Blog

Fortinet FortiNAC Remote Code Execution Vulnerability (CVS 2023-33299) Notification

Overview Recently, NSFOCUS CERT monitored that Fortinet officially fixed a Fortinet FortinaC remote code execution vulnerability (CVE-2023-33299). Unauthenticated remote attackers can exploit this vulnerability by sending a customized request to the service running on TCP port 1050, and an attacker who successfully exploits this vulnerability can execute arbitrary code on...

An Insight into RSA 2023: Capabilities Utilization for Container Escape

At the RSA Conference this year, researchers from Cyberason shared the topic of Container Escape: All You Need Is Cap (Capabilities), detailing three methods of using Cap permissions for container escape, hoping to make users pay attention to the permission allocation of Capabilities when using containers and maintain best practices....

VMware Aria Operations for Networks Remote Code Execution Vulnerability (CVS 2023-20887) Notification

Overview Recently, NSFOCUS CERT detected a remote code execution vulnerability in VMware Aria Operations for Networks. Due to a specific flaw in the createSupportBundle method, the string entered by the user is not properly validated when executing system calls. Unauthenticated remote attackers can exploit this vulnerability through command injection, ultimately...

Digital Transformation – New Era for Macau 2023

V-Transform Expo, June 16, 2023, Macau Tower Convention and Entertainment center, Macau NSFOCUS, a leading provider of network security solutions and services, exhibited at V-Transform Expo 2023 in Macau as Silver Sponsor, organized by Vastcom Technology Limited. Our team joined a day of insightful sessions on cybersecurity, artificial intelligence, digital transformation, machine learning, cloud computing...etc....

An Insight into RSAC 2023: Convergence of Threat Intelligence and AI

I. Overview In cybersecurity, big data is transforming threat intelligence and artificial intelligence, providing security teams with the flexibility to respond to changing environments. At the 2023 RSAC, Microsoft Vice President John Lambert discussed the convergence of intelligence and AI at the intersection of data and threats. The topic focused...