Today, the U.S. Department of Homeland Security (DHS) released the Cyber Safety Review Board’s (CSRB) first report, which includes 19 actionable recommendations for government and industry.
The report suggests that even though Log4j remains a risk, a government-wide response helped drive remediation of the vulnerability. The board also identified the need for additional funding to support the mostly volunteer open source software security community.
Here is what a few cybersecurity industry experts had to say about the release of the CSRB report:
##
Tim Mackey, Principal Security Strategist at the Mountain View-based Synopsys Cybersecurity Research Center:
“Rarely do we get a comprehensive review of the impact and root causes of a cyber incident so quickly after the incident occurred, but that is precisely what we have from the CSRB in their report on Log4Shell and log4j.
Open source software is fundamentally managed differently than commercial software, but open source software plays a key role in the success of commercial software. The “long-tail” scenario outlined in the report is one we’ve seen with countless past vulnerabilities, and one that favors attackers since their success is based on having at least one victim who hasn’t patched their systems. Given management of open source software is different than commercial software, and open source powers commercial software, reliance on a commercial vendor to alert consumers of a problem presumes that the vendor is properly managing their usage of open source and that they are able to identify and alert all users of their impacted software – even if support for that software has ended.
With patch management being a challenge at the best of times, to mitigate the risk of unknown open source governance within vendors, software consumers should implement a trust-but-verify model to validate whether the software they’re given doesn’t contain unpatched vulnerabilities.”
++
Michael Skelton (Codingo), Senior Director of Security Operations at Bugcrowd, a San Francisco, Calif.-based leader in crowdsourced cybersecurity:
“Dealing with Log4J is a marathon, one that will take years more to resolve. Java, and Log4j are prevalent everywhere, not only in core projects but in dependencies that other projects rely on, making detection and mitigation not as simple an exercise as it may be with other vulnerabilities. While the initial wave of Log4J findings has subsided, we do still see Log4J over bug bounty programs somewhat frequently as the crowd dives deeper into the vulnerability, and looks into the dependencies of projects for its presence.”
++
John Bambenek, Principal Threat Hunter at Netenrich, a San Jose, Calif.-based security and operations analytics SaaS company:
“The Log4j vulnerability was first widely known in December. This report is eight months after that. At this point, anyone still vulnerable is highly unlikely to read this report or in much of a position to do anything about it if they did. Most of the American economy is small to medium business who almost always never have a CISO and likely not even a CIO. Until we find ways to make the public without security budgets safe, no high level list of best practices will move the ball significantly.”
++
Matthew Warner, CTO and Co-Founder at Blumira, an Ann Arbor, Mich.-based provider of automated threat detection and response technology:
“The complexity of patching unknown log4j systems continues to add more difficulties for organizations. A purchased appliance may have a vulnerable version of Log4j without any knowledge of the organization. There continues to be exploitation of Log4j across internet-exposed VMWare Horizon servers that have not been patched, even within hours of CISA notifications of vulnerable hosts. In the grand scheme of cybersecurity, however, Log4j is not unprecedented; even three years after exposure there continues to be exposed RDP that is vulnerable to BlueKeep.
Vulnerabilities that live within infrastructure have longevity and stickiness due to the complexity of networks and IT turnover that results in undocumented devices. It will take many years for the industry to remove and update all legacy Log4j solutions and support to identify impacted solutions, and getting this information to organizations will be necessary for privacy/public partnership success.”
++
Terry Olaes, Director of Sales Engineering, Skybox, Security Posture Management company:
“Cybercriminals were swift to weaponize this critical remote code execution vulnerability when it was disclosed back in December, with far-reaching consequences. A CISA official estimated that hundreds of millions of devices are likely affected due to its widespread use. Skybox Research Lab, has been tracking Log4j since the exploit was publicly released in December 2021, and while the findings of the report are unfortunate, they are not surprising given Log4j’s widespread use across market-leading vendors. Log4j threats expose victims that lack mature cybersecurity risk models to attacks that have remote code execution (RCE) vectors like ransomware, and there will likely be many attacks associated with this vulnerability for years to come.
In the years ahead, threat actors will innovate new and creative ways to exploit common tools like Log4j. As a result, preventing breaches requires immediately minimizing your exposure through smart and targeted mitigation. For a widespread vulnerability like Log4j, patching all of the instances isn’t practical. Not only is it time-consuming, it’s also hugely costly as well. History shows that the ‘patch everything’ strategy is a monumental waste of effort due to the fact that typically it’s a very small subset of devices that are actually exposed to the attack itself. That is why it is crucial to take a more proactive approach to vulnerability management by learning to identify and prioritize exposed vulnerabilities across the entire threat landscape.
Organizations should ensure they have solutions capable of quantifying the business impact of cyber risks into economic impact. This will help them identify and prioritize the most critical threats based on the size of the financial impact, among other risk analyses such as exposure-based risk scores. Organizations should also emphasize exposure analysis, which identifies exploitable vulnerabilities and correlates data with an organization’s network configurations and security controls to determine if a system is vulnerable to a cyberattack. This strategy includes path analysis, which determines which attack vectors or network paths could be used to access vulnerable systems. They must also enhance the maturity of their vulnerability management programs to ensure they can quickly discover whether or not a vulnerability impacts them and how urgent it is to remediate.”
++
Brad Crompton, Intelligence Director at Intel 471:
“It is highly recommended users upgrade Log4j to the latest version. Where upgrading Log4j is not feasible instantaneously, exploitation attempts still can be averted by removing the JndiLookup class from the classpath. Intel 471 has not seen a sustained effort to leverage the vulnerability in attacks, but that does not mean threat actors won’t use the vulnerability in the future.”
##





