DefSec Wire
  • Home
  • Defense
    • Army
    • Marine Corps
    • Navy
    • Air Force
    • Space Force
  • Air
  • Land
  • Sea
  • Space
  • Cyber
  • Industry
  • Security
No Result
View All Result
  • United States flag United States
  • Australia flag Australia
  • United Kingdom flag United Kingdom
  • Europe flag Europe
  • New Zealand flag New Zealand
  • Canada flag Canada
DefSec Wire
  • Home
  • Defense
    • Army
    • Marine Corps
    • Navy
    • Air Force
    • Space Force
  • Air
  • Land
  • Sea
  • Space
  • Cyber
  • Industry
  • Security
No Result
View All Result
DefSec Wire
No Result
View All Result
Home Security

NSA and CISA release guidance urging memory-safe languages to strengthen software security

Lila Carvello by Lila Carvello
October 12 2025
in Security
0
172
SHARES
2.5k
VIEWS
Share on LinkedInFacebookTwitter

The National Security Agency and the Cybersecurity and Infrastructure Security Agency are urging software makers to adopt memory-safe programming languages, publishing new joint guidance designed to curb a leading source of security flaws.

The Cybersecurity Information Sheet outlines how languages that enforce memory safety can block entire classes of bugs that attackers routinely exploit. The document explains that these languages build in guardrails—including automatic memory management, bounds checks and protections against data races—so developers don’t have to implement them by hand.

You Might Also Like

NSA and allies warn of Russian state-backed cyber campaign targeting Western logistics and tech firms

NSA’s AISC issues joint guidance on AI data security risks and best practices

The guidance emphasizes practical migration paths. Rather than mandating wholesale rewrites, it recommends incremental adoption, interoperability with existing codebases, and targeted refactoring of high-risk components. For organizations that must continue using languages without built-in memory safety, the paper also describes ways to harden those environments and reduce exposure.

Beyond security, the agencies say teams can expect gains in reliability and developer productivity when they move to memory-safe tooling. The paper includes examples and case studies to illustrate the impact and tradeoffs.

The release targets a broad audience but singles out software producers that support National Security Systems and critical infrastructure, urging them to begin planning for memory-safe development as part of their long-term engineering roadmaps.

Memory safety issues have historically accounted for a large share of serious software vulnerabilities across the industry, contributing to breaches, crashes and service disruptions. The agencies frame language choice as a foundational control that can prevent these failures before they reach production.

The full report, Memory Safe Languages: Reducing Vulnerabilities in Modern Software Development, is available on the Department of Defense website: http://media.defense.gov/2025/Jun/23/2003742198/-1/-1/0/CSI_MEMORY_SAFE_LANGUAGES_REDUCING_VULNERABILITIES_IN_MODERN_SOFTWARE_DEVELOPMENT.PDF

Tags: Cybersecurity and Infrastructure Security AgencyNational Security AgencyNational Security Systems
Previous Post

NSA, CISA, FBI and DC3 warn Iranian hackers may target vulnerable U.S. networks and high-value entities

Next Post

NSA and Australia’s ACSC, with partner agencies, issue three cybersecurity information sheets on SIEM and SOAR

Lila Carvello

Lila Carvello

Lila Carvello is a journalist reporting on security and intelligence in the United States and abroad. She focuses on global defence, espionage and national security developments shaping international relations.

Related News

NSA and allies warn of Russian state-backed cyber campaign targeting Western logistics and tech firms

by Lila Carvello
October 12 2025
0

The National Security Agency and a group of U.S. and foreign partners issued a cybersecurity advisory warning that Russia’s military...

NSA’s AISC issues joint guidance on AI data security risks and best practices

by Lila Carvello
October 12 2025
0

Fort Meade, Md. — The National Security Agency’s Artificial Intelligence Security Center has issued a joint cybersecurity information sheet aimed...

NSA and Australia’s ACSC, with partner agencies, issue three cybersecurity information sheets on SIEM and SOAR

by Lila Carvello
October 12 2025
0

FORT MEADE, Md. — The National Security Agency has teamed with Australia’s cyber authority and a broad coalition of allied...

NSA, CISA, FBI and DC3 warn Iranian hackers may target vulnerable U.S. networks and high-value entities

by Lila Carvello
October 12 2025
0

Fort Meade, Md. — Four U.S. government agencies have issued a joint advisory warning that cyber actors aligned with Iran’s...

Next Post

NSA and Australia’s ACSC, with partner agencies, issue three cybersecurity information sheets on SIEM and SOAR

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Trending News

Army broadens eligibility for combat patches

Army broadens eligibility for combat patches

October 1 2025

DCSA director touts DOD, industry, academia and government partnership with America’s Gatekeeper to protect the nation’s trusted workforce, spaces and secrets

October 12 2025
Army cuts training mandates to boost combat readiness

Army cuts training mandates to boost combat readiness

October 1 2025

About

DefSec Wire reports on the news that matters in the Defence, Security and Intelligence industries across the United States and the world.

Our Network

  • DefSec Wire
  • DefSec Wire Australia
  • DefSec Wire UK
  • DefSec Wire Europe
  • DefSec Wire New Zealand
  • DefSec Wire Canada

Categories

  • Air Force
  • Army
  • Defense
  • Marine Corps
  • Navy
  • Security
  • Space Force
  • Uncategorized

Tags

Air Air Combat Command Air Force AN/SPY-6(V)1 Air and Missile Defense Radar Army B-21 Carrier Strike Groups Chance Saltzman Congress Cybersecurity and Infrastructure Security Agency David Allvin Defense Counterintelligence and Security Agency Defense Intelligence Agency Department-Level Exercise Department of Defense Department of the Air Force Eric M. Smith FBI Flashpoint Fleet Marine Force Force Design GEOINT Indo-Pacific John Bentivegna Kevin Schneider Marine Corps National Background Investigation Services National Geospatial-Intelligence Agency National Security Agency National Security Systems Navy Off Duty Pacific Air Forces Pentagon Space and Cyber Conference Space Delta Space Training and Readiness Command Special Forces STARCOM Submarine Troy Meink U.S. Air Force U.S. Army U.S. Fleet Forces Command U.S. Navy

Recent Posts

  • NSA and allies warn of Russian state-backed cyber campaign targeting Western logistics and tech firms
  • NSA’s AISC issues joint guidance on AI data security risks and best practices
  • NSA and Australia’s ACSC, with partner agencies, issue three cybersecurity information sheets on SIEM and SOAR
  • NSA and CISA release guidance urging memory-safe languages to strengthen software security
  • NSA, CISA, FBI and DC3 warn Iranian hackers may target vulnerable U.S. networks and high-value entities
  • About Us
  • Terms of Service
  • Privacy Policy
  • Advertise
  • Contact

© 2025 DefSec Wire – part of the DefSec Wire Group.

No Result
View All Result
  • Home
  • Defense
    • Army
    • Marine Corps
    • Navy
    • Air Force
    • Space Force
  • Air
  • Land
  • Sea
  • Space
  • Cyber
  • Industry
  • Security

© 2025 DefSec Wire – part of the DefSec Wire Group.