In short, companies need to adopt a “secure by design” policy and fast.

CISApreviously warnedabout buffer overflow vulnerabilities and is now reiterating its message.

However, CISA noted that only a few companies have implemented this approach so far.

US cyber defense agency urges developers to eliminate buffer overflow vulnerabilities

The agency outlined several “secure by design” practices that technical leads should adopt within their organizations.