CISA Director Calls 'Log4j' Vulnerability 'One of the Most Serious'

Cybersecurity and Infrastructure Security Agency Director Jen Easterly told industry leaders in a phone briefing that a vulnerability in a widely used logging library “is one of the most serious I’ve seen in my entire career, if not the most serious.” “We expect the vulnerability to be widely exploited by sophisticated actors and we have limited time to take necessary steps in order to reduce the likelihood of damage,” she said of the Apache Log4j flaw.