Security News

Cybersecurity news aggregator

CRITICAL News SC Media

CISA urges software vendors to adopt secure by design practices

CISA is urging software vendors to adopt Secure by Design practices, emphasizing that many actively exploited vulnerabilities are decades-old, fundamental flaws like SQL injection and cross-site scripting. These weaknesses persist due to organizational culture rather than technical complexity. The agency advises software buyers to prioritize vendors who demonstrate these practices and maintain SBOMs to manage supply chain risk.
Read Full Article →

Vulnerability Management CISA urges software vendors to adopt secure by design practices August 28, 2026 Share By SC Staff (Adobe Stock) The Cybersecurity and Infrastructure Security Agency (CISA) is reiterating its call for software vendors to adopt Secure by Design (SBD) development practices, highlighting that many exploited vulnerabilities are decades old, based on information published by The Register. CISA's review of vulnerabilities from 2024 and 2025 reveals that the most frequently exploited flaws, often found in the Known Exploited Vulnerability (KEV) catalog, are rooted in long-standing weaknesses. These include injection-related vulnerabilities like cross-site scripting (XSS), OS command injections, and SQL injections, as well as issues stemming from improper input validation. These vulnerabilities, some identified as "unforgivable" as early as 2007, persist due to organizational culture and development workflows rather than technical complexity. CISA emphasizes that addressing these fundamental flaws would significantly reduce common compromises. The agency recommends that vendors take ownership of security outcomes, eliminate these persistent weaknesses, and improve automation for configurations, monitoring, and updates. Software buyers are advised to prioritize vendors who demonstrate these practices and maintain software bills of materials (SBOMs) to manage supply chain risk. Source: The Register SC Staff Related Vulnerability Management Critical vulnerability in GiveWP plugin allows remote code execution SC Staff August 28, 2026 The vulnerability, present in GiveWP versions up to 4.16.7.1, is exploitable by chaining three issues: an unsafe PHP data unserialization helper, a donation processing flow that stores attacker-controlled serialized objects, and a gadget chain within bundled libraries that enables arbitrary system command execution. Vulnerability Management CISA adds ownCloud, Linux Kernel, and JFrog Artifactory flaws to exploited vulnerabilities list SC Staff August 28, 2026 The newly cataloged vulnerabilities include CVE-2023-49105, an improper authentication flaw in ownCloud Server affecting versions 10.6.0 through 10.13.0, which allows unauthenticated attackers to access or modify user files. Vulnerability Management PaperCut issues emergency patches for actively exploited critical vulnerability Laura French August 28, 2026 Two flaws in the print management software could enable unauthenticated RCE. Related Events Cybercast State of Vulnerability Management Thu Sep 10 Cybercast Why Mythos is the cybersecurity crisis we need On-Demand Event Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms Bug Buffer Overflow Disassembly You can skip this ad in 5 seconds

Share this article