Race to solve Log4Shell, the bug that scares the internet

Ansa Live at 3 pm (ANSA)

After version 2.15.0 released last Friday to try to close the Log4Shell security flaw, the developers of the Apache software foundation have released the Log4j 2.16.0 update which seems to definitively fix the vulnerability that scares the internet. Emerged days ago, the bug would allow cybercriminals to breach the systems of a considerable number of companies globally, which rely on their IT infrastructures on the Log4j code library, which is useful for developing their apps and services. Twitter, Amazon and Apple are also interested.

And the latter has communicated that it has implemented the update of the Apache software foundation and has thus corrected, as far as it is concerned, the library used by iCloud, the platform that stores photos and other sensitive data of those who own a Cupertino device. , involved in the problem. Microsoft has released a software update for users of the online version of the Minecraft videogame, from which the first signs of the bug had come, and so has Valve, which develops the website and the Steam videogame streaming app. The company confirmed that it has analyzed its services, concluding that there are no more security risks.

According to researchers from Check Point Research, there have been attempts in Italy to exploit it on 43% of corporate networks since the leak was made public. It means that almost half of every corporate computer connected to the network in our country has undergone an attempted breach. A figure in line with the European average and just above the global threshold of 40%. A separate report by the Bit Defender specialists explains that the hackers’ activities mainly focus on using the bug to enter computer systems and from there unleash attacks directed at specific targets, such as physical energy infrastructures. The researcher expert in cybersecurity, Márcio Almeida, at the release of Log4j 2.16.0 verified that the new version is indeed free from the vulnerability and for this reason invites every company to update the code library on which it bases its projects, passing to the most recent .

.

Source From: Ansa

Share this article:

Leave a Reply

most popular