Adobe Security Advisory for December Security Updates

December 29, 2019 | NSFOCUS

Overview On December 11, local time, Adobe officially released a December security update that fixes multiple vulnerabilities in Adobe’s many products, including Adobe Photoshop CC, Adobe Acrobat and Reader, Brackets, and Adobe ColdFusion. For details, visit the following link: https://helpx.adobe.com/security.html

Communication Data Decryption Based on Frida

December 27, 2019 | NSFOCUS

After completing the audit work, I discovered many out-of-bounds vulnerabilities and our vulnerability verification shows that the vulnerable program has no lack of data encryption. Initially, I handle it in the usual way: figure out the entire encryption process and write a Burp plug-in or mitm proxy script for data encryption and decryption.

IP Reputation Report-12232019

December 26, 2019 | NSFOCUS

 Top 10 countries in attack counts: The above diagram shows the top 10 regions with the most malicious IP addresses from the NSFOCUS IP Reputation databases at December 23, 2019.

Cybersecurity Insights-10

December 25, 2019 | NSFOCUS

5.3.2 Attack Type Distribution In 2018, the most frequent attacks seen814 were SYN flood, UDP flood, ACK flood, HTTP flood and HTTPS flood attacks, which altogether accounted for 96% of all DDoS attacks. In contrast, reflection attackers contributed to no more than 3% of attacks. Compared with 2017, the year 2018 witnessed a 80% decrease […]

Advisory: Gitlab EE multiple high-risk vulnerabilities

December 24, 2019 | NSFOCUS

Vulnerability Description On December 10, 2019 local time, GitLab officially released an important version update notice, announcing three high-risk vulnerabilities in GitLab EE (Enterprise Edition). GitLab is an open source and web-based Git-repository management project.

Advisory: Two high-risk vulnerabilities in GoAhead web server

December 23, 2019 | NSFOCUS

Vulnerability Description On December 2, 2019, Cisco Talos publicly released reports of a remote code execution vulnerability (CVE-2019-5096) and a denial of service vulnerability (CVE-2019-5097) for the GoAhead web server. GoAhead is an open source, simple, lightweight, and powerful embedded Web Server. It is a Web server tailored for embedded real-time operating systems (RTOS) and […]

VMware

VMware ESXi Remote Code Execution Vulnerability (CVE-2019-5544) Threat Alert

December 20, 2019 | NSFOCUS

Overview On December 5, local time, VMware officially released a security advisory that revealed a remote code execution vulnerability (CVE-2019-5544) in VMware ESXi and Horizon DaaS. The vulnerability is due to a heap overwrite issue in OpenSLP used in ESXi and Horizon DaaS appliances. Malicious users with access to port 427 on the ESXi host […]

IP Reputation Report-12152019

December 19, 2019 | NSFOCUS

Top 10 countries in attack counts: The above diagram shows the top 10 regions with the most malicious IP addresses from the NSFOCUS IP Reputation databases at December 15, 2019.

Cybersecurity Insights-9

December 18, 2019 | NSFOCUS

5.3 DDoS Attacks 5.3.1 Attack Trend In 2018, we observed 148,000 DDoS attacks (down 28.4% from 2017), which generated a total of 643,100 TB of attack traffic, about the same volume as observed in 2017. This trend suggests that while the number of DDoS attacks is lower, the size of the attack are growing. Large […]

Harbor Multiple Vulnerabilities Threat Alert

December 17, 2019 | NSFOCUS

Overview Today, VMware released five vulnerabilities for Harbor Container Registry, including two officially classified as critical vulnerabilities (CVE-2019-19025, CVE-2019-19023), and two high-risk vulnerabilities (CVE-2019-19029, CVE- 2019-19026), and a medium-risk vulnerability (CVE-2019-3990).

Search

Subscribe to the NSFOCUS Blog