Wednesday, 19 November 2025
24.3 C
Singapore
22.3 C
Thailand
20.7 C
Indonesia
27.5 C
Philippines

FBI and CISA alert: Developers urged to tackle security vulnerabilities

FBI and CISA advise developers to address security flaws, enhancing cybersecurity.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) and the Federal Bureau of Investigation (FBI) have jointly issued a security alert, stressing the importance for software developers to address path traversal vulnerabilities before releasing their products.

Path traversal, also referred to as directory traversal or climbing, poses a significant risk in software development. This vulnerability allows threat actors to access sensitive files and directories, particularly in web applications or systems that construct file paths based on user input without proper validation.

Despite being well documented for over two decades, path traversal remains a persistent issue in software products. The agencies highlight that threat actors consistently exploit this vulnerability class, particularly targeting sectors like healthcare and public health.

In the recent alert, CISA and the FBI emphasised the urgent need for action from software manufacturers. They expressed concern that these vulnerabilities continue to put customers at risk and have even impacted critical services such as hospital and school operations.

Currently, CISA has identified 55 path traversal vulnerabilities in the Known Exploited Vulnerabilities catalogue, indicating active exploitation in the wild. The agencies urge software manufacturer executives to mandate formal testing to assess their products’ susceptibility to these vulnerabilities, referring to OWASP testing guidance.

Additionally, they encourage all software users to inquire with their partners about formal directory traversal testing. Manufacturers are advised to promptly implement mitigations to eliminate this class of defect from their products, stressing the importance of integrating security measures from the initial stages of development.

Hot this week

Hohem iSteady Pro 4 review: A versatile stabiliser for action-packed filming

Hohem iSteady Pro 4 review: A powerful three-axis gimbal for action cameras with smooth stabilisation, creative modes, and long battery life.

Meta opens AI showcase to the public in Singapore

Meta AI opens its first public showcase in Singapore, featuring interactive experiences and an exclusive preview of Ray-Ban Meta Glasses (Gen 2).

Mizuho Bank accelerates ISO 20022 compliance with new Boomi-powered platform

Mizuho Bank speeds up ISO 20022 adoption with a Boomi-powered platform that improves onboarding and streamlines payments across Asia Pacific.

vivo X300 Pro review: A flagship built for serious photography

A detailed look at the vivo X300 Pro’s camera system, design, battery life and everyday performance in real-world use.

Meta announces Southeast Asia’s most impactful Reels campaigns and creators

Meta highlights brands and creators shaping Southeast Asia’s short-form video landscape at the 2025 Reels Impact Awards.

Major web outage affects numerous global sites on 18 November

A major Cloudflare outage on 18 November caused widespread website failures as the company investigated significant service disruptions.

Call of Duty: Black Ops 7 faces backlash from players over AI-generated content

Players slam Call of Duty: Black Ops 7 over AI-generated art and gameplay issues despite strong critical reviews.

LinkedIn introduces AI-powered search to help users find the right people

LinkedIn introduces AI-powered search to help users find relevant people more quickly, starting with Premium members in the US.

UBS partners with Ant International on blockchain-based cross-border settlement

UBS and Ant International partner to explore blockchain-based cross-border payment and liquidity innovations through a new Singapore-based collaboration.

Related Articles

Popular Categories