Global tech experts race to fix ‘fully weaponised’ software flaw

10 December 2021, 23:54

Laptop
Laptop User Stock. Picture: PA

The flaw may be the worst computer vulnerability discovered in years.

A software vulnerability exploited in the online game Minecraft is rapidly emerging as a major threat to internet-connected devices around the world.

“The internet’s on fire right now,” said Adam Meyers, senior vice president of intelligence at cybersecurity firm Crowdstrike.

“People are scrambling to patch and there are script kiddies and all kinds of people scrambling to exploit it.”

I’d be hard pressed to think of a company that’s not at risk

Joe Sullivan

He said on Friday that in the 12 hours since the bug’s existence was disclosed it had been “fully weaponised”, meaning malefactors have developed and distributed tools to exploit it.

The flaw may be the worst computer vulnerability discovered in years. It opens a loophole in software code that is ubiquitous in cloud servers and enterprise software used across industry and government.

It could allow criminals or spies to loot valuable data, plant malware or erase crucial information, and much more.

“I’d be hard pressed to think of a company that’s not at risk,” said Joe Sullivan, chief security officer for Cloudflare, whose online infrastructure protects websites from malicious actors.

The single biggest, most critical vulnerability of the last decade

Amit Yoran

Untold millions of servers have it installed, and experts said the fallout would not be known for several days.

Amit Yoran, chief executive of cybersecurity firm Tenable, called it “the single biggest, most critical vulnerability of the last decade” — and possibly the biggest in the history of modern computing.

The vulnerability, dubbed Log4Shell, was rated 10 on a scale of one to 10 by the Apache Software Foundation, which oversees development of the software.

New Zealand’s computer emergency response team was among the first to report that the flaw was being “actively exploited in the wild”, hours after it was publicly reported on Thursday and a patch released.

The vulnerability, located in open-source Apache software used to run websites and other web services, was discovered on November 24 by Chinese tech giant Alibaba, the foundation said.

Finding and patching the software could be a complicated task. While most organisations and cloud providers should be able to update their web servers easily, the same Apache software is also often embedded in third-party programmes which often can only be updated by their owners.

Mr Yoran said organisations need to presume they have been compromised and act quickly.

The flaw’s exploitation was apparently first discovered in Minecraft, an online game hugely popular with children and owned by Microsoft.

Mr Meyers and security expert Marcus Hutchins said Minecraft users had already been using it to execute programmes on the computers of other users by pasting a short message in a chat box.

Microsoft said it had issued a software update for Minecraft users, adding: “Customers who apply the fix are protected.”

Researchers reported finding evidence that the vulnerability could be exploited in servers run by companies such as Apple, Amazon, Twitter and Cloudflare.

Mr Sullivan said there were no indications his company’s servers had been compromised.

By Press Association

More Technology News

See more More Technology News

Sir Elton John performing

Elton John says ‘we will not back down’ in awards speech addressing AI concerns

Live
Customers purchase Nintendo Switch 2 at an electronics retailer in Tokyo on June 5, 2025.

Nintendo Switch 2 launch live: Where to buy, best deals, and early verdict

In this photo illustration, an Apple logo is seen displayed alongside the Google logo.

Tech giants Apple and Google 'profiting from phone thefts', MPs claim

A man's hands using a laptop keyboard

Scots warned of ‘scamdemic’ as £860,000 lost to cyber criminals in 12 months

A close up image of a The North Face fleece

North Face and Cartier customer data stolen in cyber attacks

Imagery of a Zilch payments card and a virtual card

Buy now pay later provider Zilch to launch first physical card

UK’s most EV-friendly city has been revealed by new research.

Cities with slowest EV charging times and least amount of chargers revealed

View of a VodafoneThree logo outside the firm's offices

Vodafone completes Three UK mega-merger to form ‘new force’ in mobile market

A hand holding a Monzo bank card and a mobile phone showing the Monzo app

Monzo annual profit surges as paying subscribers boost digital bank

Majestic British Airways Airbus A380 taking off from London Heathrow at sunset, amazing colors

UK airspace shake-up could slash journey times and cut flight delays for millions of passengers

File photo dated 30/05/25 of the saltmarsh at Abbotts Hall in Essex. Saltmarshes are 'significant' carbon stores, but are at risk from rising sea levels, new research reveals

UK's muddy saltmarshes vital to tackle climate change, report finds

Nigel Farage

Reform backs cryptocurrency tax cut as party receives first Bitcoin donations

Digital devices on office workplace table of young business woman

‘Young people and black workers at highest risk of workplace surveillance’

Debris from the Titan submersible, recovered from the ocean floor near the wreck of the Titanic, is unloaded from the ship Horizon Arctic at the Canadian Coast Guard pier in St. John's, Newfoundland, in June 2023

The shock household item discovered in 'sludge' of OceanGate sub wreckage

Google is facing a £25 billion legal claim in the UK, accusing the tech giant of abusing its dominant position in the online search advertising market

Google facing £25 billion legal claim over abuse of search advertising market

A hand holding a phone showing the Nvidia logo

Nvidia posts strong growth despite ongoing tariff challenges