Beautiful Virgin Islands

Friday, Mar 31, 2023

Log4j software flaw 'endemic,' new cyber safety panel says

Log4j software flaw 'endemic,' new cyber safety panel says

A computer vulnerability discovered last year in a ubiquitous piece of software is an “endemic” problem that will pose security risks for potentially a decade or more, according to a new cybersecurity panel created by President Joe Biden.
The Cyber Safety Review Board said in a report Thursday that while there hasn’t been sign of any major cyberattack due to the Log4j flaw, it will still “be exploited for years to come.”

“Log4j is one of the most serious software vulnerabilities in history,” the board’s chairman, Department of Homeland Security Under Secretary Rob Silvers, told reporters Wednesday.

The Log4j flaw, made public late last year, lets internet-based attackers easily seize control of everything from industrial control systems to web servers and consumer electronics. The first obvious signs of the flaw’s exploitation appeared in Minecraft, a hugely popular online game owned by Microsoft.

The flaw’s discovery prompted urgent warnings by government officials and massive efforts by cybersecurity professionals to patch vulnerable systems.

The board said Thursday that “somewhat surprisingly” the exploitation of the Log4j bug had occurred at lower levels than experts predicted. The board also said that it was unaware of any “significant” Log4j attacks on critical infrastructure systems but noted that some cyberattacks go unreported.

The board said future attacks are likely in large part because Log4j is routinely embedded with other software and can be hard for organizations to find running in their systems.

“This event is not over,” Silvers said.

Log4j, written in the Java programming language, logs user activity on computers. Developed and maintained by a handful of volunteers under the auspices of the open-source Apache Software Foundation, it is extremely popular with commercial software developers.

A security researcher at the Chinese tech giant Alibaba notified the foundation on Nov. 24. It took two weeks to develop and release a fix. Chinese media reported that the government punished Alibaba for not reporting the flaw earlier to state officials.

The board said Thursday it found “troubling elements” with the Chinese government’s policy toward vulnerability disclosures, saying it could give Chinese state hackers an early look at computer flaws they could use for nefarious means like stealing trade secrets or spying on dissidents. The Chinese government has long denied wrongdoing in cyberspace and told the board that it encourages improved information sharing on software vulnerabilities.

The board offered a number of recommendations on mitigating the fallout of the Log4j flaw as well as improving cybersecurity generally. That includes the suggestion that universities and community colleges make cybersecurity training a required part of computer science degree and certification programs.

The Cyber Safety Review Board is modeled after the National Transportation Safety Board, which reviews plane crashes and other major accidents, and was mandated by an executive order Biden signed last May. The 15-member board is made up of FBI, National Security Agency and other government officials as well as people from the private sector. Some supporters of the new board criticized DHS for taking so long to get it up and running.

Biden’s executive order directed the board to conduct its first review on the massive Russian cyber espionage campaign known as SolarWinds. Russian hackers were able to breach several federal agencies, including accounts belonging to top cybersecurity officials at DHS, though the full fallout from that campaign is still unclear.

Silvers said DHS and the White House agreed that reviewing the Log4j flaw was a better use of the new board’s expertise and time.
Newsletter

Related Articles

Beautiful Virgin Islands
Close
0:00
0:00
Don’t Dismiss China’s Peacemaking Bid
I have a dream, MLK inspiring speech
Father obliterates council members following viral TikTok of biological male masturbating in women’s bathroom..
Aretha Franklin, Marvis Staples - Oh Happy Day
China and Brazil have signed a new deal that will allow them to trade in their own currencies, bypassing the US dollar as an intermediary
BVI Freedom Song
Elon Musk and Others Call for Pause on A.I., Citing ‘Profound Risks to Society’
Billy Preston - You Can't Beat God Giving (Live)
Nashville style execution
VIRGIN ISLANDS REGGAE CARIBBEAN RIDDIMZ
“We've had evidence prior to the pandemic that masks were largely ineffective at preventing community transmission of influenza “
Oh Happy Day Edwin Hawkins - Anthony Brown w FBCG Combined Choir
Former Starbucks CEO Howard Schultz:
'Stand by Me' performed by Karen Gibson and The Kingdom Choir
Former Starbucks CEO Howard Schultz rejects being labeled a "billionaire"
National Anthem of the British Virgin Islands - Oh, Beautiful Virgin
Jamie Dimon is being deposed over JPMorgan Chase role in Epstein lawsuits
Hello Dolly
This is how an electric car saves all the energy that he would have spent if he had lived 50 years longer.
for KING & COUNTRY - Amen (Reborn) [feat. Lecrae & The WRLDFMS Tony Wi
Brand new security footage has just been released to the public showing the Active shooter Audrey Elizabeth Hale drove to Covenant Church School in her Honda Fit this morning, parked, and shot her way into the building
Bob Marley - Get Up Stand Up
Social Media censoring users for saying the true
Yes He Can
Smart Iranian fashion designer teaching dummy TV anchors lesson about reality
What A Friend We Have In Jesus
AMERICA, 2023
Unforgettable
U.S. charges FTX's Bankman-Fried with paying $40 million bribe
Touch The Hem Of His Garment
Fallen 'Crypto King' Who Owes Millions to Investors Was Kidnapped and Tortured
The Lord's Prayer
Regulators blame social media for SVB's rapid collapse: 'Complete game changer'
THE GOD MOVEMENT...BEAUTIFUL BVI
AOC explains why she opposes banning TikTok
Siyahamba
UK: Humza Yousaf replaces Nicola Sturgeon as SNP leader and first minister in Scotland
Ray Charles And The Voices Of Jubilaton, Oh, Happy Day
In a dramatic U-turn against His Government: Judicial Reform Legislation Must Be Halted, Says Israeli Defense Minister Yoav Gallant
Ramblin' Rose
Gordon Moore, a co-founder of Intel Corporation, died at 94
Protoje - Who Knows ft. Chronixx
Powell: Silicon Valley Bank was an 'outlier'
Pressure - Virgin Islands Nice
Donald Trump arrested – Twitter goes wild with doctored pictures
Phil Wickham - House Of The Lord
NYPD is setting up barricades outside Manhattan Criminal Court ahead of Trump arrest.
My God Is Real (Yes, God Is Real)
Credit Suisse's Scandalous History Resulted in an Obvious Collapse - It's time for regulators who fail to do their job to be held accountable and serve as an example by being behind bars.
The Lion King Circle of Life by LEBO M. — LIVE at the HAVASI Symphonic
Home Secretary Suella Braverman tours potential migrant housing in Rwanda as asylum deal remains mired in legal challenges
Louis Armstrong - When The Saints Go Marching In
Paris Rioting vs Macron anti democratic law
Kanye West Sunday Service - hallelujah, salvation, and glory
'Sexual Fantasy' Assignment At US School Outrages Parents
Jonathan Nelson - I Believe (Island Medley
Credit Suisse to borrow $54 billion from Swiss central bank
From The Virgin Islands Sqad Up
Russian Hackers Preparing New Cyber Assault Against Ukraine
Common, John Legend - Glory
Jeremy Hunt insists his Budget will get young parents and over-50s back into work
Anthony Evans vs. Jesse Campbell - If I Ain't Got You
If this was in Tehran, Moscow or Hong Kong
I have a dream, MLK inspiring speech
Nashville police officer, and a female driver shooting one another
Aretha Franklin, Marvis Staples - Oh Happy Day
TRUMP: "Standing before you today, I am the only candidate who can make this promise: I will prevent World War III."
BVI Freedom Song
Mexican President Claims Mexico is Safer than the U.S.
Billy Preston - You Can't Beat God Giving (Live)
A brief banking situation report
VIRGIN ISLANDS REGGAE CARIBBEAN RIDDIMZ
Lady bites police officer and gets instantly reaction
Oh Happy Day Edwin Hawkins - Anthony Brown w FBCG Combined Choir
We are witnessing widespread bank fails and the president just gave a 5 min speech then walked off camera.
'Stand by Me' performed by Karen Gibson and The Kingdom Choir
Donald Trump's asked by Tucker Carlson question on if the U.S. should support regime change in Russia?.
National Anthem of the British Virgin Islands - Oh, Beautiful Virgin
Good news: The U.S. government is now guaranteeing all deposits, held by, Silicon Valley Bank, and the funds are available as of today
Hello Dolly
Silicon Valley Bank exec was Lehman Brothers CFO
for KING & COUNTRY - Amen (Reborn) [feat. Lecrae & The WRLDFMS Tony Wi
In a potential last-ditch effort, HSBC is considering a rescue deal to save Silicon Valley Bank UK from insolvency
Bob Marley - Get Up Stand Up
BBC Director General, Tim Davie, has apologized, but not resigned, yet, following the disruption of sports programmes over the weekend
Yes He Can
A Mississippian man, who was once considered a “ticking time bomb,” has lost a whopping 165 kilograms! What motivated this incredible transformation?
What A Friend We Have In Jesus
Elon Musk Is Planning To Build A Town In Texas For His Employees
Unforgettable
The Silicon Valley Bank’s collapse effect is spreading around the world, affecting startup companies across the globe
Touch The Hem Of His Garment
City officials in Berlin announced on Thursday that all swimmers at public pools will soon be allowed to swim topless
The Lord's Prayer
Fitness scam
THE GOD MOVEMENT...BEAUTIFUL BVI
Market Chaos as USDC Loses Peg to USD after $3.3 Billion Reserves Held by Silicon Valley Bank Closed.
Siyahamba
A primitive judge in Australia sparked outrage when he told a breastfeeding woman to leave his courtroom for being “a distraction"
Ray Charles And The Voices Of Jubilaton, Oh, Happy Day
×