[ad_1]
A loophole Open source Apache log library Log4j makes system administrators and security professionals scrambling All weekend. The vulnerability is called Log4Shell, and it exposes some of the world’s most popular applications and services to attacks. Since the vulnerability was exposed on Thursday, the outlook has not improved. If anything, it is now very clear that Log4Shell will continue to cause severe damage on the Internet in the next few years.
According to researchers, hackers have been exploiting the vulnerability since the beginning of this month. Cisco and Cloud flareBut after Apache’s disclosure on Thursday, attacks increased dramatically. According to a recent report, so far, attackers have used the vulnerability to install encrypted miners on vulnerable systems, steal system credentials, dig deeper in infected networks, and steal data. From Microsoft.
Due to the nature of the vulnerability itself, the scope of the impact is so wide. Developers use logging frameworks to track what is happening in a given application. To use Log4Shell, the attacker only needs to make the system record a carefully designed string of code. From there they can load arbitrary code and install malware or launch other attacks on the target server. It’s worth noting that hackers can introduce the snippet in a seemingly benign way, such as sending a string via email or setting it as an account username.
Major technology players, including Amazon Web Services, Microsoft, Cisco, Google Cloud, and IBM Everyone has found that at least some of their services are vulnerable and have been eager to release fixes and advise customers on how to best proceed. However, the exact degree of exposure is still under consideration. Less picky organizations or smaller developers who may lack resources and awareness will be slower to face the Log4Shell threat.
“It is almost certain that over the years, when people think of new locations to place exploit strings, they will find new long tails of vulnerable software,” said independent security researcher Chris Frohoff. “This may appear in the evaluation and penetration testing of custom enterprise applications for a long time.”
Jen Easterly, director of the US Agency for Cybersecurity and Infrastructure Security, said in a statement that the vulnerability has been exploited by “an increasing number of threat actors.” statement Saturday. As originally reported, she added in a call with critical infrastructure operators on Monday that this flaw is “one of the most serious flaws I have seen in my entire career, if not the most serious” Courtesy of CyberScoopIn the same conference call, a CISA official estimated that hundreds of millions of devices may be affected.
The hard part will keep track of all of them. Many organizations do not clearly describe every program they use and the software components in every system.UK National Cyber Security Centre Emphasize On Monday, in addition to patching the usual suspects, companies also need to “discover unknown Log4j instances.” By its nature, open source software can be merged wherever developers want, which means that when a major vulnerability occurs, exposed code may be lurking in every corner. Even before Log4Shell, software supply chain security advocates have increasingly promoted the “software bill of materials” or SBOM to make it easier to take inventory and keep up with the pace of security protection.
[ad_2]
Source link






