If you are involved in software development or use open source software, this article from the Google Cloud team, makes for interesting reading and can add some clarity to using this type of resource. Cloud CISO Perspectives: December 2021 | Google Cloud Blog
Log4j updates
Latest update about Log4j from SANS Internet Diary. Log4j 2 Security Vulnerabilities Update Guide – SANS Internet Storm Centre
Software abuse at source
Hackers are abusing the MSBuild environment to embedded malicious code into applications to evade detection. Attackers are abusing MSBuild to evade defences and implant Cobalt Strike beacons – SANS Internet Storm Centre
Installing crypto miners using Log4Shell vulnerabilities
Example of how attackers are trying to push crypto miners via Log4Shell – SANS Internet Storm Centre
Log4j in China
Chinese regulator pauses partnership with Alibaba – BBC News Alibaba Cloud in trouble with Beijing for Log4J annoucement • The Register I found this video on YouTube that has a good in-depth description of the Log4j problem. It will keep you up speed with all the acronyms, shells, code etc.