Provides high-scale telemetry on the 'remediation slog' and identifies 'End-of-Support' software as a critical long-term driver of supply chain risk.
Analysis of 150 million IT assets following the Log4Shell crisis revealed 22 million vulnerable application installations, over 80% of which were open source. Two months after disclosure, 30% of instances remained vulnerable to exploit. Alarmingly, more than 50% of the installations containing Log4j were flagged as 'end-of-support', meaning publishers would likely never provide security patches. Detections in web applications saw a spike after the holiday season, particularly in the E.U. Remediation velocity averaged 17 days, though remote exploits were patched faster (12 days) than internal systems. At the peak of the crisis, EDR solutions detected 22,000 potential scattershot ransomware attacks per week targeting the vulnerability.
30% of Log4j instances remained vulnerable two months after disclosure despite a patch being available from day one, with average remediation velocity of 17 days.
prolonged exposure to widely known and automated ransomware exploits due to slow downstream patch adoption
the 17-day average remediation velocity and 30% residual vulnerability rate demonstrate how upstream remediation patterns directly predict downstream exposure windows.
Surprisingly, more than 50% of application installations with Log4j were flagged as 'end-of-support'. This means that these publishers will likely NOT be providing Log4Shell security patches.
Risk Guard tracks unpatched vulnerabilities but does not explicitly flag packages that have reached 'End of Life' or 'End of Support' by their commercial publisher.
Risk Guard would be better if it integrated a 'Commercial Support Status' check to alert on dependencies that are functionally abandoned by their vendors.