Published in News

Chinese hackers find internet fatal flaw

by on16 December 2021


Free bit of code

Hackers linked to China and other governments are among a growing assortment of cyberattackers seeking to exploit a widespread and severe vulnerability in computer server software.

Software King of the World Microsoft said that involvement of hackers whom analysts have linked to nation-states underscored the increasing gravity of the flaw in Log4j software, a free bit of code that logs activity in computer networks and applications.

Cybersecurity researchers say it is one of the most dire cybersecurity threats to emerge in years and could enable devastating attacks, including ransomware, in both the immediate and distant future.

Government-sponsored hackers are often among the best-resourced and most capable, analysts say.

John Hultquist, vice president of intelligence analysis at the US-based cybersecurity firm Mandiant said the effects of this vulnerability will reverberate for months to come -- maybe even years – “as we try to close these doors and try to hunt down all the actors who made their way in”.

Both Microsoft and Mandiant said they have observed hacking groups linked to China and Iran launching attacks that exploit the flaw in Log4j. In an update to its website posted late Wednesday,

Microsoft said that it had also seen nation-backed hackers from North Korea and Turkey using the attack.

Some attackers appear to be experimenting with the attack; others are trying to use it to break into online targets, Microsoft said.

 

Last modified on 16 December 2021
Rate this item
(2 votes)