情報収集 トリアージ 全社周知…
tech.isid.co.jp
October 10, 2023 at 8:52 AM
spring4shell-scanner (⭐️ 11)

Scan systems and docker images for potential spring4shell vulnerabilities. Will detect in-depth (layered archives jar/zip/tar/war and scans for vul...

#go
May 25, 2026 at 8:56 PM
CVE-2022-22965 (Spring4Shell)

A reminder that:
Framework bugs scale fast
Defaults matter
JVM apps age badly without maintenance

This one didn’t need nation-state attackers—just exposed apps and bad timing.
Details here:
cvedatabase.com/cve/CVE-2022...
#Spring4Shell #CVEAlert
CVE-CVE-2022-22965 | CRITICAL Severity | CVEDatabase.com
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires...
cvedatabase.com
February 19, 2026 at 10:22 AM
💻CYBERSEC

Une nouvelle vulnérabilité zero-day dans le framework Spring Core Java appelée "Spring4Shell" a été divulguée publiquement, permettant l'exécution de code à distance non authentifié sur les applications.

bleepingcomputer.com/news/security/…
New Spring Java framework zero-day allows remote code execution
A new zero-day vulnerability in the Spring Core Java framework called 'Spring4Shell' has been publicly disclosed, allowing unauthenticated remote code execution on applications.
www.bleepingcomputer.com
November 30, 2024 at 4:09 AM
Haven’t looked into the specific yet, but probably important to get the word out:

spring4shell…

cyberkendra.com/2022/03/spring…
November 25, 2024 at 9:40 AM