New York Tech Media
  • News
  • FinTech
  • AI & Robotics
  • Cybersecurity
  • Startups & Leaders
  • Venture Capital
No Result
View All Result
  • News
  • FinTech
  • AI & Robotics
  • Cybersecurity
  • Startups & Leaders
  • Venture Capital
No Result
View All Result
New York Tech Media
No Result
View All Result
Home Cybersecurity

Security leaders want legal action for failing to patch for Log4j

New York Tech Editorial Team by New York Tech Editorial Team
March 2, 2022
in Cybersecurity
0
The impact of the Log4j vulnerability on OT networks
Share on FacebookShare on Twitter

The recently identified vulnerability in the Log4j Java logging package has created headaches for security professionals around the world. 61% of organizations responding to the latest Neustar International Security Council (NISC) survey, conducted in January 2022, said they had fielded attacks targeting this vulnerability. An even greater share (75%) reported having been impacted by Log4j, with one in five (21%) stating that impact had been significant.

Log4j vulnerability security professionals

Log4j vulnerability reduced security professionals’ trust in open-source tools

The most commonly experienced impact of Log4j was the need for IT and security teams to work over the holidays to assess risk and make critical changes to protect infrastructure and data (52%), followed by a reevaluation of software supply chain security practices (45%) and software purchasing decisions (44%). A significant share of respondents had also moved to reevaluate existing vendor relationships (35%) or said the vulnerability reduced their trust in open-source tools (34%).

87% of respondents said that given the level of cyber risk posed by Log4j, government regulatory agencies (such as the U.S. Federal Trade Commission) should take legal action against organizations that fail to patch the flaw. In the words of one security professional, these organizations “may fail to secure and protect important customer data.” Another agreed: “It puts everyone at risk. We should have control over where our clients’ data ends up.” Another responded that companies large enough to address the problem should do so, and the federal government should enforce this mitigation, because “if they don’t, who will?”

“News of the Log4j threat sent security and applications teams around the globe into a frenzy of activity – taking inventory of their internet-facing systems, checking for Log4j, checking revision levels, and putting into effect emergency patching – and while many organizations took the appropriate proactive step of reaching out to business partners and vendors to assess the potential exposure, the timing made efforts to remediate that much more of a challenge,” said Carlos Morales, SVP of solutions at Neustar Security Services.

Virtual patching to handle zero-day threats

For companies that have deployed Web Application Firewall (WAF) technology or contract WAF functions from their cloud security providers, there may be a simple solution for handling zero-day threats like Log4j: virtual patching.

“Virtual patching can trick any potential attackers into thinking that your applications are not vulnerable to a threat,” added Morales. “WAF solutions are deployed in-line with web application traffic and act as reverse proxies between the clients of the application and the origin servers. The WAF terminates the connection with the client, ensures that the client is not performing any malicious actions, and then creates a separate connection to the server, bridging data between the two. Since it is terminating the client traffic, the WAF can act on behalf of the origin server and cover up for any vulnerabilities that exist on the server. Virtual patching is one of the ways that this is done.”

In addition to Log4j, the surveyed security professionals were asked about their other top concerns during the reporting period of November and December 2021. Distributed denial-of-service (DDoS) was ranked as the greatest concern by 21% of respondents, followed by ransomware and system compromise (both 18%).

Ransomware, DDoS attacks and targeted hacking were the threats most likely to be perceived as increasing during the reporting period. The threats organizations focused their ability to respond to most during this period were vendor or customer impersonation, targeted hacking, and ransomware.

Delving into more detail on the survey participants’ top concern — DDoS attacks — revealed that 84% of enterprises had been on the receiving end of a DDoS attack at some point. 57% of responding organizations reported outsourcing their DDoS mitigation, and 60% said it typically took between 60 seconds and 5 minutes to initiate mitigation.

Credit: Source link

Previous Post

How to help humans understand robots | MIT News

Next Post

As war in Ukraine continues, European VCs examine Russian ties

New York Tech Editorial Team

New York Tech Editorial Team

New York Tech Media is a leading news publication that aims to provide the latest tech news, fintech, AI & robotics, cybersecurity, startups & leaders, venture capital, and much more!

Next Post
As war in Ukraine continues, European VCs examine Russian ties

As war in Ukraine continues, European VCs examine Russian ties

  • Trending
  • Comments
  • Latest
Meet the Top 10 K-Pop Artists Taking Over 2024

Meet the Top 10 K-Pop Artists Taking Over 2024

March 17, 2024
Panther for AWS allows security teams to monitor their AWS infrastructure in real-time

Many businesses lack a formal ransomware plan

March 29, 2022
Zach Mulcahey, 25 | Cover Story | Style Weekly

Zach Mulcahey, 25 | Cover Story | Style Weekly

March 29, 2022
How To Pitch The Investor: Ronen Menipaz, Founder of M51

How To Pitch The Investor: Ronen Menipaz, Founder of M51

March 29, 2022
Japanese Space Industry Startup “Synspective” Raises US $100 Million in Funding

Japanese Space Industry Startup “Synspective” Raises US $100 Million in Funding

March 29, 2022
UK VC fund performance up on last year

VC-backed Aerium develops antibody treatment for Covid-19

March 29, 2022
Startups On Demand: renovai is the Netflix of Online Shopping

Startups On Demand: renovai is the Netflix of Online Shopping

2
Robot Company Offers $200K for Right to Use One Applicant’s Face and Voice ‘Forever’

Robot Company Offers $200K for Right to Use One Applicant’s Face and Voice ‘Forever’

1
Menashe Shani Accessibility High Tech on the low

Revolutionizing Accessibility: The Story of Purple Lens

1

Netgear announces a $1,500 Wi-Fi 6E mesh router

0
These apps let you customize Windows 11 to bring the taskbar back to life

These apps let you customize Windows 11 to bring the taskbar back to life

0
This bipedal robot uses propeller arms to slackline and skateboard

This bipedal robot uses propeller arms to slackline and skateboard

0
Coffee Nova’s $COFFEE Token

Coffee Nova’s $COFFEE Token

May 29, 2025
Money TLV website

BridgerPay to Spotlight Cross-Border Payments Innovation at Money TLV 2025

May 27, 2025
The Future of Software Development: Why Low-Code Is Here to Stay

Building Brand Loyalty Starts With Your Team

May 23, 2025
Tork Media Expands Digital Reach with Acquisition of NewsBlaze and Buzzworthy

Creative Swag Ideas for Hackathons & Launch Parties

May 23, 2025
Tork Media Expands Digital Reach with Acquisition of NewsBlaze and Buzzworthy

Strengthening Cloud Security With Automation

May 22, 2025
How Local IT Services in Anderson Can Boost Your Business Efficiency

Why VPNs Are a Must for Entrepreneurs in Asia

May 22, 2025

Recommended

Coffee Nova’s $COFFEE Token

Coffee Nova’s $COFFEE Token

May 29, 2025
Money TLV website

BridgerPay to Spotlight Cross-Border Payments Innovation at Money TLV 2025

May 27, 2025
The Future of Software Development: Why Low-Code Is Here to Stay

Building Brand Loyalty Starts With Your Team

May 23, 2025
Tork Media Expands Digital Reach with Acquisition of NewsBlaze and Buzzworthy

Creative Swag Ideas for Hackathons & Launch Parties

May 23, 2025

Categories

  • AI & Robotics
  • Benzinga
  • Cybersecurity
  • FinTech
  • New York Tech
  • News
  • Startups & Leaders
  • Venture Capital

Tags

3D bio-printing acoustic AI Allseated B2B marketing Business carbon footprint climate change coding Collaborations Companies To Watch consumer tech crypto cryptocurrency deforestation drones earphones Entrepreneur Fetcherr Finance Fintech food security Investing Investors investorsummit israelitech Leaders LinkedIn Leaders Metaverse news OurCrowd PR Real Estate reforestation software start- up Startups Startups On Demand startuptech Tech Tech leaders technology UAVs Unlimited Robotics VC
  • Contact Us
  • Privacy Policy
  • Terms and conditions

© 2024 All Rights Reserved - New York Tech Media

No Result
View All Result
  • News
  • FinTech
  • AI & Robotics
  • Cybersecurity
  • Startups & Leaders
  • Venture Capital

© 2024 All Rights Reserved - New York Tech Media