We use cookies to give you the best experience and to help improve our website

Find out more about how we use cookies

Choose whether to use cookies:

No thanks Yes, I accept

Skip to main content

Jisc

You are in:

  • News
  • Colleges and universities must urgently patch code flaw to avoid ‘severe’ risk of cyber attack

Utilities:

  • Search the Jisc website
    Clear search results

Search the Jisc website
Clear search results

Navigation:

News

Colleges and universities must urgently patch code flaw to avoid ‘severe’ risk of cyber attack

15 December 2021

Jisc is urging colleges and universities to quickly fix an “easily-exploited” flaw in widely used computer code that presents a “severe” risk of cyber attack.

The vulnerability in Log4J, a very widely used logging program for Java software, affects a large number of applications and software commonly used in the education and research sector.

Jisc has issued technical advice to members detailing how they must patch systems and warns that the situation will need monitoring for the foreseeable future.

In the meantime, one of the most effective means by which colleges and universities can protect their cyber space against the Log4J threat is to join the Janet Network resolver service.

Included as part of members’ subscriptions to Jisc, the Janet Network resolver service mitigates the risk of user’s web requests being directed to compromised or dangerous websites. The service has just been updated to block websites specifically relating to the Log4J vulnerability.

Jisc’s director of security, Henry Hughes, says:

“Criminals are always quick to take advantage of vulnerabilities and this one appears to be particularly easy to exploit.

“Suspicious activity connected to Log4J has already been reported in the education sector, so there's no time to lose.

“Organisations that don’t implement a programme of patching immediately will be at severe risk of cyber attacks.

“While software providers are issuing fixes, it’s difficult to get a clear and full picture of where the weakness are, so it’s likely that multiple patches will need applying over the coming months.

“We will continue to monitor the situation and will update and advise IT and security teams when necessary.

“We also continue to review our own systems, to ensure that they are not vulnerable, patching and updating the small number of systems that have found to have been affected.”

A small number of Jisc services were found to use Log4J and taken offline as a precautionary measure.

The Heidi Plus service remains temporarily suspended, however the dashboards for the building digital capabilities service, the Journal Usage Statistics Portal (JUSP) and IRUS and are now back online.

Find out more

  • Member organisations that need help and advice should contact Jisc’s computer security incident response team (CSIRT)
  • The National Cyber Security Centre has also issued advice
  • Members that wish to start using Janet Network resolver service can do so through the cyber security portal, or contact their relationship manager
  • Read the Log4j vulnerability and supply chain security blog post by Jon Hunt on Jisc involve

Updated 17 December 2021

Article updated to include information about the Janet Network resolver service and provide an update on a small number of Jisc services affected.

Updated 22 December 2021

Article updated to detail Jisc services that are back online.

Updated 31 January 2022

Heidi Plus is back online.

Share this

Most read
  • Steering cyber-skilled students away from crime and into a lucrative career
  • Jisc creates framework to guide higher education to digital transformation
  • Jisc and HESA confirm merger
  • Cost of living crisis: higher education and research sectors call on suppliers to reduce prices
  • What drives communities in education and research?
Related
  • ‘Check cyber defenses in view of increased threat from Russia’
  • Cyber security in FE: what are the threats and how do we deal with them?
  • New guidance will help colleges and universities assess the strength of their cyber security
  • Lock down and lock up: how to keep systems and data safe
  • Understanding the threat of esports to the network

Share this

You may also like…

Blog

Ransomware: are your systems well protected?

Jisc and other expert organisations have been issuing advice to help protect the education and research sector against a spate of ...
Blog

Ransomware: what’s the impact and how can we stop it?

Ransomware has become a huge global problem during the pandemic, including for the education sector.

You are in:

  • News
  • Colleges and universities must urgently patch code flaw to avoid ‘severe’ risk of cyber attack

Areas

  • Connectivity
  • Cyber security
  • Cloud
  • Data analytics
  • Libraries, learning resources and research
  • Student experience
  • Trust and identity
  • Advice and guidance

Explore

  • Guides
  • Training
  • Consultancy
  • Events
  • Innovation

Useful

  • About
  • Membership
  • Get involved
  • News
  • Jobs

Get in touch

  • Contact us
  • Sign up to our newsletter
  • Twitter
  • Facebook
  • LinkedIn
  • YouTube
  • Cookies
  • Privacy
  • Modern slavery
  • Carbon reduction plan
  • Accessibility