Tag Archives: oceania

What you need to know about security flaw impacting entire internet

A critical flaw in widely used software has cybersecurity experts raising alarms and big companies racing to fix the issue.

The vulnerability, which was reported late last week, is in Java-based software known as "Log4j" that large organisations use to configure their applications — and it poses potential risks for much of the internet.

Apple's cloud computing service, security firm Cloudflare, and one of the world's most popular video games, Minecraft, are among the many services that run Log4j, according to security researchers.

READ MORE: 'What we expected': More COVID-19 cases recorded in Queensland

Minecraft Dungeons Ultimate Edition includes all six DLCs from the game.

Jen Easterly, head of the Department of Homeland Security's Cybersecurity and Infrastructure Security Agency (CISA), called it "one of the most serious flaws" seen in her career.

In a statement on Saturday, Ms Easterly said "a growing set" of hackers are actively attempting to exploit the vulnerability.

As of Tuesday, more than 100 hacking attempts were occurring per minute, according to data this week from cybersecurity firm Check Point.

"It will take years to address this while attackers will be looking… on a daily basis [to exploit it]," David Kennedy, CEO of cybersecurity firm TrustedSec, said.

"This is a ticking time bomb for companies."

Here's what you should know.

What is Log4j and why does it matter?

Log4j is one of the most popular logging libraries used online, according to cybersecurity experts. Log4j gives software developers a way to build a record of activity to be used for a variety of purposes, such as troubleshooting, auditing and data tracking. Because it is both open-source and free, the library essentially touches every part of the internet.

"It's ubiquitous. Even if you're a developer who doesn't use Log4j directly, you might still be running the vulnerable code because one of the open-source libraries you use depends on Log4j," Chris Eng, chief research officer at cybersecurity firm Veracode, told CNN Business.

"This is the nature of software: It turtles all the way down."

Companies such as Apple, IBM, Oracle, Cisco, Google and Amazon all run the software. It could present in popular apps and websites, and hundreds of millions of devices around the world that access these services could be exposed to the vulnerability.

READ MORE: NSW hits COVID-19 record of 1742 new daily cases

A critical flaw which was reported late last week, is in Java-based software known as "Log4j" that large organisations use to configure their applications.

Are hackers exploiting it?

Attackers appear to have had more than a week's head start on exploiting the software flaw before it was publicly disclosed, according to cybersecurity firm Cloudflare. Now, with such a high number of hacking attempts happening each day, some worry the worst is to yet come.

"Sophisticated, more senior threat actors will figure out a way to really weaponise the vulnerability to get the biggest gain," Mark Ostrowski, Check Point's head of engineering, said on Tuesday.

Late Tuesday, Microsoft said in an update to a blog post that state-backed hackers from China, Iran, North Korea and Turkey have tried to exploit the Log4j flaw.

READ MORE: Why is petrol so expensive right now?

Why is this security flaw so bad?

Experts are especially concerned about the vulnerability because hackers can gain easy access to a company's computer server, giving them entry into other parts of a network. It's also very hard to find the vulnerability or see if a system has already been compromised, according to Mr Kennedy.

In addition, a second vulnerability in Log4j's system was found late Tuesday. Apache Software Foundation, a nonprofit that developed Log4j and other open-source software, has released a security fix for organisations to apply.

How are companies are trying to address the issue?

Last week, Minecraft published a blog post announcing a vulnerability was discovered in a version of its game — and quickly issued a fix. Other companies have taken similar steps.

IBM, Oracle, AWS and Cloudflare have all issued advisories to customers, with some pushing security updates or outlining their plans for possible patches.

"This is such a severe bug, but it's not like you can hit a button to patch it like a traditional major vulnerability. It's going to require a lot of time and effort," Mr Kennedy said.

For transparency and to help cut down on misinformation, CISA said it would set up a public website with updates on what software products were affected by the vulnerability and how hackers exploited them.

What can you do to protect yourself?

The pressure is largely on companies to act. For now, people should make sure to update devices, software and apps when companies give prompts in the coming days and weeks.

What's next?

The US government has issued a warning to impacted companies to be on high alert over the holidays for ransomware and cyberattacks.

There is concern that an increasing number of malicious actors will make use of the vulnerability in new ways, and while large technology companies may have the security teams in place to deal with these potential threats, many other organisations do not.

"What I'm most concerned about is the school districts, the hospitals, the places where there's a single IT person who does security who doesn't have time or the security budget or tooling," Katie Nickels, Director of Intelligence at cybersecurity firm Red Canary said.

"Those are the organisations I'm most worried about — small organisations with small security budgets."

READ MORE: Passengers from Newcastle frustrated by isolation 'confusion'

Man fined for allegedly breaching isolation, travelling to Newcastle

A man has been fined for allegedly breaching self-isolation orders and travelling to Newcastle, the epicentre of the NSW Omicron outbreak.

NSW Police said the 20-year-old was informed he was a close contact of a person with COVID-19.

He was told to stay at home but instead allegedly decided to go out, heading to Argyle House on Wharf Road. He later tested positive for the virus.

READ MORE: COVID-19 shuts down Australian Netflix production

https://twitter.com/cokeefe9/status/1471337819729588225

Police said inquiries are continuing.

Newcastle is now the centre of the state's Omicron outbreak, with a superspreader event at the Argyle House making the nightclub one of several transmission venues in the region.

More than 200 COVID-19 cases have already been linked to the nightclub.

Anyone who attended the nightclub between 9pm on Wednesday, December 8 to 3am on December 9 has been deemed a close contact, and must immediately get tested and isolate for seven days.

READ MORE: CCTV shows shooter open fire outside Sydney gym

A person who caught COVID-19 at a boat party on Sydney Harbour, ignored health advice to self-isolate and went to a Newcastle club, which is now linked to hundreds of cases.

The venue posted on social media yesterday to confirm it has closed until further notice as a result of the outbreak.

Almost half of today's record-breaking COVID-19 cases in NSW were reported in the Hunter New England region, which includes Newcastle.

Of the 1742 new cases today, 633 were in the Hunter New England Local Health District.

NSW Chief Health Officer Kerry Chant said yesterday most of the COVID-19 cases in Newcastle appear to be the Omicron variant.

Just 10 people are in hospital in the Hunter region, with three in intensive care.

READ MORE: Mystery lump from woman's bushwalk ends in her hospitalisation 

Testing sites in Newcastle have been swamped by huge queues after thousands of people in the region become casual contacts.

Some people were turned away and asked to come back later after some testing sites in the city reached capacity.

NASA craft 'touches' sun for the first time

A NASA spacecraft has officially "touched" the sun, plunging through the unexplored solar atmosphere known as the corona.

Scientists announced the news on Tuesday during a meeting of the American Geophysical Union.

The Parker Solar Probe actually flew through the corona in April during the spacecraft's eighth close approach to the sun.

READ MORE: 'Streaks' seen from space as sea ice breaks away from Antarctica

Scientists said it took a few months to get the data back and then several more months to confirm.

"Fascinatingly exciting," said project scientist Nour Raouafi of Johns Hopkins University.

Launched in 2018, Parker was 8 million miles (13 million kilometres) from the centre of the sun when it first crossed the jagged, uneven boundary between the solar atmosphere and outgoing solar wind.

The spacecraft dipped in and out of the corona at least three times, each a smooth transition, according to scientists.

"The first and most dramatic time we were below for about five hours … Now you might think five hours, that doesn't sound big," the University of Michigan's Justin Kasper told reporters.

But he noted that Parker was moving so fast it covered a vast distance during that time, tearing along at more than 62 miles (100 kilometres) per second.

The corona appeared dustier than expected, according to Raouafi.

READ MORE: China switches on nuclear-powered 'artificial sun'

Future coronal excursions will help scientist better understand the origin of the solar wind, he said, and how it is heated and accelerated out into space.

Because the sun lacks a solid surface, the corona is where the action is; exploring this magnetically intense region up close can help scientists better understand solar outbursts that can interfere with life here on Earth.

Preliminary data suggest Parker also dipped into the corona during its ninth close approach in August, but scientists said more analyses are needed.

It made its 10th close approach last month.

Parker will keep drawing ever closer to the sun and diving deeper into the corona until its grand finale orbit in 2025.

The latest findings were also published by the American Physical Society.

Seven people injured after car smashes through Melbourne shops

Seven people have been injured after a car smashed through a shopping centre in Melbourne's inner-north this morning.

Police said paramedics arrived at Northcote Plaza just before 11am and treated six pedestrians who were struck by the car.

The driver also suffered non-life-threatening injuries and is currently assisting police at the scene with their enquiries.

READ MORE: Kids seriously hurt when jumping castle lifted 10m off the ground

Photos taken by shoppers showed the shopfront of a shoe store destroyed, with displays in disarray and shattered glass sprawling onto the footpath.

Witness Nikos Kolaiti said he saw a car passing by outside before it smashed through Suzanne Grae.

"There were shoes, boxes, glass everywhere … the department is cleaning up," he told 9news.com.au

"People were panicked."

Police said the pedestrians managed to escape any life-threatening injuries from the accident.

"Police have partially evacuated some occupants of the building to allow for a structural assessment," police said in a statement.

"The incident is not being treated as deliberate."

A man and a woman were taken to the Royal Melbourne Hospital in a stable condition.

Another man was treated for upper body injuries before being taken to the Royal Melbourne Hospital in a serious but stable condition.

A woman was taken to St Vincent's Hospital for further observation.

Two further people were assessed at the scene, but they did not require hospitalisation.

Anyone with information is urged to contact Crime Stoppers on 1800 333 000.

'Perfect bottleneck' hampering Australia's vaccine booster rollout

Medics have warned of a "perfect bottleneck" hampering the supply and delivery of COVID-19 booster shots, after a "surge in demand" following the emergence of the Omicron variant and a shortening of the interval between vaccine doses.

Both GP and pharmacist representatives have told 9News of growing issues in the rollout, from running out of jabs to not having enough staff to give them out.

Dr Anita Munoz, the Victorian chair of the Royal Australian College of General Practitioners (RACGP), said its members are raising alarm bells, after the gap between the second dose and a booster was narrowed to five months, down from six.

LIVE UPDATES: Third nightspot alert in NSW

Australian Prime Minister Scott Morrison gets his COVID-19 booster  with Jane Malysiak in Blacktown, NSW.

She said there are problems with ordering, delivery and supply of enough shots, especially over the festive period.

"Yes, general practitioners can boost their patients and have the capacity… the issue that's concerning everyone is logistics," Dr Munoz said.

"All of a sudden the recommendation changes and is brought forward by an entire month and many practices have found themselves with insufficient supply.

"It's created a perfect bottleneck."

She said getting more doses is taking around a month even during more normal times, leaving GPs "frustrated."

READ MORE: What you need to know about the COVID-19 booster roll-out

Dr Munoz said members feel the initial issues with the nation's vaccination rollout are being repeated, and with kids as young as five due to start getting jabbed from January, they'll be under even more pressure.

They also fear people who've had initial doses at a state vaccination hub will turn to GPs for their booster.

"There's been a hope that mistakes we learned from during the year would not be repeated, this feels like a deja vu," she said.

READ MORE: Mystery lump from woman's bushwalk ends in her hospitalisation

Dr Munoz said they've even been contacted by members who feel they can't continue giving jabs, and have struggled to break even on costs.

While GPs are paid a set amount for each vaccine they deliver, the RACGP has continually said it's not enough.

READ MORE: COVID-19 shuts down Australian Netflix production

Similarly, pharmacy bosses say they they've seen an "unpredictable, exponential surge in demand" for boosters.

They say shortening the interval for boosters has seen 1.5 million Australians added to the 2.3 million people already eligible.

NSW Health Minister Brad Hazzard takes a selfie at Granville Centre vaccination clinic in Sydney.

A spokesman for the Pharmaceutical Society of Australia (PSA) said many are now fully booked until mid January, with some running out of jabs.

He says many have ordered emergency batches which should arrive before Christmas.

However, the issue could be getting staff to give them.

"It could be a case of no available stock or not enough workforce to administer the vaccine and open up bookings," he said.

Priceline, one of the bigger chains providing vaccinations, said stores are able to share supplies and people should check online where they are available.

Mel Gannon, Priceline's national pharmacy support manager, said "most stores" have Pfizer or Moderna, or both.

Meanwhile, doctors group the Australian Medical Association (AMA) has also blasted the booster rollout.

AMA President Dr Omar Khorshid said the AMA is "extremely concerned" about what it says is a "lack of support" for GPs and pharmacies giving jabs.

"By the end of this month, close to four million people will be eligible for the booster, however, in the last week Australia has only been able to administer just over 210,000 booster doses," he said.

READ MORE: CCTV shows shooter open fire outside Sydney gym

However, former Australian deputy chief medical officer Dr Nick Coatsworth blasted the AMA's comments.

https://twitter.com/nick_coatsworth/status/1471222195183501312?ref_src=twsrc%5Etfw

"Three weeks into the omicron variant, the peanut gallery decides we're behind again," he tweeted.

Prime Minister Scott Morrison said two million Aussies are eligible for COVID-19 boosters and the interval period is being reviewed "every week".

Mr Morrison said one million vaccines were "in the distribution system".

"We've got ample supply of vaccines, there's one million out there right now," he said.

"The interval of the duration… is set on the basis of the advice of ATAGI."

Mr Morrison said there were enough jabs should that be shortened further.

The Australian Government said almost one million people have had a booster.

"Supply is not an issue and there are sufficient doses to ensure all Australians who are eligible for a booster dose can receive it as soon as they are eligible," a spokesman said.

Figures show currently just over four million people are eligible.

In January, 2022, another 3.4m will be due a booster.

That rises to four in February and 4.5m in March.