Overview Recently, NSFOCUS CERT detected that Citrix released a security notice, fixing an authentication bypass vulnerability (CVE-2022-27510). When Citrix Gateway is running with Citrix ADC as a gateway device (either using the SSL VPN feature or deployed as an ICA proxy with authentication enabled), an unauthenticated remote attacker can send...
Blog
YApi mongo Injection Vulnerability Alert
Overview Recently, NSFOCUS CERT detected that an open source API interface management platform YApi mongo injection vulnerability was publicly released on the Internet. Due to the splicing of a certain function in YApi, MongoDB injection can be realized. Unauthenticated remote attackers can exploit this vulnerability to obtain the user token...
NSFOCUS – Nextwave (Thailand) Partner Event
Wednesday 2 Nov 2022 at Glowfish Together with Nextwave, NSFOCUS held the partner event Future Defense-in-Depth Security and Beyond. Apart from Anti-Distributed Denial of Service System (ADS) that NSFOCUS has experience for over 20 years, other Defense Security also have been developed to meet the needs of customers for both...
NSFOCUS Gains CREST Accreditation for Penetration Test Service
Santa Clara, Calif. November 10, 2022  – NSFOCUS, a global provider of intelligent hybrid security solutions, today announced it has received CREST’s internationally recognized accreditation for its Penetration Test services, an addition to its existing accreditation for the vulnerability assessment service.  CREST uses a rigorous quality assurance process to ensure its member...
Cyber Defense Initiative Conference (CDIC) 2022
During November 9th to 10th, NSFOCUS participated in Cyber Defense Initiative Conference (CDIC) in Thailand. Our experts Orajit Jamsai and Krittipol Hirunmaporn presented our hybrid Anti-DDoS solution and cloud security services during these 2 days. It was an amazing event for us to connect with Thailand's cybersecurity community.
The Increasing Trend of Software Supply Chain Attacks
Compared with traditional security threats, supply chain threats have a spreading influence. Vulnerabilities of upstream products will affect all downstream roles, causing security risks to spread along the supply chain and consequently expanding the attack area. In recent years, several influential supply chain attacks have taken place, involving open-source components,...





