{"id":25444,"date":"2022-07-15T07:46:09","date_gmt":"2022-07-15T11:46:09","guid":{"rendered":"https:\/\/www.technewsday.com\/?p=25444"},"modified":"2022-07-18T11:33:12","modified_gmt":"2022-07-18T15:33:12","slug":"attackers-are-still-exploiting-log4j-flaw-cyber-review-board-warns","status":"publish","type":"post","link":"https:\/\/technewsday.com\/staging\/attackers-are-still-exploiting-log4j-flaw-cyber-review-board-warns\/","title":{"rendered":"Attackers Are Still Exploiting Log4j Flaw, Cyber Review Board Warns"},"content":{"rendered":"<p id=\"arIndex_1\" data-ar-index=\"0\">According to the Cyber Safety Review Board, attackers are exploiting Log4j vulnerability, albeit at a lower level than experts predicted.<\/p>\n<p id=\"arIndex_2\" data-ar-index=\"1\">The review board described the Log4j vulnerability as an &#8220;endemic vulnerability&#8221; that is likely to persist or even persist for decades.<\/p>\n<p id=\"arIndex_3\" data-ar-index=\"2\">Log4j is undoubtedly difficult to track because the short line of code that makes up the Java-based utility is embedded in open source software.<\/p>\n<p id=\"arIndex_4\" data-ar-index=\"3\">The board found that successful exploitation of the Log4j vulnerability gives attackers access to compromised systems. Moreover, because it was so difficult to detect without a comprehensive Log4j &#8220;customer list,&#8221; organizations struggled to identify and fix them.<\/p>\n<p id=\"arIndex_5\" data-ar-index=\"4\">The vulnerability is complicated because it was disclosed by a third party just before the Apache Software Foundation could issue a fix to address the vulnerability, giving attackers ample time to exploit the vulnerability.<\/p>\n<p id=\"arIndex_6\" data-ar-index=\"5\">The board therefore urges the software industry to develop a better model for vulnerability management. Log4j has also highlighted the risks associated with the open source community, which result from resource constraints.<\/p>\n<p id=\"arIndex_7\" data-ar-index=\"6\">While the solution will take some time to take effect, technology companies are also increasingly addressing the issue, with US$150 million pledged over the next two years to help strengthen open source security.<\/p>\n<p id=\"arIndex_8\" data-ar-index=\"7\">The sources for this piece include an article in <a href=\"https:\/\/www.ciodive.com\/news\/log4j-endemic-vulnerability\/627288\/\" target=\"_blank\" rel=\"noopener\">CIODIVE<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>According to the Cyber Safety Review Board, attackers are exploiting Log4j vulnerability, albeit at a lower level than experts predicted. The review board described the Log4j vulnerability as an &#8220;endemic vulnerability&#8221; that is likely to persist or even persist for decades. Log4j is undoubtedly difficult to track because the short line of code that makes [&hellip;]<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[34,57,16],"tags":[388,393],"class_list":["post-25444","post","type-post","status-publish","format-standard","hentry","category-artificial-intelligence","category-companies","category-security","tag-privacy-security","tag-security-strategies"],"acf":[],"_links":{"self":[{"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/posts\/25444","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/comments?post=25444"}],"version-history":[{"count":4,"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/posts\/25444\/revisions"}],"predecessor-version":[{"id":25479,"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/posts\/25444\/revisions\/25479"}],"wp:attachment":[{"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/media?parent=25444"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/categories?post=25444"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/tags?post=25444"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}