With 2021 drawing to a close, the year has one final major cybersecurity breach in the works – the Log4j vulnerability.
The flaw is found in multiple versions of the Apache Log4j 2 library, an open-source Java logging library developed by the Apache Foundation. The software is widely used in many applications in organisations across multiple industries, where it logs information to help other applications run.
With the zero-day weakness having been publicly disclosed on December 9th in the Java version of popular video game Minecraft, the potential scale of the problem is still unknown.
Researchers discovered that in-game chat messages in Minecraft could be used to send executable code. All an attacker has to do is make Log4j log a specific string of characters, making the vulnerability particularly simple to use.
The vulnerability in the software could be used to affect a far wider variety of services. Major players using Log4j include Apple iCloud, Cloudflare and Tesla.
It can be exploited by cybercriminals and nation-state backed hacker groups to access compromised systems, where they can then deploy and run malware.
The National Cyber Security Centre (NCSC) warned that attempted exploitation attempts are already being detected globally, including in the UK.
Microsoft warned that it has already found evidence of threat actors looking for affected systems ahead of taking action. “The bulk of attacks that Microsoft has observed at this time have been related to mass scanning by attackers attempting to thumbprint vulnerable systems, as well as scanning by security companies and researchers,” the company said.
Once a system has been identified, hackers can then install coin miners or remote access tools as preparation for a ransomware attack.
Tanium Area Vice-President, Technical Account Management, Chris Vaughan, warned: “This vulnerability is the worst that I’ve seen in my career so far, in terms of how many people and organisations are affected and how severe the impact could be.
“Ecommerce is a sector that I think will be particularly targeted by attackers due to the amount of money that runs through these websites. The timing of this vulnerability emerging is terrible for these companies as they will now be making emergency changes to their IT environments at their busiest time of the year with Christmas approaching.”
According to the NCSC, version 1 of the Log4j library is no longer supported and is affected by multiple security vulnerabilities. As such, users should migrate to the latest version of Log4j 2.
However, not all software that uses Log4j are necessarily vulnerable. As such, following security advice from is vital to ensuring systems are up to date and protected.
Recommended
- Communities of Practice – a foil for the skills crisis in tech?
- Strathclyde Uni spin-out Lupovis secures £615k tech research funding
- Data literacy programme to boost Scottish biosciences research
It is also vital for organisations to scan their systems to verify if Log4j is running, and to update it if they discover it. If there are multiple copies of Log4j present, each copy will need to be updated or mitigated.
Other actions recommended by the NCSC include installing the latest updates immediately wherever Log4j is known to be used. In addition, organisations should routinely run vulnerability scanning across their networks, to detect when updates are available.
Furthermore, it is important for organisations to deploy and improve protective network monitoring and blocking.
Vaughn added: “To minimise the impact, groups should follow the same advice that I would offer organisations from all sectors, which is to patch the vulnerability as soon as they can. They should start with external facing parts of their IT infrastructure first such as their website before shifting their focus to internal systems.
“This unfortunate news is another reminder of the importance of cyber hygiene and asset management. If you have these basics in place before an incident occurs, then you are in a much better position to either prevent any damage being done, or to minimise the impact.”
Get the latest news from DIGIT direct to your inbox
Our newsletter covers the latest technology and IT news from Scotland and beyond, as well as in-depth features and exclusive interviews with leading figures and rising stars.
We will keep you up to date on the pivotal issues impacting the sector and let you know about key upcoming events to ensure that you don’t miss out on what’s going on across the Scottish tech community.
Click here to subscribe.





