Global tech experts race to fix ‘fully weaponised’ software flaw

10 December 2021, 23:54

Laptop
Laptop User Stock. Picture: PA

The flaw may be the worst computer vulnerability discovered in years.

A software vulnerability exploited in the online game Minecraft is rapidly emerging as a major threat to internet-connected devices around the world.

“The internet’s on fire right now,” said Adam Meyers, senior vice president of intelligence at cybersecurity firm Crowdstrike.

“People are scrambling to patch and there are script kiddies and all kinds of people scrambling to exploit it.”

I’d be hard pressed to think of a company that’s not at risk

Joe Sullivan

He said on Friday that in the 12 hours since the bug’s existence was disclosed it had been “fully weaponised”, meaning malefactors have developed and distributed tools to exploit it.

The flaw may be the worst computer vulnerability discovered in years. It opens a loophole in software code that is ubiquitous in cloud servers and enterprise software used across industry and government.

It could allow criminals or spies to loot valuable data, plant malware or erase crucial information, and much more.

“I’d be hard pressed to think of a company that’s not at risk,” said Joe Sullivan, chief security officer for Cloudflare, whose online infrastructure protects websites from malicious actors.

The single biggest, most critical vulnerability of the last decade

Amit Yoran

Untold millions of servers have it installed, and experts said the fallout would not be known for several days.

Amit Yoran, chief executive of cybersecurity firm Tenable, called it “the single biggest, most critical vulnerability of the last decade” — and possibly the biggest in the history of modern computing.

The vulnerability, dubbed Log4Shell, was rated 10 on a scale of one to 10 by the Apache Software Foundation, which oversees development of the software.

New Zealand’s computer emergency response team was among the first to report that the flaw was being “actively exploited in the wild”, hours after it was publicly reported on Thursday and a patch released.

The vulnerability, located in open-source Apache software used to run websites and other web services, was discovered on November 24 by Chinese tech giant Alibaba, the foundation said.

Finding and patching the software could be a complicated task. While most organisations and cloud providers should be able to update their web servers easily, the same Apache software is also often embedded in third-party programmes which often can only be updated by their owners.

Mr Yoran said organisations need to presume they have been compromised and act quickly.

The flaw’s exploitation was apparently first discovered in Minecraft, an online game hugely popular with children and owned by Microsoft.

Mr Meyers and security expert Marcus Hutchins said Minecraft users had already been using it to execute programmes on the computers of other users by pasting a short message in a chat box.

Microsoft said it had issued a software update for Minecraft users, adding: “Customers who apply the fix are protected.”

Researchers reported finding evidence that the vulnerability could be exploited in servers run by companies such as Apple, Amazon, Twitter and Cloudflare.

Mr Sullivan said there were no indications his company’s servers had been compromised.

By Press Association

More Technology News

See more More Technology News

People ride an upward escalator next to the Dior store at the Icon Siam shopping mall on June 12, 2024 in Bangkok, Thailand.

Luxury fashion giant Dior latest high-profile retailer to be hit by cyber attack as customer data accessed

A plane spotter with binoculars from behind watching a British Airways plane landing

‘Flying taxis’ could appear in UK skies as early as 2028, minister says

Apple App Store

Take on Apple and Google to boost UK economy, think tank says

A survey of more than 1,000 employers found that around one in eight thought AI would give them a competitive edge and would lead to fewer staff.

One in three employers believe AI will boost productivity, research finds

Hands on a laptop showing an AI search

One in three employers believe AI will boost productivity, research finds

Music creators and politicians take part in a protest calling on the Government to ditch plans to allow AI tech firms to steal their work without payment or permission opposite the Houses of Parliament in London.

Creatives face a 'kind-of apocalyptic moment’ over AI concerns, minister says

Ngamba Island Chimpanzee Sanctuary on Lake Victoria, Uganda

Chimps use medicinal plants to treat each other's wounds and practice 'self-care' as scientists hail fascinating discovery

Close up of a person's hands on the laptop keyboard

Ofcom investigating pornography site over alleged Online Safety Act breaches

The Monzo app on a smartphone

Monzo customers can cancel bank transfers if they quickly spot an error

Co-op sign

Co-op to re-stock empty shelves as it recovers from major hack

The study said that it was often too easy for adult strangers to pick out girls online and send them unsolicited messages.

Social media platforms are failing to protect women and girls from harm, new research reveals

Peter Kyle leaves 10 Downing Street, London

Government-built AI tool used to cut admin work for human staff

In its last reported annual headcount in June 2024, Microsoft employed 228,000 full-time workers

Microsoft axes 6,000 jobs despite strong profits in recent quarters

Airbnb logo

Airbnb unveils revamp as it expands ‘beyond stays’ to challenge hotel sector

A car key on top of a Certificate of Motor Insurance and Policy Schedule

Drivers losing thousands to ghost broker scams – the red flags to watch out for

Marks and Spencer cyber attack

M&S customers urged to ‘stay vigilant’ for fraud after data breach confirmed