https://www.channelfutures.com/wp-content/themes/channelfutures_child/assets/images/logo/footer-new-logo.png
  • Home
  • Technologies
    • Back
    • SDN/SD-WAN
    • Cloud
    • RMM/PSA
    • Security
    • Telephony/UC/Collaboration
    • Cable
    • Mobility & Wireless
    • Fiber/Ethernet
    • Data Centers
    • Backup & Disaster Recovery
    • IoT
    • Desktop
    • Artificial Intelligence
    • Analytics
  • Strategy
    • Back
    • Mergers and Acquisitions
    • Channel Research
    • Business Models
    • Distribution
    • Technology Solutions Brokerages
    • Sales & Marketing
    • Best Practices
    • Vertical Markets
    • Regulation & Compliance
  • MSP 501
    • Back
    • 2022 MSP 501 Rankings
    • 2022 NextGen 101 Rankings
  • Intelligence
    • Back
    • Galleries
    • Podcasts
    • From the Industry
    • Reports/Digital Issues
    • Webinars
    • White Papers
  • Channel Futures TV
  • EMEA
  • Channel Chatter
    • Back
    • People on the Move
    • New/Changing Channel Programs
    • New Products & Services
    • Industry Honors
  • Resources
    • Back
    • Advisory Boards
    • Industry Organizations
    • Our Sponsors
    • Advertise
    • 2022 Editorial Calendar
  • Awards
    • Back
    • 2022 MSP 501
    • Channel Influencers
    • Circle of Excellence
    • DE&I 101
    • Channel Partners 101 (CP 101)
  • Events
    • Back
    • CP Conference & Expo
    • MSP Summit
    • Channel Partners Europe
    • Channel Partners Event Coverage
    • Webinars
    • Industry Events
  • About Us
  • DE&I
Channel Futures
  • NEWSLETTER
  • Home
  • Technologies
    • Back
    • SDN/SD-WAN
    • Cloud
    • RMM/PSA
    • Security
    • Telephony/UC/Collaboration
    • Cable
    • Mobility & Wireless
    • Fiber/Ethernet
    • Data Centers
    • Backup & Disaster Recovery
    • IoT
    • Desktop
    • Artificial Intelligence
    • Analytics
  • Strategy
    • Back
    • Mergers and Acquisitions
    • Channel Research
    • Business Models
    • Distribution
    • Technology Solutions Brokerages
    • Sales & Marketing
    • Best Practices
    • Vertical Markets
    • Regulation & Compliance
  • MSP 501
    • Back
    • 2022 MSP 501 Rankings
    • 2022 NextGen 101 Rankings
  • Intelligence
    • Back
    • Galleries
    • Podcasts
    • From the Industry
    • Reports/Digital Issues
    • Webinars
    • White Papers
  • Channel Futures TV
  • EMEA
  • Channel Chatter
    • Back
    • People on the Move
    • New/Changing Channel Programs
    • New Products & Services
    • Industry Honors
  • Resources
    • Back
    • Advisory Boards
    • Industry Organizations
    • Our Sponsors
    • Advertise
    • 2022 Editorial Calendar
  • Awards
    • Back
    • 2022 MSP 501
    • Channel Influencers
    • Circle of Excellence
    • DE&I 101
    • Channel Partners 101 (CP 101)
  • Events
    • Back
    • CP Conference & Expo
    • MSP Summit
    • Channel Partners Europe
    • Channel Partners Event Coverage
    • Webinars
    • Industry Events
  • About Us
  • DE&I
    • Newsletter
  • REGISTER
  • MSPs
  • VARs / SIs
  • Agents
  • Cloud Service Providers
  • Channel Partners Events
 Channel Futures

Security


Shutterstock

log4j on laptop

CSRB: Log4J to Remain Threat for at Least the Next Decade

  • Written by Edward Gately
  • July 14, 2022
Organizations have spent significant resources as they struggled with this problem.

The national Cyber Safety Review Board (CSRB) says Log4J, which has plagued security professionals globally for several months, will be an “endemic vulnerability” for years to come.

The U.S. Department of Homeland Security assembled the CSRB early this year. The board investigates major national cybersecurity incidents in an effort to improve the nation’s cyber resilience.

The CSRB released its first report this week examining events around the disclosure of Log4J last December. The board engaged with nearly 80 organizations and individuals representing software developers, end users, security professionals and companies.

The Java-logging library Apache Log4j can be used by hackers to take over computer servers if it isn’t patched. The library is free, which means companies have to create their own patches for it.

Log4J led to an explosion of attacks.

Log4J Exploitation Trends Difficult to Track

“At the time of writing, the board is not aware of any significant Log4j-based attacks on critical infrastructure systems,” the CSRB said in its report. “Somewhat surprisingly, the board also found that to date, generally speaking, exploitation of Log4j occurred at lower levels than many experts predicted, given the severity of the vulnerability. It has been difficult to arrive at this conclusion. While cybersecurity vendors were able to provide some anecdotal evidence of exploitation, no authoritative source exists to understand exploitation trends across geographies, industries or ecosystems. Many organizations do not even collect information on specific Log4j exploitation, and reporting is still largely voluntary.”

Most importantly, the CSRB said the Log4j event is far from over. Vulnerable instances of Log4j will remain in systems for many years to come, perhaps a decade or longer. Significant risk remains.

Organizations have spent significant resources as they struggled with this problem, the board said.

“For example, one federal cabinet department reported dedicating 33,000 hours to Log4j vulnerability response to protect the department’s own networks,” it said. “These costs, often sustained over many weeks and months, delayed other mission-critical work, including the response to other vulnerabilities.”

Michael Skelton is senior director of security operations at Bugcrowd.

Bugcrowd's Michael Skelton

Bugcrowd’s Michael Skelton

“Dealing with Log4J is a marathon, one that will take years more to resolve,” he said. “Java, and Log4j are prevalent everywhere, not only in core projects, but in dependencies that other projects rely on, making detection and mitigation not as simple an exercise as it may be with other vulnerabilities. While the initial wave of Log4J findings has subsided, we do still see Log4J over bug bounty programs somewhat frequently as the crowd dives deeper into the vulnerability, and looks into the dependencies of projects for its presence.”

Complexity of Patching Creates More Difficulties

Matthew Warner is CTO and co-founder of Blumira.

Blumira's Matthew Warner

Blumira’s Matthew Warner

“The complexity of patching unknown Log4j systems continues to add more difficulties for organizations,” he said. “A purchased appliance may have a vulnerable version of Log4j without any knowledge of the organization. There continues to be exploitation of Log4j across internet-exposed VMware Horizon servers that have not been patched, even within hours of CISA notifications of vulnerable hosts. In the grand scheme of cybersecurity, however, Log4j is not unprecedented. Even three years after exposure, there continues to be exposed remote desktop protocol (RDP) that is vulnerable to BlueKeep.”

Vulnerabilities that live within infrastructure have longevity and stickiness, Warner said. That’s due to the complexity of networks and IT turnover that results in undocumented devices.

“It will take many years for the industry to remove and update all legacy Log4j solutions and support to identify impacted solutions, and getting this information to organizations will be necessary for privacy/public partnership success,” he said.

Want to contact the author directly about this story? Have ideas for a follow-up article? Email Edward Gately or connect with him on LinkedIn.
Tags: MSPs VARs/SIs Best Practices Channel Research Cloud Security Technologies

Most Recent


  • Go to market
    Lumen Channel Leaders Talk Program Evolution, C-Suite Sponsorship, TSD Consolidation
    "[We're] working really hard to represent the channel inside the company," Dave Young said.
  • Cyble Research: Exposed VNC Ports Threaten Critical Infrastructure
    Many of the exposed VNCs belonged to industrial control systems.
  • Stock Downgrade
    Analysts React to Rackspace Earnings with Downgrades
    Since the cloud MSP reported its second-quarter earnings, investment analysts have changed their ratings.
  • Microsoft Teams on laptop
    Microsoft Targeting Partners to Sell Teams, Windows 365 to SMBs, More
    Microsoft still sees a big opportunity for Teams among SMBs. Windows 365 is also growing in this market.

Leave a comment Cancel reply

-or-

Log in with your Channel Futures account

Alternatively, post a comment by completing the form below:

Your email address will not be published. Required fields are marked *

Related Content

  • Interactive Voice Response - Microsoft Digital Contact Center Platform
    Microsoft Inspire Partner Event Begins with Digital Contact Center Launch
  • PentaFour
    Tower Arch Capital Buys Intelligent Technical Solutions as First Step Into MSP Market
  • EDR
    Carbon Black, Cisco, Crowdstrike Among Leaders in Fast-Growing EDR Market
  • Mergers and Acquisitions, MA
    MSP M&A Not Slowing Down: PentaFour, NetGain Technologies, Logically, Layer 3, More

Upcoming Events

View all

MSP Summit

September 13, 2022 - September 16, 2022

Channel Partners Conference & Expo

May 1, 2023 - May 4, 2023

Galleries

View all

Lumen Channel Leaders Talk Program Evolution, C-Suite Sponsorship, TSD Consolidation

August 15, 2022

Kaseya’s Auto-Renewal Changes Bring Glimmer of Hope to Partners Amid Turmoil

August 15, 2022

Analysts React to Rackspace Earnings with Downgrades

August 15, 2022

Industry Perspectives

View all

How to Take Shared Responsibility for Securing Cloud

August 11, 2022

Seize the Application Modernization Opportunity

August 2, 2022

A Growth Mindset: Your Organization’s Strategic Differentiator

August 1, 2022

Webinars

View all

Outsmarting RaaS: Implementation Strategies To Help Your Clients Before, During, and After a Ransomware Attack

August 23, 2022

Why it is Important to Upgrade Aging Servers and How to use Live Optics to Upgrade Efficiently

August 25, 2022

Executives at Home are Not Alright: An Intro to Digital Executive Protection

September 8, 2022

White Papers

View all

Work Goes Remote – (and Other Top ITOps Trends)

May 25, 2022

The New Bottom Line: How MSPs Can Meet the Healthcare Crisis While Evolving Their Businesses

April 19, 2022

How to build a Security Operations Center (on a budget)

April 4, 2022

Channel Futures TV

View all

ThreatLocker Preaches Zero Trust, Addresses Industry Competition

Microsoft Targeting Partners to Sell Teams, Windows 365 to SMBs, More

August 15, 2022

ScienceLogic Debuts New Partner Portal

August 9, 2022

Vonage a ‘Single Communications Stack Provider’ for Partners, Customers

June 27, 2022

Twitter

ChannelFutures

.@LumenCPP partner leaders say private equity investment in the advisory channel is validating the space to Lumen l… twitter.com/i/web/status/1…

August 15, 2022
ChannelFutures

.@KaseyaCorp's auto-renewal changes bring glimmer of hope to partners amidst turmoil. Some of our #MSP501 and… twitter.com/i/web/status/1…

August 15, 2022
ChannelFutures

.@AuCyble research shows #criticalinfrastructure at risk from exposed VNC endpoints. dlvr.it/SWhGhJ https://t.co/oMhiYxCT9L

August 15, 2022
ChannelFutures

Investment analysts are responding to @Rackspace’s Q2 earnings with downgrades, new price objectives.… twitter.com/i/web/status/1…

August 15, 2022
ChannelFutures

In a new @juniperresearch study, @twilio ranked No. 1 for its flexible CCaaS product offering. Which companies plac… twitter.com/i/web/status/1…

August 15, 2022
ChannelFutures

A few more booths left! Join an industry-leading lineup of 100+ suppliers at THE channel event of the fall. Partner… twitter.com/i/web/status/1…

August 15, 2022
ChannelFutures

.@splunk vet Bill Hustad named @Okta's new #channelchief. dlvr.it/SWXmws https://t.co/ILQesul0Cz

August 12, 2022
ChannelFutures

The Gately Report: #BHUSA edition with @Hacker0x01, @Cisco, @SaltSecurity, @CISAgov, @ExtraHop, @IBMSecurity, more.… twitter.com/i/web/status/1…

August 12, 2022

MSP 501

The industry's largest and most comprehensive partner awards program.

Newsletters and Updates

Sign up for The Channel Report, Channel Futures Update, MSP 501 Newsletter and more.

Live Channel Events

Get the latest information on the next industry-leading Channel Partners event.

Galleries

Educational slide shows and images from live events.

Media Kit And Advertising

Want to reach our audience? Access our media kit.

DISCOVER MORE FROM INFORMA TECH

  • Channel Partners Events
  • Telecoms.com
  • MSP 501
  • Black Hat
  • IoT World Today
  • Omdia

WORKING WITH US

  • Contact
  • About Us
  • Advertise
  • Newsletter

FOLLOW Channel Futures ON SOCIAL

  • Privacy
  • CCPA: “Do Not Sell My Data”
  • Cookie Policy
  • Terms
Copyright © 2022 Informa PLC. Informa PLC is registered in England and Wales with company number 8860726 whose registered and Head office is 5 Howick Place, London, SW1P 1WG.
This website uses cookies, including third party ones, to allow for analysis of how people use our website in order to improve your experience and our services. By continuing to use our website, you agree to the use of such cookies. Click here for more information on our Cookie Policy and Privacy Policy.
X