IP Reputation Report-06072020
junho 10, 2020
1.Top 10 countries in attack counts: The above diagram shows the top 10 regions with the most malicious IP addresses from the NSFOCUS IP Reputation databases at June 7, 2020. 2.Top 10 countries in attack percentage: The Belarus is in first place. The Cape Verde is in the second place. The country China (CN) is […]
Apache Kylin Remote Code Execution Vulnerability (CVE-2020-1956) Threat Alert
junho 9, 2020
Vulnerability Description Recently, Apache released a security advisory to announce the fix of a remote code execution vulnerability (CVE-2020-1956) in Apache Kylin. Apache Kylin has some RESTful APIs that will associate OS commands with user-typed strings. As Apache Kylin fails to properly verify user inputs, an attacker could execute arbitrary system commands without authorization. Currently, […]
Fastjson 1.2.68 and Earlier Remote Code Execution Vulnerability Threat Alert
junho 8, 2020
Vulnerability Description
On May 28, Fastjson 1.2.68 and before were reported to contain a remote code execution vulnerability that bypasses the autoType switch to implement deserialization of classes that contain security risks. Attackers could exploit this vulnerability to execute arbitrary code on the target machine.
(mais…)Apache Tomcat Session Deserialization Code Execution Vulnerability (CVE-2020-9484) Threat Alert
junho 5, 2020
Overview Recently, Apache Tomcat released a security advisory, announcing the fix of a remote code execution vulnerability (CVE-2020-9484) due to persistent session. An attacker can exploit this vulnerability only when the following conditions are met: The attacker can take control of the contents and name of a file on the server. The server is configured […]
IP Reputation Report-05312020
junho 4, 2020
1. Top 10 countries in attack counts: The above diagram shows the top 10 regions with the most malicious IP addresses from the NSFOCUS IP Reputation databases at May 31, 2020. 2. Top 10 countries in attack percentage: The Belarus is in first place. The Cape Verde is in the second place. The country China […]
DDoS Attack Landscape 10
junho 3, 2020
Active Families
- Gafgyt
As one of the largest IoT DDoS families, Gafgyt compromises such devices as routers and cameras by means of password cracking and exploits to receive C&C commands and launch DDoS attacks.
In 2019, the Gafgyt family continued to be active, mainly targeting North America, Europe, and Australia. The number of Gafgyt-based malware increased fourfold compared with 2018 and the
average daily increase of C&C attacks reached 34.5%. Compared with 2018, the number of DDoS attack directives increased by 175%, most of which were UDP flood attacks targeting ports 80 and
443 for HTTP services and ports 3074, 300000, 30100, and 32000 for gaming services.
Cisco Unified Contact Center Express (Unified CCX) Deserialization Code Execution Vulnerability (CVE-2020-3280) Threat Alert
junho 2, 2020
Overview
Recently, Cisco officially released a security advisory, announcing the fix of a high-risk vulnerability (CVE-2020-3280) in Unified Contact Center Express (Unified CCX). The vulnerability stems from the fact that during the deserialization operation of the software, the input provided by the user is not sufficiently restricted. The attacker can send a malicious Java object to trigger the vulnerability without authorization to execute arbitrary code.
CVSS3.0 Base Score: 9.8
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:X/RL:X/RC:X
(mais…)WellinTech KingView Multiple Vulnerabilities Threat Alert
junho 1, 2020
Overview
Some versions of WellinTech KingView are prone to multiple vulnerabilities, including the real-time database access authorization bypass vulnerability and denial-of-service vulnerability existing in the web data transmission service. Vulnerability details are as follows:
1. KingView real-time database access authorization bypass vulnerability (CNVD-C-2020-87074)
2. KingView denial-of-service vulnerability existing in the web data transmission service (CNVD-C-2020-92339)
3. KingView denial-of-service vulnerability existing in the web data transmission service (CNVD-C-2020-92346)
4. KingView denial-of-service vulnerability existing in the web data transmission service (CNVD-C-2020-92365)
5. KingView denial-of-service vulnerability existing in the web data transmission service (CNVD-C-2020-92343)
6. KingView denial-of-service vulnerability existing in the web data transmission service (CNVD-C-2020-92341)
7. KingView denial-of-service vulnerability existing in the web data transmission service (CNVD-C-2020-92351)
(mais…)NSFOCUS Named a Representative Vendor in Gartner Market for Security Threat Intelligence Products and Services
maio 30, 2020
The world’s leading research and advisory company, Gartner, has named NSFOCUS as a Representative Vendor in its May 2020 Market Guide for Security Threat Intelligence Products and Services.
This guide provides in-depth analysis of the threat intelligence (TI) market, focusing on introducing its technical value and commercial potential of threat intelligence, and selecting credible vendors globally. NSFOCUS is honored to be named in the list.
(mais…)Microsoft’s Security Bulletin for May Patches That Fix 111 Security Vulnerabilities Threat Alert
maio 29, 2020
Overview
Microsoft released the May 2020 security patch on Tuesday that fixes 111 vulnerabilities ranging from simple spoofing attacks to remote code execution in various products, including .NET Core, .NET Framework, Active Directory, Common Log File System Driver, Internet Explorer, Microsoft Dynamics, Microsoft Edge, Microsoft Graphics Component, Microsoft JET Database Engine, Microsoft Office, Microsoft Office SharePoint, Microsoft Scripting Engine, Microsoft Windows, Power BI, Visual Studio, Windows Hyper-V, Windows Kernel, Windows Scripting, Windows Subsystem for Linux, Windows Task Scheduler, and Windows Update Stack.
(mais…)