Apache Spark Shell Command Injection Vulnerability (CVE-2022-33891) Alerts

July 21, 2022 | Jie Ji

Overview Recently, NSFOCUS CERT detected that Apache officially released a security bulletin and fixed a command injection vulnerability (CVE-2022-33891) in Apache Spark. Since the Apache Spark UI enables acl through the configuration option Spark.acl.enable, by using an authentication filter, it is possible to check if a user has access to view or modify the application. […]

Microsoft’s July security update for multiple high-risk product vulnerabilities

July 18, 2022 | Jie Ji

Overview On July 13, NSFOCUS CERT detected that Microsoft released the July security update patch, which fixed 84 security issues, involving widely used products such as Windows, Microsoft Office, Windows Print Spooler Components, Windows Hyper-V, and Azure Site Recovery, and included high-risk vulnerability types such as privilege escalation and remote code execution. Among the vulnerabilities […]

Security Knowledge Graph | Build an APT Group Graph to Avoid the Information Island Effect

July 13, 2022 | Jie Ji

The security knowledge graph, a knowledge graph specific to the security domain, is the key to realizing cognitive intelligence in cyber security, and it also lays an indispensable technological foundation for dealing with advanced, continuous and complex threats and risks in cyberspace. NSFOCUS will publish a series of articles about the application of the security […]

PhNOG

July 12, 2022 | NSFOCUS

Philippine Network Operators Group 2022 June 11-13, 2022 New World Hotel Makati, Philippines

NSFOCUS was listed in 2022 Gartner® Market Guide for Security Orchestration, Automation and Response Solutions

July 6, 2022 | Jie Ji

Santa Clara, Calif. July 6, 2022 – We are pleased to announce that NSFOCUS has been listed as a Representative Vendor in 2022 Gartner® released Market Guide for Security Orchestration, Automation and Response Solutions report for our product ISOP. ISOP has flexible out-of-the-box capabilities, automated orchestration capabilities and rich intelligence operations and management capabilities to provide […]

Multiple High-Risk Vulnerability Alerts of GitLab

July 3, 2022 | Jie Ji

Overview On July 1, 2022, NSFOCUS CERT detected that GitLab officially released a security bulletin and fixed multiple security vulnerabilities in GitLab Community Edition (CE) and Enterprise Edition (EE). Please take measures to protect it as soon as possible. GitLab Remote Code Execution Vulnerability (CVE-2022-2185): A remote code execution vulnerability exists in GitLab Community Edition […]

Technologies and Applications of the Security Knowledge Graph – Employ Security Knowledge Graph and Join Hands for Cognitive Intelligence

June 28, 2022 | Jie Ji

Overview With the development of key information infrastructure technologies such as cloud computing, 5G, IoT, and the Industrial Internet, cyberspace has linked industrial physical systems, social systems of humans, and network information systems, becoming the cornerstone of the development of the digital economy. Meanwhile, the attack surface in cyberspace is extended and expanded accordingly, and […]

Zero Trust Network Access (ZTNA): Never Trust, Always Verify

June 20, 2022 | Jie Ji

After the prior two posts (SASE Popular Science Series – Understanding SD-WAN and SASE: The Relationship Between SD-WAN and SASE), you may already have a basic understanding of SD-WAN, which is used for network connections among users, assets and NSFOCUS Cloud in SASE. What security capabilities does NSFOCUS offer then? In the next few sessions, […]

Atlassian Confluence Remote Code Execution Vulnerability (CVE-2022-26134) Notification

June 17, 2022 | Jie Ji

Overview Recently, NSFOCUS CERT detected that Atlassian officially released a security bulletin for Confluence Server and Data Center OGNL injection vulnerability (CVE-2022-26134). Remote attackers can construct OGNL expressions for injection without authentication to execute arbitrary code on Confluence Server or Data Center, with a CVSS score of 10. At present, the details of the vulnerability […]

Deepening Engagement with Telcos, ISPs and MSPs to Create More Values for the Interconnected World

June 14, 2022 | Jie Ji

Santa Clara, Calif. June 13, 2022 – NSFOCUS, a leader in holistic hybrid security solutions, attended the RSA Conference 2022 held in San Francisco on June 6 – 9 in person. From a small cryptography conference at the beginning to a conference now attracting an average of over 40,000 attendees every year including many security companies […]

Search

Subscribe to the NSFOCUS Blog