The Cybersecurity and Infrastructure Security Agency and the Federal Bureau of Investigation have jointly released a Secure by Design Alert titled “Eliminating Directory Traversal Vulnerabilities in Software.”
CISA said Thursday that the alert seeks to draw attention to recent campaigns by threat actors to take advantage of directory traversal vulnerabilities, which have impacted critical infrastructure like public health and healthcare, as well as continuing exploits that have affected various critical services.
The agency notes that exploits persist despite the availability of mitigation methods. Its catalog also lists 55 known traversal vulnerabilities.
Software developers are encouraged to test their products to determine their susceptibility to the vulnerabilities.
Related Articles
The U.S. Army has signed new rapid prototype other transactional authority, also known as OTA, agreements with General Dynamics Mission Systems and Pacific Defense to build a chassis that would enable soldiers to plug and play capabilities into military vehicles. Plug-and-Play Capabilities The technology is dubbed CMFF, which is short for Command, Control, Computers, Communications, Cyber, Intelligence, Surveillance and Reconnaissance/Electronic Warfare Modular Open Suite of Standards Mounted Form Factor. It offers both hardware and software designed to converge multiple legacy systems into one chassis in ground and aviation platforms. CMFF is equipped with power, networks and radio frequency to support
The United Kingdom’s National Cyber Security Centre, in partnership with the Cybersecurity and Infrastructure Security Agency, the FBI and other international partners, has published new joint guidance aimed at helping organizations secure their operational technology environments. The document, titled “Creating and Maintaining a Definitive View of Your Operational Technology Architecture,” builds on the recent Foundations for OT Cybersecurity: Asset Inventory Guidance and provides actionable steps to strengthen defenses against cyberthreats, CISA said. CISA is a DHS agency. Potomac Officers Club’s 2025 Homeland Security Summit offers an inside look at the latest programs, technologies and strategies shaping America’s defense against evolving
The National Oceanic and Atmospheric Administration has tapped Raytheon for a mission design and feasibility study on weather imagery capabilities under its Near Earth Orbit Network, or NEON, Stratus project. The company will conduct the Stratus critical design review study under an other transaction agreement NOAA signed with Raytheon valued about $5.9 million, the agency said Friday. Raytheon’s CDR study will focus on a U.S. Space Force design adapted to NOAA’s requirements for Stratus. Under NEON, low-Earth orbit environmental satellites will be launched for weather forecasting, environmental observation and public safety. The program also seeks to demonstrate faster data delivery