Friday, 31 January 2025
25.6 C
Singapore
22.6 C
Thailand
20 C
Indonesia
25.9 C
Philippines

FBI and CISA alert: Developers urged to tackle security vulnerabilities

FBI and CISA advise developers to address security flaws, enhancing cybersecurity.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) and the Federal Bureau of Investigation (FBI) have jointly issued a security alert, stressing the importance for software developers to address path traversal vulnerabilities before releasing their products.

Path traversal, also referred to as directory traversal or climbing, poses a significant risk in software development. This vulnerability allows threat actors to access sensitive files and directories, particularly in web applications or systems that construct file paths based on user input without proper validation.

Despite being well documented for over two decades, path traversal remains a persistent issue in software products. The agencies highlight that threat actors consistently exploit this vulnerability class, particularly targeting sectors like healthcare and public health.

In the recent alert, CISA and the FBI emphasised the urgent need for action from software manufacturers. They expressed concern that these vulnerabilities continue to put customers at risk and have even impacted critical services such as hospital and school operations.

Currently, CISA has identified 55 path traversal vulnerabilities in the Known Exploited Vulnerabilities catalogue, indicating active exploitation in the wild. The agencies urge software manufacturer executives to mandate formal testing to assess their products’ susceptibility to these vulnerabilities, referring to OWASP testing guidance.

Additionally, they encourage all software users to inquire with their partners about formal directory traversal testing. Manufacturers are advised to promptly implement mitigations to eliminate this class of defect from their products, stressing the importance of integrating security measures from the initial stages of development.

Hot this week

Tumblr TV emerges as a TikTok alternative nearly a decade after its launch

Tumblr TV officially launches as a TikTok alternative nearly 10 years after its creation, attracting new users amidst TikTok's uncertain future.

Comcastโ€™s new โ€˜ultra-low lagโ€™ technology aims to transform internet speed

Comcast is rolling out ultra-low lag internet technology to improve video calls and gaming. Major cities will see upgrades, cutting latency by 78%.

Apple is developing visionOS for future smart glasses

Apple is developing a version of visionOS for smart glasses, codenamed "Atlas," while also working on a more affordable Vision Pro headset.

Perplexity submits new bid to merge with TikTok

Perplexity AI proposes merging with TikTok, offering the U.S. government up to 50% ownership in a deal shaped by Trump administration demands.

Survey shows CISOs gain influence in C-suites and boardrooms globally

Global survey shows 82% of CISOs now report directly to CEOs and 83% participate in board meetings, highlighting their growing influence in organisations.

Microsoftโ€™s AI business thrives while Xbox struggles

Microsoftโ€™s AI and cloud business is booming, but Xbox is struggling. Gaming revenue fell 7%, while AI growth surged 175% year-over-year.

Meta remains confident despite DeepSeekโ€™s advancements

Mark Zuckerberg reassures investors that DeepSeekโ€™s AI rise does not threaten Meta, as the company reports strong Q4 results and AI investment plans.

Meta agrees to US$25 million settlement over Trump account suspension lawsuit

Meta has agreed to pay US$25 million to settle Trumpโ€™s lawsuit over his account suspension, with most funds going to his presidential library.

Comcastโ€™s new โ€˜ultra-low lagโ€™ technology aims to transform internet speed

Comcast is rolling out ultra-low lag internet technology to improve video calls and gaming. Major cities will see upgrades, cutting latency by 78%.

Related Articles