The name Log4Shell refers to the fact that this bug is present in a popular Java code library called Log4j ( Logging for Java), and to the fact that, if successfully exploited, attackers get what is effectively a shell – a way to run any system code of their choosing. …and your cybersecurity Christmas decorations lit up with the latest funkily-named bug: Log4Shell.Īpparently, early reports of the bug referred to it as “LogJam”, because it allows you to JAM dodgy download requests into entries in LOG files.īut LogJam was already taken (in that one, LOG referred to discrete logarithms, as performed in cryptographic calculations, not to logfiles). Just when you thought it was safe to relax for the weekend…