CISA to brief critical infrastructure companies about urgent new Log4j vulnerability
Full article570 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
Log4j is a widely-used open-source logging tool popular in apps including Minecraft, Apple Cloud, Cloudflare and Twitter.
The Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency will host a call with critical infrastructure stakeholders Monday afternoon about a critical vulnerability affecting products with the Log4j software library, according to a statement.
CISA sent out an alert Friday that the agency had added the flaw to its list of exploited vulnerabilities, and urged federal and civilian organizations to patch and take steps to mitigate harm immediately. Log4j is a widely-used, open-source logging utility used in numerous cloud and enterprise apps including Minecraft, Apple iCloud, Cloudflare and Twitter, to track software activity. The ubiquity of the tool makes the extent of the zero-day’s potential damage likely wide-reaching.
“CISA is working closely with our public and private sector partners to proactively address a critical vulnerability affecting products containing the log4j software library,” CISA director Jen Easterly said in a statement. “This vulnerability, which is being widely exploited by a growing set of threat actors, presents an urgent challenge to network defenders given its broad use.”
Cybersecurity researchers noted over the weekend that cybercriminals were racing to take advantage of the newly announced vulnerability.
“We are proactively reaching out to entities whose networks may be vulnerable and are leveraging our scanning and intrusion detection tools to help government and industry partners identify exposure to or exploitation of the vulnerability,” Easterly said.
Botnets launching malicious cryptocurrency-generation operations have begun to exploit the vulnerability, Sophos researcher Sean Gallagher wrote Sunday. Sophos since Dec. 9 has observed thousands of attempts to exploit the Log4j flaw, including attempts to exfiltrate information from Amazon Web Services keys and other private data.
Researchers have compared the severity of the vulnerability to EternalBlue, which was used in the global WannaCry ransomware attack and the 2014 ShellShock exploit.
While most of the activities researchers have noticed so far are crimes of opportunity with criminals scanning for any vulnerable systems, research firm GreyNoise has noticed the potential for more targeted attacks. Researchers at Microsoft have also noticed attacks using CobaltStrike, which can be used to further compromise vulnerable systems.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Jail time for Maine child in 764 marks turning point in federal law enforcement
Technology
Threats
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/log4j-cisa-vulnerability/