This website collects cookies to deliver better user experience. Cookie Policy
Accept
Sign In
The Wall Street Publication
  • Home
  • Trending
  • U.S
  • World
  • Politics
  • Business
    • Business
    • Economy
    • Real Estate
    • Markets
    • Personal Finance
  • Tech
  • Lifestyle
    • Lifestyle
    • Style
    • Arts
  • Health
  • Sports
  • Entertainment
Reading: Two Months On, Many Developers Are Still Downloading Flawed Log4j Tool
Share
The Wall Street PublicationThe Wall Street Publication
Font ResizerAa
Search
  • Home
  • Trending
  • U.S
  • World
  • Politics
  • Business
    • Business
    • Economy
    • Real Estate
    • Markets
    • Personal Finance
  • Tech
  • Lifestyle
    • Lifestyle
    • Style
    • Arts
  • Health
  • Sports
  • Entertainment
Have an existing account? Sign In
Follow US
© 2024 The Wall Street Publication. All Rights Reserved.
The Wall Street Publication > Blog > Tech > Two Months On, Many Developers Are Still Downloading Flawed Log4j Tool
Tech

Two Months On, Many Developers Are Still Downloading Flawed Log4j Tool

Editorial Board Published February 10, 2022
Share
Two Months On, Many Developers Are Still Downloading Flawed Log4j Tool
SHARE

The December disclosure of a security flaw in a widely used piece of logging software known as Log4j drew grave warnings from U.S. officials that the bug could open the door for a surge in cyberattacks.

But vulnerable versions of the free tool continue to be downloaded at least tens of thousands of times each day, according to a cybersecurity company that manages a repository for such open-source projects. The flawed updates make up more than one-third of Log4j downloads from the catalog, a portion that doesn’t appear to be shrinking.

These developers “don’t know what’s going on inside their software,” said Brian Fox, chief technology officer for the cybersecurity company Sonatype Inc. that runs the repository.

The Log4j vulnerability set off a global race for many companies to patch their computer systems and highlighted how much of the digital economy relies on open-source tools. Maintained by volunteers, Log4j is a free-to-use bit of code that helps track activity across many computer applications.

Mr. Fox’s company acts as a steward for Maven Central, a repository where software developers can access open-source code such as Log4j to include in their projects. On Wednesday afternoon, the platform counted more than 7,500 downloads an hour of versions of Log4j released before its initial security updates were published in December.

That total doesn’t necessarily reflect the number of organizations affected, Mr. Fox said, as developers building or updating their software may use automated tools that repeatedly request Log4j. But the figure does represent 36% of all requests directed toward old versions of the tool during that period.

“That ratio still kind of represents what’s going on across the entire ecosystem generally,” Mr. Fox said, adding that his firm has limited insight into who is still using the flawed software. “That’s pretty terrible.”

David Nalley, president of the Apache Software Foundation, the nonprofit that oversees the distribution of Log4j, said it is possible some developers are downloading old versions of the tool for security research or after evaluating the software’s potential threats to their organizations’ systems. Apache updated Log4j in December after a researcher at Chinese e-commerce firm Alibaba Group Holding Ltd. reported a bug that could allow attackers to execute code remotely and potentially take over computer systems they target. The nonprofit released subsequent fixes in response to additional security concerns.

Flawed forms of the code are still available because so many other pieces of software still rely on them, said Mr. Nalley, who shared estimates of the continuing downloads during a hearing Tuesday before the Senate Committee on Homeland Security and Governmental Affairs.

“There would be massive breakage of a number of systems if it disappeared, because they depend upon it,” he said in an interview.

Jen Miller-Osborn, deputy director of threat intelligence at Palo Alto Networks, speaks during the Senate hearing on Tuesday.

Photo: Julia Nikhinson/Bloomberg News

Kurt John, chief information security officer for industrial conglomerate Siemens USA, advised companies that need to use such versions of Log4j to build security controls around it to detect fishy activity. Internally, Siemens USA has seen instances where Log4j was deployed in applications or networks that aren’t accessible from the internet, so they were less of a priority to fix, he said.

The bug has pushed some companies and governments to monitor the open-source tools that act as building blocks in their technology more carefully.

Last month, representatives for companies including Microsoft Corp. , Amazon.com Inc., Apple Inc. and Facebook parent Meta Platforms Inc. met with U.S. officials at the White House to discuss how to thwart such security threats. Additionally, the Biden administration last week unveiled a panel of federal officials and private-sector experts, modeled loosely on the National Transportation Safety Board, to investigate major cyber incidents. The Cyber Review Board’s first investigation will probe Log4j.

Even though the Log4j tool isn’t currently tied to many high-profile cyberattacks, security experts warn that the software’s ubiquity suggests related threats could last years. Speaking at the Senate hearing Tuesday, Jen Miller-Osborn, deputy director of threat intelligence at cybersecurity company Palo Alto Networks Inc., said attackers are using remotely controlled botnets to scan for weak points.

“The fact that [Log4j] has been adopted by botnets as well serves to highlight that this vulnerability is never going to die,” she said.

Ransomware attacks are increasing in frequency, victim losses are skyrocketing, and hackers are shifting their targets. WSJ’s Dustin Volz explains why these attacks are on the rise and what the U.S. can do to fight them. Photo illustration: Laura Kammermann

—Kim S. Nash contributed to this article

Write to David Uberti at david.uberti@wsj.com

Copyright ©2022 Dow Jones & Company, Inc. All Rights Reserved. 87990cbe856818d5eddac44c7b1cdeb8

TAGGED:Tech NewsWall Street Publication
Share This Article
Twitter Email Copy Link Print
Previous Article EV Charging Network Will Target Interstate Highways EV Charging Network Will Target Interstate Highways
Next Article Contamination at Maker of Flash-Memory Chips Poses Risk to Global Supply Chain Contamination at Maker of Flash-Memory Chips Poses Risk to Global Supply Chain

Editor's Pick

Over 300 economists urge Trump, GOP leaders to increase tax cuts earlier than huge tax hike hits Individuals

Over 300 economists urge Trump, GOP leaders to increase tax cuts earlier than huge tax hike hits Individuals

Economists Steve Moore and EJ Antoni weigh in on President Donald Trump's work to spice up U.S. manufacturing and Elon…

By Editorial Board 7 Min Read
What did Dana Chandler do? Contained in the case of the Kansas lady convicted of double homicide after three trials
What did Dana Chandler do? Contained in the case of the Kansas lady convicted of double homicide after three trials

Dana Chandler has spent many years sustaining her innocence in opposition to…

90 Min Read
The celebration that price a California lady her state monitor title
The celebration that price a California lady her state monitor title

CLOVIS —After Clara Adams appeared to have develop into a state monitor…

5 Min Read

Oponion

Warren Buffett Says Markets Have Become a ‘Gambling Parlor’

Warren Buffett Says Markets Have Become a ‘Gambling Parlor’

OMAHA, Neb.—As recently as February, Warren Buffett lamented he wasn’t…

April 30, 2022

Opinion: Battle-tested Los Angeles reveals resilience and group in face of fireside

“Trial by fire.”It’s a cliché, however…

January 9, 2025

Gwendlyn Brown Lastly Reveals Why She Didn’t Attend Her Mother’s Marriage ceremony

The Brown household has been going…

October 22, 2024

Michael Strahan Divorced: His Historical past of Marriage, Defined

Studying Time: 3 minutes Michael Strahan…

June 7, 2025

49ers’ Brock Purdy full go for follow Wednesday

SANTA CLARA — Has the 49ers’…

September 25, 2024

You Might Also Like

The Landscape of International Trade in 2025: Constant Evolution and Strategic Shifts
TechTrending

The Landscape of International Trade in 2025: Constant Evolution and Strategic Shifts

The international trade landscape is in constant flux, and the year 2025 is no exception. According to expert Manoel Gil…

3 Min Read
TLI Ranked Highest-Rated 3PL on Google Reviews
TechTrending

TLI Ranked Highest-Rated 3PL on Google Reviews

EXTON, PA — Translogistics, Inc. (TLI), a trailblazer in the 3PL and managed logistics space since its founding in 1994,…

12 Min Read
The Finest LED Face Masks and Pink-Gentle Remedy for At-Dwelling Therapies
Tech

The Finest LED Face Masks and Pink-Gentle Remedy for At-Dwelling Therapies

Finest Cooling LED Face Masks{Photograph}: SHARKShark CryoGlow Pink Blue & Infrared iQLED Face Masks & Underneath Eye CoolingThe Shark CryoGlow…

4 Min Read
Which Google Pixel Telephone Ought to You Purchase?
Tech

Which Google Pixel Telephone Ought to You Purchase?

Google Pixel telephones are our favourite Android telephones right here at WIRED and have been for a number of years.…

6 Min Read
The Wall Street Publication

About Us

The Wall Street Publication, a distinguished part of the Enspirers News Group, stands as a beacon of excellence in journalism. Committed to delivering unfiltered global news, we pride ourselves on our trusted coverage of Politics, Business, Technology, and more.

Company

  • About Us
  • Newsroom Policies & Standards
  • Diversity & Inclusion
  • Careers
  • Media & Community Relations
  • WP Creative Group
  • Accessibility Statement

Contact

  • Contact Us
  • Contact Customer Care
  • Advertise
  • Licensing & Syndication
  • Request a Correction
  • Contact the Newsroom
  • Send a News Tip
  • Report a Vulnerability

Term of Use

  • Digital Products Terms of Sale
  • Terms of Service
  • Privacy Policy
  • Cookie Settings
  • Submissions & Discussion Policy
  • RSS Terms of Service
  • Ad Choices

© 2024 The Wall Street Publication. All Rights Reserved.

Welcome Back!

Sign in to your account

Lost your password?