On Monday the CISA and the FBI published a “secure-by-design” alert urging technology manufacturers to eliminate the “unforgivable” class of vulnerabilities known as SQL injection.
It states that threat actors were able to exploit just such a vulnerability in MOVEit file transfer software last year to devastating effect – data exfiltration from thousands of MOVEit corporate clients impacting the personal details of tens of millions of customers.
“Despite widespread knowledge and documentation of SQLi vulnerabilities over the past two decades, along with the availability of effective mitigations, software manufacturers continue to develop products with this defect, which puts many customers at risk.
“CISA and the FBI urge senior executives at technology manufacturing companies to mount a formal review of their code to determine its susceptibility to SQLi compromises. If found vulnerable, senior executives should ensure their organizations’ software developers begin immediate implementation of mitigations to eliminate this entire class of defect from all current and future software products,” the alert noted.
The alert offered the following guidelines for technology manufacturers:
- Take Ownership of Customer Security Outcomes
- Embrace Radical Transparency and Accountability
- Build Organizational Structure and Leadership to Achieve These Goals
Emily Phelps, Director, Cyware:
“This CISA and FBI initiative, particularly in eliminating SQL injection vulnerabilities, is important. It highlights the need for proactive cybersecurity measures to protect sensitive data from well-known threats. This effort is not just about improving security; it’s about building a foundation of trust between technology providers and their users, ensuring that privacy and safety are prioritized.
“Collaboration between the private and public sectors is crucial. By working together, these sectors can share knowledge, tools, and strategies, making it much harder for cyber threats to penetrate their defenses.”
It’s 2024 and SQL Injection vulnerabilities should be a thing of the past. I’m not sure why this has to be constantly deemed to be unacceptable. But hopefully everyone gets the message and does something to relegate them to the history books.
CISA, FBI, DHS Release Guidance For Limited Resourced Civil Society Organizations
Posted in Commentary with tags CISA, DHS, FBI on May 15, 2024 by itnerdYesterday in partnership with the DHS, the FBI and numerous international agencies, CISA released a joint guidance document to help civil society organizations and individuals reduce the risk of cyber intrusions and encourage software manufactures to actively commit to implementing Secure by Design practices to help protect vulnerable and high-risk communities.
“Civil society, comprised of organizations and individuals such as– nonprofit, advocacy, cultural, faith-based, academic, think tanks, journalist, dissident, and diaspora organizations, communities involved in defending human rights and advancing democracy–are considered high-risk communities. Often these organizations and their employees are targeted by state-sponsored threat actors who seek to undermine democratic values and interests,” CISA’s release read.
Civil society organizations and individuals are encouraged to implement the following best practices as defined by CISA’s Cross-Sector Cybersecurity Performance Goals:
Software manufacturers are strongly encouraged to embrace Secure by Design principles and mitigations to improve the security posture for their customers include:
Dave Ratner, CEO, HYAS had this to say:
“Security by design is a good practice to implement and goes hand-in-hand with the equivalent for enterprise network design — designing for cyber resiliency. Too often security is an after-thought; with both security by design for software engineering, and cyber resiliency design for networks and organizations, the overall design becomes foundationally secure, and that’s exactly what is needed going forward to combat the continued onslaught of new and innovative attacks and risks.“
What I like about this initiative is that it is targeting a group of people who likely don’t spend a lot of time and effort to make sure that they are secure. Yet they are low hanging fruit for threat actors. Hopefully this generates results and civil society organizations and individuals are better protected as a result.
Leave a comment »