Posts

Showing posts with the label Log4j

Log4j software flaw ‘endemic,’ new cyber safety panel says

 By Alan Suderman,  AP A computer vulnerability discovered last year in a ubiquitous piece of software is an “endemic” problem that will pose security risks for potentially a decade or more, according to a new cybersecurity panel created by President Joe Biden. The Cyber Safety Review Board said in a report Thursday that while there hasn’t been sign of any major cyberattack due to the Log4j flaw, it will still “be exploited for years to come.” “Log4j is one of the most serious software vulnerabilities in history,” the board’s chairman, Department of Homeland Security Under Secretary Rob Silvers, told reporters Wednesday. The Log4j flaw, made public late last year, lets internet-based attackers easily seize control of everything from industrial control systems to web servers and consumer electronics. The first obvious signs of the flaw’s exploitation appeared in Minecraft, a hugely popular online game owned by Microsoft. The flaw’s discovery prompted urgent warnings by governme...

Amazon Web Services fixes container escape in Log4Shell hotfix

Image
By Bill Toulas, Bleeping Computer Amazon Web Services (AWS) has fixed four security issues in its hot patch from December that addressed the critical Log4Shell vulnerability (CVE-2021-44228) affecting cloud or on-premise environments running Java applications with a vulnerable version of the Log4j logging library or containers. The hot patch packages from Amazon are not exclusive to AWS resources and allowed escaping a container in the environment and taking control of the host. The flaws could also be exploited through unprivileged processes to elevate privileges and execute code as with root permissions. The vulnerabilities are currently tracked as CVE-2021-3100, CVE-2021-3101, CVE-2022-0070, and CVE-2022-0071. All of them have been assessed as high-severity risks with a score of 8.8 out of 10. Hot patch trouble Security researchers at Palo Alto Network's Unit 42 discovered that Amazon's Log4Shell hot-fix solutions would keep searching for Java processes and patch them on the...

Microsoft Defender flags Google Chrome updates as suspicious

Image
By Sergiu Gatlan, Bleeping Computers Microsoft Defender for Endpoint has been tagging Google Chrome updates delivered via Google Update as suspicious activity due to a false positive issue. According to Windows system admins reports, the security solution (formerly known as Microsoft Defender ATP) began marking Chrome updates as suspicious starting last evening. Those who encountered this issue reported seeing "Multi-stage incident involving Execution & Defense evasion" alerts on affected Windows endpoints monitored using Defender for Endpoint. In a Microsoft 365 Defender service advisory issued after reports of these alarming alerts started showing up online, Microsoft revealed that they were erroneously triggered by a false positive and not due to malicious activity. "Admins may receive a false positive alert for Google Update on Microsoft Defender for Endpoint monitored devices," Microsoft said. Roughly one and a half hours later, the advisory was updated, wi...