Umbrel os Security - Malware detected - log4j?

I have just installed this week the latest version of umbrel os, and after security tests i see the device reaching out to known listed malware/log4j targets and on ports 7777, 13962, 14178, 60668,
i will check this further:

1 - stopping all apps (I had around 4 running)
2 - starting and checking apps individually

My questions:
1 - Does Umbrel or anyone checks the base os for security concerns?
2 - Does Umbrel or anyone checks the apps on the marketplace?

Thanks in advance, any contribution is valid

After all the initial troubleshooting, some vulnerabilities detected and further risk considerations (even before going for deeper app’s analysis, I’ve decided to leave umbrel os for now (for another more established and interested in working for a stable secure product),

I really liked the umbrel os idea and maybe at some point in the future it will make sense to recheck and reevaluate…