Blog

F5 BIG-IP/BIG-IQ High-Risk Vulnerabilities Threat Alert

Vulnerability Description On March 11, NSFOCUS observed that F5 released a security bulletin to announce the fix of multiple high-risk vulnerabilities, CVE-2021-22986, CVE-2021-22987, CVE-2021-22988, CVE-2021-22989, CVE-2021-22990, CVE-2021-22991, and CVE-2021-22992, which affect BIG-IP and BIG-IQ in F5. Users are advised to take preventive measures as soon as possible. BIG-IP is an...

GitLab Remote Code Execution Vulnerability Threat Alert

Vulnerability Description On March 19, 2021, NSFOCUS detected that GitLab released patches for a code execution vulnerability in GitLab Community Edition (CE) and Enterprise Edition (EE), which was assigned a CVSS base score of 9.9. Unauthorized authenticated attackers could craft malicious requests via controllable markdown rendering options, thereby executing arbitrary...

NSFOCUS Web Application Firewall Attains ICSA Labs Certification

MILPITAS, Calif. – March 22, 2021 – We are pleased to announce that our web application firewall, NSFOCUS WAF, was awarded ICSA Labs Web Application Firewall Certification following rigorous and thorough testing. ICSA Labs, an independent division of Verizon, offers third-party testing and certification of security and health IT products,...

Microsoft March Security Updates for Multiple High-Risk Product Vulnerabilities

Vulnerability Description On March 10, 2021, Beijing time, Microsoft released March 2021 Security Updates that fix 89 vulnerabilities, including high-risk ones like remote code execution and privilege escalation in various widely used products such as Microsoft Windows, Microsoft Office, Microsoft Exchange Server, Internet Explorer, and Visual Studio. In these security...

‘FreakOut’ Malware Analysis – FreakOut Samples

Produced by: NSFOCUS Security Labs FreakOut samples appearing in the campaign were a typical IRC bot Trojan program written in Python. The Trojan program would connect to IRC channels in hardcoded C&C and act as instructed by C&C to collect information, launch DDoS attacks, interact with shells, and conduct ARP...

‘FreakOut’ Malware Analysis – Groups Behind FreakOut

Produced by: NSFOCUS Security Labs In early January 2021, NSFOCUS Security Labs captured an unknown malicious program called "out.py" via its real-time data platform, which is usually spread with the domain name "gxbrowser.net". NSFOCUS Security Labs conducted an in-depth research on the samples and payloads of the malware and compared...

NSFOCUS
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.