NSFOCUS Leads the Market with Advanced WAAP Technology
junho 19, 2024
SANTA CLARA, Calif., June 19, 2024 – NSFOCUS, a global leader in cybersecurity solutions, proudly announces that in the recently released IDC report, China WAAP Vendor Technology Capability Assessment, 2024, NSFOCUS’s WAAP technology received outstanding evaluations with perfect scores in five key areas: Web Application Firewall (WAF), Bot Traffic Management, Threat Intelligence, Application-layer DDoS Protection, […]
Microsoft’s Security Update Notification in June of High-Risk Vulnerabilities in Multiple Products
junho 18, 2024
Overview Recently, NSFOCUS CERT detected that Microsoft released a security update patch for June, which fixed 49 security issues involving widely used products such as Windows, Azure, Microsoft Office and Microsoft Visual Studio, including high-risk vulnerabilities such as privilege escalation and remote code execution. Among the vulnerabilities fixed in Microsoft’s monthly update this month, there […]
NTA Model Limitation for Upgrade to Version 4.5R90F05
junho 14, 2024
The models that support upgrading to V4.5R90F05 are NX3-HD2100/HD2200/HD3000 /vNTA. Due to hardware device limitations (including but not limited to memory, data disk size, etc.) used in the NTA NX3-1000E/2000E model, upgrading the system to V4.5R90F05 is highly likely to result in the system not functioning properly. Therefore, upgrading the software version to V4.5R90F05 is […]
PHP CGI Windows Platform Remote Code Execution Vulnerability (CVE-2024-4577) Advisory
junho 12, 2024
Overview NSFOCUS CERT has monitored the disclosure of a PHP CGI Windows platform remote code execution vulnerability (CVE-2024-4577) on the internet recently. Due to PHP’s oversight of the Best-Fit character mapping feature of the Windows system during its design, running PHP in CGI mode on the Windows platform and using the following language settings (Simplified […]
NSFOCUS: Pioneering Technology and Industry Leadership
junho 7, 2024
We are excited to share that NSFOCUS has been recognized in Forrester’s The Insider Risk Solutions Landscape, Q2 2024 report. This accolade underscores our unwavering commitment to being a leader and innovator in the cybersecurity industry. Insider Risk Management is a field filled with internationally renowned security vendors and tech giants. Unlike traditional segmented markets […]
Linux Kernel Privilege Escalation Vulnerability (CVE-2024-1086) Notice
junho 6, 2024
Overview Recently, NSFOCUS CERT detected that the details and verification tools of a Linux kernel privilege escalation vulnerability (CVE-2024-1086) are disclosed on the internet. Because the netfilter: nf _ tables component of the Linux kernel has a post-release reuse vulnerability, the nft _ verdict _ init () function allows positive values to be used as […]
NTP Reflection Protection in ADS
junho 5, 2024
An NTP amplification attack is a reflection-based volumetric distributed denial-of-service (DDoS) attack in which an attacker exploits a Network Time Protocol (NTP) server functionality to overwhelm a targeted network or server with an amplified amount of UDP traffic, rendering the target and its surrounding infrastructure inaccessible to regular traffic. An NTP amplification attack can be […]
NSFOCUS Sets a New Benchmark as the World’s First to Achieve Dual-Domain CMMI V3.0 Level 5 Certification
junho 4, 2024
SANTA CLARA, Calif., June 4, 2024 – NSFOCUS, a global leader in cybersecurity solutions, proudly announces a groundbreaking achievement: becoming the world’s first company to receive CMMI V3.0 Level 5 certification in both Development (DEV) and Security (SEC) domains. Following the CMMI Institute’s recent update to version 3.0 on April 1, 2024, this landmark accomplishment […]
Contextual Intelligence is the Key
maio 29, 2024
With the increasing complexity and frequency of cybersecurity threats, organizations face many network threats. The importance of threat intelligence has become increasingly prominent. During this year’s RSA Conference, Sierra Stanczyk, the Senior Manager of Global Threat intelligence at PwC, and Allison Wikoff, the Director of Global Threat Intelligence for the Americas at PwC, shared “Connecting […]
Confluence Remote Code Execution Vulnerability (CVE-2024-21683) Notification
maio 22, 2024
Overview Recently, NSFOCUS CERT detected that Atlassian issued a security announcement and fixed the remote code execution vulnerability in Confluence Data Center and Server (CVE-2024-21683), with a CVSS score of 8.3. Authenticated attackers can realize remote code execution by constructing malicious requests, which will have a great impact on the confidentiality, integrity and availability of […]