Photo 36737936 © Flynt | Dreamstime.com
The FBI warned this year to keep an eye out for a spike in cyberattacks during the holidays. Now, what security experts have called the worst vulnerability that has existed on the internet is here. If only this were an exaggeration, but there’s reason to believe this claim.
The unassumingly-named ‘Log4Shell’ has been reported by
AP News to be “possibly the biggest [vulnerability] in the history of modern computing” because no one is safe from the zero-day attack, including, potentially, tech giants Apple,
Amazon, Twitter, and Cloudfare. Even more startling is that a fix can’t be deployed across the board—each of the millions of servers believed to be at risk has to individually run their own patch, so companies might be vulnerable for a period of time without knowing it.
Log4Shell is especially dangerous because it allows malicious actors to infiltrate computer systems and servers that rely on the open-sourced, java-based Log4J logging function, a utility “ubiquitous in cloud servers and enterprise software” used by numerous industries and governments—
without a password, describes
AP News. This gives them access to any computer, where they can install a code to obtain users’ data, download malware, and more.
Up until just recently, Minecraft had been a notable victim of this hack, and cybercriminals could easily penetrate target computers by entering a few lines of text in the game’s chat feature. As per
BGR,
Minecraft owner Microsoft has since fixed the vulnerability in a new software update, and all players are urged to install the latest version immediately.
The problem has only kept growing. After reports of Log4Shell were published, many other attackers jumped in to exploit the hack as they wouldn’t need people’s passwords to get into computers. The hope is to raise awareness about this issue so businesses take note and prepare a fix.
“The internet’s on fire right now,” Adam Meyers, senior vice president of intelligence at cybersecurity firm Crowdstrick, told
AP News. “People are scrambling to patch and all kinds of people scrambling to exploit it.” He added that malicious individuals have “fully weaponized” Log4Shell soon after learning of it.
Amit Yoran, CEO of cybersecurity company Tenable, called it “the single biggest, most critical vulnerability of the last decade.” It is so widespread that companies must always presume they’ve been subjected to the hack, he warned. When it first discovered the vulnerability on November 24, the open-source Apache Software Foundation rated Log4Shell
a perfect 10 on a scale of zero to 10—and a patch only arrived on December 9.
“I’d be hard-pressed to think of a company that’s not at risk,” shared Cloudfare security officer Joe Sullivan.
The most important thing right now is to update any software you have if an update is available. Organizations should also have a patch ready ASAP.
[via
BGR and
AP News, cover photo 36737936 ©
Flynt | Dreamstime.com]