London Daily

Focus on the big picture.
Tuesday, Apr 07, 2026

Log4j software flaw 'endemic,' new cyber safety panel says

Log4j software flaw 'endemic,' new cyber safety panel says

A computer vulnerability discovered last year in a ubiquitous piece of software is an “endemic” problem that will pose security risks for potentially a decade or more, according to a new cybersecurity panel created by President Joe Biden.
The Cyber Safety Review Board said in a report Thursday that while there hasn’t been sign of any major cyberattack due to the Log4j flaw, it will still “be exploited for years to come.”

“Log4j is one of the most serious software vulnerabilities in history,” the board’s chairman, Department of Homeland Security Under Secretary Rob Silvers, told reporters Wednesday.

The Log4j flaw, made public late last year, lets internet-based attackers easily seize control of everything from industrial control systems to web servers and consumer electronics. The first obvious signs of the flaw’s exploitation appeared in Minecraft, a hugely popular online game owned by Microsoft.

The flaw’s discovery prompted urgent warnings by government officials and massive efforts by cybersecurity professionals to patch vulnerable systems.

The board said Thursday that “somewhat surprisingly” the exploitation of the Log4j bug had occurred at lower levels than experts predicted. The board also said that it was unaware of any “significant” Log4j attacks on critical infrastructure systems but noted that some cyberattacks go unreported.

The board said future attacks are likely in large part because Log4j is routinely embedded with other software and can be hard for organizations to find running in their systems.

“This event is not over,” Silvers said.

Log4j, written in the Java programming language, logs user activity on computers. Developed and maintained by a handful of volunteers under the auspices of the open-source Apache Software Foundation, it is extremely popular with commercial software developers.

A security researcher at the Chinese tech giant Alibaba notified the foundation on Nov. 24. It took two weeks to develop and release a fix. Chinese media reported that the government punished Alibaba for not reporting the flaw earlier to state officials.

The board said Thursday it found “troubling elements” with the Chinese government’s policy toward vulnerability disclosures, saying it could give Chinese state hackers an early look at computer flaws they could use for nefarious means like stealing trade secrets or spying on dissidents. The Chinese government has long denied wrongdoing in cyberspace and told the board that it encourages improved information sharing on software vulnerabilities.

The board offered a number of recommendations on mitigating the fallout of the Log4j flaw as well as improving cybersecurity generally. That includes the suggestion that universities and community colleges make cybersecurity training a required part of computer science degree and certification programs.

The Cyber Safety Review Board is modeled after the National Transportation Safety Board, which reviews plane crashes and other major accidents, and was mandated by an executive order Biden signed last May. The 15-member board is made up of FBI, National Security Agency and other government officials as well as people from the private sector. Some supporters of the new board criticized DHS for taking so long to get it up and running.

Biden’s executive order directed the board to conduct its first review on the massive Russian cyber espionage campaign known as SolarWinds. Russian hackers were able to breach several federal agencies, including accounts belonging to top cybersecurity officials at DHS, though the full fallout from that campaign is still unclear.

Silvers said DHS and the White House agreed that reviewing the Log4j flaw was a better use of the new board’s expertise and time.
Newsletter

Related Articles

0:00
0:00
Close
King Charles Faces Criticism From Some UK Christians Over Absence of Easter Message
Former UK Defence Secretary Raises Concerns Over Ability to Counter Iran Missile Threat
UK Signals Non-Involvement in Iran Conflict as Trump Reasserts Firm Deterrence Stance
US and UK Strengthen Medical Device Cooperation Following Tariff Removal
Trump Backs Steve Hilton for California Governor, Highlighting Reform Agenda
UK Seeks Closer Ties With Anthropic as AI Policy Divergence Emerges Across Atlantic
Experts Warn of Evolving Extremism After Teens Arrested in UK Ambulance Arson Case
UK Convenes Talks to Safeguard Shipping Through Strait of Hormuz After Conflict Escalation
Trump Highlights Strong Leadership in Critique of UK Stance on Iran
UK Authorities Review Kanye West’s Entry Status Following Festival Backlash
UK Considers Deploying Aircraft Carrier for US Independence Day Celebrations Amid Renewed Transatlantic Focus
United Kingdom Moves to Attract AI Firm Anthropic Amid Tensions with US Defense Officials
RAF Intercepts Iranian Drones in Middle East to Defend Allied Security Interests
Labour Signals Shift on Foie Gras and Fur Restrictions to Advance EU Trade Talks
Seven Arrested Near RAF Base as UK Authorities Respond to Protest Activity
Economic Pressures Mount as Analysts Warn UK Growth Is Being Constrained by Policy Burdens
UK Green Party’s Push for Church-State Separation Sparks Debate Over National Identity
Strategic Island Emerges as Growing Challenge for United States and United Kingdom Defense Planning
Pepsi Pulls Sponsorship from UK Festival Following Backlash Linked to Kanye West
Signs Emerge of Declining Enthusiasm for Social Media in the United Kingdom
Security Alert Raised Ahead of Meghan Markle’s Planned Visit to Australia
UK Food Halls Defy Hospitality Slowdown, Emerging as Bright Spot in Challenging Market
UK Sets Firm Conditions for Military Action, Insisting on Legal Mandate and Clear Strategy
UK Medicines Regulator Launches Probe into Peptide Clinics Over Health Claims
New North Sea Drilling Unlikely to Significantly Cut UK Gas Imports, Analysis Finds
Woman Linked to UK’s First All-Female Terror Plot Faces Deportation
Downed US Aircraft Over Iran Linked to Operations from UK Airfield
Two Men and Teen Detained in UK Following Attack on Jewish Charity Ambulance
UK Police Launch Inquiry After Firearms Left Unattended Outside Mayor’s Residence
Giuffre Family Calls on King Charles to Meet Epstein Survivors During US Visit
Amber Wind Warning Issued as Storm Dave Approaches Parts of the United Kingdom
Prince Harry and Meghan’s Australia Visit Set to Draw Heightened Global Attention
UK Considers Entry Fees for Overseas Visitors at Major Museums Ahead of 2026 Travel Season
UK Prime Minister and Kuwait Crown Prince Coordinate Security Response After Regional Escalation
Calls Grow to Expand Fully Paid Maternity Leave for UK Teachers Amid Workforce Pressures
UK Secures Tariff-Free Access to US Market in Landmark Pharmaceuticals Agreement
Trump Projects Strength in Critique of UK Leadership and Naval Readiness
UK FinTech Setback as VibePay and Smartlayer Cease Operations Amid Funding Pressures
UK Leads Global Coalition of Over Forty Nations to Address Strait of Hormuz Crisis
UK Firms Urged to Accelerate Preparation as New Sustainability Reporting Rules Take Shape
UK Moves Rapid Sentry Air Defence System to Kuwait After Drone Strike Escalation
Transatlantic Relations Tested as UK Seeks Balance While Trump Reshapes Strategic Approach
Trump’s Strategic Pressure on UK Seen as Push for Stronger Alignment and Fairer Terms
UK Focuses on Trade Finance to Secure Critical Materials for Defence and Energy Sectors
Majority of UK Businesses Hit by Middle East Conflict While Confidence Holds Firm
UK Royal Navy Faces Renewed Scrutiny as Debate Intensifies Over Capability and Readiness
Reform UK Faces Mounting Distractions as Policy Agenda Struggles to Gain Traction
Investigation Launched Into Northern Cyprus IVF Clinics After UK Families Receive Incorrect Sperm
International Meeting Issues Unified Call to Safeguard Navigation Through Strait of Hormuz
Potential Strait of Hormuz Closure Raises Concerns Over UK Food and Medicine Supply Chains
×