2018 DDoS Attack Landscape-1

April 5, 2019 | Adeline Zhang

NSFOCUS Security Lab research has seen a dramatic decrease in DDoS attacks between 2017 and 2018.  We are in consensus with other TI vendors  as to most of the driving factors behind this large scale reduction, except one. This webinar 1 will show why NSFOCUS is breaking from the pack on one of the key […]

Internet Explorer and Edge Browsers 0-Day Vulnerability Threat Alert

April 4, 2019 | Adeline Zhang

Overview Recently, a foreign researcher announced a 0-day vulnerability with Microsoft Edge and Internet Explorer (IE). Enticing a user to click a malicious link, an attacker could exploit this vulnerability to bypass the same-origin policy of the two kinds of browsers to launch a universal cross-site scripting (UXSS) attack to steal the user’s sensitive information.

IP Reputation Report-03292019

April 2, 2019 | Adeline Zhang

Top 10 countries in attack counts:

UC Browser Potential Man-in-the-Middle Vulnerability Threat Alert

April 2, 2019 | Adeline Zhang

Overview Recently, a foreign researcher discovered a potential vulnerability in the UC browser which may affect hundreds of millions of users around the world. A hidden feature is found in the UC browser to download auxiliary software modules for execution by bypassing some restrictions of an application store. This feature is used to add new […]

PostgreSQL Arbitrary Code Execution Vulnerability (CVE-2019-9193) Threat Alert

April 1, 2019 | Adeline Zhang

1 Vulnerability Overview Recently, a security researcher disclosed details about a PostgreSQL privilege escalation code execution vulnerability (CVE-2019-9193), which allows attackers with read access to database server-side files to execute arbitrary system commands.

Daily Communication——Use of Shared Folders

March 29, 2019 | Adeline Zhang

Case Analysis Public shared folders usually house various documents from different departments, many of which contain sensitive data. Sensitive files reside in such folders mainly because people forget to delete them after copying them, thus exposing sensitive data to intranet hackers and rogue insiders.

Apache Tomcat DoS Vulnerability (CVE-2019-0199) Threat Alert

March 28, 2019 | Adeline Zhang

1 Vulnerability Overview Recently, The Apache Software Foundation announced the existence of a denial-of-service (DoS) vulnerability in Apache Tomcat HTTP/2. Specifically, the HTTP/2 implementation accepts streams with excessive numbers of SETTINGS frames and also permits clients to keep streams open without reading/writing request/response data. Thus, too many connection requests from clients can cause server-side thread […]

Technical Report on Container Security (V)-3

March 27, 2019 | Adeline Zhang

Security Tools – StackRox About StackRox StackRox features a distributed architecture that collects and analyzes data throughout the application lifecycle to detect and block malicious actors, and finally meet the requirement for protecting containerized cloud-native applications. StackRox delivers continuous detection through its unique combination of distributed sensors and centralized analysis and machine learning to provide […]

NSFOCUS Attack Threat Monitoring Wins 2019 Cyber Defense Magazine InfoSec Award

March 26, 2019 | Adeline Zhang

Earlier this month at RSA we released the newest service in our arsenal of holistic hybrid security solutions, Attack Threat Monitoring (ATM). We were thrilled not only to demo ATM at our RSA booth, but even more pleased to release the service to the public having already won an award. Cyber Defense Magazine examines thousands […]

Adobe Security Bulletins for March 2019 Security Updates Threat Alert

March 26, 2019 | Adeline Zhang

Overview On March 12, 2019 (local time), Adobe released security updates which address multiple vulnerabilities in Adobe Photoshop CC and Adobe Digital Editions.

Search

Subscribe to the NSFOCUS Blog