Need to detect open source Java vulnerabilities grows, Azul releases tool designed to help
Ever since Log4j highlighted the dangers of insecure open source components, securing the software supply chain has become a top priority, to the point where Amazon, Ericsson, Google, Intel, Microsoft and VMWare joined forces to pledge to invest $30 million to help maintain these projects at the Open Source Software Security Summit II.
However, there is still lots of work to be done to improve the standard of open source security, and Log4j stands as a testament to the damage that vulnerable java-based components can reap.
That’s why today, security vendor Azul announced the release of Azul Vulnerability Detection, an agentless cloud-solution designed for identifying and tracking Java vulnerabilities.
It’s a solution designed to help enterprises identify and track code and check it against a curated database of common vulnerabilities and exposures (CVEs) so they can accurately identify Java vulnerabilities with minimal performance impact. Read More...