If hackers are exploiting the Log4j flaw, CISA says we might not know yet
Full article822 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
The agency harkened back to the long delay between vulnerability discovery and the Equifax breach.
Federal officials cautioned Monday that, while the widespread Log4j vulnerability hasn’t led to any major known intrusions in the U.S., there could be a “lag” between when the flaw became known, and when attackers exploit it.
Cybersecurity and Infrastructure Security Agency Director Jen Easterly said that there were months between the discovery of the vulnerability that led to the 2017 Equifax breach, which exposed the personal information of nearly 150 million Americans, and word of the breach itself, invoking one of the most notable hacks in history.
“We do expect Log4j to be used in intrusions well into the future,” Easterly said on a call with reporters. “There may be a lag between when this vulnerability is being used and when it is being actively deployed.”
Apache Struts, an open-source tool, was at the center of the Equifax breach, and Apache’s Log4j is a ubiquitous open-source logging tool. Easterly said that CISA, a division of the Homeland Security Department, has catalogued Log4j’s presence in more than 2,800 distinct commercial products. That means it’s likely present in hundreds of millions of tech assets, she said.
Further, exploiting the so-called Log4Shell vulnerability — which Easterly has deemed the most severe she’s seen in her career — “is pretty trivial,” she said.
“A threat actor can use the vulnerability to compromise the target system by typing only 12 characters into a text message, email subject line or chat window,” she said.
Easterly credited the work of her agency, industry, international governments and the research community for leading a patching effort that also might have stymied the influx of Log4j-related intrusions.
That doesn’t mean everyone has remained unscathed since its uncovering one month ago. Attackers took down the Belgian Defense Ministry using the exploit, and an unnamed “large academic institution” is among the victims, reportedly at the hands of Chinese hackers.
U.S. government agencies appear to have been spared so far, said Eric Goldstein, executive assistant director for cybersecurity at CISA. While CISA says that unspecified “large” agencies have met CISA’s patching deadlines, Goldstein didn’t say when smaller agencies that haven’t met the deadline would be up to speed.
“We’re working with each of these agencies, side by side and day by day. We have dedicated teams who are focusing on helping each of the agencies along in this process,” he said. “The number of impacted assets at these agencies are small and so we do hope that they will be able to fully remediate these assets in short order.”
Additionally, Goldstein said, “We have no confirmed ransomware intrusions where we can authoritatively say the Log4Shell was used at the originating vulnerability for the intrusion.”
Security researchers have said ransomware gangs are using the vulnerability in ransomware attacks.
More Scoops
Open-source security is posing challenges governments can’t easily solve
A diffuse landscape, fruitful targets, companies not stepping up, AI’s influence and flagging U.S. government efforts all figure into a shifting threat.
Top CISA official Eric Goldstein to depart agency next month
Cyber Safety Review Board needs stronger authorities, more independence, experts say
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Chinese espionage groups swarm to exploit triple-link chain of zero-days
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/cisa-log4j-lag-easterly-goldstein-equifaqx/