Global tech experts race to fix ‘fully weaponised’ software flaw

10 December 2021, 23:54

Laptop
Laptop User Stock. Picture: PA

The flaw may be the worst computer vulnerability discovered in years.

A software vulnerability exploited in the online game Minecraft is rapidly emerging as a major threat to internet-connected devices around the world.

“The internet’s on fire right now,” said Adam Meyers, senior vice president of intelligence at cybersecurity firm Crowdstrike.

“People are scrambling to patch and there are script kiddies and all kinds of people scrambling to exploit it.”

He said on Friday that in the 12 hours since the bug’s existence was disclosed it had been “fully weaponised”, meaning malefactors have developed and distributed tools to exploit it.

The flaw may be the worst computer vulnerability discovered in years. It opens a loophole in software code that is ubiquitous in cloud servers and enterprise software used across industry and government.

It could allow criminals or spies to loot valuable data, plant malware or erase crucial information, and much more.

“I’d be hard pressed to think of a company that’s not at risk,” said Joe Sullivan, chief security officer for Cloudflare, whose online infrastructure protects websites from malicious actors.

Untold millions of servers have it installed, and experts said the fallout would not be known for several days.

Amit Yoran, chief executive of cybersecurity firm Tenable, called it “the single biggest, most critical vulnerability of the last decade” — and possibly the biggest in the history of modern computing.

The vulnerability, dubbed Log4Shell, was rated 10 on a scale of one to 10 by the Apache Software Foundation, which oversees development of the software.

New Zealand’s computer emergency response team was among the first to report that the flaw was being “actively exploited in the wild”, hours after it was publicly reported on Thursday and a patch released.

The vulnerability, located in open-source Apache software used to run websites and other web services, was discovered on November 24 by Chinese tech giant Alibaba, the foundation said.

Finding and patching the software could be a complicated task. While most organisations and cloud providers should be able to update their web servers easily, the same Apache software is also often embedded in third-party programmes which often can only be updated by their owners.

Mr Yoran said organisations need to presume they have been compromised and act quickly.

The flaw’s exploitation was apparently first discovered in Minecraft, an online game hugely popular with children and owned by Microsoft.

Mr Meyers and security expert Marcus Hutchins said Minecraft users had already been using it to execute programmes on the computers of other users by pasting a short message in a chat box.

Microsoft said it had issued a software update for Minecraft users, adding: “Customers who apply the fix are protected.”

Researchers reported finding evidence that the vulnerability could be exploited in servers run by companies such as Apple, Amazon, Twitter and Cloudflare.

Mr Sullivan said there were no indications his company’s servers had been compromised.

By Press Association

More Technology News

See more More Technology News

Exclusive
Jordan Stephens, Rizzle Kicks star.

Rizzle Kicks star says children 'rely' on online communities for connection as he says 'boredom' to blame for rising crime

A message on an iPhone

Media denied entry to tribunal thought to be about Apple and Government data row

Education Secretary Bridget Phillipson (PA)

Disruptive phones have no place in schools, Education Secretary says

A finger hovering over a phone screen with the Facebook, Instagram and WhatsApp logos

Fact check: Hoax posts about killers and stabbings in local Facebook groups

A drone in the air with countryside behind

Drones used to sow tree seeds in scheme to restore lost South West rainforests

ASCL president Manny Botwe

Technology ‘being weaponised’ against schools and teachers – union leader

A woman using a laptop as she holds a bank card

Phishing campaign impersonating Booking.com targeting UK hospitality

Crypto regulation

NCA officer charged following alleged Bitcoin theft

Sir Keir Starmer walking out the door of 10 Downing Street carrying folders under his left arm

Starmer’s plans to shape up ‘flabby’ Civil Service could trigger union clash

A person holds an iphone showing the app for Google chrome search engine

Apple and Google browser dominance harming consumer choice, says watchdog

A. Lunar Eclipse, Red supermoon, Blood moon / 
on 28th September 2015.

Blood moon 2025: Rare lunar eclipse to be visible in the UK this week - here's how to see it

Several customers took to X to discuss their situation (PA)

Vodafone customers report internet problems in CityFibre outage

Children in school

No nationwide smartphone ban in Welsh schools, report recommends

TikTok is set to launch new parental monitoring tools.

TikTok to launch new parental monitoring tools as app sets limit for teens

TikTok on a phone

Prescriptions for ADHD drugs jump 18% year-on-year, figures show

Elon Musk said there was a cyberattack on X (Kirsty Wigglesworth/PA)

Pointing finger at Ukraine after X outage is ‘dangerous’, cyber expert says