‘The internet’s on fire’ as techs race to fix software flaw
[ad_1]
The photo shows a screenshot of a Minecraft logo displayed on a smartphone’s screen.
Pavlo Gonchar | SOPA Images | LightRocket | Getty Images
A critical vulnerability in a widely used software tool — one quickly exploited in the online game Minecraft — is rapidly emerging as a major threat to organizations around the world.
Crowdstrike’s senior vice president for intelligence, Adam Meyers said that “the internet is on fire right now.” He stated that “people are scrambling for patches” and “all kinds of people trying to exploit it.” On Friday, he stated that the bug had been “fully weaponsized” in 12 hours after it was discovered. This means that malefactors have developed tools and distributed them to exploit the bug.
This flaw could be the most serious computer vulnerability ever discovered. This vulnerability was discovered in an utility used in enterprise and cloud software across government and industry. It is a vulnerability that if not fixed will allow criminals, hackers, and novice programming professionals easy access to the internal network, where they can steal valuable data, install malware, and erase critical information.
Joe Sullivan is the chief security officer at Cloudflare. His online infrastructure helps protect websites against malicious actors. Experts say the impact of this technology will not be apparent for many days, despite it being installed on millions upon millions of servers.
Amit Yoran, CEO of the cybersecurity firm Tenable, called it “the single biggest, most critical vulnerability of the last decade” — and possibly the biggest in the history of modern computing.
Log4Shell was the vulnerability that led to the exploit. It was given a rating of 10 by the Apache Software Foundation. This foundation oversees the development of the software. An exploit allows anyone to access any computer with the software that is not patched.
Experts said the extreme ease with which the vulnerability lets an attacker access a web server — no password required — is what makes it so dangerous.
New Zealand’s Computer Emergency Response Team was one of the first to reveal that the flaw was “actively exploited” in the wild, just hours following its public disclosure on Thursday.
It was discovered in Apache open-source software that is used for websites. The vulnerability was first reported to the foundation by Alibaba on November 24, it stated. The fix took more than two weeks to create and publish.
However, patching the systems across the globe could prove difficult. Though most organisations and cloud providers, such as Amazon, should be able update their web servers quickly, many Apache programs are embedded in third party applications that cannot be updated.
Yoran of Tenable said that organizations should assume they have been compromised and respond quickly.
Minecraft was the first to show signs that this flaw had been exploited. Minecraft is an immensely popular online game owned by Microsoft. Marcus Hutchins, security expert and Meyers both claimed that Minecraft users had already used it to run programs on other computers by simply entering a message into a chat window.
Microsoft claimed it had released a Minecraft update. Microsoft stated, “Customers who apply this fix are protected.”
According to researchers, the vulnerability can be exploited on servers operated by Apple, Amazon, Twitter, and Cloudflare.
Cloudflare’s Sullivan stated that there was no evidence his company’s servers were compromised. Apple, Amazon, and Twitter didn’t immediately reply to our requests for comment.
[ad_2]
