The US has clearly had enough of software vendors shipping products with "unforgivable" vulnerabilities, and is now urging them to launch formal code reviews to stamp out SQL injection flaws. The Federal Bureau of Investigation (FBI) and Cybersecurity and Infrastructure Security Agency (CISA) issued a Secure by Design Alert on Monday, reminding the tech community that there is no excuse for the decades-old vulnerability type to still be causing issues today. They cited the MOVEit supply chain attacks from last year, ones enabled by a SQL injection zero day, as an example of the damage such issues can cause. Defunct ransomware and extortion outfit Cl0p was responsible for the MOVEit MFT attacks last year. Cybersecurity biz Emsisoft set up a web page to track the number of victims and despite Progress Software releasing patches fairly quickly, the group was responsible for breaches at 2,769 organizations, as of this week's data. This meant that around 95 million individuals have been affected so far. The call from authorities extends to software vendors' customers too. They've been advised to hold their vendors to account by asking them if a formal code review into a product's susceptibility to SQL injection exploits has occurred and what mitigations have been put in place. SQL injection vulnerabilities exist where developers allow user-input data to be supplied to a database directly as a SQL command. This can then lead to all manner of nastiness, including the modification or...
Uncle Sam's had it up to here with 'unforgivable' SQL injection flaws
The Register
·Connor Jones
·Published Mar 26, 2024
·Updated
Affected Software
1 affected component
Progress Software MOVEit MFT
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses the US government's stance on addressing persistent SQL injection vulnerabilities in software products.
2
What security implications are discussed in the article?
The article highlights the risks associated with SQL injection flaws, which can lead to data breaches and unauthorized access.
3
What products or software are affected?
The article specifically mentions Progress Software's MOVEit MFT product as being impacted by SQL injection vulnerabilities.
4
What action is the FBI recommending to software vendors?
The FBI is urging software vendors to conduct formal code reviews to eliminate SQL injection flaws.
5
Why does the article describe SQL injection flaws as 'unforgivable'?
The article characterizes SQL injection flaws as 'unforgivable' due to their prevalence and potential for significant security breaches.