• Big Story
  • News
    • News
    • Consumer Technology
    • Market Updates
    • Technology Insights
  • Interviews
  • Opinion
  • Digital Transformation Series
  • Special Reports
    • MWC Africa
    • Nigeria 5G Spectrum Auction
Thursday, May 14, 2026
  • Login
  • Register
Technology Times | Latest and Breaking Nigeria Tech News
No Result
View All Result
Technology Times | Latest and Breaking Nigeria Tech News
No Result
View All Result
Technology Times | Latest and Breaking Nigeria Tech News
No Result
View All Result
Your text
Remita Remita Remita
ADVERTISEMENT

FBI, CISA warn software makers of flaws exploited by cybercriminals

Fejiro AwowedebyFejiro Awowede
13/02/2025
in News
Reading Time: 4 mins read
1 0
A A
0
fbi-cisa-warn-software-makers-of-security-flaws

The US Federal Bureau of Investigation (FBI) and Cybersecurity and Infrastructure Security Agency (CISA) have jointly alerted software manufacturers to address buffer overflow vulnerabilities in their products.

ADVERTISEMENT

The US Federal Bureau of Investigation (FBI) and Cybersecurity and Infrastructure Security Agency (CISA) have jointly alerted software manufacturers to address buffer overflow vulnerabilities in their products.

These vulnerabilities, which cybercriminals frequently exploit to gain unauthorised access to systems, occur when a program writes more data to a buffer than it can hold, and can lead to system crashes or allow attackers to execute malicious code.

vbr-ngcert-warns-of-critical-ransomware-attacks
The Cybersecurity and Infrastructure Security Agency (CISA) and the Federal Bureau of Investigation (FBI) have issued a joint alert urging software manufacturers to address buffer overflow vulnerabilities in their products. Image credit: Gencraft.

“The software development community has twenty years of extensive knowledge and effective solutions for buffer overflows—however, many software manufacturers continue to expose customers to products with these vulnerabilities,” the alert says.

“The software development community has twenty years of extensive knowledge and effective solutions for buffer overflows—however, many software manufacturers continue to expose customers to products with these vulnerabilities,” the alert says. It describes buffer overflow vulnerabilities as a critical subset of memory safety flaws that cybercriminals frequently exploit to gain unauthorized access to systems.

What are buffer overflow vulnerabilities?

According to CISA and the FBI, buffer overflow vulnerabilities “arise when threat actors access or write information in the wrong part of a computer’s memory (i.e., outside the memory buffer).”

A buffer overflow occurs when a program writes more data to a memory buffer than it can hold, causing data to overflow into adjacent memory locations. This can lead to system crashes, data corruption, or, in more severe cases, allow attackers to execute malicious code. 

According to CISA and the FBI, these vulnerabilities can be categorised into two main types:

  • Stack-based buffer overflows (CWE-121): These occur when excess data is written to a memory stack, potentially allowing attackers to overwrite critical program variables and execute arbitrary code.
  • Heap-based buffer overflows (CWE-122): These occur when data overflows into dynamically allocated memory, which can be harder to detect and exploit but still pose a significant security threat.

FBI, CISA on why vulnerabilities dangerous?

Threat actors often use buffer overflow vulnerabilities as an entry point to infiltrate systems and move laterally across networks. Exploiting these vulnerabilities can allow attackers to:

  • Gain unauthorized access to sensitive data.
  • Install and execute malicious software.
  • Corrupt system memory, leading to application crashes or erratic behavior.
  • Bypass security mechanisms such as authentication protocols.

CISA and the FBI say that the continued use of unsafe software development practices, particularly the reliance on memory-unsafe programming languages like C and C++, is a major factor in the persistence of these vulnerabilities. “Despite the existence of well-documented, effective mitigations for buffer overflow vulnerabilities, many manufacturers continue to use unsafe software development practices that allow these vulnerabilities to persist,” the agencies warn.

Cybersecurity researchers have identified several buffer overflow vulnerabilities in widely used software. For instance, vulnerabilities like CVE-2025-21333 and CVE-2025-0282 were recently reported. Additionally, in early 2024, vulnerabilities in the Autel MaxiCharger electric vehicle (EV) charger (CVE-2024-23967, CVE-2024-23957) were exploited due to improper handling of encoded data, leading to potential remote code execution.

Related Articles

Nigeria targets 30% growth in .ng domain adoption amid reforms, NiRA says

CAC says company records remain secure after cyber incident, denies data compromise

CBN raises urgent alarm over phishing scams targeting Nigerians

Minister convenes cybersecurity advisory council session today

Nigeria wants African nations to align digital strategy on AI, cybersecurity

Ouranos taps finance, HR, and strategy expertise to power board

Nigeria cannot secure cyberspace by enforcement alone, AGF Fagbemi warns

Nigeria Police arrest suspects in Microsoft 365 phishing crackdown

Nigeria‘s digital health drive to boost access, FG says

Interpol seeks Nigerian, global experts to tackle AI Deepfake threats

Recommendations for software developers

CISA and the FBI are urging software manufacturers to adopt secure by design principles and take proactive steps to eliminate buffer overflow vulnerabilities. The alert outlines several key recommendations:

  1. Use memory-safe languages:
    • Where feasible, developers should transition to programming languages that inherently prevent buffer overflows, such as PERL, Swift, or Java.
    • “We recommend manufacturers develop and implement a phased transition plan for increasing memory-safe language usage,” the alert advises.
  2. Enable compiler-based protections:
    • Software teams should enable compiler flags that enforce buffer overflow protections and utilize stack canaries, which detect and prevent stack-based overflows.
  3. Regularly run tests:
    • The use of AddressSanitizer and MemorySanitizer during development can help detect memory safety issues before they become vulnerabilities.
    • Regular security audits, static analysis, and fuzz testing should be integrated into the software development lifecycle.
  4. Enhance transparency and accountability:
    • Software vendors should publish a memory-safety roadmap outlining their strategy for mitigating vulnerabilities.
    • “Conduct root cause analysis of past vulnerabilities, including buffer overflows, to spot trends and patterns. Where possible, take actions to eliminate entire classes of vulnerabilities across products, rather than the superficial causes,” the alert states.

CISO and the FBI say consumers should “demand that software is secure by design. Organisations looking to acquire software that is secure by design should refer to our Secure by Demand guidance and incorporate the following product security considerations into their procurement lifecycle:

Before procurement: Ask questions to understand how each software manufacturer ensures product security. 

During procurement: Integrate the organisation’s product security requirements into contract language.

Following procurement: Continually assess product security and security outcomes.”

The Secure by Design initiative, spearheaded by CISA and other global cybersecurity agencies, seeks to foster a cultural shift in the technology industry. This initiative urges companies to prioritise security at the outset of the software development life cycle rather than relying on post-deployment patches. “Products that are secure by design reasonably protect against malicious cyber actors exploiting the most common and dangerous classes of product defect,” the alert says.

Large tech companies, including Google, Microsoft, Amazon Web Services (AWS), and Mozilla, have already begun transitioning to memory-safe languages in critical areas. Google’s Android team, for example, started using Rust in 2019, significantly reducing memory safety vulnerabilities in Android OS. Google in a blog post revealed that “the percentage of memory safety vulnerabilities in Android dropped from 76% to 24% over 6 years as development shifted to memory safe languages.”

Stay ahead with real-time reports, breaking news, and exclusive insights delivered directly to your phone. Don't settle for outdated information. Join TECHNOLOGYTIMES NEWS on WhatsApp for 24/7 updates.

Join Our Whatsapp Channel
Tags: cyber attackscybersecuritycybersecurity and infrastructure security agencyFBIFederal Bureau of Investigation
Share26Tweet16Share5SendShare
Previous Post

CNF slams new ATM fees by CBN

Next Post

Apple TV app debuts on Android

Fejiro Awowede

Fejiro Awowede

Technology Times Reporter

Related Posts

Basil Udotai (standing), speaks on cyber threat issues at the Technology Times Outlook Review of Nigeria Cybercrimes Act 2015, held recently in Lagos.
News

Kaspersky: Businesses pay premium for cybersecurity breaches

byKayode Oladeinde
25/08/2015
Basil Udotai (standing), speaks on cyber threat issues at the Technology Times Outlook Review of Nigeria Cybercrimes Act 2015, held recently in Lagos.
News

FBI: Forensic tech given EFCC ‘aids Nigeria cybercrime war’

byKayode Oladeinde
30/08/2015
cbn-raises-urgent-alarm-over-phishing-scams
News

CBN raises urgent alarm over phishing scams targeting Nigerians

byOladapo Riliwan
22/04/2026
Mr Emmanuel Asika, HP Nigeria Country Head says employees are critical part of organisations' plans to address cybersecurity.
Opinion

Cybersecurity:- Why employee collaboration is key 

byTechnology Times Contributor
30/03/2023
Cybersecurity: Telecoms industry tops target of cyber attacks in 2024
News

Cybersecurity: Telecoms industry tops target of cyber attacks in 2024

byFejiro Awowede
05/08/2024
nitda-tackles-nigeria-cybersecurity-skills-gap
News

NITDA seeks to address Nigeria’s cybersecurity skills gap, DG says

byOladapo Riliwan
18/10/2024
Udotai advocates ‘single law enforcement’ for cybercrimes in Nigeria
News

Udotai advocates ‘single law enforcement’ for cybercrimes in Nigeria

byKolade Akinola
24/08/2015
ai-will-empower-workers-ai-experts-say
News

AI will empower, not replace workers, AI experts say at Zenith Bank Tech Fair 2024

byOladapo Riliwan
26/11/2024
News

Cyber attackers defaced 23 government websites in 2012, security firm says

byTechnology Times Staff
20/02/2013
banire-govt-private-to-fix-cybercrime-nigeria
News

Banire seeks govt-private sector tie to check cybercrime in Nigeria

byFejiro Awowede
24/09/2024
Next Post
Apple TV app debuts on Android

Apple TV app debuts on Android

mtn-nigeria-apologises-for-price-increase

'Forgive and forget': MTN Nigeria apologises for price increase 'mistake'

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

I agree to the Terms & Conditions and Privacy Policy.

one × 1 =

Latest Articles

nucap-nigeria-drives-rural-broadband-expansion

NUCAP: Nigeria dangles $35 million offer for 10% of SPV to drive rural broadband expansion

13/05/2026
google-unveils-gemini-intelligence-to-bring-ai

Google unveils Gemini Intelligence to bring AI-powered automation to Android devices

13/05/2026
fg-3mtt-tie-10m-hello-cv-partnership-nigeria

FG, 3MTT tie $10m Hello.cv partnership for Nigerian tech talent

12/05/2026
national-research-and-innovation-development-fund

FEC approves National Research and Innovation Development Fund to boost Nigeria’s tech ecosystem

12/05/2026
nigeria-launches-cooperative-digitisation

Nigeria launches cooperative digitisation drive with planned Cooperative Bank

12/05/2026
ADVERTISEMENT
CrownCrystal Technologies CrownCrystal Technologies CrownCrystal Technologies
ADVERTISEMENT
ADVERTISEMENT

Most Read

  • minister-orders-telcos-to-fix-telecoms-quality

    Minister orders telcos to fix network quality, wants NCC to tighten telecoms enforcement

    68 shares
    Share 27 Tweet 17
  • Babymomsi: FemTech startup seeks investors for baby tracking app 

    101 shares
    Share 40 Tweet 25
  • NUCAP: Nigeria dangles $35 million offer for 10% of SPV to drive rural broadband expansion

    63 shares
    Share 25 Tweet 16
  • For the first time, Airtel Africa’s data revenue surpasses voice calls

    63 shares
    Share 25 Tweet 16
  • China Mobile makes local traffic debut in Nigeria as world’s largest mobile operator connects IXPN

    76 shares
    Share 30 Tweet 19
  • FG, 3MTT tie $10m Hello.cv partnership for Nigerian tech talent

    60 shares
    Share 24 Tweet 15
  • Nigeria’s data consumption hits 4 million terabytes in Q1 2026

    79 shares
    Share 32 Tweet 20
  • Enugu Gaming Conference 2026 spotlights Nigeria’s iGaming tech future

    58 shares
    Share 23 Tweet 15
  • SEC: e-Dividend portal upgrade tackles unclaimed dividends

    331 shares
    Share 132 Tweet 83
  • Health Ministry advances plan for gene-based medicine in Nigeria

    57 shares
    Share 23 Tweet 14
eGovernance Nigeria Magazine eGovernance Nigeria Magazine eGovernance Nigeria Magazine
ADVERTISEMENT

Latest Videos

  • TT TV
data-privacy-and-nigerias-online-consumers

Data privacy and Nigeria’s online consumers | Technology Times Live TV

11/08/2025
9mobile Rebranding Livestream | Technology Meets Tenacity | Technology Times Live

9mobile Rebranding Livestream | Technology Meets Tenacity | Technology Times Live

08/08/2025
teniola-advocates-dynamic-billing-for-nigerians

Teniola advocates dynamic billing to protect Nigerian consumers | Technology Times Policy eXchange

14/04/2025
watch-mtn-nigeria-board-lawsuit-interview

#Watch: MTN Nigeria’s board is filled with ex-regulators—is this a conflict of interest?

24/03/2025
engr-banjo-on-local-content-in-nigeris-telecoms

Watch: Engr. Banjo on local content in Nigeria’s telecoms market

23/03/2025
Load More
Facebook Twitter Youtube LinkedIn RSS

ABOUT TECHNOLOGY TIMES

technology-times-logo

Nigeria Technology Media Group

Founded in 2004, Technology Times’ trusted technology news, market intelligence, views and business services reach readers and partners across Nigeria, Africa and beyond.

Advertising

Sign up for TT eNews

Get in touch here

CONTACT US

WhatsApp: +234 201 454 1818
WhatsApp: +234 815 700 0100
Email: info@technologytimes.ng
Web: www.technologytimes.ng

LEGAL & COMPLIANCE

technology-times-logoHome

TT Privacy Policy

TT Terms & Conditions

TT Website Disclaimer

TT Guest Post Guidelines

TT Sitemap

VOffice

  • credicorp-portal-for-nigeria-consumer-credit

    CREDICORP: FG opens portal on www.credicorp.ng for Nigerians to access consumer credit

    15747 shares
    Share 6299 Tweet 3937
  • CUG: NCC caps call rate at ₦50, bans data bundling

    5065 shares
    Share 2026 Tweet 1266
  • 9mobile rebrands today, targets multibillion-naira comeback in mobile market

    4424 shares
    Share 1770 Tweet 1106
  • Exclusive: Boardroom battle erupts at 9mobile, threatens spectrum trade deal with MTN

    3893 shares
    Share 1557 Tweet 973

©2004-2025 Technology Times, owned and operated by Digital Transformation Media Limited (DTML), Nigeria or its affiliates. All rights reserved.

Welcome Back!

Sign In with Facebook
Sign In with Google
OR

Login to your account below

Forgotten Password? Sign Up

Create New Account!

Sign Up with Facebook
Sign Up with Google
OR

Fill the forms below to register

*By registering into our website, you agree to the Terms & Conditions and Privacy Policy.
All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

No Result
View All Result
  • Big Story
  • News
    • News
    • Consumer Technology
    • Market Updates
    • Technology Insights
  • Interviews
  • Opinion
  • Digital Transformation Series
  • Special Reports
    • MWC Africa
    • Nigeria 5G Spectrum Auction
  • Login
  • Sign Up

©2004-2025 Technology Times, owned and operated by Digital Transformation Media Limited (DTML), Nigeria or its affiliates. All rights reserved.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy Policy Page.