A Look at Qatar’s Infrastructure Construction Through Cyberspace Surveying and Mapping Technology

November 28, 2022 | Adeline Zhang

As the 2022 FIFA World Cup kicked off on Sunday, Nov 20, 2022, no country can be more notable than Qatar these days. In this article, we will get you familiar with the host nation Qatar, and show you its infrastructure construction level through analysis of cyberspace services. Qatar and the FIFA 2022 World Cup […]

The Increasingly Complex and Varied Vectors to Attack Software Supply Chain

November 23, 2022 | Adeline Zhang

Unlike vulnerability exploitation in products, attack vectors and implementation channels targeting the supply chain in the real environment are more diverse. Due to the advantages of low development cost, the widespread use of open-source components in projects has become the mainstream development method. The conflict between a rule-relaxed open community and limited maintenance resources provides […]

Atlassian Bitbucket Server and Data Center Command Injection Vulnerability (CVE-2022-43781) Alert

November 23, 2022 | Jie Ji

Overview Recently, NSFOCUS CERT found that Atlassian officially fixed a command injection vulnerability in Bitbucket Server and Data Center. Due to flaws in Bitbucket Server and Data Center, attackers with user name control rights can implement command injection through environment variables, and eventually cause commands to be executed arbitrarily on the system. The CVSS score […]

Apache Airflow Remote Code Execution Vulnerability (CVE-2022-40127)

November 22, 2022 | Jie Ji

Overview On November 21, NSFOCUS CERT discovered on Internet a PoC of a remote code execution vulnerability (CVE-2022-40127) in Apache Airflow. Due to the flaw in Example Dags in Apache Airflow, an attacker with UI access rights can use this vulnerability to trigger Dags, and then by manually providing the run_id parameter, attacker can execute […]

API Protection: The New Focus in the Web Application Firewall Market

November 21, 2022 | Adeline Zhang

Application programming interfaces (APIs) have become a role that can’t be ignored in digital transformation, whether in application modernization or agile business strategies. At the application development stage, APIs are standard service interfaces. When it comes to interfacing with third-party services, APIs are a common choice. In the microservice architecture, APIs are an integral part […]

NSFOCUS Named a Representative Vendor by Gartner® in the Report of Tool: Vendor Identification for Data Loss Prevention 2022

November 18, 2022 | Adeline Zhang

NSFOCUS has been recognized as one of the Representative Vendors in the Report of Tool: Vendor Identification for Data Loss Prevention 2022 1. The COVID-19 pandemic has accelerated the process of digital transformation. With the vigorous development of digital economy and information industry, the rapid implementation and application of 5G, zero trust, AI, and blockchain […]

NSFOCUS Recognized by Gartner in Hype Cycle for Security in China, 2022

November 17, 2022 | Adeline Zhang

Gartner® recently published the report of Hype Cycle™ for Security in China, 2022. NSFOCUS has been named a Sample Vendor for situational awareness and 7 other technologies, which NSFOCUS believes validates its innovation and latest practice in security management and situational awareness. According to the report, “situational awareness (SA) technologies in China “are modern, centralized […]

Citrix Gateway and Citrix ADC Authentication Bypass Vulnerability (CVE-2022-27510) Alert

November 13, 2022 | Jie Ji

Overview Recently, NSFOCUS CERT detected that Citrix released a security notice, fixing an authentication bypass vulnerability (CVE-2022-27510). When Citrix Gateway is running with Citrix ADC as a gateway device (either using the SSL VPN feature or deployed as an ICA proxy with authentication enabled), an unauthenticated remote attacker can send malicious packets to the target […]

YApi mongo Injection Vulnerability Alert

November 12, 2022 | Jie Ji

Overview Recently, NSFOCUS CERT detected that an open source API interface management platform YApi mongo injection vulnerability was publicly released on the Internet. Due to the splicing of a certain function in YApi, MongoDB injection can be realized. Unauthenticated remote attackers can exploit this vulnerability to obtain the user token (including necessary parameters such as […]

NSFOCUS – Nextwave (Thailand) Partner Event

November 11, 2022 | Jie Ji

Wednesday 2 Nov 2022 at Glowfish Together with Nextwave, NSFOCUS held the partner event Future Defense-in-Depth Security and Beyond. Apart from Anti-Distributed Denial of Service System (ADS) that NSFOCUS has experience for over 20 years, other Defense Security also have been developed to meet the needs of customers for both On-Prems, Cloud and Hybrid Security. […]

Search

Subscribe to the NSFOCUS Blog

Archive