Year: 2025

RSAC 2025 Innovation Sandbox | MIND: Data Security Innovator Leading the AI Era

April 21, 2025

The RSA Conference 2025 is set to kick off on April 28. Known as the “Oscars of Cybersecurity”, RSAC Innovation Sandbox has become a benchmark for innovation in the cybersecurity industry. Let’s focus on the new hotspots in cybersecurity and understand the new trends in security development. Today, let’s get to know the company MIND. […]

Critical Patch Update Announcement in April for All Oracle Products

April 18, 2025

Overview On April 16, 2025, NSFOCUS CERT detected that Oracle officially released the Critical Patch Update (CPU) for April. A total of 390 vulnerabilities with different degrees were fixed this time. This security update involves Oracle MySQL Connectors, Oracle MySQL Server, Oracle Java SE, Oracle Fusion Middleware, Oracle Financial Services Applications, Oracle Communications Applications and […]

NSFOCUS WAF New UI Showcase: Brand New Policy and Template Management Workflow

Imagem que ilustra o que é WAF.

April 15, 2025

Three-Tier Protection Rules • Basic Protection: Pre-configured, general and popular security rules for out-of-box deployment.• Optional/Advanced Protection: Advanced rules, customized for specific Web/API applications for optimum protection. Basic Protection HTTP Protocol Verification Server Plug-in Crawler Web General Illegal Upload Information Disclosure Semantic Engine Scan Protection Optional Protection HTTP Access Control Sensitive Information Filter Smart Engine […]

Microsoft’s April Security Update of High-Risk Vulnerabilities in Multiple Products

April 11, 2025

Overview On April 9, NSFOCUS CERT detected that Microsoft released a security update patch for April, fixing 126 security problems in widely used products such as Windows, Microsoft Office, Azure, Microsoft Edge for iOS, Microsoft Visual Studio, etc. This includes high-risk vulnerabilities such as privilege escalation and remote code execution. Among the vulnerabilities fixed in […]

NSFOCUS WAF New UI Walkthrough: Site Configuration

Imagem que ilustra o que é WAF.

April 9, 2025

Basic Information Functional Configuration Manage Advanced Features in One Page Security Settings Key Benefits

Vite Arbitrary File Read Vulnerability (CVE-2025-31486)

April 9, 2025

Overview Recently, NSFOCUS CERT detected that Vite issued a security bulletin to fix the Vite arbitrary file read vulnerability (CVE-2025-31486); Because the Vite development server does not strictly verify the path when processing URL requests, unauthenticated attackers can bypass path access restrictions by constructing special URLs and read arbitrary files on the target server. At […]

Vite Arbitrary File Read Vulnerability (CVE-2025-31125)

April 3, 2025

Overview Recently, NSFOCUS CERT detected that Vite issued a security bulletin to fix the Vite arbitrary file read vulnerability (CVE-2025-31125); Because the Vite development server does not strictly verify the path when processing URL requests, unauthenticated attackers can bypass path access restrictions by constructing special URLs and read arbitrary files on the target server. At […]

New UI for NSFOCUS WAF V6.0R09F00 – Experience a Smoother Site Management

Imagem que ilustra o que é WAF.

April 3, 2025

NSFOCUS understands that the Security Operations team is facing increasing threats to their web applications and workloads are rising accordingly, a simple yet easy-to-use WAF has become more important than ever for effective Security Operations. The upcoming NSFOCUS Web Application Firewall (WAF) V6.0R09F00 (hereafter called as 6090) not only comprehensively reconstructs the architecture but also […]

A Deep Analysis of the Ransomware Group Babuk2’s Recent Activities

Uma imagem que ilustra um hacker.

March 28, 2025

Overview Recently, NSFOCUS CERT detected that the Babuk2 group has been frequently publishing sensitive data of several well-known organizations on its dark web site. The data is from multiple sectors, including government, finance, internet, healthcare, and education, across various countries and regions. Up to this month, at least 71 victims’ data has been disclosed, and […]

Vite Arbitrary File Read vulnerability (CVE-2025-30208)

March 28, 2025

Overview Recently, NSFOCUS CERT detected that Vite issued a security announcement and fixed the arbitrary file reading vulnerability of Vite (CVE-2025-30208). Since the Vite development server does not strictly verify the path when processing URL requests, unauthenticated attackers can bypass path access restrictions by constructing special URLs to obtain sensitive files outside the project root […]

Search

Subscribe to the NSFOCUS Blog