Urgent.News

What's breaking now, across thousands of outlets.

Science

CISA: Most exploited vulnerabilities should have been eradicated decades ago

Organizational culture and systemic gaps in Secure by Design adoption blamed for sorry state of affairs

CISA: Most exploited vulnerabilities should have been eradicated decades ago

The Cybersecurity and Infrastructure Security Agency (CISA) has expressed concern that most exploited vulnerabilities should have been eradicated decades ago. In its latest review, CISA found that many of the vulnerabilities that receive Common Vulnerabilities and Exposures (CVEs) and make it to the Known Exploited Vulnerability (KEV) catalog are decades-old flaws that should have been addressed.

Injection-related vulnerabilities, such as cross-site scripting (XSS), OS command injections, and SQL injections, were among the most common. These were joined by bugs introduced by vendors that didn't properly mitigate against improper input validation. CISA stated that threat actors continue to succeed because simple, preventable software weaknesses remain unaddressed.

Resolving fundamental issues would eliminate a significant portion of today's most common compromises. The persistence of these vulnerabilities is attributed to organizational culture, developer workflows, and systemic gaps in Secure by Design adoption. CISA is again recommending organizations adopt Secure by Design (SBD) practices to eliminate stubborn vulnerability classes and shoulder less of the security burden.

Written by urgent.news from The Register Science's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

This story

This is one outlet's version. Read the fullest account.

Read the original at theregister.com →

More in Science

More from Friday 28 August →