CISA Unveils Exceptionally Risky Software Bad Practices
Summary
The U.S. cyber defense agency is warning software providers against developing new product lines using memory-unsafe languages and other "exceptionally risky practices" that threaten critical infrastructure sectors and national security. "It’s 2024, and basic, preventable software defects continue to enable crippling attacks against hospitals, schools, and other critical infrastructure," CISA Director Jen Easterly said in a statement accompanying the guidance, adding: "This has to stop." CISA and the FBI also warn that failing to publish timely notices of newly-discovered vulnerabilities in products that service critical infrastructure sectors "significantly elevates risk to national security." Many software providers are still failing to implement some of the most basic cybersecurity measures into their new product offerings, according to Neil Carpenter, field chief technology officer for Orca Security. "The sad truth is [CISAs] latest advisory encapsulates the litany of poor product design decisions made over the years that result in countless organizations being compromised," Carpenter told ISMG.