Microsoft’s May security update for multiple high-risk product vulnerabilities

Overview On May 10, NSFOCUS CERT monitored that Microsoft had released a security update patch for May, which fixed 38 security issues, involving Win32k, Windows OLE, Microsoft SharePoint Server, Windows Pragmatic General Multicast (PGM) and other widely used products, including high-risk vulnerability types such as privilege enhancement and remote code...

NSFOCUS 2022 Cybersecurity Insights: A Summary

NSFOCUS is a leading provider of enterprise-level network security solutions and services. NSFOCUS has released the annual cybersecurity insights report in April, which analyzed the overall trends, threats, and challenges in the cyber landscape. The full NSFOCUS Cybersecurity Insights for 2022 report is available here. Here are some of the...

GitLab Code Execution Vulnerability (CVS 2023-2478)

Overview Recently, NSFOCUS CERT monitored that GitLab officially issued a security notice, and fixed a code execution vulnerability in GitLab Community Edition (CE) and Enterprise Edition (EE) (CVE-2023-2478). Remote attackers with low privileges can add malicious Runners to any project of the instance through GraphQL endpoints, further exploiting the ability...

Packet Forwarding Mode

The packet Forwarding Mode is mainly used for debugging network faults. If this function is enabled, it indicates that the ADS device will directly forward network packets without any checks. The Packet Forwarding Enable feature can be reminded through the ADS webpage if this function is enabled. If you want...

TA569 Suspected of Phishing Attack against Russia and Germany

I. Overview On April 18, 2023, NSFOCUS Security Labs discovered a spear phishing attack against Russia during daily threat hunting. After correlation analysis of the event, NSFOCUS Security Labs confirmed that the attacker also launched a similar phishing attack against Germany. The active time of the attacker, the attack target,...