ADD ANI AS A TRUSTED SOURCE
googleads
Menu
US

US reveals new software vulnerability, warns hundreds of millions of devices at risk

Washington [US], December 14 (ANI): The US on Monday revealed a new software vulnerability and warned that hundreds of millions of devices are at risk.

ANI Dec 14, 2021 06:17 IST googleads

Representative Image

Washington [US], December 14 (ANI): The US on Monday revealed a new software vulnerability and warned that hundreds of millions of devices are at risk.
A senior Biden administration cyber official, Jen Easterly, Director of the US Cybersecurity and Infrastructure Security Agency (CISA) warned executives from major US industries that they need to take action to address "one of the most serious" flaws she has seen in her career, reported CNN.
As major tech firms struggle to contain the fallout from the incident, US officials held a call with industry executives warning that hackers are actively exploiting the vulnerability.
"This vulnerability is one of the most serious that I've seen in my entire career, if not the most serious," said Easterly on a phone call shared with CNN. Big financial firms and health care executives attended the phone briefing.
"We expect the vulnerability to be widely exploited by sophisticated actors and we have limited time to take necessary steps in order to reduce the likelihood of damaging incidents," Easterly said.
CNN has reached out to CISA for comment on the call. CyberScoop, a technology news site, first reported on the contents of the call.
It's the starkest warning yet from US officials about the software flaw since news broke late last week that hackers were using it to try to break into organizations' computer networks.
It's also a test of new channels that federal officials have set up for working with industry executives after the widespread hacks exploiting SolarWinds and Microsoft software revealed in the last year.
Experts told CNN it could take weeks to address the vulnerabilities and that suspected Chinese hackers are already attempting to exploit them.
The vulnerability is in Java-based software known as "Log4j" that large organizations, including some of the world's biggest tech firms, use to log information in their applications. Tech giants like Amazon Web Services and IBM have moved to address the bug in their products.
It offers a hacker a relatively easy way to access an organization's computer server. From there, an attacker could devise other ways to access systems on an organization's network.
The Apache Software Foundation, which manages the Log4j software, has released a security fix for organizations to apply.
Organizations are now in a race against time to figure out how if they have computers running the vulnerable software that were exposed to the internet. Cybersecurity executives across government and industry are working around the clock on the issue, reported CNN.
"We're going to have to make sure we have a sustained effort to understand the risk of this code throughout US critical infrastructure," Jay Gazlay, another CISA official, said on the phone call.
Chinese-government linked hackers have already begun using the vulnerability, according to Charles Carmakal, senior vice president and chief technology officer for cybersecurity firm Mandiant, reported CNN.
To address the issue, CISA said it would set up a public website with information on what software products were affected by the vulnerability, and the techniques that hackers were using to exploit it. (ANI)

Get the App

What to Read Next

US

Trump describes Michigan synagogue attack as "terrible"

Trump describes Michigan synagogue attack as

Speaking at a Women's History Month event at the White House, the US president said he had been fully briefed on the situation and described the incident as "terrible."

Read More
Asia

India consistently supported Maldives in crisis: Mohamed Nasheed

India consistently supported Maldives in crisis: Mohamed Nasheed

He highlighted India's role as a "first responder" for the Maldives, emphasising that India's support during critical periods has been fundamental to the stability and security of the island nation.

Read More
US

Ending Iran's nuclear ambitions over oil profits: Trump clarifies

Ending Iran's nuclear ambitions over oil profits: Trump clarifies

In a post by the White House, President Trump, while acknowledging that the United States is currently the world's leading oil producer and stands to benefit financially from higher crude prices, emphasised that his administration's overriding mission remains the permanent dismantling of Iran's nuclear program.

Read More
Middle East

"Blocking Strait of Hormuz must continue," says Ayatollah Mojtaba

In his first address to the Iranian people. Ayatollah Mojtaba Khamenei called for the continued blockade of the Strait of Hormuz, a move that will raise tensions.

Read More
Middle East

Mojtaba Khamenei calls on Muslim neighbours to clarify stance

Mojtaba Khamenei calls on Muslim neighbours to clarify stance

"The countries of the region must clarify their stance regarding the aggressors against our dear homeland and the killers of our people. I recommend that they shut down those bases as soon as possible; for they must surely have realized by now that America's claim of establishing security and peace has been nothing but a lie," he said.

Read More
Home About Us Our Products Advertise Contact Us Terms & Condition Privacy Policy

Copyright © aninews.in | All Rights Reserved.