Tech Companies Racing to Fix At-Risk Internet Software

2021-12-17

00:00 / 00:00
复读宝 RABC v8.0beta 复读机按钮使用说明
播放/暂停
停止
播放时:倒退3秒/复读时:回退AB段
播放时:快进3秒/复读时:前进AB段
拖动:改变速度/点击:恢复正常速度1.0
拖动改变复读暂停时间
点击:复读最近5秒/拖动:改变复读次数
设置A点
设置B点
取消复读并清除AB点
播放一行
停止播放
后退一行
前进一行
复读一行
复读多行
变速复读一行
变速复读多行
LRC
TXT
大字
小字
滚动
全页
1
  • Computer security experts around the world are trying to fix one of the worst software weaknesses found in years.
  • 2
  • The vulnerability is in an open-source program widely used by government and industry.
  • 3
  • It has become a major threat to organizations around the world.
  • 4
  • "The internet's on fire right now," said Adam Meyers.
  • 5
  • He is the vice president at the cybersecurity company Crowdstrike.
  • 6
  • The problem is found in an open-source Apache utility called log4j.
  • 7
  • It is used to run websites and other web services.
  • 8
  • The vulnerability is known as "Log4Shell."
  • 9
  • The software problem's severity was rated 10 on a scale from one to 10 by the Apache Software Foundation,
  • 10
  • which oversees development of the software.
  • 11
  • The vulnerability was reported on November 24 by the Chinese technology company Alibaba.
  • 12
  • It took two weeks to develop a patch.
  • 13
  • Last week, Meyers said that within 12 hours of discovering the problem it had been "fully weaponized."
  • 14
  • He said criminals have already developed and distributed tools to exploit it.
  • 15
  • Experts say the bug, another word for a software problem, may be the worst computer weakness discovered in years.
  • 16
  • The Apache software is used in almost all cloud computing servers, across industry and government.
  • 17
  • Unless it is fixed, the bug gives criminals the ability to easily access internal networks.
  • 18
  • There, they could steal important data, put malware in place, and do much more damage.
  • 19
  • Joe Sullivan is the head of security for Cloudflare, a company that protects websites from security threats.
  • 20
  • "I'd be hard-pressed to think of a company that's not at risk," he said.
  • 21
  • Millions of servers have the software, and experts said the impact would not be known for several days.
  • 22
  • Amit Yoran is the head the cybersecurity company Tenable.
  • 23
  • He called it "the single biggest, most critical vulnerability of the last decade,"
  • 24
  • and maybe the history of modern computing.
  • 25
  • Experts said the vulnerability makes it easy for an attacker to access a web server, and makes it very dangerous.
  • 26
  • There is no password required to access a server.
  • 27
  • Patching the bug could be a difficult job.
  • 28
  • Most organizations and cloud providers like Amazon should be able to update their web servers easily.
  • 29
  • But the same Apache software is also used by many third-party programs, which often can only be updated by their owners.
  • 30
  • Yoran, of Tenable, said organizations need to act as if they have been affected and fix the problem.
  • 31
  • The first clear signs of the bug's exploitation appeared in Minecraft, an online game popular with children.
  • 32
  • Attackers were able to take over one of the world-building game's servers before Microsoft,
  • 33
  • which owns Minecraft, patched the problem.
  • 34
  • Microsoft said it had completed a software update for Minecraft users.
  • 35
  • "Customers who apply the fix are protected," the company said.
  • 36
  • Researchers say the vulnerability could also be exploited in servers run by companies like Apple, Amazon, Twitter and Cloudflare.
  • 37
  • I'm Dan Novak.
  • 1
  • Computer security experts around the world are trying to fix one of the worst software weaknesses found in years.
  • 2
  • The vulnerability is in an open-source program widely used by government and industry. It has become a major threat to organizations around the world.
  • 3
  • "The internet's on fire right now," said Adam Meyers. He is the vice president at the cybersecurity company Crowdstrike.
  • 4
  • The problem is found in an open-source Apache utility called log4j. It is used to run websites and other web services. The vulnerability is known as "Log4Shell."
  • 5
  • The software problem's severity was rated 10 on a scale from one to 10 by the Apache Software Foundation, which oversees development of the software.
  • 6
  • The vulnerability was reported on November 24 by the Chinese technology company Alibaba. It took two weeks to develop a patch.
  • 7
  • Last week, Meyers said that within 12 hours of discovering the problem it had been "fully weaponized." He said criminals have already developed and distributed tools to exploit it.
  • 8
  • Experts say the bug, another word for a software problem, may be the worst computer weakness discovered in years. The Apache software is used in almost all cloud computing servers, across industry and government.
  • 9
  • Unless it is fixed, the bug gives criminals the ability to easily access internal networks. There, they could steal important data, put malware in place, and do much more damage.
  • 10
  • Joe Sullivan is the head of security for Cloudflare, a company that protects websites from security threats.
  • 11
  • "I'd be hard-pressed to think of a company that's not at risk," he said. Millions of servers have the software, and experts said the impact would not be known for several days.
  • 12
  • Amit Yoran is the head the cybersecurity company Tenable. He called it "the single biggest, most critical vulnerability of the last decade," and maybe the history of modern computing.
  • 13
  • Experts said the vulnerability makes it easy for an attacker to access a web server, and makes it very dangerous. There is no password required to access a server.
  • 14
  • Patching the bug could be a difficult job. Most organizations and cloud providers like Amazon should be able to update their web servers easily. But the same Apache software is also used by many third-party programs, which often can only be updated by their owners.
  • 15
  • Yoran, of Tenable, said organizations need to act as if they have been affected and fix the problem.
  • 16
  • The first clear signs of the bug's exploitation appeared in Minecraft, an online game popular with children. Attackers were able to take over one of the world-building game's servers before Microsoft, which owns Minecraft, patched the problem.
  • 17
  • Microsoft said it had completed a software update for Minecraft users. "Customers who apply the fix are protected," the company said.
  • 18
  • Researchers say the vulnerability could also be exploited in servers run by companies like Apple, Amazon, Twitter and Cloudflare.
  • 19
  • I'm Dan Novak.
  • 20
  • The Associated Press reported this story. Dan Novak adapted for VOA Learning English. Susan Shand was the editor.
  • 21
  • _______________________________________
  • 22
  • Words in This Story
  • 23
  • vulnerability - n. something open to attack, harm, or damage​
  • 24
  • utility - n. a computer program that does a specific task​
  • 25
  • patch - n. a program that corrects or updates an existing program​
  • 26
  • exploit - v. to use in a way that helps you unfairly​
  • 27
  • malware - n. a computer program that is designed to damage or break into a computer​