PanamaTimes

Saturday, Dec 21, 2024

'Potential for damage incalculable': Experts sound alarm over cyber vulnerability in widely used software

'Potential for damage incalculable': Experts sound alarm over cyber vulnerability in widely used software

While the first victims hit by hackers were Minecraft players, experts warn the cyber vulnerability could soon be exploited by spies and organised criminals.

Security experts are sounding the alarm over a newly discovered software vulnerability, and organisations have been advised to "urgently" check whether it leaves them exposed to hackers.

Alerts have been issued by the British and American governments as a growing number of hacking groups - potentially including spies and organised criminals - are exploiting the vulnerability to break into computer networks.

The British government said it was treating "this issue with the utmost seriousness" as the US warned the vulnerability was "being widely exploited by a growing set of threat actors".

Researchers in the private sector said "the potential for damage is incalculable" with one describing the severity as: "The internet is on fire right now."

The UK government said it was treating the issue 'with the utmost seriousness'


What is the issue?


It is very rare for enterprise software to be completely written from the ground up for every different product.

Instead this software often depends on a shared library of open-source code maintained by charity organisations and distributed without any royalties.

The new vulnerability has been discovered in one such bit of code.

Known as Log4j, the open-source tool is an Apache Software Foundation project and used almost ubiquitously in enterprise software products and cloud services.

It won't directly impact people using personal devices, but any data they have with organisations that operate web servers could be at risk.

A fix has already been published by Apache - which described the vulnerability as "critical" - and large companies who control and update their own software should be able to quickly patch the vulnerability.

But because Log4j is so widely used as a logging utility there are likely to be thousands of companies exposed because the flaw affects third-party software which they cannot directly update.

Apache credited Chen Zhaojun, a security researcher at Chinese company Alibaba, for discovering and reporting the issue.

Minecraft players were among the first victims.


Who has been affected?


The first wave of victims were people playing the Microsoft-owned computer game Minecraft.

Hackers were able to post a short message in the Minecraft chatbox to remotely execute commands on the computers of other players.

Microsoft said it has patched the issue for Minecraft players and told customers they would be protected if they applied the fix.

The most obvious first wave of attacks all involved "cryptojacking", when hackers hijack victim's computers to use their processing power to mine cryptocurrencies.

Microsoft warned that alongside installing coin miners it had seen hackers exploiting the flaw to steal credentials and data from victim's computers.

"The internet's on fire right now. People are scrambling to patch and all kinds of people are scrambling to exploit it," said Adam Meyers, senior vice president of intelligence at cyber security company Crowdstrike.

The software flaw could be used to attack banks and even governments


'A very serious threat'


"I cannot overstate the seriousness of this threat," warned Lotem Finkelstein, director of threat intelligence for Check Point Software Technologies.

Mr Finkelstein warned that the cryptojacking activity "creates just the sort of background noise that serious threat actors will try to exploit in order to attack a whole range of high value targets".

Check Point has detected hundreds of thousands of attempts to exploit this vulnerability across more than a third of all corporate global networks.

"Security teams need to jump on this with utmost urgency as the potential for damage is incalculable," Mr Finkelstein added.

Newsletter

Related Articles

PanamaTimes
0:00
0:00
Close
A large group of unauthorized migrants is traveling through Mexico with the aim of reaching the USA before Trump assumes office.
A Democrat Congresswoman with blue and black hair is having a breakdown over "President Musk."
Argentina Defies Predictions with Record $17 Billion Trade Surplus, But Is the Growth Sustainable?
Disney's High Seas Gamble: Navigating the Waters of Cruise Expansion
The Surprising Impact of Extreme Heat on Mexico's Youth
Polarization: The Word That Unites a Divided Era
Exoneration in the Subway: The Complexities of Self-Defense and Public Safety
The Tragic Passing of UnitedHealthcare CEO Highlights Corporate Security Challenges
Global Developments: Violence in Sinaloa, Political Chaos in the Bahamas, Venezuelan Voting Disputes, and a Major UK Drug Bust
OpenAI and Anduril: Charting AI's Path in Modern Warfare
The Pardon of Hunter Biden: A Symbol of Hypocrisy
Biden Crafted the Strategy Used by Trump
South Korea's Democracy Tested: President Yoon’s Martial Law Reversal Sparks Political Reckoning
Seoul Crisis: Yoon Suk Yeol's Martial Law Blunder Triggers Political Upheaval
Generative AI's Limited Impact on Elections Highlighted by Meta
France at the Precipice: Barnier’s Administration Confronts Unprecedented No-Confidence Vote
Jaguar Unveils Electric Concept Car, Type 00
White House Defends Presidential Pardon of Hunter Biden
xAI by Elon Musk: Transforming Ambition with a $50 Billion Valuation
President-elect Donald Trump, has announced on Truth Social that Kashyap "Kash" Patel, will be the next Director of the FBI
A Historic Milestone or Risky Precedent? The Assisted Dying Bill Splits both Parliament and the Nation in England and Wales
Trump's Tariff Threat Looms Large as Trudeau Heads to Mar-a-Lago for Talks
Canada's Oil Industry Faces Uncertainty Amidst Trump's Tariff Threat
World Court to Assess Global Legal Responsibilities on Climate Change
What the Pink Elephant Test Reveals About Thought Control
Trudeau Visits Trump in Florida Amid Rising Tariff Concerns
Is Elon Musk the Unofficial President of America?
Impact of Proposed US Tariffs on Canadian Oil Exports
U.S. policymakers face a contentious debate over whether to engage with Nicolás Maduro's regime in Venezuela.
COP29's Carbon Trading Deal Faces Major Criticisms
Indian Diplomats in Canada Monitored: Government Raises Alarm
Putin Warns Trump of Ongoing Safety Concerns
Claudia Sheinbaum Challenges Trump's Migration Claims
Insights from Dostoevsky: The Impact of Self-Deception
Trump Administration Nominees Face Threats, FBI Confirms
Elon Musk Criticizes Fighter Jets, Advocates for Drone Warfare
Kim Kardashian's Social Media Activity Fuels Political Speculation
An Examination of AI's Influence on Future Work and Life
Tulsi Gabbard's Contentious Nomination for Director of National Intelligence
$100,000 Trump Watch Faces Slow Sales
Surge in Golden Visa Interest Among Americans Post-Trump Election
Elon Musk and Vivek Ramaswamy Aim to Reduce US Federal Spending
Donald Trump nominated Linda McMahon for the position of Secretary of Education.
Russia Pledges Response Following Ukraine's Use of US Long-Range Missiles
Joe Biden Joins G20 Leaders' Photo Re-Take in Rio
Trump Plans to Reverse Biden's Fuel and EV Regulations
WHO Approves Second Vaccine for Mpox Emergency Use
Donald Trump's Unnamed Presence Looms Over G20 Summit
Trump Media and Technology Group's Shares Surge Amid Crypto Exchange Acquisition Talks
The Rising Menace of AI-Generated Deepfake Pornography
×