Monday, 30 June 2025
30.6 C
Singapore
34.4 C
Thailand
21.6 C
Indonesia
29.7 C
Philippines

FBI and CISA alert: Developers urged to tackle security vulnerabilities

FBI and CISA advise developers to address security flaws, enhancing cybersecurity.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) and the Federal Bureau of Investigation (FBI) have jointly issued a security alert, stressing the importance for software developers to address path traversal vulnerabilities before releasing their products.

Path traversal, also referred to as directory traversal or climbing, poses a significant risk in software development. This vulnerability allows threat actors to access sensitive files and directories, particularly in web applications or systems that construct file paths based on user input without proper validation.

Despite being well documented for over two decades, path traversal remains a persistent issue in software products. The agencies highlight that threat actors consistently exploit this vulnerability class, particularly targeting sectors like healthcare and public health.

In the recent alert, CISA and the FBI emphasised the urgent need for action from software manufacturers. They expressed concern that these vulnerabilities continue to put customers at risk and have even impacted critical services such as hospital and school operations.

Currently, CISA has identified 55 path traversal vulnerabilities in the Known Exploited Vulnerabilities catalogue, indicating active exploitation in the wild. The agencies urge software manufacturer executives to mandate formal testing to assess their products’ susceptibility to these vulnerabilities, referring to OWASP testing guidance.

Additionally, they encourage all software users to inquire with their partners about formal directory traversal testing. Manufacturers are advised to promptly implement mitigations to eliminate this class of defect from their products, stressing the importance of integrating security measures from the initial stages of development.

Hot this week

GitLab and IBM launch unified DevSecOps solution for mainframes

GitLab and IBM launch GitLab Ultimate for IBM Z to modernise mainframe development with CI/CD, integrated DevSecOps, and hybrid cloud support.

Microsoft to announce major Xbox layoffs next week

Microsoft is preparing to cut more Xbox jobs next week as part of a larger restructure. Layoffs are also expected in its sales division.

Sharp launches AQUOS wish5 smartphone in Singapore with focus on safety and sustainability

Sharp launches AQUOS wish5 in Singapore, featuring vibration SOS alert, military-grade durability, and eco-conscious materials.

Google launches Gemini AI for schools and students, raising questions about future of learning

Google launches Gemini AI in schools with safety tools and fact-checking, sparking debate on its impact on learning and student development.

Baidu’s Apollo Go eyes Southeast Asia in global robotaxi push

Baidu's Apollo Go plans to launch robotaxi services in Southeast Asia by late 2025 as global autonomous driving competition heats up.

Cheapest SIM-only plans in Singapore 2025: Flexible, contract-free mobile data

Compare the cheapest SIM-only plans in Singapore for 2025, with up to 1TB data, 5G access, roaming, and no-contract options from S$8/month.

Android 16 to alert you if your phone connects to a fake cell tower

Android 16 will warn you if your phone connects to a fake tower, helping protect your calls, texts, and location from silent spying.

Runway moves into gaming with new AI platform Game Worlds

Runway launches Game Worlds, an AI platform aiming to reshape game creation and expand its success from film into the gaming industry.

TikTok trials new ‘bulletin boards’ to rival Instagram’s broadcast channels

TikTok is testing bulletin boards, a new feature similar to Instagram's broadcast channels, for direct creator-to-fan updates.

Related Articles

Popular Categories