Blog

Making Secure Boot Even More Secure

January 18, 2024 | NSFOCUS

Secure Boot lays the foundation for the security of the entire computer system. However, in practice, there are potential security risks in secure boot. I. Overview In the previous post “Secure Boot 101: Getting Started with Secure Boot”, we introduced several core concepts of Secure Boot. In reality, users’ computers are often encrypted, and using […]

Key Patch Updates for All Series of Oracle Products in January

January 18, 2024 | NSFOCUS

Overview Recently, NSFOCUS CERT found that Oracle officially released a Critical Patch Update announcement (CPU) in January. A total of 413 vulnerabilities of different levels were fixed this time. This security update involves Oracle WebLogic Server, Oracle MySQL, Oracle Java SE, Oracle Fusion Middleware, Oracle HTTP Server and other commonly used products. Oracle strongly recommends […]

Confluence Remote Code Execution Vulnerability (CVE-2023-22527) Alert

January 17, 2024 | NSFOCUS

Overview On January 16, NSFOCUS CERT detected that Atlassian officially released a security announcement fixing the remote code execution vulnerability (CVE-2023-22522) in Confluence Data Center and Confluence Server. This vulnerability is caused by template injection. Unauthenticated attackers can inject malicious requests into Confluence pages to implement remote code execution on affected targets. The CVSS score […]

NSFOCUS Reveals New Botnet Family RDDoS

January 16, 2024 | NSFOCUS

1. Introduction of the New Botnet RDDoS In early November 2023, NSFOCUS’s Global Threat Hunting System detected that an unknown elf file was spreading widely, which aroused our vigilance. After further analysis, we confirmed that this batch of elf samples belonged to a new botnet family. NSFOCUS Security Research Labs named the botnet Trojan as […]

GitLab Arbitrary User Password Reset Vulnerability

January 13, 2024 | NSFOCUS

Overview Recently, NSFOCUS CERT detected that GitLab officially released a security announcement and fixed multiple security vulnerabilities in GitLab Community Edition (CE) and Enterprise Edition (EE), including two serious vulnerabilities. Affected users should take protective measures as soon as possible. CVE-2023-7028: In GitLab CE/EE, users can reset their passwords through the auxiliary email address. Due […]

Key Events of 2023 for NSFOCUS WAF

January 10, 2024 | NSFOCUS

Summarizing the past, embracing the future. Let’s take a look at the key events of NSFOCUS WAF in 2023. Market Recognition June 2023: NSFOCUS Tops China’s Hardware WAF Market for Four Consecutive Years in IDC market share research report on China’s hardware WAF market share; August 2023: Gartner named NSFOCUS a Representative Vendor of API […]

NSFOCUS named a Major Player in IDC MarketScape: Worldwide Risk-Based Vulnerability Management Platforms 2023 Vendor Assessment

January 9, 2024 | NSFOCUS

SANTA CLARA, Calif., January 9, 2024 – NSFOCUS, a global provider of intelligent hybrid security solutions, today announced that NSFOCUS has been named a Major Player in the IDC MarketScape: Worldwide Risk-Based Vulnerability Management Platforms 2023 Vendor Assessment (doc #US50302323, November 2023).   IDC MarketScape vendor analysis model is designed to provide an overview of […]

Enhancing Web Security: NSFOCUS WAF Integration Solutions

January 4, 2024 | NSFOCUS

According to an industry report, over 75% of cybersecurity attacks target the web application layer. Additionally, statistics indicate that more than two-thirds of websites lack adequate security measures. With digital transformation, organizations are moving more business operations to the Internet. New-generation applications are accessed through various channels like the Web and APIs, leading to increased […]

Secure Boot 101: Getting Started with Secure Boot

January 2, 2024 | NSFOCUS

Secure Boot aims to add an additional layer of protection to the boot process, laying the foundation for overall computer security. Secure Boot technology, much like a vigilant guardian, ensures that only digitally signed and trusted components are allowed to initiate the system boot process, fortifying the system against unauthorized and potentially malicious software. As […]

NSFOCUS Zero Trust Solution Makes It Into The Security Service Edge Solutions Landscape Report

December 27, 2023 | NSFOCUS

SANTA CLARA, Calif., Dec 27, 2023 – NSFOCUS, a global provider of intelligent hybrid security solutions, today announced that NSFOCUS is included in the Security Service Edge Solutions Landscape for Q4 2023 recently published by Forrester, an internationally authoritative research and consulting firm. Forrester believes that security service edge (SSE) solutions can provide Zero Trust […]