WaterISAC Navigation
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
Home H2OSecCon 2026 CISA Alert - CISA and FBI Release Secure by Design Alert on Eliminating Cross-Site Scripting Vulnerabilities
Become a Member

Log in

  • Upcoming Events
  • Resource Center
  • Tools
  • Webcasts
  • Contaminant Databases
  • Community Partners
  • About
  • Log in

  • My Account

  • Logout

  • Report Incident
  • Contact Us
  • NRWA Signup
  • WaterISAC Champions
More Resources

CISA Alert – CISA and FBI Release Secure by Design Alert on Eliminating Cross-Site Scripting Vulnerabilities

Author: Chase Snow

Created: Tuesday, September 17, 2024 - 17:36

Categories: Cybersecurity, Federal & State Resources, Security Preparedness

Today, CISA and the FBI issued another Secure by Design Alert this time focused on Eliminating Cross-Site Scripting (XSS) Vulnerabilities. This is part of an ongoing initiative to significantly reduce the prevalence of various vulnerability types. While XSS vulnerabilities are preventable and should not be present in new software products, they are still being discovered offering opportunities for exploitation by threat actors.

This acts as a reminder for all organizations implementing new software, including utilities, that XSS vulnerabilities persist.

CISA urges technology manufacturers to instruct their technical teams to review previous occurrences of these vulnerabilities and develop strategic plans to prevent them in the future. Visit CISA’s Secure by Design webpage for more information and access the full alert at CISA.

Related Resources

Members Only

(TLP:AMBER) DHS Office of Intelligence and Analysis Reports (May 21, 2026)

May 21, 2026 in Cybersecurity, Federal & State Resources, Security Preparedness

(TLP:CLEAR) Weekly Vulnerabilities to Prioritize – May 21, 2026

May 21, 2026 in Cybersecurity, Security Preparedness
Members Only

(TLP:GREEN) PEAR Ransomware Claims U.S. Drinking Water Utility as Victim

May 21, 2026 in Cybersecurity, Security Preparedness

Become a Member
FAQs
About
Report Incident

Terms & Conditions
Privacy Policy
AI Policy
Contact Us

LinkedIn

1250 I Street NW, Suite 350
Washington, DC 20005
1-866-H2O-ISAC (1-866-426-4722)
© 2026 WaterISAC. All Rights Reserved.

Toggle the Widgetbar