CTO and co-founder
Sonatype

BIO:

CTO and co-founder

Articles and Comments By Brian Fox

Expert Commentary
What Organizations Need To Know About Log4j? Experts Weigh In On Log4Shell Anniversary
December 05 , 2022 by Brian Fox
Log4j was a stark reminder of the critical importance of securing the software supply chain. It was...
Expert Commentary
New Critical Vuln In Component That Allow Encryption Across Internet - Industry Comment
October 27 , 2022 by Brian Fox
For many years, I have included a thought experiment in each presentation I give. It shouldn’t be...
Expert Commentary
Experts Insight On Spring4Shell Vulnerability
April 01 , 2022 by Brian Fox
There are two vulnerabilities that are being mixed up here — one in Spring Cloud released as CVE-2...
Expert Commentary
Log4j Breaches At Least 6 U.S. State Governments
March 09 , 2022 by Brian Fox
The news of China’s APT41 hacking group breaching U.S. state government networks tracks with the t...
Expert Commentary
What Experts Say On Critical Log4j Vulnerability?
December 13 , 2021 by Brian Fox
This new Log4j vulnerability is likely going to be another “flashbulb memory” event in the timel...
Expert Commentary
Microsoft, Uber And Tesla Amongst Tech Companies Vulnerable To New Automated Supply Chain Attack - Expert Insight
February 10 , 2021 by Brian Fox
This software supply chain attack, where security researcher Alex Birsan took advantage of a concept...