* . *
  • About
  • Advertise
  • Privacy & Policy
  • Contact
Friday, August 8, 2025
Earth-News
  • Home
  • Business
  • Entertainment
    Themed Entertainment Design – Purdue Polytechnic

    Innovative Themed Entertainment Design: Creating Immersive Experiences

    Rachael Leigh Cook and Brandon Routh ‘Happy to Have Found Each Other’ Following Respective Divorces – yahoo.com

    Rachael Leigh Cook and Brandon Routh ‘Happy to Have Found Each Other’ Following Respective Divorces – yahoo.com

    ‘Billie Jean’ – Hyde Park Herald

    The Enduring Magic Behind ‘Billie Jean’ Revealed

    Hank Hill returns to a changed world in new ‘King of the Hill’ episodes – New Haven Register

    Hank Hill Navigates a Bold New World in Thrilling New ‘King of the Hill’ Episodes

    Exclusive | Fox Takes Stake in IndyCar Owner Penske Entertainment – The Wall Street Journal

    Exclusive | Fox Takes Stake in IndyCar Owner Penske Entertainment – The Wall Street Journal

    Go-to entertainment: why gaming was made for the toilet – The Guardian

    Why Gaming Is the Ultimate Way to Pass Time in the Bathroom

  • General
  • Health
  • News

    Cracking the Code: Why China’s Economic Challenges Aren’t Shaking Markets, Unlike America’s” – Bloomberg

    Trump’s Narrow Window to Spread the Truth About Harris

    Trump’s Narrow Window to Spread the Truth About Harris

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Trending Tags

    • Trump Inauguration
    • United Stated
    • White House
    • Market Stories
    • Election Results
  • Science
  • Sports
  • Technology
    MBU showcases student work at Occupational Therapy Technology Fair – WHSV

    Discover the Most Innovative Student Projects at the Occupational Therapy Technology Fair

    BlackSky Technology Inc. (BKSY) Reports Q2 Loss, Lags Revenue Estimates – Yahoo Finance

    BlackSky Technology Inc. Reports Q2 Loss, Misses Revenue Targets

    Improved Technology Access: A Key to Closing the Healthcare Gap for African Americans – BIOENGINEER.ORG

    LMI Expands Technology Org, Appoints New Leaders – GovCon Wire

    LMI Expands Technology Team with Dynamic New Leadership Appointments

    Midland Innovation and Technology Charter School closing down – CBS News

    Midland Innovation and Technology Charter School Closes Permanently

    Future Trends In HR Technology – Dataconomy

    Future Trends In HR Technology – Dataconomy

    Trending Tags

    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • Mark Zuckerberg
No Result
View All Result
  • Home
  • Business
  • Entertainment
    Themed Entertainment Design – Purdue Polytechnic

    Innovative Themed Entertainment Design: Creating Immersive Experiences

    Rachael Leigh Cook and Brandon Routh ‘Happy to Have Found Each Other’ Following Respective Divorces – yahoo.com

    Rachael Leigh Cook and Brandon Routh ‘Happy to Have Found Each Other’ Following Respective Divorces – yahoo.com

    ‘Billie Jean’ – Hyde Park Herald

    The Enduring Magic Behind ‘Billie Jean’ Revealed

    Hank Hill returns to a changed world in new ‘King of the Hill’ episodes – New Haven Register

    Hank Hill Navigates a Bold New World in Thrilling New ‘King of the Hill’ Episodes

    Exclusive | Fox Takes Stake in IndyCar Owner Penske Entertainment – The Wall Street Journal

    Exclusive | Fox Takes Stake in IndyCar Owner Penske Entertainment – The Wall Street Journal

    Go-to entertainment: why gaming was made for the toilet – The Guardian

    Why Gaming Is the Ultimate Way to Pass Time in the Bathroom

  • General
  • Health
  • News

    Cracking the Code: Why China’s Economic Challenges Aren’t Shaking Markets, Unlike America’s” – Bloomberg

    Trump’s Narrow Window to Spread the Truth About Harris

    Trump’s Narrow Window to Spread the Truth About Harris

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Trending Tags

    • Trump Inauguration
    • United Stated
    • White House
    • Market Stories
    • Election Results
  • Science
  • Sports
  • Technology
    MBU showcases student work at Occupational Therapy Technology Fair – WHSV

    Discover the Most Innovative Student Projects at the Occupational Therapy Technology Fair

    BlackSky Technology Inc. (BKSY) Reports Q2 Loss, Lags Revenue Estimates – Yahoo Finance

    BlackSky Technology Inc. Reports Q2 Loss, Misses Revenue Targets

    Improved Technology Access: A Key to Closing the Healthcare Gap for African Americans – BIOENGINEER.ORG

    LMI Expands Technology Org, Appoints New Leaders – GovCon Wire

    LMI Expands Technology Team with Dynamic New Leadership Appointments

    Midland Innovation and Technology Charter School closing down – CBS News

    Midland Innovation and Technology Charter School Closes Permanently

    Future Trends In HR Technology – Dataconomy

    Future Trends In HR Technology – Dataconomy

    Trending Tags

    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • Mark Zuckerberg
No Result
View All Result
Earth-News
No Result
View All Result
Home Technology

CISA urges devs to weed out OS command injection vulnerabilities

July 11, 2024
in Technology
CISA urges devs to weed out OS command injection vulnerabilities
Share on FacebookShare on Twitter

CISA

​CISA and the FBI urged software companies on Wednesday to review their products and eliminate path OS command injection vulnerabilities before shipping.

The advisory was released in response to recent attacks that exploited multiple OS command injection security flaws (CVE-2024-20399, CVE-2024-3400, and CVE-2024-21887) to compromise Cisco, Palo Alto, and Ivanti network edge devices.

Velvet Ant, the Chinese state-sponsored threat actor that coordinated these attacks, deployed custom malware to gain persistence on hacked devices as part of a cyber espionage campaign.

“OS command injection vulnerabilities arise when manufacturers fail to properly validate and sanitize user input when constructing commands to execute on the underlying OS,” today’s joint advisory explains.

“Designing and developing software that trusts user input without proper validation or sanitization can allow threat actors to execute malicious commands, putting customers at risk.”

CISA advises developers to implement well-known mitigations to prevent OS command injection vulnerabilities at scale while designing and developing software products:

Use built-in library functions that separate commands from their arguments whenever possible instead of constructing raw strings fed into a general-purpose system command.
Use input parameterization to keep data separate from commands; validate and sanitize all user-supplied input.
Limit the parts of commands constructed by user input to only what is necessary.

Tech leaders should be actively involved in the software development process. They can do this by ensuring that the software uses functions that generate commands safely while preserving the command’s intended syntax and arguments.

Additionally, they should review threat models, use modern component libraries, conduct code reviews, and implement rigorous product testing to ensure the quality and security of their code throughout the development lifecycle.

CISA OS command injection tweet

“OS command injection vulnerabilities have long been preventable by clearly separating user input from the contents of a command. Despite this finding, OS command injection vulnerabilities—many of which result from CWE-78—are still a prevalent class of vulnerability,” CISA and the FBI added.

“CISA and FBI urge CEOs and other business leaders at technology manufacturers to request their technical leaders to analyze past occurrences of this class of defect and develop a plan to eliminate them in the future.”

OS command injection security bugs took the fifth spot in MITRE’s top 25 most dangerous software weaknesses, surpassed only by out-of-bounds write, cross-site scripting, SQL injection, and use-after-free flaws.

In May and March, two other “Secure by Design” alerts urged tech executives and software developers to weed out path traversal and SQL injection (SQLi) security vulnerabilities.

>>> Read full article>>>
Copyright for syndicated content belongs to the linked Source : BleepingComputer – https://www.bleepingcomputer.com/news/security/cisa-urges-devs-to-weed-out-os-command-injection-vulnerabilities/

Tags: CommandtechnologyUrges
Previous Post

What Is NVIDIA Reflex & Should You Enable It?

Next Post

ViperSoftX malware covertly runs PowerShell using AutoIT scripting

Icing‐related injuries in polar bears (Ursus maritimus) at high latitudes – Laidre – 2024 – Ecology – ESA Journals

Frozen Peril: The Devastating Impact of Icing Injuries on Polar Bears in the High Arctic

August 8, 2025
Carnegie Science Center launching new name in September – CBS News

Carnegie Science Center Unveils Exciting New Name This September

August 8, 2025
Petersburg youth explore Coho Creek for science education – Petersburg Pilot

Petersburg Youth Dive into Science with Hands-On Exploration of Coho Creek

August 8, 2025
Is there a path to healthier aging? What the latest research shows | Bodyworks – The Oklahoman

Is there a path to healthier aging? What the latest research shows | Bodyworks – The Oklahoman

August 8, 2025
MBU showcases student work at Occupational Therapy Technology Fair – WHSV

Discover the Most Innovative Student Projects at the Occupational Therapy Technology Fair

August 8, 2025
Official | Evann Guessand completes €35m Aston Villa move – Yahoo Sports

Official | Evann Guessand completes €35m Aston Villa move – Yahoo Sports

August 8, 2025
Trailer: Netflix Animation Welcomes Viewers to the Whimsical World of Dr. Seuss! – Animation Magazine

Trailer Unveils the Whimsical World of Dr. Seuss in Netflix Animation!

August 8, 2025
Spending on AI data centers is so massive that it’s taken a bigger chunk of GDP growth than shopping—and it could crash the American economy – Fortune

Spending on AI data centers is so massive that it’s taken a bigger chunk of GDP growth than shopping—and it could crash the American economy – Fortune

August 8, 2025
SPC Health Programs Showcase: Featuring Nursing, Radiography, and Surgical Services Degrees – St. Petersburg College

Explore Exciting Career Paths in Nursing, Radiography, and Surgical Services at SPC Health Programs Showcase

August 8, 2025
Top Trump officials discussed Epstein at White House meeting Wednesday night – CNN

Top Trump officials discussed Epstein at White House meeting Wednesday night – CNN

August 8, 2025

Categories

Archives

August 2025
MTWTFSS
 123
45678910
11121314151617
18192021222324
25262728293031
« Jul    
Earth-News.info

The Earth News is an independent English-language daily published Website from all around the World News

Browse by Category

  • Business (20,132)
  • Ecology (760)
  • Economy (783)
  • Entertainment (21,659)
  • General (16,347)
  • Health (9,822)
  • Lifestyle (793)
  • News (22,149)
  • People (784)
  • Politics (792)
  • Science (15,996)
  • Sports (21,280)
  • Technology (15,763)
  • World (765)

Recent News

Icing‐related injuries in polar bears (Ursus maritimus) at high latitudes – Laidre – 2024 – Ecology – ESA Journals

Frozen Peril: The Devastating Impact of Icing Injuries on Polar Bears in the High Arctic

August 8, 2025
Carnegie Science Center launching new name in September – CBS News

Carnegie Science Center Unveils Exciting New Name This September

August 8, 2025
  • About
  • Advertise
  • Privacy & Policy
  • Contact

© 2023 earth-news.info

No Result
View All Result

© 2023 earth-news.info

No Result
View All Result

© 2023 earth-news.info

Go to mobile version