Arab Press

بالشعب و للشعب
Saturday, Feb 22, 2025

'Potential for damage incalculable': Experts sound alarm over cyber vulnerability in widely used software

'Potential for damage incalculable': Experts sound alarm over cyber vulnerability in widely used software

While the first victims hit by hackers were Minecraft players, experts warn the cyber vulnerability could soon be exploited by spies and organised criminals.

Security experts are sounding the alarm over a newly discovered software vulnerability, and organisations have been advised to "urgently" check whether it leaves them exposed to hackers.

Alerts have been issued by the British and American governments as a growing number of hacking groups - potentially including spies and organised criminals - are exploiting the vulnerability to break into computer networks.

The British government said it was treating "this issue with the utmost seriousness" as the US warned the vulnerability was "being widely exploited by a growing set of threat actors".

Researchers in the private sector said "the potential for damage is incalculable" with one describing the severity as: "The internet is on fire right now."

The UK government said it was treating the issue 'with the utmost seriousness'


What is the issue?


It is very rare for enterprise software to be completely written from the ground up for every different product.

Instead this software often depends on a shared library of open-source code maintained by charity organisations and distributed without any royalties.

The new vulnerability has been discovered in one such bit of code.

Known as Log4j, the open-source tool is an Apache Software Foundation project and used almost ubiquitously in enterprise software products and cloud services.

It won't directly impact people using personal devices, but any data they have with organisations that operate web servers could be at risk.

A fix has already been published by Apache - which described the vulnerability as "critical" - and large companies who control and update their own software should be able to quickly patch the vulnerability.

But because Log4j is so widely used as a logging utility there are likely to be thousands of companies exposed because the flaw affects third-party software which they cannot directly update.

Apache credited Chen Zhaojun, a security researcher at Chinese company Alibaba, for discovering and reporting the issue.

Minecraft players were among the first victims.


Who has been affected?


The first wave of victims were people playing the Microsoft-owned computer game Minecraft.

Hackers were able to post a short message in the Minecraft chatbox to remotely execute commands on the computers of other players.

Microsoft said it has patched the issue for Minecraft players and told customers they would be protected if they applied the fix.

The most obvious first wave of attacks all involved "cryptojacking", when hackers hijack victim's computers to use their processing power to mine cryptocurrencies.

Microsoft warned that alongside installing coin miners it had seen hackers exploiting the flaw to steal credentials and data from victim's computers.

"The internet's on fire right now. People are scrambling to patch and all kinds of people are scrambling to exploit it," said Adam Meyers, senior vice president of intelligence at cyber security company Crowdstrike.

The software flaw could be used to attack banks and even governments


'A very serious threat'


"I cannot overstate the seriousness of this threat," warned Lotem Finkelstein, director of threat intelligence for Check Point Software Technologies.

Mr Finkelstein warned that the cryptojacking activity "creates just the sort of background noise that serious threat actors will try to exploit in order to attack a whole range of high value targets".

Check Point has detected hundreds of thousands of attempts to exploit this vulnerability across more than a third of all corporate global networks.

"Security teams need to jump on this with utmost urgency as the potential for damage is incalculable," Mr Finkelstein added.

Newsletter

Related Articles

Arab Press
0:00
0:00
Close
The negotiation teams of Trump and Putin meet directly, establishing the groundwork for a significant advance.
Israeli Minister Urges Hamas to Surrender and Depart from Gaza.
Iran Considers Moving Its Capital Due to Urban Difficulties
Israel and Hamas Finalize Sixth Exchange of Hostages and Prisoners During Continuing Gaza Ceasefire
Leaders of BRICS to Gather in Rio de Janeiro for July Summit
Muhsin Hendricks, a trailblazing openly gay imam, was killed in South Africa.
Trump's special envoy for hostage affairs cautions Hamas against challenging Trump before Saturday's deadline.
Two British citizens apprehended in Iran amid escalating tensions.
Israel Issues Threat of Military Action as Hostage Negotiations with Hamas Continue
Hamas Coordinates Worldwide Solidarity Marches in Reaction to U.S. and Israeli Initiative
Israel Warns of Ending Gaza Ceasefire Due to Hostage Situation
King Abdullah II Dismisses US Proposal to Relocate Palestinians, Commits to Welcoming Gaza Children.
Lebanon Installs New Government with Hezbollah's Impact on Key Ministries
Report: Iran Attempted to Assassinate Trump During Election Campaign
U.S. Authorizes $7.4 Billion Arms Sale to Israel
Iran's Supreme Leader Rejects Nuclear Negotiations with the U.S.
UN Chief Denounces Trump's Gaza Plan, Cautions Against Ethnic Cleansing
Pressure Intensifies for a Free Trade Agreement between the UK and GCC in Light of Economic Difficulties
Israel to Withdraw from UN Human Rights Council Due to Accusations of Anti-Semitism
EU Reaffirms Gaza's Essential Role in Future Palestinian State Following Trump's Proposal
Iranian Currency Reaches All-Time Low Amid US 'Maximum Pressure' Initiative.
UN Reaffirms Ban on Deportation from Occupied Territories Amid US Gaza Proposal
Palestinians Fear Repeat of 'Nakba' Amid Ongoing Crisis in Gaza
UAE Aids in the Exchange of 300 Prisoners Between Russia and Ukraine
Egypt Seeks Global Backing for Two-State Solution Following US Proposal for Gaza Plan
Trump's Suggestion to 'Seize Control' of Gaza Represents a Significant Shift in US Policy
French President is the first EU leader to extend congratulations to the new Syrian President.
Tunisian President Appoints New Finance Minister Amid Economic Crisis
Trump Suggests U.S. 'Takeover' of Gaza, Prompting Global Worries
Trump's Proposal for Gaza Provokes Global Debate
President Trump Suggests Moving Gaza's Palestinian Population
Aga Khan IV, Spiritual Leader and Philanthropist, Dies at 88
Erdogan and Syria's Sharaa Talk About Collaboration to Counter Kurdish Militants
Trump Suggests U.S. Control of Gaza Strip Amid Ongoing Conflict
Trump Resumes 'Maximum Pressure' Strategy to Limit Iran's Oil Exports.
Ex-British Soldier Sentenced for Espionage on Behalf of Iran and Fleeing from Prison
Gazans in Egypt Reject Displacement, Struggle with Return to War-Torn Home
Queen Rania Urges Protection of Children’s Rights at Vatican Summit
Hamas Officials Ready to Begin Negotiations for Phase Two of Gaza Truce
Trump Expresses Caution Over Gaza Ceasefire as Netanyahu Visits Washington
Oman to Host 18th Indian Ocean Conference on Maritime Security and Trade
Emir of Kuwait Meets BlackRock CEO for Talks on Investment Opportunities
Queen Rania of Jordan Calls for Global Action on Children’s Rights at Vatican Summit
Egyptian President El-Sisi Invited for White House Meeting Following Jordanian King’s Visit
Queen Rania Calls for Protection of Children’s Rights at Vatican Summit
Israeli Military Operations Continue on Lebanon Border Amid Ceasefire Tensions
Israeli Hostage's Release Highlights Uncertainty Over Family's Fate
Israeli Military Operations Escalate in Southern Lebanon Amid Hezbollah Tensions
Zayed Award for Human Fraternity Announces 2025 Honorees
Kuwait Anticipates a 12% Increase in Budget Deficit for the 2025-2026 Fiscal Year
×