Advisory: Apache Shiro RememberMe Padding Oracle Vulnerability

November 30, 2019 | Adeline Zhang

Vulnerability Description In September 2019, Apache officially released a vulnerability topic “RememberMe Padding Oracle Vulnerability” numbered SHIRO-721. The issue pointed out that because the RememberMe field of the Apache Shiro cookie is encrypted by the AES-128-CBC mode, Shiro is vulnerable to Padding Oracle attacks. An attacker can use the Legal RememberMe cookie as the Padding […]

Microsoft Released November 2019 Security Patches to Fix 13 Critical Vulnerabilities

November 29, 2019 | Adeline Zhang

Overview Among the vulnerabilities that Microsoft has updated in this month, there are 13 critical ones which exist in products like Hyper-V, VBScript, Exchange, and Scripting Engine.

IP Reputation Report-11242019

November 28, 2019 | Adeline Zhang

Top 10 countries in attack counts:   The above diagram shows the top 10 regions with the most malicious IP addresses from the NSFOCUS IP Reputation databases at November 24, 2019. Top 10 countries in attack percentage:   The Laos is in first place. The Uzbekistan is in the second place. The country China (CN) […]

Cybersecurity Insights-6

November 27, 2019 | Adeline Zhang

4.2 Significant Increase in Device Vulnerabilities In the past few years, vulnerabilities associated with network devices have grown rapidly. This is because more network enabled devices of more diverse types are connecting to the network. The threat increases as device vendors do not take security seriously and are remiss in providing timely firmware updates. Thus, […]

Adobe Security Bulletins for November 2019 Security Updates Threat Alert

November 26, 2019 | Adeline Zhang

Overview On November 12, local time, Adobe officially released the November security update, which fixes multiple vulnerabilities in Adobe’s various products, including Adobe Bridge CC, Adobe Media Encoder, Adobe Illustrator CC, and Adobe Animate CC.

Advisory: Squid Multiple High-risk Vulnerability

November 25, 2019 | Adeline Zhang

Vulnerability Description On November 5, local time, Squid officially released a security bulletin to fix multiple vulnerabilities, including a high-risk buffer overflow vulnerability that could lead to code execution (CVE-2019-12526), ​​an information disclosure vulnerability (CVE-2019-18679) And HTTP request splitting problem (CVE-2019-18678).

Information Security in the Workplace- Attachment Virus-v

November 21, 2019 | Adeline Zhang

With the advancement of IT-based transformation and the rapid development of IT, various network technologies have seen more extensive and profound applications, along with which come a multitude of cyber security issues. Come to find out what information security issues you should beware of in the workplace.

IP Reputation Report-11172019

November 21, 2019 | Adeline Zhang

Top 10 countries in attack counts: The above diagram shows the top 10 regions with the most malicious IP addresses from the NSFOCUS IP Reputation databases at November 17, 2019. Top 10 countries in attack percentage: The Laos is in first place. The Uzbekistan is in the second place. The country China (CN) is not […]

Cybersecurity Insights-5

November 20, 2019 | Adeline Zhang

Insights into Vulnerabilities 4.1 Overall Trend The National Vulnerability Database had recorded 15,800 CVE vulnerabilities for 2018, including 4096 high-risk ones. Compared with 2017, the total number of vulnerabilities found in 2018 increased 8.2%, while the number of high-risk ones dropped by 4.8%. Although the number of vulnerabilities increased steadily, they did so slowly, possibly […]

Advisory: Open-Source Compression Library Libarchive Code Execution Vulnerability (CVE-2019-18408)

November 19, 2019 | Adeline Zhang

Overview Recently, a code execution vulnerability (CVE-2019-18408) was disclosed in the security update of Debian, Ubuntu, Gentoo and other distributions.

Search

Subscribe to the NSFOCUS Blog