ZeroHour
CyberScooppublished ()ingested @AJVicens

DHS issues emergency directive ordering all federal civilian agencies to address Log4j flaw

criticalRansomware exploited in the wildimportance 60
Full article685 words · extracted from cyberscoop.com · click to collapse
Skip to main content

Get our latest cybersecurity news first on Google.

Click here!

The directive lands amid escalating concern about the impact of the bug.

(Photo by In Pictures Ltd./Corbis via Getty Images)

U.S. cyber officials issued an emergency directive Friday giving all federal civilian agencies until Dec. 23 to assess their internet-facing networks for the Apache Log4j vulnerability and immediately patch the systems, or take other measures to mitigate the software flaw.

The directive, issued by the Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency, comes in response to “the active exploitation by multiple threat actors” of the Log4j bug, which has roiled the information security community since it emerged Dec. 10 as a vulnerability in widely used logging software. The directive also requires agencies to report to CISA by Dec. 28 all software applications affected by the bug by name and version, and what actions were taken.

“The log4j vulnerabilities pose an unacceptable risk to federal network security,” CISA Director Jen Easterly said in a statement. “If you are using a vulnerable product on your network, you should consider your door wide open to any number of threats.”

The directive is based on current exploitation of the Log4j vulnerabilities, the likelihood of exploitation, the prevalence of affected software among federal agencies, and the potential impact of a successful compromise, Easterly’s statement said.

The directive, first reported by CNN, comes amid escalating concern about how hackers would leverage the vulnerability to launch ransomware attacks or take remote control of affected systems. In comments first reported by CyberScoop, Easterly said Dec. 14 that the bug was perhaps “the most serious” she’d seen in her career, and expected it to be “widely exploited.” Another top CISA official, Jay Gazlay, estimated that hundreds of millions of devices” were likely to be affected.

The same day, threat intelligence analysts at Microsoft and cybersecurity firm Mandiant said they’d seen indications that nation-state hackers associated with the governments of China, Iran, North Korea and Turkey had begun to experiment with and leverage the bug in hacking campaigns.

On Friday, cybersecurity firm AdvIntel posted an analysis stating that hackers working with the Conti ransomware group, one of the most prolific and concerning ransomware operations, started to use the vulnerability in active ransomware attacks on Dec. 15.

More Scoops

Nadezhda Buravleva, iStock/Getty Images Plus

Open-source security is posing challenges governments can’t easily solve

A diffuse landscape, fruitful targets, companies not stepping up, AI’s influence and flagging U.S. government efforts all figure into a shifting threat.

Cybersecurity and Infrastructure Security Agency Director Jen Easterly testified before a House Homeland Security Subcommittee, at the Rayburn House Office Building on April 28, 2022. (Photo by Kevin Dietsch/Getty Images)

CISA emergency directive tells agencies to fix credentials after Microsoft breach

The U.S. Capitol is seen in Washington, DC, on November 14, 2023. (Photo by Stefani Reynolds / AFP)

Cyber Safety Review Board needs stronger authorities, more independence, experts say

Latest Podcasts

Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/log4j-emergency-directive-cisa-conti/