Friday, 19 September 2025
27.7 C
Singapore
27.5 C
Thailand
18.4 C
Indonesia
28.5 C
Philippines

FBI and CISA alert: Developers urged to tackle security vulnerabilities

FBI and CISA advise developers to address security flaws, enhancing cybersecurity.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) and the Federal Bureau of Investigation (FBI) have jointly issued a security alert, stressing the importance for software developers to address path traversal vulnerabilities before releasing their products.

Path traversal, also referred to as directory traversal or climbing, poses a significant risk in software development. This vulnerability allows threat actors to access sensitive files and directories, particularly in web applications or systems that construct file paths based on user input without proper validation.

Despite being well documented for over two decades, path traversal remains a persistent issue in software products. The agencies highlight that threat actors consistently exploit this vulnerability class, particularly targeting sectors like healthcare and public health.

In the recent alert, CISA and the FBI emphasised the urgent need for action from software manufacturers. They expressed concern that these vulnerabilities continue to put customers at risk and have even impacted critical services such as hospital and school operations.

Currently, CISA has identified 55 path traversal vulnerabilities in the Known Exploited Vulnerabilities catalogue, indicating active exploitation in the wild. The agencies urge software manufacturer executives to mandate formal testing to assess their products’ susceptibility to these vulnerabilities, referring to OWASP testing guidance.

Additionally, they encourage all software users to inquire with their partners about formal directory traversal testing. Manufacturers are advised to promptly implement mitigations to eliminate this class of defect from their products, stressing the importance of integrating security measures from the initial stages of development.

Hot this week

New Relic study shows IT outages cost Southeast Asian firms up to US$165.5 million a year

A New Relic report finds IT outages cost Southeast Asian firms up to US$165.5m yearly, with AI driving demand for observability.

Beijing AIForce Technology wins PepsiCo’s 2025 Greenhouse Accelerator in Asia Pacific

Beijing AIForce Technology wins PepsiCo’s 2025 Greenhouse Accelerator in Asia Pacific with its autonomous low-carbon tractors.

Asus unveils US$4,000 ProArt P16 with 4K tandem OLED and RTX 5090

Asus launches its ProArt P16 laptop with a 4K tandem OLED, RTX 5090 GPU, and creator-focused features, priced from US$1,999.

StarHub introduces dynamic ad pods for live TV advertising in Singapore

StarHub launches Dynamic Ad Pods in Singapore, bringing personalised, real-time ad replacement to live broadcast TV.

Cohesity and Semperis launch solution to strengthen identity resilience

Cohesity and Semperis launch Cohesity Identity Resilience to help enterprises protect and recover Active Directory and Entra ID systems.

Steam to end Windows 32-bit support in 2026

Steam will end support for 32-bit Windows on 1 January 2026, continuing only with 64-bit Windows 10 and 11.

Google to use hashes to remove non-consensual intimate imagery from search

Google partners with StopNCII to remove non-consensual intimate images from search using unique hashes.

You can turn off iOS 26 full-screen screenshot previews

Learn how to turn off iOS 26 full-screen screenshot previews while keeping editing tools accessible.

Anker recalls over 481,000 power banks after fire incidents

Anker recalls over 481,000 power banks after reports of fires, offering refunds and gift cards to affected consumers.

Related Articles

Popular Categories