• Disclosure
  • Privacy Policy
  • DMCA Policy
  • CCPA
  • Medical Disclaimer
Friday, March 31, 2023
Cameron County News Online
  • Home
  • News
  • Business
  • Technology
    • Crytpocurrency
    • Gaming
    • Gadgets
  • Sports
  • Health
  • General
    • Business Services
  • Travel
  • Press Releases
  • Popular
No Result
View All Result
  • Home
  • News
  • Business
  • Technology
    • Crytpocurrency
    • Gaming
    • Gadgets
  • Sports
  • Health
  • General
    • Business Services
  • Travel
  • Press Releases
  • Popular
No Result
View All Result
No Result
View All Result
Home News

US Warns Hundreds Of Millions Of Devices At Risk From Newly Revealed Software Vulnerability – CNN

by NewsReporter
December 14, 2021
in News
Reading Time: 5 mins read
us-warns-hundreds-of-millions-of-devices-at-risk-from-newly-revealed-software-vulnerability-–-cnn
Share on FacebookShare on Twitter

Washington (CNN)Hundreds of millions of devices around the world could be exposed to a newly revealed software vulnerability, as a senior Biden administration cyber official warned executives from major US industries Monday that they need to take action to address “one of the most serious” flaws she has seen in her career.

DHS warns of critical flaw in widely used software

As major tech firms struggle to contain the fallout, US officials held a call with industry executives warning that hackers are actively exploiting the vulnerability.

    For now, cybersecurity analysts told CNN, the pressure is on tech companies to clean up their software code and on big businesses to figure out if they are affected by the flaw. But because the vulnerability is so widespread, and likely present in things like popular apps and websites, consumers could also feel the fallout if those services get hacked.

      “This vulnerability is one of the most serious that I’ve seen in my entire career, if not the most serious,” Jen Easterly, director of the US Cybersecurity and Infrastructure Security Agency (CISA), said on a phone call shared with CNN. Big financial firms and health care executives attended the phone briefing.

        “We expect the vulnerability to be widely exploited by sophisticated actors and we have limited time to take necessary steps in order to reduce the likelihood of damaging incidents,” Easterly said.

        CNN has reached out to CISA for comment on the call. CyberScoop, a technology news site, first reported on contents of the call.

          It’s the starkest warning yet from US officials about the software flaw since news broke late last week that hackers were using it to try to break into organizations’ computer networks. It’s also a test of new channels that federal officials have set up for working with industry executives after the widespread hacks exploiting SolarWinds and Microsoft software revealed in the last year.

          New White House policy gives agencies 24 hours to assess cyberattacks of potential national security concern

          Experts told CNN it could take weeks to address the vulnerabilities and that suspected Chinese hackers are already attempting to exploit it.

          The vulnerability is in Java-based software known as “Log4j” that large organizations, including some of the world’s biggest tech firms, use to log information in their applications. Tech giants like Amazon Web Services and IBM have moved to address the bug in their products.

          It offers a hacker a relatively easy way to access an organization’s computer server. From there, an attacker could devise other ways to access systems on an organization’s network.

          The Apache Software Foundation, which manages the Log4j software, has released a security fix for organizations to apply.

          Race against time to address flaw

          But attackers had more than a week’s head start on exploiting the software flaw before it was publicly disclosed, according to cybersecurity firm Cloudflare.

          Organizations are now in a race against time to figure out if they have computers running the vulnerable software that were exposed to the internet. Cybersecurity executives across government and industry are working around the clock on the issue.

          Ransomware attack hits Virginia Legislature

          “We’re going to have to make sure we have a sustained effort to understand the risk of this code throughout US critical infrastructure,” Jay Gazlay, another CISA official, said on the phone call.

          Chinese-government linked hackers have already begun using the vulnerability, according to Charles Carmakal, senior vice president and chief technology officer for cybersecurity firm Mandiant. Mandiant declined to elaborate on what organizations the hackers were targeting.

          “Over time, everybody can arm the damn thing,” Mandiant CEO Kevin Mandia told CNN, referring to the vulnerability. “That’s the problem. And there’ll probably be great hackers hiding in the noise of the not so great.”

          The “noise” is a real problem. For cybersecurity professionals, Twitter has been a constant churn of both useful information and, in some cases, misinformation that has nothing to do with the vulnerability.

          Shopping online this holiday season? Why you need to protect yourself

          To address the issue, CISA said it would set up a public website with information on what software products were affected by the vulnerability, and the techniques that hackers were using to exploit it.

          “This will be a multiweek process where new actors are exploiting the vulnerability,” Eric Goldstein, CISA’s executive assistant director for cybersecurity, said on the phone call.

            The ubiquity of the software forced cybersecurity professionals around the country to spend the weekend checking if their systems are vulnerable.

            “For most of the information technology world, there was no weekend,” Rick Holland, chief information security officer at cybersecurity firm Digital Shadows, told CNN. “It was just another long set of days.”

            CNN’s Geneva Sands contributed reporting.

            Related Posts

            troup-county-sheriff’s-office-arrest-release-reports-for-period-ending-april-14-–-lagrange-daily-news-|-lagrange-daily-news-–-lagrange-daily-news

            Troup County Sheriff’s Office Arrest Release Reports For Period Ending April 14 – LaGrange Daily News | LaGrange Daily News – LaGrange Daily News

            by NewsReporter
            April 14, 2022
            0

            Amari Keshad Towns, 21, 115 Haley Way, LaGrange, GA, theft – other (felony Michael Randall Reynolds, 27, 1114 Alverson Road, LaGrange, GA, VGCSA-amphetamine-possession Maria Montana Phillips, 41, 421 South Lee Street D-22, LaGrange, GA, failure to appear (state) Crystal Nichol Gates, 38, no known address, remove/affix plate with intent to...

            musk-says-us.-sec-‘bastards’-forced-settlement-over-tesla-tweets-–-reuters

            Musk Says U.S. SEC ‘bastards’ Forced Settlement Over Tesla Tweets – Reuters

            by NewsReporter
            April 14, 2022
            0

            Tesla CEO Elon Musk leaves Manhattan federal court after a hearing on his fraud settlement with the Securities and Exchange Commission (SEC) in New York City, U.S. April 4, 2019. REUTERS/Brendan McDermidRegister now for FREE unlimited access to Reuters.comApril 14 (Reuters) - Tesla Inc (TSLA.O) CEO Elon Musk on Thursday...

            democrats-are-in-danger-of-losing-three-congressional-strongholds-in-south-texas-–-ksat-san-antonio

            Democrats Are In Danger Of Losing Three Congressional Strongholds In South Texas – KSAT San Antonio

            by NewsReporter
            April 14, 2022
            0

            Sign up for The Brief, our daily newsletter that keeps readers up to speed on the most essential Texas news.WASHINGTON — Fending off the Republican advance in South Texas this fall was already going to be a taller-than-usual order for Democrats. But few Democrats anticipated it would be this hard.Thanks...

            column:-crop-watch:-cold-spring-weather-prevents-early-us.-planting-–-reuters

            Column: Crop Watch: Cold Spring Weather Prevents Early U.S. Planting – Reuters

            by NewsReporter
            April 14, 2022
            0

            Acres of soybeans seen at the Pioneer-DuPont Seed facility in Addieville, Illinois U.S., September 19, 2018. Picture taken September 19, 2018. REUTERS/Lawrence BryantRegister now for FREE unlimited access to Reuters.comNAPERVILLE, Ill., April 13 (Reuters) - It is too early yet for U.S. corn and soybean planting to be in full...

            Cameron County News Online

            © 2021 Salt Lake City News Now

            Navigate Site

            • Disclosure
            • Privacy Policy
            • DMCA Policy
            • CCPA
            • Medical Disclaimer

            Follow Us

            No Result
            View All Result
            • Home
            • DMCA Policy
            • Medical Disclaimer
            • Privacy Policy
            • Disclosure
            • CCPA
            • Terms of Use

            © 2021 Salt Lake City News Now

            We use cookies on our website to give you the most relevant experience by remembering your preferences and repeat visits. By clicking “Accept All”, you consent to the use of ALL the cookies. However, you may visit "Cookie Settings" to provide a controlled consent.
            Cookie SettingsAccept All
            Manage consent

            Privacy Overview

            This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
            Necessary
            Always Enabled
            Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
            CookieDurationDescription
            cookielawinfo-checkbox-analytics11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
            cookielawinfo-checkbox-functional11 monthsThe cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
            cookielawinfo-checkbox-necessary11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
            cookielawinfo-checkbox-others11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
            cookielawinfo-checkbox-performance11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
            viewed_cookie_policy11 monthsThe cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
            Functional
            Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
            Performance
            Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
            Analytics
            Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
            Advertisement
            Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.
            Others
            Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.
            SAVE & ACCEPT