As a developer I find it very hard to stay up to date with all new leaks and exploits and even harder to correctly patch these. In the case of log4Shell, I stumbled upon it on an generic news site. A friend of mine got it from a customer that read it somewhere on the internet.
I’m working on a cybersecurity product that makes the detection and patching of exploits easier, like snyck.io but for servers & cloud infrastructures.
Can you share how you currently stay up to date of exploits and ensure your servers and code are up to par (especially enterprise infrastructure)?