This website collects cookies to deliver better user experience. Cookie Policy
Accept
Sign In
The Wall Street Publication
  • Home
  • Trending
  • U.S
  • World
  • Politics
  • Business
    • Business
    • Economy
    • Real Estate
    • Markets
    • Personal Finance
  • Tech
  • Lifestyle
    • Lifestyle
    • Style
    • Arts
  • Health
  • Sports
  • Entertainment
Reading: What Is the Log4j Vulnerability?
Share
The Wall Street PublicationThe Wall Street Publication
Font ResizerAa
Search
  • Home
  • Trending
  • U.S
  • World
  • Politics
  • Business
    • Business
    • Economy
    • Real Estate
    • Markets
    • Personal Finance
  • Tech
  • Lifestyle
    • Lifestyle
    • Style
    • Arts
  • Health
  • Sports
  • Entertainment
Have an existing account? Sign In
Follow US
© 2024 The Wall Street Publication. All Rights Reserved.
The Wall Street Publication > Blog > Tech > What Is the Log4j Vulnerability?
Tech

What Is the Log4j Vulnerability?

Editorial Board Published December 14, 2021
Share
What Is the Log4j Vulnerability?
SHARE

A flaw in widely used internet software has left companies and government officials scrambling to respond to a potentially glaring cybersecurity threat to global computer networks.

Contents
What is Log4j?How can hackers take advantage of Log4j’s vulnerability?More From WSJ Pro CybersecurityHow widespread is the Log4j flaw?Which technology suppliers are affected by the Log4j vulnerability?How can companies fix the Log4j problem?

The previously undiscovered bug, hidden inside software known as Log4j, could prove to be a boon for criminal and nation-state hackers, cybersecurity experts say. U.S. officials on Monday held an emergency call with companies that operate critical infrastructure and have urged businesses to update their networks and be on the lookout for attacks.

Here’s what we know about the Log4j flaw:

What is Log4j?

Software developers use the Log4j framework to record user activity and the behavior of applications for subsequent review. Distributed for free by the nonprofit Apache Software Foundation, Log4j has been downloaded millions of times and is among the most widely used tools to collect information across corporate computer networks, websites and applications.

How can hackers take advantage of Log4j’s vulnerability?

The Log4j flaw, disclosed by Apache last week, allows attackers to execute code remotely on a target computer, meaning that they can steal data, install malware or take control. Some cybercriminals have installed software that uses a hacked system to mine cryptocurrency, while others have developed malware that allows attackers to hijack computers for large-scale assaults on internet infrastructure.

More From WSJ Pro Cybersecurity

Security experts are particularly concerned that the vulnerability may give hackers enough of a foothold within a system to install ransomware, a type of computer virus that locks up data and systems until the attackers are paid by victims. For larger companies, these ransoms can total millions of dollars. The attacks can also cause widespread disruption, such as the infection of systems at Colonial Pipeline Co. in May that forced a six-day shutdown of the largest fuel pipeline on the East Coast.

“To be clear, this vulnerability poses a severe risk,” said Jen Easterly, director of the Cybersecurity and Infrastructure Security Agency, in a statement issued Sunday.

How widespread is the Log4j flaw?

Internet-facing systems as well as backend systems could contain the vulnerability. Log4j software is widely used in business software development. “Likely millions of servers are at risk,” said Lou Steinberg, founder of CTM Insights LLC, a tech incubator. An Apache spokeswoman said the nature of how Log4j is inserted into different pieces of software makes it impossible to track the tool’s reach.

CISA has created an information page with recommendations.

Which technology suppliers are affected by the Log4j vulnerability?

Many, and the list is growing. Among them are Apple Inc., Amazon.com Inc., Cloudflare Inc., IBM, Microsoft Corp.’s Minecraft, Palo Alto Networks Inc. and Twitter Inc. Several technology companies have issued alerts and guidance to customers about how to decrease their risk.

How can companies fix the Log4j problem?

Some patches and technical guidance are available. The Apache organization has released multiple updates in recent days and advised upgrading to the latest version of the Log4j tool. Oracle Corp. released its own patches on Friday. Microsoft recommended a series of steps to mitigate the risk of exploitation, including contacting your software application providers to be sure they are using the most up-to-date version of Java, which would include patches.

In lieu of available patches, Teresa Walsh, global head of intelligence at the Financial Services Information Sharing and Analysis Center, recommends that companies limit unnecessary outbound internet traffic, which would go some way to protecting vulnerable systems.

“Firms can reduce their risk by reducing their exposure,” she said.

—Catherine Stupp contributed to this article.

Write to David Uberti at [email protected],James Rundle at [email protected] and Kim S. Nash at [email protected]

Copyright ©2021 Dow Jones & Company, Inc. All Rights Reserved. 87990cbe856818d5eddac44c7b1cdeb8

TAGGED:Tech NewsWall Street Publication
Share This Article
Twitter Email Copy Link Print
Previous Article Millennials Are Supercharging the Housing Market Millennials Are Supercharging the Housing Market
Next Article Toyota Keeps Its EV Options Open—Maybe Too Open Toyota Keeps Its EV Options Open—Maybe Too Open

Editor's Pick

New Council of Financial Advisors report finds tariffs not inflicting inflation

New Council of Financial Advisors report finds tariffs not inflicting inflation

Former Trump administration head of financial coverage Tomas Philipson discusses President Trump’s commerce talks with South Korea and Japan, present…

By Editorial Board 4 Min Read
Denise Richards’ Husband, Aaron Phypers, Recordsdata For Divorce
Denise Richards’ Husband, Aaron Phypers, Recordsdata For Divorce

Studying Time: 3 minutes Denise Richards could quickly be headed for divorce…

4 Min Read
NBA Summer time League takeaways: Warriors rookie Will Richard makes debut vs. Spurs
NBA Summer time League takeaways: Warriors rookie Will Richard makes debut vs. Spurs

Richard makes debut SAN FRANCISCO – The Warriors‘ acquisition of their three…

5 Min Read

Oponion

The highest 5 absurd suggestions from liberal pundits for surviving holidays with Trump-voting household

The highest 5 absurd suggestions from liberal pundits for surviving holidays with Trump-voting household

Because the scent of pine fills the air and the…

December 25, 2024

Jessica Simpson Flaunts INSANE Weight Loss in Teeny, Tiny Bikini

Studying Time: 2 minutes Consideration, males…

July 11, 2025

Placing most cancers warning labels on alcohol bottles might take years, specialists say

Some trade specialists are skeptical that…

January 12, 2025

Lucy Markovic Reason behind Demise: Mannequin, Actuality Star Passes Away at 27

Studying Time: 3 minutes Lucy Markovic…

April 12, 2025

Netflix Tudum 2025: each announcement from Stranger Issues, One Piece, Squid Sport, Wednesday and extra

Refresh 2025-06-01T02:07:57.152Z Netflix Tudum 2025 is…

June 1, 2025

You Might Also Like

The 142 Prime Day Offers You Can Nonetheless Snag If You’re Fast
Tech

The 142 Prime Day Offers You Can Nonetheless Snag If You’re Fast

Prime Day could also be over, however not each deal is useless. These hand-picked Prime Day offers are nonetheless on.…

95 Min Read
These Are the Finest Offers We’ve Discovered on Pet Tech for Amazon Prime Day
Tech

These Are the Finest Offers We’ve Discovered on Pet Tech for Amazon Prime Day

Amazon Prime Day is arguably one of the best time of the 12 months to improve your pet's setup for…

17 Min Read
Banish Boredom With These Prime Day Board Recreation Offers
Tech

Banish Boredom With These Prime Day Board Recreation Offers

With summer time holidays nonetheless stretching off into the space, making the most of Prime Day board sport offers or…

13 Min Read
You Don’t Want an iPad, however Do You Need One? Then These Prime Day Apple Offers Are for You
Tech

You Don’t Want an iPad, however Do You Need One? Then These Prime Day Apple Offers Are for You

When you've got one Apple product, you normally have all of them—whether or not that is AirPods, an iPhone, an…

15 Min Read
The Wall Street Publication

About Us

The Wall Street Publication, a distinguished part of the Enspirers News Group, stands as a beacon of excellence in journalism. Committed to delivering unfiltered global news, we pride ourselves on our trusted coverage of Politics, Business, Technology, and more.

Company

  • About Us
  • Newsroom Policies & Standards
  • Diversity & Inclusion
  • Careers
  • Media & Community Relations
  • WP Creative Group
  • Accessibility Statement

Contact

  • Contact Us
  • Contact Customer Care
  • Advertise
  • Licensing & Syndication
  • Request a Correction
  • Contact the Newsroom
  • Send a News Tip
  • Report a Vulnerability

Term of Use

  • Digital Products Terms of Sale
  • Terms of Service
  • Privacy Policy
  • Cookie Settings
  • Submissions & Discussion Policy
  • RSS Terms of Service
  • Ad Choices

© 2024 The Wall Street Publication. All Rights Reserved.

Welcome Back!

Sign in to your account

Lost your password?