Widely used software with key vulnerability sends cyber defenders scrambling

Widely used software with key vulnerability sends cyber defenders scrambling
An illustration picture shows a projection of binary code on a man holding a laptop computer, in an office in Warsaw on June 24, 2013.
PHOTO: Reuters

WASHINGTON - A newly discovered vulnerability in a widely used software library is causing mayhem on the internet, forcing cyber defenders to scramble as hackers rush to exploit the weakness.

The vulnerability, known as Log4j, comes from a popular open source product that helps software developers track changes in applications that they build. It is so popular and embedded across many companies' programs that security executives expect widespread abuse.

"The Apache Log4j Remote Code Execution Vulnerability is the single biggest, most critical vulnerability of the last decade," said Amit Yoran, chief executive of Tenable, a network security firm, and the founding director of the US Computer Emergency Readiness Team.

The US government sent a warning to the private sector about the Log4j vulnerability and the looming risk it poses on Friday (Dec 10).

In a conference call on Monday, the leader of CISA said it was one of the worst vulnerabilities seen in many years. She urged companies to have staff working through the holidays to battle those using new methods to exploit the flaw.

Much of the software affected by Log4j, which bears names like Hadoop or Solr, may be unfamiliar to the public at large. But as with the SolarWinds program at the center of a massive Russian espionage operation last year, the ubiquity of these workhorse programs makes them ideal jumping-off points for digital intruders.

Juan Andres Guerrero-Saade, principal threat researcher with cybersecurity firm SentinelOne, called it "one of those nightmare vulnerabilities that there’s pretty much no way to prepare for."

While a partial fix for the vulnerability was released on Friday by Apache, the maker of Log4j, affected companies and cyber defenders will need time to locate the vulnerable software and properly implement patches. Log4j itself is maintained by a few volunteers, security experts said.

In practice, the flaw allows an outsider to enter active code into the record-keeping process. That code then tells the server hosting the software to execute a command giving the hacker control.

Read Also
Microsoft says Chinese hackers used flaws in its software to steal emails
digicult
Microsoft says Chinese hackers used flaws in its software to steal emails

The issue was first publicly disclosed by a security researcher working for Chinese technology company Alibaba Group Holding Ltd, Apache noted in its security advisory.

It is now apparent that initial exploitation was spotted Dec 2, before a patch rolled out a few days later. The attacks became much more widespread as people playing Minecraft used it to take control of servers and spread the word in gaming chats.

So far no major disruptive cyber incidents have been publicly documented as a result of the vulnerability, but researchers are seeing an alarming uptick in hacking groups trying to take advantage of the bug for espionage.

"We also expect to see this vulnerability in everyone’s supply chain," said Chris Evans, chief information security officer at HackerOne.

Multiple botnets, or groups of computers controlled by criminals, were also exploiting the flaw in a bid to add more captive machines, experts tracking the developments said.

What many experts now fear is that the bug could be used to deploy malware that either destroys data or encrypts it, like what was used against US pipeline operator Colonial Pipeline Co in May which led to shortages of gasoline in some parts of the United States.

Guerrero-Saade said his firm had already seen Chinese hacking groups moving to take advantage of the vulnerability.

US cybersecurity firms Mandiant and Crowdstrike also said they found sophisticated hacking groups leveraging the bug to breach targets. Mandiant described those hackers as "Chinese government actors" in an email to Reuters.

homepage

trending

trending
    SG60 anthology film Kopitiam Days: Director Don Aravind on setting inter-faith romance against Hotel New World collapse
    Jail for woman who forged medical documents in bid to quickly withdraw her CPF funds
    Young Malaysian couple's first trip ends in tragedy after motorbike crashes on bend in Cameron Highlands
    Woman taken to hospital after 2 cars collide along Joo Chiat Road
    4 foreigners linked to housebreaking syndicate taken back to Rail Corridor and Bukit Timah
    New Hawkers' Street outlet at Tang Plaza features 6 Michelin-recognised brands, opens on Aug 18
    Haidilao to close its first Singapore outlet at Clarke Quay after 13 years
    'Business has increased by 30%': Local drivers see improvement amid LTA enforcement against illegal ride-hailing services
    Senior Malaysian army officers who allegedly masterminded smuggling syndicate busted
    'I would be crying every day during lunch': Rebecca Lim recalls feeling inadequate in 1st acting role after childbirth
    Jalan Bukit Merah flat fire may have started from PMD's battery pack in living room: SCDF
    Popular Japanese restaurant Shaburi & Kintan Buffet to shutter after 9 years

Singapore

Singapore
    • Singapore upgrades 2025 growth forecast but warns that outlook remains 'clouded by uncertainty'
    • 2 Singapore drivers allegedly detained in Legoland for offering illegal ride-hailing services; cars seized
    • Singapore delivers ninth tranche of humanitarian aid to Gaza
    • 'Proof of love between 2 nations': Malaysian man creates SG60 shirt to thank Singaporeans who helped him through hard times
    • Compensation, rehousing options crucial to flat owners from older estates selling their flats under Vers
    • 'A serial predator': Male ex-teacher jailed for trying to engage in sexual acts with 3 teen girls on separate occasions
    • India, Singapore in talks to boost ties in industrial parks, semiconductor sector
    • 'We both want the best for Singapore': Ex-NMP Calvin Cheng resolves differences with ex-SDP chairman over Gaza comments
    • Luxury items seized in $3b money laundering case handed over to Deloitte for liquidation
    • Off-duty SCDF officer killed in Punggol crash; 15-year-old taken to hospital

Entertainment

Entertainment
    • Lee Teng and wife welcome their rainbow baby
    • Huang Zitao and Xu Yiyang to hold wedding in October with 100 fans in attendance
    • Zheng Geping awarded Public Service Medal for contributions to Woodlands CCC
    • Blackpink's Jisoo releases Your Love special video filmed at Rainforest Wild Asia in Mandai
    • Blake Lively slams 'ongoing smear campaign' she alleges to be carried out by Justin Baldoni and team
    • Demi Lovato finds it 'really healing' to perform with her Camp Rock co-stars the Jonas Brothers
    • Zoe Kravitz 'completely destroyed' Taylor Swift's Beverly Hills mansion toilet during 2-week stay
    • Jimmy Kimmel has obtained Italian citizenship
    • Taylor Swift announces new album called The Life of a Showgirl
    • Noah Centineo to star in Rambo origins movie

Lifestyle

Lifestyle
    • Ong Ye Kung rebuts KF Seetoh's claims regarding treatment of stallholders at Bukit Canberra Hawker Centre
    • Singapore ranks top in Asia for work-life balance and 25th in the world, according to Remote study
    • Embracing Singlish as part of our identity: Paiseh for what?
    • One-Michelin-starred Restaurant Euphoria shutters, chef-owner looks to 'rethink the future' of his cuisine
    • More than just a bad habit: How Kpods affect youths' physical and mental health
    • BYD Atto 2 electric compact SUV launched in Singapore
    • I've lived in Twin Vew for 4 years: What's it like living without an MRT station nearby
    • Even cheaper than Bali: 5 hidden Asian islands you (and your wallet) will love
    • 4 condo layouts and features buyers are moving away from in 2025
    • How to get your driving licence in Singapore - fast

Digicult

Digicult
    • Slim, sleek, but slightly too short-lived: Samsung Galaxy S25 Edge review
    • World's best Dota 2 teams to compete for $1m prize pool in Singapore in November
    • Apple Maps brings 3D landmarks and road-level realism to Singapore
    • The best AI tutor for O-level subjects: ChatGPT, Gemini or The Wise Otter?
    • Vivo X Fold5: A foldable contender with a few class-leading surprises
    • Here's everything in GPT-5 that's new and different than OpenAI's previous AI models
    • Australia regulator says YouTube, others 'turning a blind eye' to child abuse material
    • ZipZap car subscription service launches in Singapore
    • Sony RX1R III brings back the compact full-frame but not the Sony playbook
    • China's Premier Li proposes global AI co-operation organisation

Money

Money
    • Up 4.3%: Singapore's economy grew in Q2 despite US tariff fears
    • Ninja Van cuts 12% of Singapore workforce after 2 rounds of layoffs in 2024
    • Goh Cheng Liang, Nippon Paint billionaire and richest Singaporean, dies aged 98
    • StarHub buys rest of MyRepublic's broadband business in $105m deal; comes after Simba buys M1
    • Keppel to sell M1 unit's telco business to Simba for $1.43b
    • Singapore can deliver and thrive in a fragmented global economy: Morgan Stanley analysts
    • Over 70% of Ang Mo Kio's 4-room million-dollar resales in the past 3 years came from this project
    • DBS beats expectations with $2.82b net profit for second quarter, maintains 2025 outlook
    • Carro targets US IPO with over $3.8b valuation, sources say
    • US companies spending record amounts to protect executives as threats rise

Latest

Latest
  • China supports Thailand, Cambodia reconciliation, foreign minister says
  • WhatsApp says Russia is trying to block it
  • 1 person dead after hot air balloon crash in Netherlands
  • US returns to Mexico stolen manuscript signed by conquistador Hernan Cortes
  • Tropical storm Podul drenches southern China
  • Indonesia boosts role of military in food security initiative
  • Uruguay's lower house of parliament votes in favour of euthanasia
  • Trump threatens 'severe consequences' if Putin blocks Ukraine peace
  • Russia restricts Telegram and WhatsApp calls, citing law breaches

In Case You Missed It

In Case You Missed It
  • Man remanded after wielding knife, trying to snatch baby in Penang supermarket
  • Malaysia's border control agency gives ICA cake to mark SG60
  • Tourist in Hong Kong killed after cabby, 80, crashes into pillar outside hotel
  • 2 Malaysian men nabbed at Woodlands Checkpoint for allegedly smuggling drugs worth over $150k into Singapore
  • Parents reject $30k settlement from kindergarten in JB after son suffocates to death in school van
  • Pritam gets candid with kids’ questions on his worst subjects and favourite song in radio interview
  • Bro-code before go-mode: Meet the duo leading NDP 2025
  • LTA, Singapore bus operators reviewing Malaysia’s request to start services from JB at 4am
  • Part-time PHV driver who stopped suicide attempt among 38 recipients of MHA’s public spiritedness award
This website is best viewed using the latest versions of web browsers.