NSFOCUS

QNAP Multiple Vulnerabilities Notification

August 2, 2023

Overview Recently, NSFOCUS CERT monitored that QNAP officially released the QVPN code execution vulnerability and QANP denial-of-service vulnerability. Affected users should take protective measures as soon as possible. VPN Code Execution Vulnerability (CVS 2022-27595): There is a code execution vulnerability in the Windows version of the QVPN client, which can be exploited by authenticated local […]

Metabase Remote Code Execution Vulnerability (CVS 2023-38646) Notification

August 1, 2023

Overview Recently, NSFOCUS CERT detected a remote code execution vulnerability in Metabase (CVE-2023-38646). Unauthenticated attackers can successfully exploit this vulnerability to execute arbitrary commands with Metabase server privileges on the target server. Affected users should take protective measures as soon as possible. Reference link: https://www.metabase.com/blog/security-advisory Scope of Impact Affected version Open source version: Enterprise version: […]

NSFOCUS Tops China’s Hardware WAF Market for Four Consecutive Years

July 28, 2023

IDC released the market share research report on China’s hardware WAF market share recently. NSFOCUS ranks first with a market share of 11.9%, leading the WAF market in China for four consecutive years from 2019 to 2022. NSFOCUS’s next-generation WAF has been selected by more than 5,000 organizations and has become the preferred WAF product […]

NSFOCUS WAF Log4j2_RCE Protection

July 27, 2023

Logging events is a critical aspect of software development. While there are lots of frameworks available in Java ecosystem, Log4j has been the most popular for decades, due to the flexibility and simplicity it provides. Apache Log4j is part of the Apache Logging Services, a project of the Apache Software Foundation. Log4j 2 is a […]

Innovative Access Control Approach Published in IEEE Transactions on Systems, Man, and Cybernetics: Systems

July 26, 2023

NSFOCUS Security Labs recently collaborated with the research team from the School of Computer Science at China University of Geosciences (Wuhan) on a research paper titled “Computable Access Control: Embedding Access Control Rules into Euclidean Space“. This paper has been officially accepted and published online by the prestigious international journal “IEEE Transactions on Systems, Man, […]

Spring Security Identity Authentication Bypass Vulnerability (CVS 2023-34034)

July 25, 2023

Overview Recently, NSFOCUS CERT monitored Spring’s official security announcement and disclosed an identity bypass vulnerability in Spring Security. Using ‘**’ as the pattern in the Spring Security configuration of WebFlux can cause a pattern mismatch between Spring Security and Spring WebFlux, and may result in identity authentication bypass. CVSS score is 9.1. Affected users should […]

Atlassian Multiple High Risk Vulnerabilities Notification

July 24, 2023

Overview Recently, NSFOCUS CERT monitored that the official security announcement of Atlassian has fixed multiple high-risk vulnerabilities in the Atlassian products. Affected users should take protective measures as soon as possible. Atlas Conflict Data Center and Server Remote Code Execution Vulnerability (CVS-2023-22508/CVC-2023-22505): There is a remote code execution vulnerability in the Atlas Conflict Data Center […]

Description of ADS Attack Logs: SYN Flood Logs (Part 1)

July 20, 2023

Introduction to SYN Flood A three-way handshake is required to establish a TCP connection. First, the client sends a TCP SYN packet to the server. The server responds to the client request with an SYN-ACK packet. Then the server waits and expects an ACK packet from the client. At this time, the connection is in […]

NSFOCUS Continuously Dominating the Anti-DDoS Hardware Market in China with Unparalleled Market Share

July 20, 2023

According to the IDC China Anti- DDoS Hardware Market Share, 2022: Opportunities and Challenges Coexist published on June 29, 2023, NSFOCUS, with its Anti-DDoS solution powered by a robust protection algorithm and excellent services, has again claimed the leading position in China’s Anti-DDoS hardware market. NSFOCUS keeps ahead of this market for many years running […]

Oracle Products Key Patches Update Notice for July 2023

July 19, 2023

Overview On July 19, NSFOCUS CERT found that Oracle officially released the Critical Patch Update in July with 508 vulnerabilities included. This security update involved Oracle WebLogic Server, Oracle MySQL, Oracle Financial Services Applications, Oracle Enterprise Manager, Oracle Retail Applications and other commonly used products. Oracle strongly recommends its customers apply critical patches to update […]

Search

Subscribe to the NSFOCUS Blog