Ilkka Turunen

Ilkka serves as Field CTO at Sonatype. He is a software engineer with a knack for rapid web-development and cloud computing and with technical experience on multiple levels of the XaaS cake. Ilkka is interested in anything and everything, always striving to learn any relevant skills that help towards building Sonatype for success.

A New OpenSSL Vulnerability Is Coming - Get Ready to Patch

By Ilkka Turunen on October 26, 2022 News

3 minute read time

On Tuesday 1st of November, between 1-5pm UTC a new version of the widely adopted OpenSSL 3.x series will be released for general consumption.
Read More...

Weaponizing Open Source Through Job Recruiting

By Ilkka Turunen on October 03, 2022 News

7 minute read time

There have been troubling new reports of threat actors weaponizing open source to target employee machines at technology companies, governments, and more.
Read More...

Spring4Shell – By the Numbers

By Ilkka Turunen on April 04, 2022 component vulnerability

6 minute read time

Spring4Shell, a new 0-day RCE, is not quite as bad as Log4shell but has a wide blast radius. We dive into the numbers on how the world is fixing the issue.
Read More...

New Spring Framework RCE Vulnerability Confirmed - What to Do?

7 minute read time

A new remote code execution flaw dubbed Springshell is affecting Spring-beans, exploiting a previously unknown security vulnerability.
Read More...

Sonatype Celebrates February 3rd 2022 as World Open Source Day

By Ilkka Turunen on February 03, 2022 Everything Open Source

5 minute read time

We declare February 3rd World Open Source day. Why? Our roots lie firmly in Open Source and we want to celebrate maintainers across the world & give back
Read More...

Meet an Open Source Contributor: Sal Kimmich

By Ilkka Turunen on February 03, 2022 Everything Open Source

4 minute read time

Meet Sal Kimmich one of the incredible open source contributors at Sonatype. Learn more about why and how they got into open source.
Read More...

Helping The Open Source Community Find, Fix, and Remediate Log4j

By Ilkka Turunen on December 15, 2021 vulnerabilities

5 minute read time

Assistance to protect the software supply chain from Log4j and other logging vulnerabilities. Open source intel, Pull Request Protection, SBOMs, and more.
Read More...

Log4shell by the numbers- Why did CVE-2021-44228 set the Internet on Fire?

By Ilkka Turunen on December 14, 2021 vulnerabilities

6 minute read time

What the download numbers tell us about the impact of the critical vulnerability CVE-2021-44228
Read More...

What is the Log4j Exploit?

By Ilkka Turunen on December 10, 2021 vulnerabilities

7 minute read time

A serious 0-day Remote Code Execution exploit in log4j, the most popular java logging framework, was discovered today. Immediate action is needed from software maintainers.
Read More...