Cybersecurity

Alibaba Admits It Was Slow to Report Software Bug After Beijing Rebuke

  • AliCloud engineer notified Apache community of Log4j flaw
  • Regulator reportedly suspended cooperation with AliCloud
WATCH: Alibaba says it slow to report a major bug in widely used software because it was unaware of its severity. Jamie Tarabay reports.Source: Bloomberg
Lock
This article is for subscribers only.

Alibaba Group Holding Ltd. conceded it was slow to report a major vulnerability in widely used software because it was unaware of its severity, a day after China’s tech industry overseer suspended cooperation on cybersecurity with the online retail giant.

Alibaba’s admission on Thursday clouded its role in uncovering potentially one of the more serious software vulnerabilities of recent years. Alibaba Cloud researcher Chen Zhaojun discovered the flaw in the Log4j open-source software and in November emailed it to members of the Apache Software Foundation community, which helps maintain the tool.