Blog

Multiple Apache HTTP Server Security Vulnerabilities

Overview Recently, NSFOCUS CERT found that Apache has issued an official security notice to fix multiple Apache HTTP Server vulnerabilities. Affected users should take protective measures as soon as possible. Apache HTTP Server Request Smuggling Vulnerability (CVE-2023-25690): When mod_ When proxy is enabled with some form of RewriteRule or ProxyPassMatch,...

Bread Crumbs of Threat Actors (Feb 13 – 26, 2023)

From 13 to 26 February 2023, NSFOCUS Security Labs found activity clues from 66 APT groups, one malware family (CoinMiner), and 426 threat actors targeting critical infrastructure. APT Groups Among the 66 APT groups discovered, the APT28 affected the most significant number of hosts from 13 to 26 February. Number...

The Hong Kong Institute of Bankers – Cybersecurity Solutions Day

Smart Cybersecurity Defence for the Future, March 8, 2023, Hong Kong Convention and Exhibition Centre, Hong Kong NSFOCUS participated Cybersecurity Solutions Day hosted by The Hong Kong Institute of Bankers as a Platinum Sponsor. Our Principal Security Solution Architect David Gao attended The Hong Kong Institute of Bankers Cybersecurity Solutions Day as a panel speaker...

Microsoft Word Remote Code Execution Vulnerability (CVE-2023-21716)

Overview Recently, NSFOCUS CERT found the PoC that disclosed Microsoft Word remote execution code vulnerability (CVE-2023-21716) on the Internet. Because the RTF parser in Microsoft Word will trigger a heap corruption vulnerability when processing a font table (*  fonttbl *) that contains too many fonts (*  f # # #...

NSFOCUS
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.