Saudi Assistant Minister holds defense cooperation talks in Pakistan    GACA fines for civil aviation violations exceed SR5.3 million in Q1    NMDC showcases innovation and saustainability at AACE conference    Attack sends message to Iran but Israelis divided over response    Children among seven dead in Russian strike on Dnipropetrovsk region    US vetoes Palestinian attempt to gain statehood at the United Nations    Saudi Arabia expresses regret over UN Security Council's decision on Palestinian membership    Beijing half marathon: Top three stripped of medals after investigation    Taylor Swift releases surprise double album    Markets rocked as US says Israel has struck Iran    Centuries-old defensive moat and fortification wall unearthed in Historic Jeddah    Dhul Qadah 29 is the last day for Umrah pilgrims to leave the Kingdom 90-day duration of visa begins from the date of entering the Kingdom; Hajj Ministry clarifies    'Saudi hospitality sector to generate SR42 billion investments and 120,000 jobs by 2030'    Poignant shot from Gaza wins World Press Photo of the Year 2024    Saudi Pro League postpones Al-Hilal vs. Al-Ahli match; Al-Ahli rejects rescheduling    50% traffic fine reduction takes effect    Al Ain ends Al Hilal's record streak with a 4-2 win in AFC Champions League semi-final    'Zarqa Al Yamama': Tickets now available for Saudi Arabia's first opera premiering April 25    Turki Alalshikh announces groundbreaking 5 vs 5 Riyadh Season bout featuring international boxing stars    Diriyah Biennale Foundation announces shortlist for AlMusalla Prize, set to revolutionize musalla architecture    JK Rowling in 'arrest me' challenge over hate crime law    Trump's Bible endorsement raises concern in Christian religious circles    Hollywood icon Will Smith shares his profound admiration for Holy Qur'an    We have celebrated Founding Day for three years - but it has been with us for 300    Exotic Taif Roses Simulation Performed at Taif Rose Festival    Asian shares mixed Tuesday    Weather Forecast for Tuesday    Saudi Tourism Authority Participates in Arabian Travel Market Exhibition in Dubai    Minister of Industry Announces 50 Investment Opportunities Worth over SAR 96 Billion in Machinery, Equipment Sector    HRH Crown Prince Offers Condolences to Crown Prince of Kuwait on Death of Sheikh Fawaz Salman Abdullah Al-Ali Al-Malek Al-Sabah    HRH Crown Prince Congratulates Santiago Peña on Winning Presidential Election in Paraguay    SDAIA Launches 1st Phase of 'Elevate Program' to Train 1,000 Women on Data, AI    41 Saudi Citizens and 171 Others from Brotherly and Friendly Countries Arrive in Saudi Arabia from Sudan    Saudi Arabia Hosts 1st Meeting of Arab Authorities Controlling Medicines    General Directorate of Narcotics Control Foils Attempt to Smuggle over 5 Million Amphetamine Pills    NAVI Javelins Crowned as Champions of Women's Counter-Strike: Global Offensive (CS:GO) Competitions    Saudi Karate Team Wins Four Medals in World Youth League Championship    Third Edition of FIFA Forward Program Kicks off in Riyadh    Evacuated from Sudan, 187 Nationals from Several Countries Arrive in Jeddah    SPA Documents Thajjud Prayer at Prophet's Mosque in Madinah    SFDA Recommends to Test Blood Sugar at Home Two or Three Hours after Meals    SFDA Offers Various Recommendations for Safe Food Frying    SFDA Provides Five Tips for Using Home Blood Pressure Monitor    SFDA: Instant Soup Contains Large Amounts of Salt    Mawani: New shipping service to connect Jubail Commercial Port to 11 global ports    Custodian of the Two Holy Mosques Delivers Speech to Pilgrims, Citizens, Residents and Muslims around the World    Sheikh Al-Issa in Arafah's Sermon: Allaah Blessed You by Making It Easy for You to Carry out This Obligation. Thus, Ensure Following the Guidance of Your Prophet    Custodian of the Two Holy Mosques addresses citizens and all Muslims on the occasion of the Holy month of Ramadan    







Thank you for reporting!
This image will be automatically disabled when it gets reported by several people.



Log4j security flaw could impact the entire internet
Published in The Saudi Gazette on 16 - 12 - 2021

A critical flaw in widely used software has cybersecurity experts raising alarms and big companies racing to fix the issue, CNN reports.
The vulnerability, which was reported late last week, is in Java-based software known as "Log4j" that large organizations use to configure their applications -- and it poses potential risks for much of the internet.
Apple's cloud computing service, security firm Cloudflare, and one of the world's most popular video games, Minecraft, are among the many services that run Log4j, according to security researchers.
Jen Easterly, head of the Department of Homeland Security's Cybersecurity and Infrastructure Security Agency (CISA), called it "one of the most serious flaws" seen in her career. In a statement on Saturday, Easterly said "a growing set" of hackers are actively attempting to exploit the vulnerability.
As of Tuesday, more than 100 hacking attempts were occurring per minute, according to data this week from cybersecurity firm Check Point.
"It will take years to address this while attackers will be looking... on a daily basis [to exploit it]," said David Kennedy, CEO of cybersecurity firm TrustedSec. "This is a ticking time bomb for companies."
What is Log4j and why does it matter?
Log4j is one of the most popular logging libraries used online, according to cybersecurity experts. Log4j gives software developers a way to build a record of activity to be used for a variety of purposes, such as troubleshooting, auditing and data tracking. Because it is both open-source and free, the library essentially touches every part of the internet.
"It's ubiquitous. Even if you're a developer who doesn't use Log4j directly, you might still be running the vulnerable code because one of the open source libraries you use depends on Log4j," Chris Eng, chief research officer at cybersecurity firm Veracode, told CNN Business. "This is the nature of software: It turtles all the way down."
Companies such as Apple, IBM, Oracle, Cisco, Google and Amazon, all run the software. It could present in popular apps and websites, and hundreds of millions of devices around the world that access these services could be exposed to the vulnerability.
Are hackers exploiting it?
Attackers appear to have had more than a week's head start on exploiting the software flaw before it was publicly disclosed, according to cybersecurity firm Cloudflare. Now, with such a high number of hacking attempts happening each day, some worry the worst is to yet come.
"Sophisticated, more senior threat actors will figure out a way to really weaponize the vulnerability to get the biggest gain," Mark Ostrowski, Check Point's head of engineering, said Tuesday.
Late Tuesday, Microsoft said in an update to a blog post that state-backed hackers from China, Iran, North Korea and Turkey have tried to exploit the Log4j flaw.
Why is this security flaw so bad?
Experts are especially concerned about the vulnerability because hackers can gain easy access to a company's computer server, giving them entry into other parts of a network. It's also very hard to find the vulnerability or see if a system has already been compromised, according to Kennedy.
In addition, a second vulnerability in Log4j's system was found late Tuesday. Apache Software Foundation, a nonprofit that developed Log4j and other open source software, has released a security fix for organizations to apply.
How are companies are trying to address the issue?
Last week, Minecraft published a blog post announcing a vulnerability was discovered in a version of its game -- and quickly issued a fix. Other companies have taken similar steps.
US warns hundreds of millions of devices at risk from newly revealed software vulnerability
US warns hundreds of millions of devices at risk from newly revealed software vulnerability
IBM, Oracle, AWS and Cloudflare have all issued advisories to customers, with some pushing security updates or outlining their plans for possible patches.
"This is such a severe bug, but it's not like you can hit a button to patch it like a traditional major vulnerability. It's going to require a lot of time and effort," said Kennedy.
For transparency and to help cut down on misinformation, CISA said it would set up a public website with updates on what software products were affected by the vulnerability and how hackers exploited them.
What can you do to protect yourself?
The pressure is largely on companies to act. For now, people should make sure to update devices, software and apps when companies give prompts in the coming days and weeks.
The US government has issued a warning to impacted companies to be on high alert over the holidays for ransomware and cyberattacks.
There is concern that an increasing number of malicious actors will make use of the vulnerability in new ways, and while large technology companies may have the security teams in place to deal with these potential threats, many other organizations do not.
"What I'm most concerned about is the school districts, the hospitals, the places where there's a single IT person who does security who doesn't have time or the security budget or tooling," said Katie Nickels, Director of Intelligence at cybersecurity firm Red Canary. "Those are the organizations I'm most worried about -- small organizations with small security budgets."


Clic here to read the story from its source.