Widely Used Software With Log4j Vulnerability Sends Cyber Defenders Scrambling

The Apache Log4j Remote Code Execution Vulnerability is said to be the “single biggest, most critical vulnerability” of the last decade.

Advertisement
By Reuters | Updated: 14 December 2021 18:11 IST
Highlights
  • Log4j comes from a popular open-source product
  • US government warned the private sector about Log4j and its risks
  • A partial fix for the vulnerability was released on Friday by Apache

The US government sent a warning to the private sector about the Log4j vulnerability

A newly discovered vulnerability in a widely used software library is causing mayhem on the Internet, forcing cyber defenders to scramble as hackers rush to exploit the weakness. The vulnerability, known as Log4j, comes from a popular open-source product that helps software developers track changes in applications that they build. It is so popular and embedded across many companies' programs that security executives expect widespread abuse.

"The Apache Log4j Remote Code Execution Vulnerability is the single biggest, most critical vulnerability of the last decade," said Amit Yoran, chief executive of Tenable, a network security firm, and the founding director of the US Computer Emergency Readiness Team. The US government sent a warning to the private sector about the Log4j vulnerability and the looming risk it poses on Friday.

In a conference call on Monday, the leader of CISA said it was one of the worst vulnerabilities seen in many years. She urged companies to have staff working through the holidays to battle those using new methods to exploit the flaw.

Advertisement

Much of the software affected by Log4j, which bears names like Hadoop or Solr, may be unfamiliar to the public at large. But as with the SolarWinds program at the center of a massive Russian espionage operation last year, the ubiquity of these workhorse programs makes them ideal jumping-off points for digital intruders.

Advertisement

Juan Andres Guerrero-Saade, the principal threat researcher with cybersecurity firm SentinelOne, called it "one of those nightmare vulnerabilities that there's pretty much no way to prepare for." While a partial fix for the vulnerability was released on Friday by Apache, the maker of Log4j, affected companies and cyber defenders will need time to locate the vulnerable software and properly implement patches. Log4j itself is maintained by a few volunteers, security experts said.

In practice, the flaw allows an outsider to enter active code into the record-keeping process. That code then tells the server hosting the software to execute a command giving the hacker control. The issue was first publicly disclosed by a security researcher working for Chinese technology company Alibaba Group Holding Ltd, Apache noted in its security advisory.

Advertisement

It is now apparent that initial exploitation was spotted on December 2, before a patch rolled out a few days later. The attacks became much more widespread as people playing Minecraft used it to take control of servers and spread the word in gaming chats.

So far no major disruptive cyber incidents have been publicly documented as a result of the vulnerability, but researchers are seeing an alarming uptick in hacking groups trying to take advantage of the bug for espionage. "We also expect to see this vulnerability in everyone's supply chain," said Chris Evans, chief information security officer at HackerOne.

Advertisement

Multiple botnets, or groups of computers controlled by criminals, were also exploiting the flaw in a bid to add more captive machines, experts tracking the developments said.

What many experts now fear is that the bug could be used to deploy malware that either destroys data or encrypts it, like what was used against U.S. pipeline operator Colonial Pipeline in May which led to shortages of gasoline in some parts of the United States. Guerrero-Saade said his firm had already seen Chinese hacking groups moving to take advantage of the vulnerability.

The US cybersecurity firms Mandiant and Crowdstrike also said they found sophisticated hacking groups leveraging the bug to breach targets. Mandiant described those hackers as "Chinese government actors" in an email to Reuters.


Will Snapdragon's new 2022 chips make it more prominent as a brand? We discuss this on Orbital, the Gadgets 360 podcast. Orbital is available on Spotify, Gaana, JioSaavn, Google Podcasts, Apple Podcasts, Amazon Music and wherever you get your podcasts.
Affiliate links may be automatically generated - see our ethics statement for details.
 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Advertisement

Related Stories

Popular Mobile Brands
  1. Samsung Galaxy S25 FE Tipped to Go On Sale At This Price in India
  2. Samsung Galaxy F17 5G With 5,000mAh Battery Launched in India
  3. Vivo X300 Pro Will Launch With These Upgrades Over the Vivo X200 Pro
  4. OTT Releases This Week: Coolie, Saiyaara, a Tamannaah Bhatia Web Series
  5. Amazon's 10-Minute Delivery Service is Now Available in This City
  6. Acer Nitro V15 (2025) Launched in India With This Nvidia RTX 50-Series GPU
  7. Need the iPhone 17 Series on Launch Day? Blinkit Promises 10-Min Delivery
  8. Experts Warn Against Charlie Kirk Tokens Amidst Backlash, Volatility
  9. Oppo F31 Series Specifications Confirmed Ahead of India Launch
  10. Realme P3 Lite 5G Price in India Revealed Ahead of Launch
  1. Love Is Blind Season 9: Release Date, Cast, Trailer, and What to Expect
  2. Beauty in Black Season 2 Is Now Streaming on Netflix: This Is What You Need to Know
  3. Experts Warn Against Crypto Tokens Linked to Charlie Kirk Amidst Backlash, Volatility
  4. Vivo X300 Series Key Specifications, Performance Upgrades Revealed Ahead of Anticipated Launch
  5. Xiaomi Moaan InkPalm Mini Plus 2 E-Reader Launched With 5.84-Inch Display, 512GB Storage
  6. iPhone 17 Series Still Behind Samsung Smartphones in Battery Longevity: Report
  7. Police Police OTT Release: Know When, Where to Watch the Tamil Crime Drama Series
  8. Union Minister Jayant Chaudhary, Wife Disclose Over Rs. 43 Lakh in Crypto Assets
  9. The Naked Gun OTT Release Date Revealed: Know When and Where to Watch the Liam Neeson Starrer Online
  10. Samsung Galaxy S25 FE Price in India Leaked; Might Be Similar to Price of Galaxy S24 FE at Launch
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.