Connect with us
X
Categories:

Technology

‘Endemic’ Log4j bug set to persist in the wild for at least a decade, US government warns

Published

on

‘Endemic’ Log4j bug set to persist in the wild for at least a decade, US government warns
Share this post:

Inaugural report from cyber safety panel outlines strengths and weaknesses exposed by momentous security flaw.

The ‘Log4Shell’ vulnerability in open source library Log4j has reached “endemic” proportions and the aftershock could reverberate for “a decade or longer”, according to a landmark US government report.

The inaugural report by the Cyber Safety Review Board (CSRB) provided 19 recommendations for how organizations and government agencies can bolster their networks and applications against the threat.

The CSRB was established in February 2022 by the Department of Homeland Security (DHS) as mandated by a cybersecurity-focused Executive Order that was signed by President Biden a year earlier.

The public-private initiative is tasked with reviewing serious cybersecurity events and delivering strategic recommendations to government, industry, and the information security community.

‘Transformational institution’

The Log4Shell vulnerability, which surfaced in December 2021, offers a potent combination of super-criticality – notching a maximum CVSS severity score of 10 – and enormous attack surface given Log4j’s near-ubiquity in providing Java-based logging to myriad applications.

Secretary of homeland security Alejandro Mayorkas said the CSRB was a “transformational institution that will advance our cyber resilience in unprecedented ways”, and its report will help “strengthen our cyber resilience and advance the public-private partnership that is so vital to our collective security”.

Tim Mackey, principal security strategist at the Synopsys Cybersecurity Research Centre, said the report was unusual in providing “a comprehensive review of the impact and root causes of a cyber incident so quickly”.

The CSRB report (PDF), published on July 14, said “vulnerable instances of Log4j will remain in systems for many years to come, perhaps a decade or longer. Significant risk remains.”

The Apache Software Foundation, which maintains Log4j, was praised for its “well-established software development lifecycle” and “for recognizing the criticality of the problem” in quickly issuing patches.

The report also hailed the rapid production of effective guidance, tools, and threat information by vendors and governments.

Further down the supply chain, however, “organizations still struggled to respond to the event, and the hard work of upgrading vulnerable software is far from complete across many organizations”.

Moreover, the event highlighted “security risks unique to the thinly-resourced, volunteer-based open source community”, which the CSRB said needed more support from both public and private sector stakeholders.

RECOMMENDED  Bug Bounty Radar: September 2022’s newest bug bounty programs

‘Hard to believe’

The report said the CSRB was “not aware of any significant Log4j-based attacks on critical infrastructure systems”, and that hostile exploitation seemed to have “occurred at lower levels than many experts predicted”.

However, Matt Chiodi, chief trust officer at security vendor Cerby, found these claims “very hard to believe”, noting that – as the CSRB itself acknowledged – organizations are not obliged to report exploitation of serious vulnerabilities.

Chiodi also said the recommendations, which among other things cover mitigating ongoing Log4j risks and migrating to a proactive vulnerability management model, “are too opaque for companies to implement in their current form”.

He advised organizations to get “deadly serious about knowing your assets and moving toward a zero-trust architecture”, noting that “most organizations have terrible asset management practices”, particularly in relation to “homegrown applications in the cloud”.

Mackey, meanwhile, cautioned against “reliance on a commercial vendor to alert consumers of a problem presumes that the vendor is properly managing their usage of open source and that they are able to identify and alert all users of their impacted software – even if support for that software has ended.”

With this in mind, “software consumers should implement a trust-but-verify model to validate whether the software they’re given doesn’t contain unpatched vulnerabilities”.


Get More Stories Like This On: Facebook: @AllNaijaEntertainment, Twitter: @AllNaijaEntertainment
General10 hours ago

Skylar Grey – Everything I Need [LYRICS]

General10 hours ago

[Music] Diddy – Dirty Money – “Coming Home” Feat. Skylar Grey

General10 hours ago

Diddy – Dirty Money – “Coming Home” Feat. Skylar Grey [LYRICS]

General10 hours ago

[Music] African China – Amen

General10 hours ago

[Music] African China – Baba God

General10 hours ago

African China – Baba God [LYRICS]

General10 hours ago

Machine Gun Kelly (MGK) “Home” Feat X Ambassadors & Bebe Rexha [LYRICS]

General11 hours ago

Passenger – Let Her Go [LYRICS]

General11 hours ago

[Music] Eminem – “No Love” Feat. Lil Wayne

General11 hours ago

Eminem – “No Love” Feat. Lil Wayne [LYRICS]

Music11 hours ago

[Music] Tatiana Manaois – Buzz Kill

General11 hours ago

Tatiana Manaois – Buzz Kill [LYRICS]

General11 hours ago

James Blunt – Goodbye My Lover [LYRICS]

General11 hours ago

Major Lazer – “Particula” Feat. Nasty C , Ice Prince, Patoranking & Jidenna [LYRICS]

General11 hours ago

James Blunt – You’re Beautiful [LYRICS]

General11 hours ago

Justin Timberlake – Mirrors [LYRICS]

General11 hours ago

[Music] Darey – “Pray For Me” feat. Soweto Gospel Choir

General11 hours ago

Eminem – “Love The Way You Lie” Feat. Rihanna [LYRICS]

General11 hours ago

Goldlink ft. Miguel – Got Friends [LYRICS]

General11 hours ago

Sia – I’m Still Here [LYRICS]

General11 hours ago

Yo Gotti ft. Nicki Minaj – Rake It Up [LYRICS]

General12 hours ago

Shane McMahon – Here Comes The Money [LYRICS]

General12 hours ago

Journey – Faithfully [LYRICS]

General12 hours ago

[Music] Journey – Faithfully

General12 hours ago

Eminem – Not Afraid [LYRICS]

General12 hours ago

[Music] Journey – Don’t Stop Believin’

General12 hours ago

Journey – Don’t Stop Believin’ [LYRICS]

General12 hours ago

21 Savage – Bank Account [LYRICS]

General12 hours ago

Demi Lovato – Sober [LYRICS]

General13 hours ago

Beyonce ft. Jay-Z – Apeshit [LYRICS]

General13 hours ago

Nasty C ft. ASAP Ferg – King [LYRICS]

General13 hours ago

Lil Wayne – Uproar [LYRICS]

Ed Sheeran
Lyrics13 hours ago

Ed Sheeran – Perfect [LYRICS]

General13 hours ago

[Music] Mo’Hits All Star – Close To You

General13 hours ago

Lil Dicky ft. Chris Brown – Freaky Friday [LYRICS]

Michael Jackson
Lyrics13 hours ago

Michael Jackson – Stranger In Moscow [LYRICS]

General13 hours ago

[Music] Celine Dion – I Drove All Night

General13 hours ago

Celine Dion – I Drove All Night [LYRICS]

General13 hours ago

Tatiana Manaois – Hey Little Lady [LYRICS]

Music13 hours ago

[Music] Tatiana Manaois – Live Better

Gnash (singer)
Music4 days ago

[Music] Gnash Ft Olivia O’Brien – I Hate you, I Love you

John Legend
Music1 day ago

[INSTRUMENTAL] John Legend – All Of Me

Alan Walker
Music5 days ago

Alan Walker – Faded [INSTRUMENTAL]

21 Savage
Music2 days ago

[Video] 21 Savage ft. Offset & Metro Boomin – Rap Saved Me

Wiz Khalifa
Music4 days ago

[Instrumental] Wiz Khalifa – See You Again ft. Charlie Puth

General7 days ago

[Music] Sapientdream – Pastlives

Salvation Ministry Choir Amen
Lyrics2 days ago

Salvation Ministry Choir – Amen [LYRICS]

General5 days ago

[Music] The Chainsmokers – ‘Don’t Let Me Down’ Feat. Daya

General7 days ago

[Music] Timbaland – Apologize ft. OneRepublic

Powfu (singer)
Music4 days ago

[Music] Powfu – Death Bed (Coffee for Your Head) Feat. Beabadoobee

General5 days ago

[Music] Wyclef Jean – “Sweetest Girl (Dollar Bill)” Feat. Akon, Lil Wayne, Niia

General3 days ago

[Music] Zayn Malik – Entertainer

Wiz Khalifa - See You Again ft. Charlie Puth
Music4 days ago

[Music] Wiz Khalifa – See You Again ft. Charlie Puth

Music3 days ago

[Music] Exalted Tribe (HICC) – We Dey Halla

Anna Kendrick
Music4 days ago

[Music] Anna Kendrick – Cups (Pitch Perfect’s “When I’m Gone”)

General10 hours ago

[Music] Diddy – Dirty Money – “Coming Home” Feat. Skylar Grey

General2 days ago

[Music] John Legend – Love Me Now

Right Said Fred
Music4 days ago

[Music] Right Said Fred – Stand Up (For the Champions)

Salvation Ministries Mass Choir
Music2 days ago

[Music] Salvation Ministries Choir – Chioma Me Eh(Good God)

General15 hours ago

[Music] Celine Dion – If That’s What It Takes

Salvation Ministries Mass Choir
Lyrics2 days ago

Salvation Ministries Choir – Chioma Me Eh(Good God) [LYRICS]

General16 hours ago

[Music] P!nk – Try

General6 days ago

[Music] Shaggy – Strength Of A Woman

General2 days ago

[Music] Jaden Smith – Goku

Music4 days ago

[Music] Wiz Khalifa – See You Again (Remix) Feat Charlie Puth, Eminem, Tyga, & Chris Brown

R. Kelly
Music4 days ago

[Music] R. Kelly – World’s Greatest

General1 day ago

Magic! — Rude [LYRICS]

General12 hours ago

[Music] Journey – Don’t Stop Believin’

General7 days ago

[Music] Justin Bieber – Love Me

General2 days ago

[Music] Cardi B – Bartier Cardi ft. 21 Savage

General7 days ago

[Music] Lionel Richie – Angel

General3 days ago

[Music] Tyga ft. Offset – Taste

General16 hours ago

[Music] P!nk – “Just Give Me A Reason” Feat. Nate Ruess

General7 days ago

[Music] BIG SHAQ – Man’s Not Hot

General3 days ago

[Music] 21 Savage ft. Offset & Metro Boomin – Rap Saved Me

General7 days ago

[Music] Shayne Ward – Breathless

General6 days ago

[Music] Post Malone – Candy Paint

General6 days ago

[Music] R Kelly – When A Woman Loves

General7 days ago

[Music] Bill Withers – Lean On Me

General19 hours ago

[Music] African China – Western Union

ANE Billboard Hots



Join "ANE sabi" clique

Don't miss a thing, get ogbonge ANE latest updates to fuel your conversation daily.