Saudi Press

Saudi Arabia and the world
Wednesday, Mar 11, 2026

Log4j software flaw 'endemic,' new cyber safety panel says

Log4j software flaw 'endemic,' new cyber safety panel says

A computer vulnerability discovered last year in a ubiquitous piece of software is an “endemic” problem that will pose security risks for potentially a decade or more, according to a new cybersecurity panel created by President Joe Biden.
The Cyber Safety Review Board said in a report Thursday that while there hasn’t been sign of any major cyberattack due to the Log4j flaw, it will still “be exploited for years to come.”

“Log4j is one of the most serious software vulnerabilities in history,” the board’s chairman, Department of Homeland Security Under Secretary Rob Silvers, told reporters Wednesday.

The Log4j flaw, made public late last year, lets internet-based attackers easily seize control of everything from industrial control systems to web servers and consumer electronics. The first obvious signs of the flaw’s exploitation appeared in Minecraft, a hugely popular online game owned by Microsoft.

The flaw’s discovery prompted urgent warnings by government officials and massive efforts by cybersecurity professionals to patch vulnerable systems.

The board said Thursday that “somewhat surprisingly” the exploitation of the Log4j bug had occurred at lower levels than experts predicted. The board also said that it was unaware of any “significant” Log4j attacks on critical infrastructure systems but noted that some cyberattacks go unreported.

The board said future attacks are likely in large part because Log4j is routinely embedded with other software and can be hard for organizations to find running in their systems.

“This event is not over,” Silvers said.

Log4j, written in the Java programming language, logs user activity on computers. Developed and maintained by a handful of volunteers under the auspices of the open-source Apache Software Foundation, it is extremely popular with commercial software developers.

A security researcher at the Chinese tech giant Alibaba notified the foundation on Nov. 24. It took two weeks to develop and release a fix. Chinese media reported that the government punished Alibaba for not reporting the flaw earlier to state officials.

The board said Thursday it found “troubling elements” with the Chinese government’s policy toward vulnerability disclosures, saying it could give Chinese state hackers an early look at computer flaws they could use for nefarious means like stealing trade secrets or spying on dissidents. The Chinese government has long denied wrongdoing in cyberspace and told the board that it encourages improved information sharing on software vulnerabilities.

The board offered a number of recommendations on mitigating the fallout of the Log4j flaw as well as improving cybersecurity generally. That includes the suggestion that universities and community colleges make cybersecurity training a required part of computer science degree and certification programs.

The Cyber Safety Review Board is modeled after the National Transportation Safety Board, which reviews plane crashes and other major accidents, and was mandated by an executive order Biden signed last May. The 15-member board is made up of FBI, National Security Agency and other government officials as well as people from the private sector. Some supporters of the new board criticized DHS for taking so long to get it up and running.

Biden’s executive order directed the board to conduct its first review on the massive Russian cyber espionage campaign known as SolarWinds. Russian hackers were able to breach several federal agencies, including accounts belonging to top cybersecurity officials at DHS, though the full fallout from that campaign is still unclear.

Silvers said DHS and the White House agreed that reviewing the Log4j flaw was a better use of the new board’s expertise and time.
Newsletter

Related Articles

Saudi Press
0:00
0:00
Close
Aramco Warns Global Oil Market Faces ‘Catastrophic’ Shock if Strait of Hormuz Remains Closed
Iran Launches Drone and Missile Attacks Across Gulf Targets Including Saudi Arabia, Kuwait and Bahrain
Saudi Arabia Elevates Fahad Al-Saif as Vision 2030 Enters Crucial Implementation Phase
Saudi Aramco Expands Routes to Move Oil Without Reliance on the Strait of Hormuz
Saudi Arabia and Pakistan Reaffirm Mutual Defense Cooperation Following Iran Strike
Saudi Arabia Plans Major Ukrainian Arms Deal to Counter Iranian Drone Threat
Pentagon Signals Intensification of U.S. Air Campaign as Iran Conflict Escalates
U.S. Senator Lindsey Graham Raises Prospect of Mutual Defense Pact With Saudi Arabia Amid Iran Conflict
Why Saudi Arabia Is Unlikely to Have Wanted U.S. Airstrikes on Iran
Saudi Arabia’s Red Sea Oil Exports Set to Reach Record High as Gulf Routes Face Disruption
Saudi Arabia Pushes East–West Oil Pipeline Toward Full Capacity as Hormuz Crisis Disrupts Global Energy Flows
Oil Prices Retreat From Peak as G7 Weighs Release of Strategic Reserves
Pentagon Identifies U.S. Soldier Who Died After Iranian Strike on Saudi Air Base
Why Saudi Arabia’s $50 Billion ‘The Line’ Megacity Slowed — and How Artificial Intelligence Is Reshaping the Plan
United States Withdraws Diplomatic Staff from Saudi Arabia and Southeast Turkey as Regional Conflict Escalates
Fanatics Moves Tom Brady Flag Football Showcase from Saudi Arabia to Los Angeles Amid Regional War
Saudi Arabia Seeks Strategic Support from Pakistan After Iranian Missile and Drone Attacks
Saudi Arabia Begins Oil Output Cuts as Hormuz Disruption Forces Storage Limits
Saudi Arabia Travel Advisory Tightened as Middle East War Triggers Regional Security Alerts
Saudi Arabia Warns Iran It Will Be ‘Biggest Loser’ as Drone Strikes Spread Across Gulf States
Lindsey Graham Urges Saudi Arabia to Join US Effort Against Iran as War Expands
Saudi Crown Prince Holds Strategic Calls With Spanish and Ukrainian Leaders Amid Regional Tensions
Kuwait’s Jazeera Airways Shifts Operations to Saudi Arabia Amid Regional Airspace Disruptions
Saudi Arabian Grand Prix: Why Jeddah’s Night Race Has Become One of Formula One’s Most Distinctive Events
F1 Leadership Addresses Bahrain and Saudi Arabia Races as Middle East Conflict Raises Safety Concerns
Zelenskyy Offers Saudi Crown Prince Assistance to Counter Iranian Drone Threat
Seventh U.S. Service Member Dies from Injuries After Iranian Strike in Saudi Arabia
Civilian Infrastructure Increasingly Hit as Iran Conflict Expands and Saudi Arabia Reports First Fatalities
Saudi Arabia Warns Iran to Halt Attacks and Signals Potential Retaliation
US Embassy in Riyadh Issues Security Alert Urging Americans to Shelter in Place Amid Regional Attacks
Projectile Strike on Saudi Residential Building Kills Two as Regional Conflict Expands
Saudi Arabia Warns Iran While Expanding Diplomatic Efforts to Contain Widening Middle East War
Iran’s President Rejects U.S. Surrender Demand as Drone and Missile Strikes Hit Gulf States
Saudi Arabia Intercepts Drone Swarm Targeting Strategic Shaybah Oil Field
Pakistan Faces Growing Pressure to Balance Ties With Iran and Saudi Arabia as Regional War Intensifies
Middle East Conflict Tests Mohammed bin Salman’s Vision to Transform Saudi Arabia Into a Global Hub
Proposed U.S.–Saudi Nuclear Deal Could Ease Traditional Nonproliferation Requirements
Iran Claims Strike on U.S.-Linked Oil Tanker Near Saudi Waters as Maritime Tensions Escalate
Saudi Arabia Says Air Defences Destroyed 23 Drones and Three Missiles Amid Escalating Regional Conflict
Saudi Arabia Warns Iran Against ‘Miscalculation’ After Missile and Drone Attacks Across Gulf
Iranian Missiles Intercepted Across Gulf as Air Defences Activate in Saudi Arabia, Qatar, UAE and Bahrain
U.S. Justice Department Pursues Criminal Cases Against Cuban Officials in New Legal Push
Abrupt Cancellation of U.S. Army Exercise Sparks Speculation Over Possible Middle East Deployment
Saudi Arabia Led OPEC Output Surge Ahead of Iran Strikes, Survey Finds
Cristiano Ronaldo Travels to Spain for Hamstring Treatment After Injury in Saudi Pro League Match
Saudi Aramco Reroutes Oil to Red Sea as Strait of Hormuz Disruptions Hit Gulf Exports
Saudi Arabia Presses Ahead With Economic Diversification Despite Fiscal and External Deficits
Middle East Conflict Puts Bahrain and Saudi Arabian Formula One Races at Risk
Iran Targets Israeli Diplomatic Site in Bahrain and US Air Base in Qatar as Regional Conflict Expands
Saudi Arabia Intercepts Three Ballistic Missiles Targeting Prince Sultan Air Base
×