Year: 2023

An Insight into RSAC 2023: Convergence of Threat Intelligence and AI

Uma imagem que ilustra um cérebro em desenho artificial.

June 19, 2023

I. Overview In cybersecurity, big data is transforming threat intelligence and artificial intelligence, providing security teams with the flexibility to respond to changing environments. At the 2023 RSAC, Microsoft Vice President John Lambert discussed the convergence of intelligence and AI at the intersection of data and threats. The topic focused on how defenders can leverage […]

Openfire Console Identity Authentication Bypass Vulnerability (CVS 2023-32315) Notification

June 16, 2023

Overview Recently, NSFOCUS CERT detected an identity authentication bypass vulnerability in the Openfire console (CVE-2023-32315). The Admin Console of Openfire is a web-based application that has been found to be vulnerable to path traversal attacks by setting up the environment. Unauthenticated attackers use the unauthenticated Openfire setting environment in a configured Openfire environment to access […]

An Insight into RSAC 2023: Web Application and API Security Trend

Uma imagem que possui API escrito no fundo.

June 15, 2023

At this year’s RSA conference, Akamai Senior Vice President Rupesh Chokshi shared a topic entitled Spotlight on latest web application and API attack data, highlighting the latest web application vulnerabilities and API attack trends. This article will explore this topic, starting from the data trends of application vulnerabilities and API attacks in recent years, describing […]

Fortinet FortiOS SSL VPN Remote Code Execution Vulnerability (CVS 2023-27997)

June 14, 2023

Overview Recently, NSFOCUS CERT found that Fortinet has officially fixed a remote code execution vulnerability in FortiOS SSL VPN (CVS-2023-27997). Due to the heap-based Buffer overflow error in SSL VPN, an unauthenticated attacker can trigger the vulnerability by sending a specially crafted packet, which can ultimately enable the execution of arbitrary code on the target […]

Illegal Upload Protection

June 13, 2023

When a client uploads a file to a server, NSFOCUS WAF performs protection based on the file type. If the file type matches an illegal upload restriction policy, NSFOCUS WAF allows or blocks the upload based on the corresponding action specified in the policy, and logs the event. On the Illegal Upload Restriction page, customers […]

Turkey Companies Targeted by RedBeard with Phishing Attacks

June 12, 2023

I. Summary Recently, NSFOCUS Security Labs observed some phishing attacks targeting Turkish companies, including the Turkish industrial group Borusan Holding, communication operator Turkcell, bank Vakıf Katılım, and online lottery service company Nesine. The attacker placed different types of phishing documents and new Trojan programs in this group of activities to steal file data of the […]

Nacos Raft Protocol Deserialization Code Execution Vulnerability

June 9, 2023

Overview Recently, NSFOCUS CERT found that there was a deserialization vulnerability in Nacos’s Raft protocol. Due to the Nacos cluster’s unrestricted use of Hessian for deserialization when processing some Jraft requests, attackers can execute code. Affected users should take protective measures as soon as possible. Vulnerability Details Vulnerability PoC Vulnerability EXP Utilization in the wilderness […]

An Insight into RSAC 2023: Lateral Movement in Kubernetes

June 8, 2023

At the RSA Conference 2023, Yossi Weizman, Senior Security Researcher at Microsoft Defender for Cloud, shared with us the lateral movement of the Kubernetes (aka K8s) cluster and its impact on the cloud environment. Based on Yossi’s speech and NSFOCUS researchers’ understanding, this paper describes the use of lateral movement from the perspective of attack, […]

An Insight into RSAC 2023: 6 Keywords of RSAC 2023

Uma imagem que de uma tela de computador com um texto escrito segurança.

June 7, 2023

Keyword 1: Stronger Together Alone we can do so little; together we can do so much.” – Helen Keller The theme of this year’s conference is “Stronger Together”. What does “Stronger” mean? What is the specific scope to be “Together”? “Stronger” refers to the ability of the business itself to resist security risks. Although defensive […]

NSFOCUS Lua-based Anti-DDoS Solution

June 6, 2023

Limitations of Pre-configured DDoS Protection Policies Lots of organizations have realized that DDoS defense is critical to the availability of network infrastructure. But most Anti-DDoS solutions in the market still rely on pre-configured protection policies with multiple threshold options to offer multi-layered protection at different levels. However, this approach has some limitations: Considering these limitations, […]

Search

Subscribe to the NSFOCUS Blog