Microsoft’s April Security Update of High-Risk Vulnerabilities in Multiple Products

April 11, 2025 | NSFOCUS

Overview On April 9, NSFOCUS CERT detected that Microsoft released a security update patch for April, fixing 126 security problems in widely used products such as Windows, Microsoft Office, Azure, Microsoft Edge for iOS, Microsoft Visual Studio, etc. This includes high-risk vulnerabilities such as privilege escalation and remote code execution. Among the vulnerabilities fixed in […]

Imagem que ilustra o que é WAF.

NSFOCUS WAF New UI Walkthrough: Site Configuration

April 9, 2025 | NSFOCUS

Basic Information Functional Configuration Manage Advanced Features in One Page Security Settings Key Benefits

Vite Arbitrary File Read Vulnerability (CVE-2025-31486)

April 9, 2025 | NSFOCUS

Overview Recently, NSFOCUS CERT detected that Vite issued a security bulletin to fix the Vite arbitrary file read vulnerability (CVE-2025-31486); Because the Vite development server does not strictly verify the path when processing URL requests, unauthenticated attackers can bypass path access restrictions by constructing special URLs and read arbitrary files on the target server. At […]

Vite Arbitrary File Read Vulnerability (CVE-2025-31125)

April 3, 2025 | NSFOCUS

Overview Recently, NSFOCUS CERT detected that Vite issued a security bulletin to fix the Vite arbitrary file read vulnerability (CVE-2025-31125); Because the Vite development server does not strictly verify the path when processing URL requests, unauthenticated attackers can bypass path access restrictions by constructing special URLs and read arbitrary files on the target server. At […]

Imagem que ilustra o que é WAF.

New UI for NSFOCUS WAF V6.0R09F00 – Experience a Smoother Site Management

April 3, 2025 | NSFOCUS

NSFOCUS understands that the Security Operations team is facing increasing threats to their web applications and workloads are rising accordingly, a simple yet easy-to-use WAF has become more important than ever for effective Security Operations. The upcoming NSFOCUS Web Application Firewall (WAF) V6.0R09F00 (hereafter called as 6090) not only comprehensively reconstructs the architecture but also […]

Uma imagem que ilustra um hacker.

A Deep Analysis of the Ransomware Group Babuk2’s Recent Activities

March 28, 2025 | NSFOCUS

Overview Recently, NSFOCUS CERT detected that the Babuk2 group has been frequently publishing sensitive data of several well-known organizations on its dark web site. The data is from multiple sectors, including government, finance, internet, healthcare, and education, across various countries and regions. Up to this month, at least 71 victims’ data has been disclosed, and […]

Vite Arbitrary File Read vulnerability (CVE-2025-30208)

March 28, 2025 | NSFOCUS

Overview Recently, NSFOCUS CERT detected that Vite issued a security announcement and fixed the arbitrary file reading vulnerability of Vite (CVE-2025-30208). Since the Vite development server does not strictly verify the path when processing URL requests, unauthenticated attackers can bypass path access restrictions by constructing special URLs to obtain sensitive files outside the project root […]

Kubernetes Ingress-nginx Remote Code Execution Vulnerability (CVE-2025-1974)

March 27, 2025 | NSFOCUS

Overview Recently, NSFOCUS CERT detected that Kubernetes issued a security announcement and fixed the Kubernetes Ingress-nginx remote code execution vulnerability (CVE-2025-1974). The Ingress controller deployed in Kubernetes Pod can be accessed through the network without authentication. When the Admission webhook is open, an unauthenticated attacker can remotely inject any nginx configuration by sending a special […]

Disposal Advisory for Apache Tomcat Remote Code Execution Vulnerability (CVE-2025-24813)

March 25, 2025 | NSFOCUS

Vulnerability Overview Apache Tomcat Remote Code Execution Vulnerability (CVE-2025-24813) NSFOCUS Detection Methods NSFOCUS Remote Security Assessment System (RSAS), Web Vulnerability Scanning System (WVSS) and Network Intrusion Detection System (IDS) have the ability to scan and detect this vulnerability. Users who deploy the above devices are requested to upgrade to the latest version. Upgrade site: NSFOCUS_Product Support Service_Product Upgrade  […]

Next.js Middleware Permission Bypass Vulnerability (CVE-2025-29927)

March 25, 2025 | NSFOCUS

Overview Recently, NSFOCUS CERT detected that Next.js issued a security announcement and fixed the middleware permission bypass vulnerability (CVE-2025-29927). Because Next.js lacks effective verification of the source of the x-middleware-subrequest header, when configuring to use middleware for authentication and authorization, an unauthenticated attacker can bypass system permission controls by manipulating the x-middleware-subrequest header to access […]

Search

Subscribe to the NSFOCUS Blog