← Back to advisories & guidance
January 31, 2024
CISA
Alert
Co-sealed by: CISA, FBI
Summary
Today, CISA and the Federal Bureau of Investigation (FBI) published guidance on Security Design Improvements for SOHO Device Manufacturers as a part of the new Secure by Design (SbD) Alert series that focuses on how manufacturers should shift the burden of security away from customers by integrating security into product design and development. Eliminate exploitable defects—during the product design and development phases—in SOHO router web management interfaces (WMIs). Adjust default device configurations in a way that: Automates update capabilities. CISA and FBI also urge manufacturers to protect against Volt Typhoon activity and other cyber threats by disclosing vulnerabilities via the Common Vulnerabilities and Exposures (CVE) program as well as by supplying accurate Common Weakness Enumeration (CWE) classification for these vulnerabilities. The Alert also urges manufacturers to implement incentive structures that prioritize security during product design and development. Build organizational structure and leadership to achieve these goals.
News Coverage
No coverage found in monitored research blogs or news feeds.
CVEs Referenced in This Publication
No CVEs are referenced in this publication.
Vendors Named in This Publication
No KEV-catalogued vendors are named in this publication.