Sunday, 20 April 2025
25 C
Singapore
37 C
Thailand
22.3 C
Indonesia
29.6 C
Philippines

FBI and CISA alert: Developers urged to tackle security vulnerabilities

FBI and CISA advise developers to address security flaws, enhancing cybersecurity.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) and the Federal Bureau of Investigation (FBI) have jointly issued a security alert, stressing the importance for software developers to address path traversal vulnerabilities before releasing their products.

Path traversal, also referred to as directory traversal or climbing, poses a significant risk in software development. This vulnerability allows threat actors to access sensitive files and directories, particularly in web applications or systems that construct file paths based on user input without proper validation.

Despite being well documented for over two decades, path traversal remains a persistent issue in software products. The agencies highlight that threat actors consistently exploit this vulnerability class, particularly targeting sectors like healthcare and public health.

In the recent alert, CISA and the FBI emphasised the urgent need for action from software manufacturers. They expressed concern that these vulnerabilities continue to put customers at risk and have even impacted critical services such as hospital and school operations.

Currently, CISA has identified 55 path traversal vulnerabilities in the Known Exploited Vulnerabilities catalogue, indicating active exploitation in the wild. The agencies urge software manufacturer executives to mandate formal testing to assess their products’ susceptibility to these vulnerabilities, referring to OWASP testing guidance.

Additionally, they encourage all software users to inquire with their partners about formal directory traversal testing. Manufacturers are advised to promptly implement mitigations to eliminate this class of defect from their products, stressing the importance of integrating security measures from the initial stages of development.

Hot this week

Audeze unveils LCD-S20: Premium headphone tech now more affordable

Audeze’s new LCD-S20 offers studio users premium headphone tech like SLAM at a much more affordable price point.

OpenAI may soon require a verified ID to access future AI models

OpenAI may soon require verified ID for access to advanced AI models, aiming to boost safety and prevent misuse of its tools.

Samsung halts global One UI 7 update after serious bug found

Samsung halts its global One UI 7 update rollout due to a bug that locks Galaxy S24 users out of their phones.

Tenable warns AI growth is outpacing cloud security readiness

Tenable warns that rapid AI adoption using open-source tools and cloud services is outpacing security, leaving organisations exposed to growing risks.

Google removes over 5 billion ads in 2024 as AI boosts enforcement against online scams

Google’s Ads Safety Report 2024 shows how AI helped remove over 5.1 billion ads and block 700,000 scam accounts from its platform.

AMD’s RX 9070 GRE leak could bring welcome news for gamers

Leaked AMD’s RX 9070 GRE specs suggest a strong mid-range GPU with 12GB memory and fast clocks, perfect for modern gamers.

Intel’s new CEO reshapes leadership, promotes AI chief and plans closer work with engineers

Intel CEO Lip-Bu Tan is reshaping leadership, promoting a new AI chief, and aiming for a leaner, more engineering-driven company.

Apple’s iPhone sales drop in China amid growing trade tensions

Apple’s iPhone sales in China fell 9% as local brands grew, and trade tensions created more uncertainty for the smartphone market.

ASUS and Hatsune Miku team up for colourful new gaming gear

ASUS and Hatsune Miku join forces to launch a vibrant limited-edition gaming gear set, arriving in Singapore this June.

Related Articles

Popular Categories