This website collects cookies to deliver better user experience. Cookie Policy
Accept
Sign In
The Wall Street Publication
  • Home
  • Trending
  • U.S
  • World
  • Politics
  • Business
    • Business
    • Economy
    • Real Estate
    • Markets
    • Personal Finance
  • Tech
  • Lifestyle
    • Lifestyle
    • Style
    • Arts
  • Health
  • Sports
  • Entertainment
Reading: Software Flaw Sparks Global Race to Patch Bug
Share
The Wall Street PublicationThe Wall Street Publication
Font ResizerAa
Search
  • Home
  • Trending
  • U.S
  • World
  • Politics
  • Business
    • Business
    • Economy
    • Real Estate
    • Markets
    • Personal Finance
  • Tech
  • Lifestyle
    • Lifestyle
    • Style
    • Arts
  • Health
  • Sports
  • Entertainment
Have an existing account? Sign In
Follow US
© 2024 The Wall Street Publication. All Rights Reserved.
The Wall Street Publication > Blog > Tech > Software Flaw Sparks Global Race to Patch Bug
Tech

Software Flaw Sparks Global Race to Patch Bug

Editorial Board Published December 12, 2021
Share
Software Flaw Sparks Global Race to Patch Bug
SHARE

Companies and governments around the world rushed over the weekend to fend off cyberattacks looking to exploit a serious flaw in a widely used piece of Internet software that security experts warn could give hackers sweeping access to networks.

Contents
Newsletter Sign-upTechnology

Cybersecurity researchers said the bug, hidden in an obscure piece of server software called Log4j, represents one of the biggest risks seen in recent years because the code is so widely used on corporate networks.

The Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency issued an urgent alert about the vulnerability and urged companies to take action. CISA Director Jen Easterly said on Saturday, “To be clear, this vulnerability poses a severe risk. We will only minimize potential impacts through collaborative efforts between government and the private sector.” Germany’s cybersecurity organization over the weekend issued a “red alert” about the bug. Australia called the issue “critical.”

Security experts warned that it could take weeks or more to assess the extent of the damage and that hackers exploiting the vulnerability could access sensitive data on networks and install back doors they could use to maintain access to servers even after the flawed software has been patched.

“‘It is one of the most significant vulnerabilities that I’ve seen in a long time.’”

— Aaron Portnoy of security firm Randori

“It is one of the most significant vulnerabilities that I’ve seen in a long time,” said Aaron Portnoy, principal scientist with the security firm Randori.

Security experts noted that many companies have other processes in place that would prevent a malicious hacker from running software and breaking into these companies, potentially limiting the fallout from the bug.

Microsoft Corp. , in an alert to customers, said “attackers are probing all endpoints for vulnerability.” Amazon.com Inc., Twitter Inc. and Cisco Systems Inc. were among the companies that have said they were carrying out investigations into the depth of the problem. Amazon, the world’s biggest cloud computing company, said in a security alert, “We are actively monitoring this issue, and are working on addressing it.”

The software flaw was reported late last month to the Log4j development team, a group of volunteer coders who distribute their software free-of-charge as part of the Apache Software Foundation, according to Ralph Goers, a volunteer with the project. The foundation, a nonprofit group that helps oversee the development of many open-source programs, alerted its user community about the vulnerability on Dec. 9.

“It’s a very critical issue,” Mr. Goers said. “People need to upgrade to get the fix,” he said. Log4j is used on servers to keep records of users’ activities so they can be reviewed later on by security or software development teams.

Because Log4j is distributed free, it is unclear how many servers are affected by the bug, but the logging software has been downloaded millions of times, Mr. Goers said.

Software providers that include Log4j in their products, such as International Business Machines Corp.’s Red Hat, Oracle Corp. and VMware Inc., have said they are deploying patches.

It isn’t the first time that open-source software has sparked security concerns. In 2014, internet users world-wide were urged to reset their passwords after another issue, known as Heartbleed, was discovered in OpenSSL, an obscure yet similarly ubiquitous piece of internet software built by volunteers.

Hackers started exploiting the flaw widely early Friday, including to gain access to servers running Microsoft’s Minecraft gaming software, researchers said. The researchers soon observed widespread scanning and attempts to trigger the Log4j bug across the Internet. In a note published Friday, Microsoft advised some Minecraft gamers that they should upgrade their software to patch the bug.


Newsletter Sign-up

Technology

A weekly digest of tech reviews, headlines, columns and your questions answered by WSJ’s Personal Tech gurus.


During a roughly 24-hour period, the security firm Check Point Software Technologies Ltd. said it saw more than 100,000 attempts to exploit the bug, about half of which it estimated were from malicious cyberattackers. The rest were by legitimate researchers, either governments scanning national infrastructure or security researchers, Check Point said.

A Dutch researcher, Cas van Cooten, said he discovered the bug on Apple Inc.’s servers, potentially giving him a way of running code within Apple’s network. Mr. van Cooten said he immediately reported the issue to Apple.

“It would have been trivial for a malicious hacker to weaponize this,” he said. An Apple spokesman didn’t respond to messages seeking comment.

Another researcher, Carson Owlett, said that consultants working with his security firm, Black Mirage LLC, were able to detect the bug on systems run by other companies, including Twitter and LinkedIn, also owned by Microsoft.

“Our teams are looking into it, but we have no details to share at this time,” a Twitter spokeswoman said via email Friday. A LinkedIn spokeswoman said via text message that “while we’re responding to this, just as security teams at many companies are, we’re not experiencing any active issue.”

Because all sorts of data are logged by servers, everything from email addresses to web navigation requests, these attempts could give attackers a foothold on a vulnerable server deep in corporate networks, said Ryan McGeehan, an independent security consultant who was formerly a director of security at Facebook. “A successful attack is like creating a wormhole,” he said. “The attacker can’t be sure where they’ll end up.”

Cisco is investigating more than 150 of its products to look for the Log4j bug. So far, it has found three vulnerable products and determined that 23 aren’t vulnerable, a company spokesman said Saturday.

Write to Robert McMillan at [email protected]

Copyright ©2021 Dow Jones & Company, Inc. All Rights Reserved. 87990cbe856818d5eddac44c7b1cdeb8

TAGGED:Tech NewsWall Street Publication
Share This Article
Twitter Email Copy Link Print
Previous Article The crisis that didn’t happen: How Dems got it wrong about ending the COVID-19 eviction ban The crisis that didn’t happen: How Dems got it wrong about ending the COVID-19 eviction ban
Next Article How Do You Feel About Inflation? The Answer Will Help Determine Its Longevity How Do You Feel About Inflation? The Answer Will Help Determine Its Longevity

Editor's Pick

Trisha Paytas Welcomes Child #3, Reveals Tremendous-Distinctive Title

Trisha Paytas Welcomes Child #3, Reveals Tremendous-Distinctive Title

Studying Time: 2 minutes Trisha Paytas has welcomed her third little one. The well-known YouTuber has additionally revealed their unorthodox…

By Editorial Board 4 Min Read
Closure of I-680 deliberate in Fremont this weekend
Closure of I-680 deliberate in Fremont this weekend

FREMONT — Southbound lanes of Interstate 680 might be closed to visitors…

1 Min Read
6 Greatest Hermes Cologne – Males’s Luxurious Fragrances For 2025 | Fashion
6 Greatest Hermes Cologne – Males’s Luxurious Fragrances For 2025 | Fashion

We independently consider all advisable services. Any services or products put ahead…

13 Min Read

Oponion

Dow craters, DOGE dividend? and DOJ eyes UnitedHealth

Dow craters, DOGE dividend? and DOJ eyes UnitedHealth

'The Claman Countdown' panelists Steve Sosnick and Keith Fitz-Gerald consider…

February 21, 2025

Farmers Feel the Squeeze of Inflation

Inflation is growing on the farm.…

February 15, 2022

While Electric Vehicles Proliferate, Charging Stations Lag Behind

U.S. efforts to build a national…

May 30, 2022

Bhad Bhabie Debuts Surprising New Look Amidst Ongoing Feud

Studying Time: 3 minutes Bhad Bhabie…

February 20, 2025

Cybersecurity Firms Cut Staff as Fears About Economy, Funding Mount

Cybersecurity companies have laid off hundreds…

December 21, 2022

You Might Also Like

This Is the Excellent Sleeping Bag
Tech

This Is the Excellent Sleeping Bag

Yearly, my household kicks off summer time—aka tenting season—with a weekend within the excessive desert, the place it’s a blisteringly…

4 Min Read
What You Ought to Know About Fiberglass and Chemical substances in Flame Retardant Mattresses
Tech

What You Ought to Know About Fiberglass and Chemical substances in Flame Retardant Mattresses

What do mattresses and a field of matches have in widespread? It is not simply that they’re each rectangular—each can…

6 Min Read
I Thought the Dell 14 Plus Was Mid Till the Value Dropped This A lot
Tech

I Thought the Dell 14 Plus Was Mid Till the Value Dropped This A lot

Once I first reviewed the Dell 14 Plus (6/10, WIRED Overview), my important criticism was over the value. On the…

4 Min Read
You’ve Most likely Heard of a California King Mattress. However What About an Alberta King?
Tech

You’ve Most likely Heard of a California King Mattress. However What About an Alberta King?

King-sized mattresses are the biggest mattress measurement you will get, proper? Shock! It’s not simply the usual king anymore. With…

6 Min Read
The Wall Street Publication

About Us

The Wall Street Publication, a distinguished part of the Enspirers News Group, stands as a beacon of excellence in journalism. Committed to delivering unfiltered global news, we pride ourselves on our trusted coverage of Politics, Business, Technology, and more.

Company

  • About Us
  • Newsroom Policies & Standards
  • Diversity & Inclusion
  • Careers
  • Media & Community Relations
  • WP Creative Group
  • Accessibility Statement

Contact

  • Contact Us
  • Contact Customer Care
  • Advertise
  • Licensing & Syndication
  • Request a Correction
  • Contact the Newsroom
  • Send a News Tip
  • Report a Vulnerability

Term of Use

  • Digital Products Terms of Sale
  • Terms of Service
  • Privacy Policy
  • Cookie Settings
  • Submissions & Discussion Policy
  • RSS Terms of Service
  • Ad Choices

© 2024 The Wall Street Publication. All Rights Reserved.

Welcome Back!

Sign in to your account

Lost your password?