Wednesday, 5 November 2025
30.6 C
Singapore
27.6 C
Thailand
23.9 C
Indonesia
28.3 C
Philippines

FBI and CISA alert: Developers urged to tackle security vulnerabilities

FBI and CISA advise developers to address security flaws, enhancing cybersecurity.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) and the Federal Bureau of Investigation (FBI) have jointly issued a security alert, stressing the importance for software developers to address path traversal vulnerabilities before releasing their products.

Path traversal, also referred to as directory traversal or climbing, poses a significant risk in software development. This vulnerability allows threat actors to access sensitive files and directories, particularly in web applications or systems that construct file paths based on user input without proper validation.

Despite being well documented for over two decades, path traversal remains a persistent issue in software products. The agencies highlight that threat actors consistently exploit this vulnerability class, particularly targeting sectors like healthcare and public health.

In the recent alert, CISA and the FBI emphasised the urgent need for action from software manufacturers. They expressed concern that these vulnerabilities continue to put customers at risk and have even impacted critical services such as hospital and school operations.

Currently, CISA has identified 55 path traversal vulnerabilities in the Known Exploited Vulnerabilities catalogue, indicating active exploitation in the wild. The agencies urge software manufacturer executives to mandate formal testing to assess their products’ susceptibility to these vulnerabilities, referring to OWASP testing guidance.

Additionally, they encourage all software users to inquire with their partners about formal directory traversal testing. Manufacturers are advised to promptly implement mitigations to eliminate this class of defect from their products, stressing the importance of integrating security measures from the initial stages of development.

Hot this week

Airwallex launches refreshed startup programme to empower founders

Airwallex launches an expanded startup programme in Singapore, offering financial infrastructure, mentorship, and AI innovation tools.

ECOVACS: Advancing smart living and robotics adoption in Southeast Asia

ECOVACS is reshaping smart living in Southeast Asia with AI-driven, multi-scenario robotics built for local homes and lifestyles.

Cloudera recognised as leader in Forrester’s 2025 data fabric platforms report

Cloudera named a leader in Forrester’s 2025 data fabric platforms report for its scalable, unified, and intelligent data management.

Denodo and ST Engineering partner to advance AI-driven sensemaking technologies

Denodo and ST Engineering partner to develop AI-driven data technologies to enhance decision-making and operational intelligence.

VoidZero secures US$12.5 million Series A to launch unified JavaScript toolchain Vite+

VoidZero raises US$12.5 million Series A to launch Vite+, a unified JavaScript toolchain aimed at boosting developer productivity.

Final Fantasy Tactics modders restore missing bonus content to The Ivalice Chronicles remaster

Fans are restoring missing Final Fantasy Tactics features through mods, bringing back War of the Lions content for the new remaster.

Motorola refreshes Moto G and Moto G Play smartphones for 2026

Motorola launches new Moto G and Moto G Play models for 2026, featuring upgraded cameras, improved displays, and stylish Pantone colour options.

Apple may launch an affordable Mac laptop in early 2026

Apple may launch its first affordable Mac laptop in early 2026, aiming to attract students and everyday users with a price under US$1,000.

WhatsApp reportedly testing companion app for Apple Watch

WhatsApp is testing a companion app for Apple Watch, allowing users to view and reply to messages directly from their wrist.

Related Articles

Popular Categories