article thumbnail

What is Spring4Shell? Detect and mitigate new zero-day vulnerabilities in the Java Spring Framework

Dynatrace

CVE recently published three new critical vulnerabilities in the Java Spring Framework, including one called Spring4Shell. Many applications are potentially affected, as Spring dominates the Java ecosystem , with 60% of developers using it in their main Java applications. Denial of Service in Spring Expressions: CVE-2022-22950.

Java 195
article thumbnail

InfoSec 2022 guide: How DevSecOps practices drive organizational resilience

Dynatrace

Not surprisingly, the theme of Infosec Europe 2022 Conference is “Stronger together,” putting an emphasis on IT collaboration. Cloud operations and observability boost resilience for American Family – blog. Software intelligence as code enables tailored observability, AIOps, and application security at scale – blog.

Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

Trending Sources

article thumbnail

RSA 2022 guide: DevSecOps transformation with runtime vulnerability management

Dynatrace

At RSA 2022 , the theme is Transform. Software intelligence as code enables tailored observability, AIOps, and application security at scale – blog. AIOps capabilities drive intelligent cloud observability – blog. AIOps strategy central to proactive multicloud managemen t – blog.

Strategy 229
article thumbnail

The top eight DevSecOps trends in 2022

Dynatrace

This is fueling key DevSecOps trends in 2022. As DevSecOps practices gather steam in 2022, there are several concurrent technology trends that will likely further DevSecOps adoption. Log4Shell enables an attacker to use remote code execution to engage with software that uses the Java logging library Log4j versions 2.0

article thumbnail

Black Hat 2022 highlights zero-day attacks as key theme

Dynatrace

Zero-day attacks are a key theme at Black Hat 2022 , a security conference taking place August 6-11 in Las Vegas. – blog. Security as code demands proactive DevSecOps – blog. DevOps vs. DevSecOps – blog. DevSecOps automation with security gates for release validation – blog. Read more now. What is Log4Shell?

DevOps 130
article thumbnail

OneAgent release notes version 1.241

Dynatrace

Rollout starts June 8, 2022. Find Java Apache HttpClient v5 and turn it on. Added automatic tracing support for JMS messaging on z/OS Java. The following operating systems will no longer be supported starting 01 July 2022. The following operating systems will no longer be supported starting 01 August 2022.

Java 159
article thumbnail

Advance DevSecOps practices with a vulnerability management strategy

Dynatrace

At the annual conference Dynatrace Perform 2022, the theme is “Empowering the game changers.” The vulnerability is located in Log4j 2, an open-source Apache Java software used to run logging services in a host of front-end and backend applications. Perform 2022 conference coverage , check out our guide. For our complete?

Strategy 208