Worldwide IT Outage – What We Know So Far
A major IT outage caused major disruptions at airports, GP surgeries, and retail stores. Computer systems across the world crashed, experiencing the “Blue...
Read Full ArticleCritical vulnerabilities in open-source software pose potential risks for a wide range of businesses, governments and individuals.
Log4shell, the vulnerability within the widely-used logging tool Log4j, means that anyone who uses Log4j to catalogue activity in their software applications or online services is at risk.
In the case of real estate software and PropTech, this could mean sensitive data such as floorplans, occupancy or budget information open to nefarious sources.
Apple, Minecraft, IBM, Cisco, Google and Amazon all use Log4j, and the issue was initially disclosed on December 9, 2021.
The National Cyber Security Centre is calling Log4shell “potentially the most severe computer vulnerability in years.” They also state that, If left unfixed, attackers can break into systems, steal passwords and logins, extract data, and infect networks with malicious software.
Esri UK, who provides indoor mapping software for facilities managers, has informed their customers that they are actively investigating the impact of the Log4j 2 library critical vulnerabilities, as some Esri products contain this common logging tool.
Esri’s GIS mapping tool is used by organisations such as Oxford University, Westminster City Council and The British Red Cross.
Oracle, AWS and Cloudflare have all issued advice to their customers.
The NCSC has issued the following guidance for board members of large businesses: https://www.ncsc.gov.uk/blog-post/log4j-vulnerability-what-should-boards-be-asking
The Cybersecurity and Infrastructure Security Agency is also keeping developers informed on the issue: https://www.cisa.gov/uscert/apache-log4j-vulnerability-guidance
Picture: a photograph showing a laptop's keyboard.
Article written by Ella Tansley | Published 17 December 2021
A major IT outage caused major disruptions at airports, GP surgeries, and retail stores. Computer systems across the world crashed, experiencing the “Blue...
Read Full ArticleA Freedom of Information request has revealed that there was a resurgence in ransomware-related incidents following a quieter 2022. In the first six months...
Read Full ArticleESG Platform Deepki has acquired French SaaS business Nooco, a company created by VINCI Energies. Nooco measures and optimises the carbon footprint of building...
Read Full ArticleFrancis West is CEO of Security Everywhere, a company which helps SMEs to secure their money, data and reputation with managed security services. Francis is a trusted...
Read Full ArticleThe UK’s IT security watchdog has fined Interserve for breaching data protection law and failing to prevent a cyber attack. The Information Commissioner’s...
Read Full ArticleData-driven facilities management is now the expected norm, but security concerns about IoT systems still remain amongst FMs and tenants. The Internet of Things (IoT)...
Read Full ArticleIt has been confirmed that a ransomware attack is causing a major outage for NHS IT systems. Services affected include software used by NHS 111 and other patient notes...
Read Full ArticleThe operational technology that powers connected devices across building systems is providing more entry points for cyber criminals to exploit, says research and advisory...
Read Full ArticleThe Building Engineering Services Association (BESA) says it has carried out a thorough review of the security procedures behind its online training schemes...
Read Full ArticleFacilio has announced the launch of Connected CMMS, reportedly the only software platform to consolidate all property maintenance, client engagement, vendor management,...
Read Full Article