Sunday, 13 July 2025
27.5 C
Singapore
28.5 C
Thailand
19.9 C
Indonesia
28.1 C
Philippines

FBI and CISA alert: Developers urged to tackle security vulnerabilities

FBI and CISA advise developers to address security flaws, enhancing cybersecurity.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) and the Federal Bureau of Investigation (FBI) have jointly issued a security alert, stressing the importance for software developers to address path traversal vulnerabilities before releasing their products.

Path traversal, also referred to as directory traversal or climbing, poses a significant risk in software development. This vulnerability allows threat actors to access sensitive files and directories, particularly in web applications or systems that construct file paths based on user input without proper validation.

Despite being well documented for over two decades, path traversal remains a persistent issue in software products. The agencies highlight that threat actors consistently exploit this vulnerability class, particularly targeting sectors like healthcare and public health.

In the recent alert, CISA and the FBI emphasised the urgent need for action from software manufacturers. They expressed concern that these vulnerabilities continue to put customers at risk and have even impacted critical services such as hospital and school operations.

Currently, CISA has identified 55 path traversal vulnerabilities in the Known Exploited Vulnerabilities catalogue, indicating active exploitation in the wild. The agencies urge software manufacturer executives to mandate formal testing to assess their products’ susceptibility to these vulnerabilities, referring to OWASP testing guidance.

Additionally, they encourage all software users to inquire with their partners about formal directory traversal testing. Manufacturers are advised to promptly implement mitigations to eliminate this class of defect from their products, stressing the importance of integrating security measures from the initial stages of development.

Hot this week

Microsoft to exit Pakistan after 25 years, shifting to reseller model

Microsoft ends its 25-year presence in Pakistan, shifting to a reseller model amid global cuts and broader industry challenges.

Stop Killing Games hits 1.2 million signatures, but challenges remain

The Stop Killing Games petition passed 1.2M signatures, but fake entries and industry pushback may slow its path to EU law.

Beyerdynamic’s retro-style Aventho 100 headphones now offer 60-hour battery life and more upgrades

Beyerdynamic's new Aventho 100 headphones offer 60-hour battery life, aptX Lossless support, USB-C connectivity, and an improved design at a lower price.

Kahoot! teams up with Tour de France to deliver interactive learning experiences

Kahoot! partners with Tour de France to bring interactive cycling-themed learning to classrooms, fan parks, and homes worldwide.

Infor expands partnership with AWS to accelerate generative AI adoption

Infor strengthens partnership with AWS to deliver generative AI solutions across industries and boost global reach via AWS Marketplace.

OpenAI preparing to launch AI-powered web browser to rival Chrome

OpenAI plans to launch a new AI-powered web browser, aiming to transform the browsing experience using ChatGPT technology.

Singapore to get Huawei’s 480kW ultra-fast EV charger by the end of 2025

Huawei brings 480kW ultra-fast EV charger to Singapore by late 2025, slashing charge times and boosting support for commercial vehicles.

Samsung, Google, and Qualcomm share their vision for where mobile AI is heading

Samsung, Google, and Qualcomm share how mobile AI will become more helpful, personal, and invisible in your everyday life.

Razer unveils DeathAdder V4 Pro with pro-level features and ultra-lightweight design

Razer’s DeathAdder V4 Pro lands with 8000Hz wireless polling, a lighter design, and esports-level precision for serious gamers.

Related Articles

Popular Categories