A Revolutionary Security Architecture Empowers ISPs, MSSPs and Hosting Providers To Deliver SOC-as-a-Service To Customers Santa Clara, Calif. April 26, 2023 – NSFOCUS, a leading provider of network security solutions and services, is proud to announce the launch of NSFOCUS T-ONE CLOUD, a cutting-edge security architecture designed specifically for Internet Service...
Blog
NSFOCUS Blocked an 8-Day Persistent DDoS Attack with 386.5 Gbps Peak Traffic
What happened In March 2023, NSFOCUS security team blocked the worst DDoS attack of the year. The attack was targeted at an Internet service provider customer located in Brazil, with a peak attack traffic of 386.5 Gbps and astonishing total attack traffic of 1184.4 Tbps. This large-scale DDoS attack lasted...
Spring Boot Security Bypass Vulnerability (CVS-2023-20873) Notice
Overview Recently, NSFOCUS CERT found that Spring officially issued a security notice, which fixed a Spring Boot authentication bypass vulnerability (CVE-2023-20873). When Spring Boot is deployed to Cloud Foundry and there is code/cloudFoundryapplication/* * that can handle matching requests, and used in conjunction with a catch all request mapping that...
Communication Port Between ADS M & Portal
Scenario Integrate Portal on the External Network with ADS M on the Internal Network. Required Ports The Portal has a dedicated public IP address. ADS M intranet uses a single public egress IP for external connectivity, and any access to the public network must go through this IP. To establish...
Apache Druid Remote Code Execution Vulnerability Notice
Overview Recently, NSFOCUS CERT found that an Apache Druid remote code execution vulnerability was publicly disclosed online. Under default configuration, Apache Druid supports loading data from Kafka. Unauthenticated remote attackers can implement JNDI injection attacks by modifying Kafka connection configuration properties, ultimately leading to the execution of arbitrary code on...
Google Chrome Skia Integer Overflow Vulnerability (CVS 2023-2136) Notice
Overview Recently, NSFOCUS CERT found that Google officially fixed an integer overflow vulnerability in Chrome Skia (CVE-2023-2136). Due to a flaw in Skia, when the value exceeds the maximum limit of integer type due to arithmetic operations, an integer overflow will occur. The attacker triggers this vulnerability by inducing users...





