NSFOCUS

RSAC 2024 Innovation Sandbox | The Future Frontline: Harmonic Security’s Data Protection in the AI Era

April 26, 2024

The RSA Conference 2024 will kick off on May 6. Known as the “Oscars of Cybersecurity,” the RSAC Innovation Sandbox has become a benchmark for innovation in the cybersecurity industry. Let’s focus on the new hotspots in cybersecurity and understand the new trends in security development. Today, let’s get to know Harmonic Security. Introduction of […]

2024 Global DDoS Attack Trends: Insights, Challenges, and Defense Strategies

April 23, 2024

As the digital landscape rapidly evolves, so too do the tactics and technologies employed by cyber attackers. Building upon the comprehensive insights of the 2023 NSFOCUS Global DDoS Landscape report just released, we delve into the anticipated trends for 2024. (Download the 2023 Global DDoS Attack Landscape Report) 1. DDoS Attacks Often Serve as a […]

NSFOCUS Unveils 2023 Global DDoS Attack Landscape Report

April 23, 2024

SANTA CLARA, Calif., April 23, 2024 – NSFOCUS, a global leader in cybersecurity solutions, today announced the release of its annual report, the 2023 Global DDoS Attack Landscape Report. This comprehensive analysis provides critical insights into the evolving landscape of Distributed Denial of Service (DDoS) attacks, offering essential knowledge for organizations to stay ahead in […]

NTA Email Alert Configuration

April 19, 2024

There are two separate email configurations on NTA which do not affect each other. One is the region/IP group email alert, the other is the global email alert. 1.  Region/IP Group Email Alert Configuration -> Objects -> Regions -> Edit Corresponding Region/IP Group Email addresses configured on the Region -> Basic Information page will receive […]

WebLogic T3/IIOP Information Disclosure Vulnerability (CVE-2024-21006/CVE-2024-21007)

April 18, 2024

Overview Recently, NSFOCUS CERT detected that Oracle has released a security announcement and fixed two information disclosure vulnerabilities (CVE-2024-21006/CVE-2024-21007) in Oracle WebLogic Server. Due to the defects of T3/IIOP protocol, unauthenticated attackers can send malicious requests through servers affected by T3/IIOP protocol. Access to sensitive information on the target system. Affected users should take measures […]

Palo Alto Networks PAN-OS Command Injection Vulnerability (CVE-2024-3400)

April 18, 2024

Overview Recently, NSFOCUS CERT detected that Palo Alto Networks issued a security announcement and fixed the command injection vulnerability (CVE-2024-3400) in PAN-OS. Since GlobalProtect gateway or portal configured in PAN-OS does not strictly filter user input, unauthenticated attackers can construct special packets to execute arbitrary code on the firewall with root privileges. The CVSS score […]

NSFOCUS Recognized as a Representative Vendor in the Gartner® Market Guide for Network Detection and Response

April 15, 2024

SANTA CLARA, Calif., April 15, 2024 – NSFOCUS, a global leader in cybersecurity solutions, has been named a representative vendor in the 2024 Gartner Market Guide for Network Detection and Response. As a key strategic product, NSFOCUS’s network threat detection and response solutions have rapidly evolved and delivered exceptional performance, earning notable recognition within the […]

NIPS Troubleshooting Steps for No Log

April 12, 2024

NIPS aims to accurately monitor abnormal network traffic, automatically blocking various types of aggressive traffic in real-time, particularly application layer threats. It aims to take proactive measures instead of merely providing alerts at the time of or after detecting malicious traffic. When malicious traffic is detected and blocked, a threat log is recorded and displayed […]

XZ-Utils Supply Chain Backdoor Vulnerability Updated Advisory (CVE-2024-3094)

April 7, 2024

Vulnerability Overview Recently, NSFOCUS CERT detected that the security community disclosed a supply chain backdoor vulnerability in XZ-Utils (CVE-2024-3094), with a CVSS score of 10. Since the underlying layer of SSH relies on liblzma, when certain conditions are met, an attacker can use this vulnerability to bypass SSH authentication and gain unauthorized access on the […]

Policy Adjustment Based on Attack Events in ADS

April 5, 2024

This article provides a brief explanation of policy fine-tuning in ADS. Please note that fine-tuning the protection policy is a time-consuming process. This article focuses on how to check attack details in ADS based on attack events and optimize policies accordingly. Due to different versions of ADS, the screenshots shown in the article may differ […]

Search

Subscribe to the NSFOCUS Blog