Sunday, 24 November 2024
27.9 C
Singapore

FBI and CISA alert: Developers urged to tackle security vulnerabilities

FBI and CISA advise developers to address security flaws, enhancing cybersecurity.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) and the Federal Bureau of Investigation (FBI) have jointly issued a security alert, stressing the importance for software developers to address path traversal vulnerabilities before releasing their products.

Path traversal, also referred to as directory traversal or climbing, poses a significant risk in software development. This vulnerability allows threat actors to access sensitive files and directories, particularly in web or systems that construct file paths based on user input without proper validation.

Despite being well documented for over two decades, path traversal remains a persistent issue in software products. The agencies highlight that threat actors consistently exploit this vulnerability class, particularly targeting sectors like healthcare and public .

In the recent alert, CISA and the FBI emphasised the urgent need for action from software manufacturers. They expressed concern that these vulnerabilities continue to put customers at risk and have even impacted critical services such as hospital and school operations.

Currently, CISA has identified 55 path traversal vulnerabilities in the Known Exploited Vulnerabilities catalogue, indicating active exploitation in the wild. The agencies urge software manufacturer executives to mandate formal testing to assess their products’ susceptibility to these vulnerabilities, referring to OWASP testing guidance.

Additionally, they encourage all software users to inquire with their partners about formal directory traversal testing. Manufacturers are advised to promptly implement mitigations to eliminate this class of defect from their products, stressing the importance of integrating security measures from the initial stages of development.

Hot this week

New features in GPT-4o enhance creativity and efficiency

GPT-4o enhances creative writing with improved speed, capabilities, and cost-efficiency, offering tailored and natural responses for users.

Hong Kong’s PC Partner moves HQ to Singapore amidst shifting supply chains

PC Partner moves to Singapore and opens an Indonesian factory, diversifying amid US-China tensions and rising global demand.

Splunk launches advanced observability and security solutions for Microsoft Azure customers

Splunk and Microsoft launch native solutions on Azure, enhancing digital transformation with AI-powered observability and security tools.

Xiaomi’s Q3 2024 revenue exceeds expectations, driven by strong growth across key sectors

Xiaomi's Q3 2024 revenue reaches a record high, with growth across smartphones, IoT, and EVs, and continued investment in cutting-edge technology.

Google reportedly cancels Pixel Tablet 2 and exits tablet market again

Google cancels the Pixel Tablet 2, signalling another exit from the tablet market. Poor sales and competition from Apple may be to blame.

Nvidia’s bold 1997 rivalry with Intel revealed in new book

Nvidia CEO Jensen Huang’s bold 1997 statement reveals the company’s early rivalry with Intel, as detailed in a new book, The Nvidia Way.

Steam sets stricter rules and better support for season pass content

Steam introduces stricter rules for season passes, requiring precise content details and refunds for undelivered DLC, improving fairness for players.

Anti-deepfake declaration faces scrutiny over possible AI involvement

Minnesota's anti-deepfake law faces controversy as an affidavit supporting it shows signs of AI-generated text with non-existent citations.

Google reportedly cancels Pixel Tablet 2 and exits tablet market again

Google cancels the Pixel Tablet 2, signalling another exit from the tablet market. Poor sales and competition from Apple may be to blame.

Related Articles

Popular Categories