Microsoft’s August Security Update on High-Risk Vulnerabilities in Multiple Products

August 15, 2024 | NSFOCUS

Overview On August 14, NSFOCUS CERT detected that Microsoft released a security update patch for August, which fixed 90 security issues involving widely used products such as Windows, Microsoft Office, Visual Studio and Azure, including high-risk vulnerabilities such as privilege escalation and remote code execution. Among the vulnerabilities fixed in Microsoft’s monthly update this month, […]

New APT Group Actor240524: A Closer Look at Its Cyber Tactics Against Azerbaijan and Israel

August 8, 2024 | NSFOCUS

Overview Leveraging NSFOCUS’s Global Threat Hunting System, NSFOCUS Security Labs (NSL) captured an attack campaign targeting Azerbaijan and Israel on July 1, 2024. By analyzing the tactics, attack vectors, weapons, and infrastructure of the attack in this incident, it was found that the exposed attack characteristics have no direct connection with known APT groups. Therefore, […]

NSFOCUS Recognized as a Sample Vendor in Gartner’s Hype Cycle for Private Mobile Network Services, 2024

August 6, 2024 | NSFOCUS

SANTA CLARA, Calif., August 6, 2024 – NSFOCUS, a global cybersecurity leader, has been acknowledged as a Sample Vendor in Gartner’s Hype Cycle for Private Mobile Network Services, 2024. This prestigious recognition highlights NSFOCUS’s innovative Attack Surface Management (ASM) solution, which stands out for its comprehensive approach to managing digital assets and mitigating potential digital […]

Breaking News: Microsoft Azure Faces Service Disruption Amidst DDoS Attack

August 1, 2024 | NSFOCUS

Microsoft acknowledged a service disruption that affected a range of its cloud services on July 30, 2024. The incident, which spanned from 11:45 UTC to 19:43 UTC, saw customers globally experiencing difficulties connecting to services such as Azure App Services, Application Insights, and the Azure portal, among others. The unexpected surge in usage was attributed […]

NSFOCUS RSAS New Features Unleashed

July 31, 2024 | NSFOCUS

NSFOCUS Remote Security Assessment System (RSAS) is a specialized, all-encompassing vulnerability scanner tailored for clients performing security assessments. It is adept at swiftly identifying a full spectrum of weaknesses within network systems. NSFOCUS RSAS is not just a scanning tool; it’s a comprehensive solution that efficiently identifies a plethora of vulnerabilities across networks, encompassing new […]

Lessons Learned from the CrowdStrike Incident: Strengthening Organizational Resilience

July 25, 2024 | NSFOCUS

On July 19, 2024, a major global digital catastrophe unfolded as a faulty Windows update led by cybersecurity firm CrowdStrike’s Falcon software caused widespread system crashes and service disruptions across vital sectors in over 20 countries. This incident has exposed the deficiencies of Microsoft and its partners in product stability and risk management. Security software, […]

TransparentTribe’s Spear-Phishing Targeting Indian Government Departments

July 24, 2024 | NSFOCUS

Overview Leveraging our global threat hunting system, NSFOCUS Security Research Labs discovered spear-phishing email attacks by the APT group TransparentTribe targeting Indian government departments on February 2, 2024. The timing of these attacks coincides with the presidential election in India, scheduled for April-May of this year, and the bait documents are related to the “President’s […]

JumpServer File Read and Upload Vulnerability (CVE-2024-40628/CVE-2024-40629) Notification

July 19, 2024 | NSFOCUS

Overview Recently, NSFOCUS CERT detected that JumpServer issued a security announcement and fixed the file reading and uploading vulnerabilities in JumpServer (CVE-2024-40628/CVE-2024-40629). Due to improper permission configuration of the Ansible module in JumpServer, an attacker with a low-privilege account can use the ansible playbook to read arbitrary files in the celery container, resulting in disclosure […]

Critical Patch Update Notice in July for All Series of Oracle Products

July 19, 2024 | NSFOCUS

Overview On July 17, 2024, NSFOCUS CERT detected that Oracle officially released a critical patch update announcement CPU (Critical Patch Update) for July. A total of 397 vulnerabilities of varying degrees were fixed this time. This security update involves Oracle WebLogic Server, Oracle MySQL, Oracle Java SE, Oracle Fusion Middleware, Oracle Financial Services Applications, Oracle […]

NSFOCUS Recognized in Forrester’s Enterprise Firewall Landscape Report, Q2 2024

July 17, 2024 | NSFOCUS

SANTA CLARA, Calif., July 17, 2024 – NSFOCUS, a leading cybersecurity company, is proud to announce its inclusion in the prestigious The Enterprise Firewall Landscape, Q2 2024 report by Forrester, a globally recognized research and advisory firm. NSFOCUS has been distinguished as a Notable Vendor for its innovative Next-Generation Firewall (NGFW) solution. Since the introduction […]

Search

Subscribe to the NSFOCUS Blog