Ano: 2023

Atlassian Confluence Improper Authentication Vulnerability (CVC-2023-22518) Notification

novembro 2, 2023

Overview Recently, NSFOCUS CERT monitored that Atlassian officially fixed an improper authentication vulnerability in the Atlassian Communication Data Center and Server (CVE-2023-22518). Unauthenticated remote attackers can bypass the authentication of the target system to a certain extent by constructing malicious requests and obtain the authority to take over the server through the backend interface, achieving […]

F5 BIG-IP Remote Code Execution Vulnerability (CVE-2023-46747) Notification

outubro 31, 2023

Overview Recently, NSFOCUS CERT monitored that F5 had released a security announcement to fix a remote code execution vulnerability in BIG-IP (CVE-2023-46747). Due to the problem of F5 BIG-IP forwarding AJP protocol through Apache httpd, requests were smuggled, which could bypass permission verification. Unauthenticated remote attackers can access the BIG-IP system through the BIG-IP management […]

Introduction to WAF Exception Policy

outubro 27, 2023

Exception policies are supplements or restrictions to configured basic or advanced protection policies. On the Exception Policy page, you can create, edit, delete, and duplicate exception policies. You can also create and edit exception policies on the Website Protection page. Configuration procedure: Choose Security Management > Policy Management > Exception Policy, click Create in the […]

Citrix NetScaler ADC and Gateway Sensitive Information Disclosure Vulnerability (CVC-2023-4966) Notification

outubro 26, 2023

Overview Recently, NSFOCUS CERT detected a sensitive information disclosure vulnerability in Citrix NetScaler ADC and Gateway (CVE-2023-4966). When the device is configured as a gateway (VPN virtual server, ICA proxy, CVPN, RDP proxy) or AAA virtual server, unauthorized remote attackers can exploit this vulnerability to access sensitive information and cause information leakage. The CVSS score […]

NSFOCUS Achieves Three Certifications, Paving the Path to Sustainable and Environmentally Responsible Development

Sustainable and Environmentally Responsible Development

outubro 26, 2023

SANTA CLARA, Calif., Oct 26, 2023 – NSFOCUS, a global leader in intelligent hybrid security solutions, proudly announces its recent acquisition of three significant certifications: the “Verification Statement of Greenhouse Gas Emissions,” the “Energy Management System Certificate,” and the “Certificate of Product Carbon Footprint.” Verification Statement of Greenhouse Gas Emissions In the face of the […]

Apache ActiveMQ Remote Code Execution Vulnerability Notification

outubro 25, 2023

Overview Recently, NSFOCUS CERT found that the open source message middleware ActiveMQ developed by the Apache Software Foundation had an XML external entity injection vulnerability. Since the port 61616 was opened by default after the installation of ActiveMQ was started, and the TcpTransport function did not perform necessary checks on the data, an attacker could […]

O que é computação em nuvem? Como funciona o cloud computing

Uma imagem que ilustra o que é computação em nuvem.

outubro 24, 2023

A computação em nuvem está presente por todos os lados, mas você tem ideia do que isso significa? Neste artigo, vamos explorar mais sobre esse mundo, desvendar conceitos, funcionamento e os diferentes tipos de nuvem.  Além disso, abordamos como a inteligência artificial impacta esse campo, como proteger os dados na nuvem e serviços para proteção. […]

Israeli-Palestinian Conflict: Multifaceted Alliances and Fierce Cyberspace Battle

outubro 23, 2023

Background On October 7th, accompanied by the launch of thousands of rockets, the Palestinian Islamic Resistance Movement (Hamas) declared a military operation against Israel. As real-world conflict escalated, hacktivist organizations from various countries, including Russia, India, Indonesia, and Iraq, began engaging in continuous cyber warfare within the cyberspace domains of both sides. The primary methods […]

GovWare 2023

outubro 21, 2023

GovWare, Oct 17-19, 2023, Sands Expo Convention Centre, Singapore. The conference & exhibition was held with the theme of “Fostering Trust Through Collaboration in the New Digital Reality”. NSFOCUS participated this pivotal event in APAC to introduce our latest effective continuous threat exposure management (CTEM) program and XDR-powered threat analysis and response. 

HTTP/2 Protection in ADS R90F03

outubro 20, 2023

Function Description For HTTPS application layer protection, ADS establishes a TLS connection with a client in replace of the server, and then authenticates the client through the application-layer protocol HTTP. If the client properly responds to the HTTP packet from ADS, ADS deems this client reliable and will add it to the trust list so […]

Search

Inscreva-se no Blog da NSFOCUS