Friday, 27 December 2024
29.4 C
Singapore

FBI and CISA alert: Developers urged to tackle security vulnerabilities

FBI and CISA advise developers to address security flaws, enhancing cybersecurity.

The U.S. Cybersecurity and Infrastructure Agency (CISA) and the Federal Bureau of Investigation (FBI) have jointly issued a security alert, stressing the importance for software developers to address path traversal vulnerabilities before releasing their products.

Path traversal, also referred to as directory traversal or climbing, poses a significant risk in software . This vulnerability allows threat actors to access sensitive files and directories, particularly in web applications or systems that construct file paths based on user input without proper validation.

Despite being well documented for over two decades, path traversal remains a persistent issue in software products. The agencies highlight that threat actors consistently exploit this vulnerability class, particularly targeting sectors like healthcare and public health.

In the recent alert, CISA and the FBI emphasised the urgent need for action from software manufacturers. They expressed concern that these vulnerabilities continue to put customers at risk and have even impacted critical services such as hospital and school operations.

Currently, CISA has identified 55 path traversal vulnerabilities in the Known Exploited Vulnerabilities catalogue, indicating active exploitation in the wild. The agencies urge software manufacturer executives to mandate formal testing to assess their products’ susceptibility to these vulnerabilities, referring to OWASP testing guidance.

Additionally, they encourage all software users to inquire with their partners about formal directory traversal testing. Manufacturers are advised to promptly implement mitigations to eliminate this class of defect from their products, stressing the importance of integrating security measures from the initial stages of development.

Hot this week

Trump indicates TikTok could stay in the US after campaign success

Donald Trump hints at keeping TikTok in the US while also addressing plans to tackle the Ukraine war, migrant crime, and transgender issues.

Apple could release M4 MacBook Air sooner than expected in Q1 2025

Apple could release the M4 MacBook Air in Q1 2025, featuring upgrades like a Centre Stage camera and Thunderbolt 4 ports.

ZOWIE XL2566X+ review: A 400Hz esports monitor that redefines gaming performance

Experience unmatched gaming performance with the ZOWIE XL2566X+, featuring 400Hz refresh rate and DyAc 2 for esports excellence.

Asus unveils NUC 14 Pro AI: The first mini PC with Copilot Plus support

Discover Asus' NUC 14 Pro AI, the first mini PC with Copilot Plus support. It boasts Intel Core Ultra processors, advanced features, and a compact design.

Foxconn invests in electric vehicle battery plant to diversify business beyond Apple iPhones

Foxconn invests US$82M in a Zhengzhou EV battery plant, diversifying into electric vehicles as part of its shift beyond Apple iPhone production.

Google unveils AI model that shows its reasoning process

Google introduces Gemini 2.0 Flash Thinking, an AI model that solves complex questions while revealing its step-by-step reasoning process.

Bluesky introduces a mentions tab in your notifications

Bluesky’s latest update adds a mentions tab, improves reply settings, reserves old usernames, and plans for a subscription service next year.

Lilium halts operations and lays off 1,000 workers after funding struggles

Lilium, a flying taxi company, lays off 1,000 workers and halts operations after struggling to secure VTOL air taxi technology funding.

Interlock ransomware targets critical infrastructure with FreeBSD-specific attacks

Interlock ransomware targets FreeBSD servers, highlighting the need for enhanced security measures in critical infrastructure.

Related Articles

Popular Categories