Thursday, 6 March 2025
28.1 C
Singapore
39.9 C
Thailand
25.3 C
Indonesia
28.1 C
Philippines

FBI and CISA alert: Developers urged to tackle security vulnerabilities

FBI and CISA advise developers to address security flaws, enhancing cybersecurity.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) and the Federal Bureau of Investigation (FBI) have jointly issued a security alert, stressing the importance for software developers to address path traversal vulnerabilities before releasing their products.

Path traversal, also referred to as directory traversal or climbing, poses a significant risk in software development. This vulnerability allows threat actors to access sensitive files and directories, particularly in web applications or systems that construct file paths based on user input without proper validation.

Despite being well documented for over two decades, path traversal remains a persistent issue in software products. The agencies highlight that threat actors consistently exploit this vulnerability class, particularly targeting sectors like healthcare and public health.

In the recent alert, CISA and the FBI emphasised the urgent need for action from software manufacturers. They expressed concern that these vulnerabilities continue to put customers at risk and have even impacted critical services such as hospital and school operations.

Currently, CISA has identified 55 path traversal vulnerabilities in the Known Exploited Vulnerabilities catalogue, indicating active exploitation in the wild. The agencies urge software manufacturer executives to mandate formal testing to assess their products’ susceptibility to these vulnerabilities, referring to OWASP testing guidance.

Additionally, they encourage all software users to inquire with their partners about formal directory traversal testing. Manufacturers are advised to promptly implement mitigations to eliminate this class of defect from their products, stressing the importance of integrating security measures from the initial stages of development.

Hot this week

Microsoft to shut down Skype in May and focus on Teams

Microsoft will shut down Skype on May 5 and focus on Teams. Users can transfer their chats and contacts to Teams for a seamless switch.

Garmin expands golf range with Approach G20 Solar and Approach CT1 tracking tags

Garmin Singapore launches Approach G20 Solar GPS golf handheld and Approach CT1 tracking tags to help golfers improve performance.

Proofpoint ranked top in 4 out of 5 categories in 2025 Gartner report on email security platforms

Proofpoint ranked first in 4 out of 5 categories in Gartnerโ€™s 2025 Critical Capabilities Report for Email Security Platforms.

Apple unveils MacBook Air with M4 chip, new Sky Blue colour, and lower prices

Apple unveils the MacBook Air with the M4 chip, a Sky Blue colour, and lower prices. Pre-orders are open now, and retail availability will be on March 12.

Adobe: Driving Singapore’s digital transformation through Smart Nation 2.0

Adobe is driving Singaporeโ€™s Smart Nation 2.0 with AI, personalisation, and accessibility, enhancing citizen engagement and digital governance.

Trump proposes US crypto reserve, raising concerns over economic impact

Trump proposes a US Crypto Reserve, raising concerns about its impact on the economy and the dollar. Could this move benefit crypto donors over taxpayers?

Apple unveils MacBook Air with M4 chip, new Sky Blue colour, and lower prices

Apple unveils the MacBook Air with the M4 chip, a Sky Blue colour, and lower prices. Pre-orders are open now, and retail availability will be on March 12.

Assassin’s Creed Shadows confirmed for day-one Mac release

Ubisoft confirms that Assassinโ€™s Creed Shadows will launch on Macs from day one, supporting M-series chips. The game will be released on March 20.

Trump grants automakers a one-month delay on tariffs to move production to the U.S.

Trump grants automakers a one-month delay on tariffs, urging them to move production from Canada and Mexico to the U.S. before April 2.

Related Articles