WebLogic T3/IIOP Information Disclosure Vulnerability (CVE-2024-21006/CVE-2024-21007)

abril 18, 2024 | NSFOCUS

Overview Recently, NSFOCUS CERT detected that Oracle has released a security announcement and fixed two information disclosure vulnerabilities (CVE-2024-21006/CVE-2024-21007) in Oracle WebLogic Server. Due to the defects of T3/IIOP protocol, unauthenticated attackers can send malicious requests through servers affected by T3/IIOP protocol. Access to sensitive information on the target system. Affected users should take measures […]

Palo Alto Networks PAN-OS Command Injection Vulnerability (CVE-2024-3400)

abril 18, 2024 | NSFOCUS

Overview Recently, NSFOCUS CERT detected that Palo Alto Networks issued a security announcement and fixed the command injection vulnerability (CVE-2024-3400) in PAN-OS. Since GlobalProtect gateway or portal configured in PAN-OS does not strictly filter user input, unauthenticated attackers can construct special packets to execute arbitrary code on the firewall with root privileges. The CVSS score […]

Uma imagem que ilustra como funciona a segurança de API.

Segurança de API: O que é e como otimizar a proteção?

abril 16, 2024 | Eduardo Guerra

A segurança de API (Application Programming Interface) é uma preocupação central para desenvolvedores e empresas que buscam proteger seus sistemas contra acessos não autorizados e violações de dados. As APIs são essenciais para a comunicação entre diferentes softwares, facilitando a integração de sistemas e a automação de tarefas, mas também podem ser pontos vulneráveis se […]

NSFOCUS Recognized as a Representative Vendor in the Gartner® Market Guide for Network Detection and Response

abril 15, 2024 | NSFOCUS

SANTA CLARA, Calif., April 15, 2024 – NSFOCUS, a global leader in cybersecurity solutions, has been named a representative vendor in the 2024 Gartner Market Guide for Network Detection and Response. As a key strategic product, NSFOCUS’s network threat detection and response solutions have rapidly evolved and delivered exceptional performance, earning notable recognition within the […]

XZ-Utils Supply Chain Backdoor Vulnerability Updated Advisory (CVE-2024-3094)

abril 7, 2024 | NSFOCUS

Vulnerability Overview Recently, NSFOCUS CERT detected that the security community disclosed a supply chain backdoor vulnerability in XZ-Utils (CVE-2024-3094), with a CVSS score of 10. Since the underlying layer of SSH relies on liblzma, when certain conditions are met, an attacker can use this vulnerability to bypass SSH authentication and gain unauthorized access on the […]

Uma imagem que ilustra ataques ddos e um sistema de segurança.

O que é um Ataque DDoS? Veja como funciona e como se proteger

abril 5, 2024 | Eduardo Guerra

Ataques DDoS, ou Distributed Denial of Service, são ataques cibernéticos que visam a sobrecarregar um servidor ou serviço online com um grande volume de tráfego virtual. Estes ataques são feitos para bloquear um serviço, servidor ou site para que os usuários não possam acessar ou utilizar o serviço. Entre os ataques mais realizados, o DDoS […]

JumpServer Remote Code Execution Vulnerability (CVE-2024-29201/CVE-2024-29202) Notice

abril 3, 2024 | NSFOCUS

Overview Recently, NSFOCUS CERT detected that JumpServer issued a security announcement and fixed two remote code execution vulnerabilities. At present, the PoC of the vulnerability has been made public. Affected users should take protective measures as soon as possible. CVE-2024-29201: Since the Ansible module in JumpServer does not perform complete input verification, attackers with low-privilege […]

Uma imagem que ilustra um teclado com uma tecla escrita ddos attack.

Modern DDoS Attacks and the Rise of DDoS Coalitions

abril 2, 2024 | NSFOCUS

DDoS attacks have become an indispensable weapon to paralyze network systems in cyber warfare. Emerging DDoS attacks, such as HTTP/2 Rapid Reset and SLP reflection amplification attacks, are constantly emerging. Both attackers and defenders are struggling to upgrade their technology in order to discover new offensive and defensive strategies. DDoS attacks are no longer limited […]

XZ Utils Backdoor Vulnerability (CVE-2024-3094) Advisory

abril 1, 2024 | NSFOCUS

Overview NSFOCUS CERT recently detected that a backdoor vulnerability in XZ Utils (CVE-2024-3094) was disclosed from the security community, with a CVSS score of 10. Because the SSH underlying layer relies on liblzma, an attacker could exploit this vulnerability to bypass SSH authentication and gain unauthorized access to affected systems, allowing arbitrary code execution. After […]

Linux Kernel Privilege Escalation Vulnerability (CVE-2024-1086) Alert

março 29, 2024 | NSFOCUS

NSFOCUS CERT has detected that details and a proof-of-concept (PoC) tool for a Linux kernel privilege escalation vulnerability CVE-2024-1086, have been publicly disclosed recently. Due to a use-after-free vulnerability in the netfilter: nf_tables component of the Linux kernel, the nft_verdict_init() function allows the use of positive values as a drop error in the hook verdict. […]

Procurar