Overview Recently, NSFOCUS CERT detected that Apple has officially fixed a 0-day vulnerability in Apple WebKit. Remote attackers can trigger this vulnerability by inducing the victim to open a specially crafted web page, which can ultimately enable the execution of arbitrary code on the target system. At present, the vulnerability...
Category: Blog
GitLab Unauthorized Access Vulnerability (CVS 2023-3484) Notification
Overview Recently, NSFOCUS CERT monitored that GitLab officially issued a security notice, which fixed an unauthorized access vulnerability in Gitlab EE. In some cases, remote attackers with low privileges can change the name or path of a public top-level group beyond their authority. The CVSS score is 8.0. Affected users...
An Insight into RSA 2023: 5 Open Source Security Tools All Developers Should Know About
In the process of developing code, developers will worry about whether there are security problems in the image of code, dependencies and projects packaged. In the RSAC 2023 this year, David Melamed and Luke O'Malley recommended five open source security tools in their speech "5 Open Source Security Tools All...
Alert: Vulnerability Researchers and Red Team Members Targeted in Watering Hole Attack
Background NSFOCUS researchers detected a code poisoning attack against vulnerability researchers and red team members recently. Attackers use implanted malicious programs in multiple code repositories under the cover of two highly exploitable vulnerabilities of Linux and VMware exposed this year. Once a user downloads the code and compiles it locally,...
Good News! NSFOCUS Named as a Representative Vendor in Gartner® Market Guide for Security Orchestration, Automation and Response Solutions Again
Santa Clara, Calif. July 4, 2023 – We are thrilled to announce that NSFOCUS has been included as a Representative Vendor in Gartner Market Guide for Security Orchestration, Automation and Response Solutions again. It is the 2nd consecutive year for NSFOCUS to be listed in this report. This report provides...
Grafana Identity Authentication Bypass Vulnerability (CVS 2023-3128) Notification
Overview Recently, NSFOCUS CERT detected a vulnerability in Grafana's authentication bypass (CVE-2023-3128). Azure AD can support multiple users with the same email address. When configuring Azure AD to support multiple users, unauthenticated attackers can exploit this vulnerability by creating malicious email account requests. Due to Grafana's failure to uniquely authenticate...





