
"CISA and NSA Unveil Top Cybersecurity Misconfigurations Threatening US Security"
The US Cybersecurity and Infrastructure Security Agency (CISA) and the National Security Agency (NSA) have identified unchanged default credentials as the top cybersecurity misconfiguration that leads to cyberattacks. The agencies' top ten major cybersecurity misconfigurations also include improper separation of user and admin privileges and insufficient network monitoring. The cybersecurity advisory (CSA) released by CISA aims to encourage software manufacturers to adopt secure-by-design and secure-by-default principles throughout the development cycle. The CSA highlights the importance of addressing systemic weaknesses in organizations and emphasizes the need for software manufacturers to reduce the burden on network defenders.