HomeSecurityNCSC calls on vendors to eliminate vulnerabilities

NCSC calls on vendors to eliminate vulnerabilities

The UK's leading cybersecurity body (NCSC) has called on the industry to eradicate an entire category of vulnerabilities by implementing improved secure programming practices.

See also: Hackers exploit vulnerabilities in SimpleHelp RMM

NCSC vulnerabilities

The National Cybersecurity Center (NCSC) said in a post on Wednesday that it aims to eliminate so-called “ unforgivable vulnerabilities .” Its approach focuses on making it easier for vendors and developers to implement “ top-notch ” protections with greater ease and efficiency.

The code, which is expected to be published later this year, will start as a voluntary framework of practices. However, this could change in the future, noted Ollie N, head of vulnerability management at the NCSC.

At the same time, the NCSC has released a new document that aims to make it easier for security researchers to evaluate vulnerabilities, dividing them into “forgivable” and “unforgivable.” The aim of this initiative is to strengthen market pressure for improved security.

He explained that some vulnerabilities simply shouldn't exist in the software because the mitigations are simple to implement.

See also: Critical Fleet Server vulnerability exposes sensitive information

CVEs are increasing annually to record highs as the global code base grows and both researchers and malicious actors get better at finding flaws.

NCSC calls on vendors to eliminate vulnerabilities

However, although the challenges this represents for end-user organizations could be significantly mitigated if the unforgivable vulnerabilities were addressed at their root, the market simply does not currently have the incentive to do so, the NCSC argued.

In his annual review, he complained about the prioritization of new features over security in the software industry.

“This document intends to generate discussion with vendors and invites them to work on eliminating vulnerability classes and making the top-level mitigations discussed in the document easier to implement.“

See also: Hackers exploit old vulnerabilities in Ivanti CSA

Security vulnerabilities are weaknesses or flaws in software, hardware, or organizational processes that can be exploited by malicious actors to gain unauthorized access to systems, data, or networks. These vulnerabilities can come from outdated software, misconfigurations, or inadequate access controls. Addressing security vulnerabilities requires proactive measures, such as regular updates, vulnerability assessments, and implementing strong security protocols to mitigate potential risks.

Source: infosecurity-magazine

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS