This website collects cookies to deliver better user experience. Cookie Policy
Accept
Sign In
The Wall Street Publication
  • Home
  • Trending
  • U.S
  • World
  • Politics
  • Business
    • Business
    • Economy
    • Real Estate
    • Markets
    • Personal Finance
  • Tech
  • Lifestyle
    • Lifestyle
    • Style
    • Arts
  • Health
  • Sports
  • Entertainment
Reading: Two Months On, Many Developers Are Still Downloading Flawed Log4j Tool
Share
The Wall Street PublicationThe Wall Street Publication
Font ResizerAa
Search
  • Home
  • Trending
  • U.S
  • World
  • Politics
  • Business
    • Business
    • Economy
    • Real Estate
    • Markets
    • Personal Finance
  • Tech
  • Lifestyle
    • Lifestyle
    • Style
    • Arts
  • Health
  • Sports
  • Entertainment
Have an existing account? Sign In
Follow US
© 2024 The Wall Street Publication. All Rights Reserved.
The Wall Street Publication > Blog > Tech > Two Months On, Many Developers Are Still Downloading Flawed Log4j Tool
Tech

Two Months On, Many Developers Are Still Downloading Flawed Log4j Tool

Editorial Board Published February 10, 2022
Share
Two Months On, Many Developers Are Still Downloading Flawed Log4j Tool
SHARE

The December disclosure of a security flaw in a widely used piece of logging software known as Log4j drew grave warnings from U.S. officials that the bug could open the door for a surge in cyberattacks.

But vulnerable versions of the free tool continue to be downloaded at least tens of thousands of times each day, according to a cybersecurity company that manages a repository for such open-source projects. The flawed updates make up more than one-third of Log4j downloads from the catalog, a portion that doesn’t appear to be shrinking.

These developers “don’t know what’s going on inside their software,” said Brian Fox, chief technology officer for the cybersecurity company Sonatype Inc. that runs the repository.

The Log4j vulnerability set off a global race for many companies to patch their computer systems and highlighted how much of the digital economy relies on open-source tools. Maintained by volunteers, Log4j is a free-to-use bit of code that helps track activity across many computer applications.

Mr. Fox’s company acts as a steward for Maven Central, a repository where software developers can access open-source code such as Log4j to include in their projects. On Wednesday afternoon, the platform counted more than 7,500 downloads an hour of versions of Log4j released before its initial security updates were published in December.

That total doesn’t necessarily reflect the number of organizations affected, Mr. Fox said, as developers building or updating their software may use automated tools that repeatedly request Log4j. But the figure does represent 36% of all requests directed toward old versions of the tool during that period.

“That ratio still kind of represents what’s going on across the entire ecosystem generally,” Mr. Fox said, adding that his firm has limited insight into who is still using the flawed software. “That’s pretty terrible.”

David Nalley, president of the Apache Software Foundation, the nonprofit that oversees the distribution of Log4j, said it is possible some developers are downloading old versions of the tool for security research or after evaluating the software’s potential threats to their organizations’ systems. Apache updated Log4j in December after a researcher at Chinese e-commerce firm Alibaba Group Holding Ltd. reported a bug that could allow attackers to execute code remotely and potentially take over computer systems they target. The nonprofit released subsequent fixes in response to additional security concerns.

Flawed forms of the code are still available because so many other pieces of software still rely on them, said Mr. Nalley, who shared estimates of the continuing downloads during a hearing Tuesday before the Senate Committee on Homeland Security and Governmental Affairs.

“There would be massive breakage of a number of systems if it disappeared, because they depend upon it,” he said in an interview.

Jen Miller-Osborn, deputy director of threat intelligence at Palo Alto Networks, speaks during the Senate hearing on Tuesday.

Photo: Julia Nikhinson/Bloomberg News

Kurt John, chief information security officer for industrial conglomerate Siemens USA, advised companies that need to use such versions of Log4j to build security controls around it to detect fishy activity. Internally, Siemens USA has seen instances where Log4j was deployed in applications or networks that aren’t accessible from the internet, so they were less of a priority to fix, he said.

The bug has pushed some companies and governments to monitor the open-source tools that act as building blocks in their technology more carefully.

Last month, representatives for companies including Microsoft Corp. , Amazon.com Inc., Apple Inc. and Facebook parent Meta Platforms Inc. met with U.S. officials at the White House to discuss how to thwart such security threats. Additionally, the Biden administration last week unveiled a panel of federal officials and private-sector experts, modeled loosely on the National Transportation Safety Board, to investigate major cyber incidents. The Cyber Review Board’s first investigation will probe Log4j.

Even though the Log4j tool isn’t currently tied to many high-profile cyberattacks, security experts warn that the software’s ubiquity suggests related threats could last years. Speaking at the Senate hearing Tuesday, Jen Miller-Osborn, deputy director of threat intelligence at cybersecurity company Palo Alto Networks Inc., said attackers are using remotely controlled botnets to scan for weak points.

“The fact that [Log4j] has been adopted by botnets as well serves to highlight that this vulnerability is never going to die,” she said.

Ransomware attacks are increasing in frequency, victim losses are skyrocketing, and hackers are shifting their targets. WSJ’s Dustin Volz explains why these attacks are on the rise and what the U.S. can do to fight them. Photo illustration: Laura Kammermann

—Kim S. Nash contributed to this article

Write to David Uberti at [email protected]

Copyright ©2022 Dow Jones & Company, Inc. All Rights Reserved. 87990cbe856818d5eddac44c7b1cdeb8

TAGGED:Tech NewsWall Street Publication
Share This Article
Twitter Email Copy Link Print
Previous Article EV Charging Network Will Target Interstate Highways EV Charging Network Will Target Interstate Highways
Next Article Contamination at Maker of Flash-Memory Chips Poses Risk to Global Supply Chain Contamination at Maker of Flash-Memory Chips Poses Risk to Global Supply Chain

Editor's Pick

Aneudy Neo Gonzalez, Esq.: A Legal Mind Shaping the Future of Healthcare and Community Advocacy

Aneudy Neo Gonzalez, Esq.: A Legal Mind Shaping the Future of Healthcare and Community Advocacy

Aneudy Neo Gonzalez, Esq. is a respected attorney, educator, and advocate whose career bridges law, healthcare, and community empowerment. With nearly…

By Editorial Board 5 Min Read
Haley Kalil Reveals HUGE Purpose for Matt Kalil Divorce
Haley Kalil Reveals HUGE Purpose for Matt Kalil Divorce

Studying Time: 4 minutes What brought on mannequin and influencer Haley Kalil…

6 Min Read
Why Republicans suppose it’s okay to starve poor folks
Why Republicans suppose it’s okay to starve poor folks

Explaining the Proper is a weekly collection that appears at what the correct…

6 Min Read

Oponion

Native officers have a robust software to warn residents of emergencies. They don’t all the time use it.

Native officers have a robust software to warn residents of emergencies. They don’t all the time use it.

Native officers can faucet a federal warning system to ship…

September 23, 2025

Stock Futures Rise, Treasury Yields Tick Higher

U.S. stock futures edged higher to…

November 1, 2021

Single-family residence in Fremont sells for $1.7 million

Bay Space Residence Report 37742 Elmore…

January 9, 2025

Sateliot will get 30 M from the European Funding Financial institution

Highlights: Sateliot is a Spanish startup…

December 4, 2024

Uber Expects to Be Cash-Flow Positive by Fourth Quarter of 2022

Uber Technologies Inc. UBER -6.07% spooked…

February 10, 2022

You Might Also Like

Trump’s Hatred of EVs Is Making Gasoline Vehicles Extra Costly
Tech

Trump’s Hatred of EVs Is Making Gasoline Vehicles Extra Costly

This story initially appeared on Mom Jones and is a part of the Local weather Desk collaboration.As President Donald Trump…

6 Min Read
Gear Information of the Week: Fairphone Lands within the US, and WhatsApp Is Lastly on the Apple Watch
Tech

Gear Information of the Week: Fairphone Lands within the US, and WhatsApp Is Lastly on the Apple Watch

The one smartphone producer with a ten/10 iFixit repairability rating is lastly bringing its merchandise to the US, but it…

5 Min Read
Why Are We All Nonetheless Carrying Round Automobile Keys?
Tech

Why Are We All Nonetheless Carrying Round Automobile Keys?

My iPhone Pockets shops theater and transit tickets and all of my credit score and debit playing cards, and it…

5 Min Read
Department’s Sale of the 12 months Brings Nice Reductions to Our Favourite House Workplace Gear
Tech

Department’s Sale of the 12 months Brings Nice Reductions to Our Favourite House Workplace Gear

It is arduous to seek out house workplace furnishings that appears nice at a palatable worth. That is why you…

9 Min Read
The Wall Street Publication

About Us

The Wall Street Publication, a distinguished part of the Enspirers News Group, stands as a beacon of excellence in journalism. Committed to delivering unfiltered global news, we pride ourselves on our trusted coverage of Politics, Business, Technology, and more.

Company

  • About Us
  • Newsroom Policies & Standards
  • Diversity & Inclusion
  • Careers
  • Media & Community Relations
  • WP Creative Group
  • Accessibility Statement

Contact

  • Contact Us
  • Contact Customer Care
  • Advertise
  • Licensing & Syndication
  • Request a Correction
  • Contact the Newsroom
  • Send a News Tip
  • Report a Vulnerability

Term of Use

  • Digital Products Terms of Sale
  • Terms of Service
  • Privacy Policy
  • Cookie Settings
  • Submissions & Discussion Policy
  • RSS Terms of Service
  • Ad Choices

© 2024 The Wall Street Publication. All Rights Reserved.

Welcome Back!

Sign in to your account

Lost your password?