Hackers launch more than 1.2 million attacks with Log4J flaw

[ad_1]

Hackers, including Chinese state-backed groups, have launched more than 1.2 million attacks on companies globally since last Friday, according to researchers, through a previously unnoticed vulnerability in widely used open source software called Log4J.

Cybersecurity group Check Point said attacks related to the vulnerability have accelerated since Friday, and its researchers have at times seen more than 100 attacks per minute.

Among the culprits are “Chinese government attackers,” according to Charles Carmackal, chief technology officer of Mandiant Electronics.

The flaw in Log4J allows attackers to easily remote control computers running applications in Java, a popular programming language.

Jane Easterly, director of the US Cyber ​​and Infrastructure Security Agency (CISA), told industry executives that the vulnerability was “one of the most dangerous, if not the most critical, I’ve seen in my entire career,” according to US media reports. She said hundreds of millions of devices are likely to be affected.

Check Point said that in many cases, hackers were taking control of computers for use in cryptocurrency mining, or to become part of botnets, which are large networks of computers that can be used to flood websites with traffic, to send spam, or for other purposes. other. Illegal purposes.

CISA and the UK’s National Center for Cyber ​​Security have now issued alerts urging organizations to make upgrades related to the Log4J vulnerability, as experts try to assess the implications. Amazon, Apple, IBM, Microsoft and Cisco were among those who rushed to put in place fixes, but no serious breaches have been publicly reported so far.

The vulnerability is the latest to hit corporate networks, after flaws surfaced last year in commonly used software from Microsoft and IT company Solarwinds. These vulnerabilities were initially exploited by state-backed spying groups from China and Russia respectively.

Mandiant’s Karmakal said Chinese state-backed actors were also trying to exploit the Log4J bug, but declined to share more details. Researchers at SentinelOne told the media that they noticed Chinese hackers exploiting this vulnerability.

According to Check Point, nearly half of all attacks were carried out by known cyber attackers. These included groups using Tsunami and Mirai – malware that turns devices into botnets, or networks used to launch remotely controlled hacks such as denial of service attacks. They also included groups that use XMRig, a program that mines Monero’s hard-to-track digital currency.

“With this vulnerability, attackers gain nearly unlimited power — they can extract sensitive data, upload files to the server, delete data, install ransomware or divert to other servers,” said Nicholas Skipras, head of engineering at Acunetix, the vulnerability scanner. It was “amazingly easy” to launch an attack, he said, adding that it “will be exploited for months to come.”

The source of the vulnerability is faulty code developed by unpaid volunteers at the non-profit Apache Software Foundation, which operates several open source projects, raising questions about the security of critical parts of the IT infrastructure. Log4J has been downloaded millions of times.

Experts say the flaw has been unnoticed since 2013. Matthew Prince, CEO of online group Cloudflare, said it began actively exploiting it as of December 1, although there was “no evidence of mass exploitation until public disclosure” by Apache. the following week.

Sources

1/ https://Google.com/

2/ https://news.google.com/__i/rss/rd/articles/CBMiP2h0dHBzOi8vd3d3LmZ0LmNvbS9jb250ZW50L2QzYzI0NGYyLWVhYmEtNGM0Ni05YTUxLWIyOGZjMTNkOTU1MdIBAA?oc=5

The mention sources can contact us to remove/changing this article

[ad_2]

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Posts