Scarinci Hollenbeck, LLC
The Firm
201-896-4100 info@sh-law.comFirm Insights
Author: Scarinci Hollenbeck, LLC
Date: February 14, 2022
The Firm
201-896-4100 info@sh-law.comThe Federal Trade Commission (FTC) is advising companies to work quickly to remediate the Log4j security vulnerability. Failure to act could result in an FTC enforcement action under applicable laws such as the Federal Trade Commission Act and the Gramm Leach Bliley Act.
Log4j is very broadly used in a variety of consumer and enterprise services, websites, and applications—as well as in operational technology products—to log security and performance information. In December, a critical security flaw was discovered, which could be exploited by an unauthenticated remote actor to take control of an affected system.
On January 3, 2022, Microsoft warned that the vulnerabilities in Apache Log4j 2, referred to as “Log4Shell”, remain a “complex and high-risk” situation for companies. It further advised that due to the “many software and services that are impacted and given the pace of updates, this is expected to have a long tail for remediation, requiring ongoing, sustainable vigilance.”
In light of the severity of the vulnerabilities and the likelihood of exploitation by sophisticated cyber threat actors, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) urges vendors and users to immediately identify, mitigate, and update affected products using Log4j to the latest version. It also recommends that companies conduct a security review to determine if there is a security concern or compromise.
On January 4, 2022, the FTC issued an alert regarding the Log4j security vulnerability, noting that it poses a severe risk to millions of consumer products to enterprise software and web applications. The FTC encouraged companies to update their Log4j software package to the most current version found and follow guidance issued by CISA.
The FTC also advised companies to ensure remedial steps are taken to avoid legal repercussions, emphasizing that the failure to identify and patch instances of the software may violate the Federal Trade Commission Act (FTC Act).
“When vulnerabilities are discovered and exploited, it risks a loss or breach of personal information, financial loss and other irreversible harms,” the agency wrote. “The duty to take reasonable steps to mitigate known software vulnerabilities implicates laws including, among others, the Federal Trade Commission Act and the Gramm Leach Bliley Act. It is critical that companies and their vendors relying on Log4j act now, in order to reduce the likelihood of harm to consumers, and to avoid FTC legal action.”
The FTC alert also cited its enforcement action against Equifax, which involved the company’s failure to patch a known vulnerability and the disclosure of the personal information of 147 million consumers. Equifax agreed to pay $700 million to settle actions by the FTC, the Consumer Financial Protection Bureau, and all fifty states. According to the FTC, it intends to use its “full legal authority” to pursue companies that fail to take reasonable steps to protect consumer data from exposure as a result of Log4j, or similar known vulnerabilities in the future.
If you have any questions or if you would like to discuss the matter further, please contact me, Maryam Meseha, or the Scarinci Hollenbeck attorney with whom you work, at 201-896-4100.
No Aspect of the advertisement has been approved by the Supreme Court. Results may vary depending on your particular facts and legal circumstances.
The Trump Administration’s new tariffs are having an oversized impact on small businesses, which already tend to operate on razor thin margins. Many businesses have been forced to raise prices, find new suppliers, lay off staff, and delay growth plans. For businesses facing even more dire financial circumstances, there are additional tariff response options, including […]
Author: Brian D. Spector
Business partnerships, much like marriages, function exceptionally well when partners are aligned but can become challenging when disagreements arise. Partnership disputes often stem from conflicts over business strategy, financial management, and unclear role definitions among partners. Understanding Business Partnership Conflicts Partnership conflicts place significant stress on businesses, making proactive measures essential. Partnerships should establish detailed […]
Author: Christopher D. Warren
*** The original article was featured on Bloomberg Tax, April 28, 2025 — As a tax attorney who spends much of my time helping people and companies who have large, unresolved issues with the IRS or one or more state tax departments, it often occurs to me that the best service that I can provide […]
Author: Scott H. Novak
On January 28, 2025, the Trump Administration terminated Gwynne Wilcox from her position as a Member of the National Labor Relations Board (NLRB or the Board). Gwynne Wilcox, a union side lawyer for Levy Ratner, was confirmed to the Board for an original term in 2021 and confirmed again for a successive five-year term expiring […]
Author: Matthew F. Mimnaugh
Breach of contract disputes are the most common type of business litigation. Therefore, nearly all New York and New Jersey businesses will likely have to deal with a contract dispute at least once. Understanding when to file a breach of contract lawsuit and how long you have to sue for breach of contract is essential […]
Author: Brittany P. Tarabour
Closing your business can be a difficult and challenging task. For corporations, the process includes formal approval of the dissolution, winding up operations, resolving tax liabilities, and filing all required paperwork. Whether you need to understand how to dissolve a corporation in New York or New Jersey, it’s imperative to take all of the proper […]
Author: Christopher D. Warren
No Aspect of the advertisement has been approved by the Supreme Court. Results may vary depending on your particular facts and legal circumstances.
Consider subscribing to our Firm Insights mailing list by clicking the button below so you can keep up to date with the firm`s latest articles covering various legal topics.
Stay informed and inspired with the latest updates, insights, and events from Scarinci Hollenbeck. Our resource library provides valuable content across a range of categories to keep you connected and ahead of the curve.
Let`s get in touch!
Sign up to get the latest from the Scarinci Hollenbeck, LLC attorneys!