Blog

Sustainable and Environmentally Responsible Development

NSFOCUS Achieves Three Certifications, Paving the Path to Sustainable and Environmentally Responsible Development

October 26, 2023 | NSFOCUS

SANTA CLARA, Calif., Oct 26, 2023 – NSFOCUS, a global leader in intelligent hybrid security solutions, proudly announces its recent acquisition of three significant certifications: the “Verification Statement of Greenhouse Gas Emissions,” the “Energy Management System Certificate,” and the “Certificate of Product Carbon Footprint.” Verification Statement of Greenhouse Gas Emissions In the face of the […]

Apache ActiveMQ Remote Code Execution Vulnerability Notification

October 25, 2023 | NSFOCUS

Overview Recently, NSFOCUS CERT found that the open source message middleware ActiveMQ developed by the Apache Software Foundation had an XML external entity injection vulnerability. Since the port 61616 was opened by default after the installation of ActiveMQ was started, and the TcpTransport function did not perform necessary checks on the data, an attacker could […]

Israeli-Palestinian Conflict: Multifaceted Alliances and Fierce Cyberspace Battle

October 23, 2023 | NSFOCUS

Background On October 7th, accompanied by the launch of thousands of rockets, the Palestinian Islamic Resistance Movement (Hamas) declared a military operation against Israel. As real-world conflict escalated, hacktivist organizations from various countries, including Russia, India, Indonesia, and Iraq, began engaging in continuous cyber warfare within the cyberspace domains of both sides. The primary methods […]

NSFOCUS AISecOps: Elevating Your Security Operations Efficacy and Mitigating Alert Fatigue

October 19, 2023 | NSFOCUS

In the realm of security operations, enterprises often face challenges such as a high volume of alerts, an inability to pinpoint real threats, insufficient security knowledge, and a lack of operational staff. While the operational platforms of major security firms exhibit similarities in functionality, some companies diligently analyze customer pain points and requirements, continually enhancing […]

Six Algorithms for Defending Against the Novel “HTTP/2 Rapid Reset” DDoS Attack

October 18, 2023 | NSFOCUS

A recently discovered HTTP/2 protocol-based Distributed-Denial-of-Service (DDoS) vulnerability has been identified by multiple cloud service providers. This vulnerability enables attackers to achieve an unprecedented record of 398 million requests per second. This vulnerability has been identified as CVE-2023-44487, potentially making it one of the largest layer 7 DDoS attacks ever recorded. What is HTTP/2 Rapid […]

Continuous Threat Exposure Management

NSFOCUS Launches CTEM Offerings to Mitigate Threat Exposure

October 17, 2023 | NSFOCUS

NSFOCUS CTEM Offerings: A Comprehensive Solution to Enhance Your Security Posture Singapore – October 17, 2023 – NSFOCUS, a globally recognized leader in cybersecurity solutions, is pleased to announce a comprehensive suite of security offerings designed to enhance the Continuous Threat Exposure Management (CTEM) program for organizations of all sizes. CTEM is a 5-step process […]

APT Group DarkPink

APT Group DarkPink Exploits WinRAR 0-Day to Target Multiple Entities in Vietnam and Malaysia

October 13, 2023 | NSFOCUS

Overview NSFOCUS Security Labs has been continuously monitoring the newly discovered WinRAR 0-day vulnerability, CVE-2023-38831. It has come to our attention that the advanced persistent threat group known as DarkPink has recently begun exploiting this vulnerability to target government entities in Vietnam and Malaysia. In this round of attack activities, DarkPink attackers have incorporated the […]

NSFOCUS post: AI in cybersecurity

Countdown to GovWare 2023 – The Application of Artificial Intelligence (AI) in Cybersecurity

October 12, 2023 | NSFOCUS

The stage is set, and the countdown has begun. GovWare 2023, a pivotal event in cybersecurity, is just around the corner. From a thorough review of the event agenda, we discerned that many speeches, keynotes and panels will be centered around the application of Artificial Intelligence (AI) in cybersecurity. As we eagerly await GovWare 2023, […]

Microsoft’s October security update for multiple high-risk product vulnerabilities

October 12, 2023 | NSFOCUS

Overview On October 11, NSFOCUS CERT monitored that Microsoft had released a security update patch for October, fixing 104 security problems, involving Microsoft WordPad, Skype for Business, Windows Layer 2 Tunneling Protocol, Microsoft Message Queuing and other widely used products, including high-risk vulnerability types such as privilege enhancement, remote code execution, etc. Among the vulnerabilities […]

curl SOCKS5 Heap Overflow Vulnerability (CVC-2023-38545) Notification

October 12, 2023 | NSFOCUS

Overview Recently, NSFOCUS monitored curl’s official security announcement, which fixed the SOCKS5 heap buffer overflow vulnerability (CVE-2023-38545) and cookie injection vulnerability (CVE-2023-38546). The details of the vulnerability have been made public. Affected users should upgrade curl as soon as possible. SOCKS5 Heap Buffer Overflow Vulnerability (CVS 2023-38545) When curl is required to pass the host […]