FTC warns of potential penalties for firms that fail to fix Log4j software flaws
Full article633 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
The agency says the warning applies to future vulnerabilities too.
The Federal Trade Commission Tuesday warned companies that if they fail to take action to remedy a major recent software vulnerability in open-source software tool Log4j, there could be legal repercussions.
“When vulnerabilities are discovered and exploited, it risks a loss or breach of personal information, financial loss, and other irreversible harms,” the agency warned. “It is critical that companies and their vendors relying on Log4j act now, in order to reduce the likelihood of harm to consumers, and to avoid FTC legal action.”
Log4j is ubiquitous in software used throughout the technology industry, and is found in products built by companies including Amazon, Google and Microsoft. The widespread use of such technology has made it difficult to identify potential victims. At the same time, the popularity has made it an easy target for a range of cybercriminals to exploit.
The warning shot from the top consumer protection agency comes as lawmakers debate the specifics of a federal law overseeing requirements for companies that suffer a breach.
The FTC has in the past applied its oversight authority to such consumer concerns.
Tuesday’s notice cites Equifax’s $700 million settlement with the agency in 2019 as a cautionary tale. The FTC’s complaint alleged that Equifax’s failure to patch a known flaw led to the exposure of the personal information of 147 million customers. Such breaches have continued in the years since: Morgan Stanley on Monday reached a $60 million settlement with customers who accused the bank of exposing their personal data with outdated IT.
The FTC plans to apply its legal authority to protect consumers in the cases of “similar known vulnerabilities in the future,” the notice adds.
The agency pointed companies to guidance from the Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency, which has issued a series of alerts and advisories on how to patch. CISA set a deadline of Dec. 23 for civilian federal agencies to patch the vulnerability. A CISA spokesperson confirmed Tuesday that the agency “received status reports from all large agencies, which have either patched or deployed alternate mitigations to address the risk,” but did not clarify which non-“large” agencies had not met the deadline.
The debacle with Log4j has highlighted a systemic deficit of resources to keep the open-source projects critical to the internet safe, as MIT Technology Review reported. The FTC indicated it was interested in at looking such concerns “as we work to address the root issues that endanger user security.”
Tim Starks contributed reporting to this story.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Chinese espionage groups swarm to exploit triple-link chain of zero-days
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/ftc-warns-of-action-against-firms-that-fail-to-fix-log4j-software-flaws/