CISA urges tech makers: Ditch default passwords for safer devices!

December 19, 2023
1 min read

Recently, the Cybersecurity and Infrastructure Security Agency (CISA) has requested technology device manufacturers to take measures to eliminate default passwords due to the threats posed by IRGC actors. The use of default passwords makes it easier for hackers to gain access to devices and exploit them for nefarious purposes.

The critical infrastructure of the United States was recently targeted by threat actors who were successful in their attempts to exploit it. The attackers were able to gain access to the infrastructure by exploiting static default passwords.

Based on recent and continuing threat activity, CISA is issuing an alert to require all technology manufacturers to remove default passwords from all product designs, releases, and updates. Evidence has shown that it is insufficient to rely on consumers to change their passwords, and action by technology manufacturers is necessary to effectively address the threats.

To address the problem of default passwords, manufacturers are urged to:

  • Provide instance-unique setup passwords with the product.
  • Establish time-limited setup passwords that require activation of more secure authentication methods, including phishing-resistant MFA, and disable themselves after the setup process.

Manufacturers should also ensure that design and development teams engineer products with built-in security and safety by default.

This request by CISA highlights the importance of maintaining strong security measures and regularly updating passwords to prevent unauthorized access to critical infrastructure systems. It also emphasizes the need for manufacturers to take responsibility for the security of their devices and eliminate default passwords.

Latest from Blog

Bridging the cyber talent gap: tips for CISOs

TLDR: – Global cyber threats have increased twofold in recent years, leading to a talent gap of nearly 4 million cyber professionals worldwide. – Existing cyber staff are under strain, with vacancies

North Korean hackers pivot to ransomware attacks

TLDR: North Korean hackers from APT45 have shifted from cyber espionage to ransomware attacks APT45 has targeted critical infrastructure and is linked to ransomware families SHATTEREDGLASS and Maui A North Korea-linked threat

Cyber insurance evolves to cover all your online needs

TLDR: Cyber insurance coverage is evolving to help raise security baselines across businesses. Only one-quarter of companies have a standalone cyber insurance policy. In today’s evolving cybersecurity landscape, cyber insurance coverage is