Overview The Magniber is a notorious ransomware. Unlike the common ransomware families such as Hive and LockBit that target companies, it is primarily used to blackmail individuals with a relatively low ransom around USD 2,500. The Magniber ransomware can neither be transmitted automatically nor used to upload user files, but...
Blog
GovWare Focus 2022
GovWare 2022 went back in-person in Singapore from 18th to 20th Oct 2022. The conference & exhibition was held with the theme of “Fostering a safe and sustainable cyberspace amidst disruption.†At the 3-day event, Richard, Hai Siang, Meng Kiat and Cindy were there to introduce our newly launched Cloud WAAP service, DDoS...
Apache Dubbo Remote Code Execution Vulnerability (CVE-2022-39198) Notification
Overview On October 19, NSFOCUS CERT found that Apache issued a security notice to fix a remote code execution vulnerability (CVE-2022-39198) in Dubbo. Due to a deserialization vulnerability in Dubbo's hessian-lite, an attacker can exploit this vulnerability to remotely execute arbitrary code on the target system. Relevant users are requested...
Software Supply Chain Security: Overview
Software supply chain security is one of the key considerations in modern supply chain security. NSFOCUS Security Labs has conducted long-term research on security of the software supply chain. We’d like to publish a series of posts to share our observations, explore security issues existing in the software supply chain,...
NSFOCUS Launches Cloud WAAP Service for APAC Region at GovWare 2022
Santa Clara, Calif. October 18, 2022  – NSFOCUS, a global provider of intelligent hybrid security solutions, today launched its Cloud Web application and API Protection (WAAP) service for the Asia Pacific Region at the GovWare Conference & Exhibition held at Sands Expo and Convention Centre in Singapore on 18-20 October...
NSFOCUS WAF Secure Data Transfer
NSFOCUS WAF secures data transmission by restricting domain names, URLs, and request methods, and it can improve transmission security by converting ordinary HTTP requests into HTTPS requests forcibly. Configuration precondition: Configure HTTP and HTTPS sites and ensure that both HTTP and HTTPS sites can be accessed. Configuration method: Step 1:...





