• News/
  • https://www.theregister.com/2024/03/26/fbi_cisa_sql_injection/

Uncle Sam's had it up to here with 'unforgivable' SQL injection flaws

The Register
·
Connor Jones
·
Published Mar 26, 2024
·
Updated

The US has clearly had enough of software vendors shipping products with "unforgivable" vulnerabilities, and is now urging them to launch formal code reviews to stamp out SQL injection flaws. The Federal Bureau of Investigation (FBI) and Cybersecurity and Infrastructure Security Agency (CISA) issued a Secure by Design Alert on Monday, reminding the tech community that there is no excuse for the decades-old vulnerability type to still be causing issues today. They cited the MOVEit supply chain attacks from last year, ones enabled by a SQL injection zero day, as an example of the damage such issues can cause. Defunct ransomware and extortion outfit Cl0p was responsible for the MOVEit MFT attacks last year. Cybersecurity biz Emsisoft set up a web page to track the number of victims and despite Progress Software releasing patches fairly quickly, the group was responsible for breaches at 2,769 organizations, as of this week's data. This meant that around 95 million individuals have been affected so far. The call from authorities extends to software vendors' customers too. They've been advised to hold their vendors to account by asking them if a formal code review into a product's susceptibility to SQL injection exploits has occurred and what mitigations have been put in place. SQL injection vulnerabilities exist where developers allow user-input data to be supplied to a database directly as a SQL command. This can then lead to all manner of nastiness, including the modification or...

Read full article

Affected Software

1 affected component
Progress Software MOVEit MFT

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses the US government's stance on addressing persistent SQL injection vulnerabilities in software products.

2

What security implications are discussed in the article?

The article highlights the risks associated with SQL injection flaws, which can lead to data breaches and unauthorized access.

3

What products or software are affected?

The article specifically mentions Progress Software's MOVEit MFT product as being impacted by SQL injection vulnerabilities.

4

What action is the FBI recommending to software vendors?

The FBI is urging software vendors to conduct formal code reviews to eliminate SQL injection flaws.

5

Why does the article describe SQL injection flaws as 'unforgivable'?

The article characterizes SQL injection flaws as 'unforgivable' due to their prevalence and potential for significant security breaches.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203