Blog

2023 Cybersecurity Regulation Recap (Part 4): Tech Development & Governance

February 13, 2024 | NSFOCUS

In 2023, countries worldwide continued to strengthen their cybersecurity capabilities and systems in response to their national needs, using regulatory means to enhance their cybersecurity management. Based on continuous tracking and research, NSFOCUS summarized the development of global cybersecurity regulations and policies in 2023, hoping to provide valuable insights and guidance for stakeholders, policymakers, and […]

CTEM: Navigating the Future of Attack Surface

February 8, 2024 | NSFOCUS

This article introduces the concept of Continuous Threat Exposure Management (CTEM), delving into the philosophy behind CTEM, its five stages, and exploring key technologies that support its implementation. I.      Introduction In mid-October 2023, Gartner released the top 10 strategic technology trends for 2024 that enterprises need to explore, as depicted in Figure 1. Gartner categorized these trends into three […]

2023 Cybersecurity Regulation Recap (Part 3): Privacy Protection

February 6, 2024 | NSFOCUS

In 2023, countries worldwide continued to strengthen their cybersecurity capabilities and systems in response to their national needs, using regulatory means to enhance their cybersecurity management. Based on continuous tracking and research, NSFOCUS summarized the development of global cybersecurity regulations and policies in 2023, hoping to provide valuable insights and guidance for stakeholders, policymakers, and […]

Runc Container Escape Vulnerability Alert

February 2, 2024 | NSFOCUS

Overview Recently, NSFOCUS CERT detected that the runc officially issued a security notice and fixed a container escaping vulnerability (CVE-2024-21626). Since the internal file descriptor of runc is leaked during initialization and the final working directory is not verified to be located in the mount namespace of the container, attackers can conduct container escaping in […]

2023 Cybersecurity Regulation Recap (Part 2): Data Security

February 1, 2024 | NSFOCUS

In 2023, countries worldwide continued to strengthen their cybersecurity capabilities and systems in response to their national needs, using regulatory means to enhance their cybersecurity management. Based on continuous tracking and research, NSFOCUS summarized the development of global cybersecurity regulations and policies in 2023, hoping to provide valuable insights and guidance for stakeholders, policymakers, and […]

SecLLM: Enhancing Cyber Security with Large Language Model – Technical White Paper Overview

January 31, 2024 | NSFOCUS

Drawing on years of accumulated expertise in security and high-quality data in the field of “artificial intelligence + security,” NSFOCUS has announced the release of its Technical White Paper: Enhancing Network Security with Security Large Language Model (SecLLM). This white paper shares the best practices and lessons learned during the development of NSFOCUS SecLLM, exploring […]

Jenkins Arbitrary File Read Vulnerability (CVE-2024-23897) Notice

January 30, 2024 | NSFOCUS

Overview Recently, NSFOCUS CERT detected that Jenkins issued a security announcement and fixed an arbitrary file reading vulnerability in the Jenkins CLI (CVE-2024-23897). Since one function of its CLI command parser is enabled by default in Jenkins, the specific parser function expandAtFiles can replace the character following the file path in the @ parameter with […]

2023 Cybersecurity Regulation Recap (Part 1): Network Security

January 30, 2024 | NSFOCUS

In 2023, countries worldwide continued to strengthen their cybersecurity capabilities and systems in response to their national needs, using regulatory means to enhance their cybersecurity management. Based on continuous tracking and research, NSFOCUS summarized the development of global cybersecurity regulations and policies in 2023, providing a brief commentary and presenting NSFOCUS’s perspective on some important […]

Collaboration Achievement: NSFOCUS and China University of Geosciences Article Secures Spotlight in Acclaimed Journal TIFS

January 26, 2024 | NSFOCUS

In a recent achievement, the paper BABD: A Bitcoin Address Behavior Dataset for Pattern Analysis, a collaboration between the NSFOCUS research team and Professor Ren Wei’s team at the Computer School of China University of Geosciences, has been featured in the prestigious journal IEEE Transactions on Information Forensics and Security (TIFS). IEEE Transactions on Information […]

GitLab Arbitrary File Write Vulnerability (CVE-2024-0402) Alert

January 26, 2024 | NSFOCUS

Overview Recently, NSFOCUS CERT detected that GitLab officially released a security announcement and fixed an arbitrary file write vulnerability (CVE-2024-0402) in GitLab Community Edition (CE) and Enterprise Edition (EE). Due to path traversal issues, authenticated attackers can copy files to any location on the GitLab server when creating workspaces. The CVSS score is 9.9, affected […]