Overview Recently, NSFOCUS CERT detected that a Fastjson 1.2.x remote code execution vulnerability without gadget was disclosed online; Due to the defects in the internal type parsing logic of Fastjson deserialization, unauthenticated attackers can construct specially crafted malicious JSON data to bypass the traditional autoType black and white list protection...
Autor: NSFOCUS
WordPress Remote Code Execution Vulnerability (CVE-2026-63030/CVE-2026-60137) Notice
Overview Recently, NSFOCUS CERT detected that WordPress issued a security bulletin to fix the WordPress remote code execution vulnerability (CVE-2026-63030/CVE-2026-60137), known as wp2shell; Unauthenticated attackers can bypass authentication through REST API batch requests, use SQL injection to obtain administrator password hashes, and use plug-in installation functions to implant WebShell to...
NSFOCUS Releases 2025 APT Group Research Annual Report
SANTA CLARA, Calif., July 20, 2026 – In 2025, geopolitical conflict and technological transformation have become deeply intertwined, and the iterative leaps in artificial intelligence (AI) have reshaped the landscape of cybersecurity offense and defense. Empowered by AI, Advanced Persistent Threats (APTs) now exhibit greater stealth and destructive power, becoming a...
Microsoft’s July Security Update of High-Risk Vulnerability Notice for Multiple Products
Overview On July 15, NSFOCUS CERT monitored that Microsoft released its July security update patch, fixing 622 security issues. These affect widely used products such as Windows, Microsoft Office, Microsoft SQL Server, Visual Studio Code, Microsoft Edge, Azure, etc., which include high-risk vulnerability types such as remote code execution vulnerabilities,...
NSFOCUS Officially Appoints SiS Technologies Pte Ltd as a New Distributor in Singapore
Strategic partnership to expand access to NSFOCUS's enterprise cybersecurity solutions through SiS Technologies' established local channel ecosystem SANTA CLARA, Calif., July 15, 2026 – NSFOCUS, a pioneering leader in cybersecurity, today announced the appointment of SiS Technologies Pte Ltd as one of its official distributors in Singapore. Under this agreement, SiS...
AI Security Incident Case: Ghostcommit Attack Leveraged Images to Steal Secrets
Overview On July 11, 2026, two researchers from the ASSET Research Group at the University of Missouri-Kansas City, Sudipta Chattopadhyay and Murali Ediga, disclosed a novel attack technique named Ghostcommit. This attack is capable of exfiltrating the entire contents of a target's .env file. The ingenuity of this attack lies...



