Black Friday is Now! Don’t miss out on up to 60% OFF InvestingProCLAIM SALE

Canadian agency breached as hackers exploit new software bug

Published 03/13/2017, 04:53 PM
© Reuters.  Canadian agency breached as hackers exploit new software bug
APA
-

(Reuters) - Canada's government said on Monday that it shut down its website for filing federal taxes after hackers broke into a web server at the nation's statistics bureau last week by exploiting a newly disclosed software bug.

Statistics Canada, which said it stopped the intrusion before hackers stole any data, is the first high-profile organization to say it was hacked due to a new security bug in software known as Apache (NYSE:APA) Struts 2. The software is commonly used in websites of governments, banks, retailers and other large organizations.

Other victims have not yet come forth, although security firms said they expect more attacks to surface after details on the easy-to-exploit vulnerability were posted on security forums and hacking websites last week.

Technicians at big corporations and government agencies around the world spent the weekend combing their networks for vulnerable software and patching it, said Chris Camacho, chief strategy officer with cyber intelligence firm Flashpoint.

He said the vulnerability was actively being exploited by hackers, but declined to provide details, citing client confidentiality.

The impact of the vulnerability surfaced in Canada late Friday when the federal government shut down the tax agency's website to prevent attacks after it identified that it was running vulnerable software.

“We went after this one specifically because we recognized there was a specific and credible threat to certain government IT systems,” John Glowacki, a government security official, said at a press conference.

Glowacki said he that he understood some other countries "are actually having greater problems with this specific vulnerability,” but declined to identify the nations or discuss the problems.

The vulnerability surfaced last week when the Apache Software Foundation released an update to fix the bug, saying it could enable hackers to gain remote control of a web server.

That could allow them to steal data, secretly gain access to a victim's network or shut down a website, said Chris Wysopal, chief technology officer with security software maker Veracode.

“This vulnerability is super easy to exploit," Wysopal said. "You just point it to the web server and put in the command that you want to run."

Latest comments

Risk Disclosure: Trading in financial instruments and/or cryptocurrencies involves high risks including the risk of losing some, or all, of your investment amount, and may not be suitable for all investors. Prices of cryptocurrencies are extremely volatile and may be affected by external factors such as financial, regulatory or political events. Trading on margin increases the financial risks.
Before deciding to trade in financial instrument or cryptocurrencies you should be fully informed of the risks and costs associated with trading the financial markets, carefully consider your investment objectives, level of experience, and risk appetite, and seek professional advice where needed.
Fusion Media would like to remind you that the data contained in this website is not necessarily real-time nor accurate. The data and prices on the website are not necessarily provided by any market or exchange, but may be provided by market makers, and so prices may not be accurate and may differ from the actual price at any given market, meaning prices are indicative and not appropriate for trading purposes. Fusion Media and any provider of the data contained in this website will not accept liability for any loss or damage as a result of your trading, or your reliance on the information contained within this website.
It is prohibited to use, store, reproduce, display, modify, transmit or distribute the data contained in this website without the explicit prior written permission of Fusion Media and/or the data provider. All intellectual property rights are reserved by the providers and/or the exchange providing the data contained in this website.
Fusion Media may be compensated by the advertisers that appear on the website, based on your interaction with the advertisements or advertisers.
© 2007-2024 - Fusion Media Limited. All Rights Reserved.