CISA urges software devs to weed out path traversal vulnerabilities
ID: 6e2e668f-a577-5dcc-9cc8-e1806b56a06e
STIX ID: report--6e2e668f-a577-5dcc-9cc8-e1806b56a06e
Feed Name: Bleeping Computer
Threat Score
CISA and the FBI issued a Secure by Design alert urging software manufacturers to eliminate directory traversal (path traversal) vulnerabilities after recent exploitation in critical infrastructure; the notice cites CVE-2024-1708 and CVE-2024-20345 and links exploitation to ransomware campaigns (Black Basta, Bl00dy) that chained traversal with authentication bypasses to deliver Cobalt Strike and LockBit variants, and recommends concrete mitigations for developers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
