Overview On January 11, ThinkPHP addressed a remote code execution vulnerability. This vulnerability stems from the Request class's (thinkphp/library/think/Request.php) lack of sufficient input validation when handling requests, which finally leads to remote code execution. (mais…)
Blog
Technical Report on Container Security (IV)-3
Container Security Protection – Host Security Host Security Hardening of Basic Host Security Containers share the operating system kernel with the host. Therefore, host configuration determines whether containers can be executed in a secure manner. For example, vulnerable software puts the host at risk of arbitrary code execution; opening ports...
Microsoft’s January 2019 Patch Fixes 51 Security Vulnerabilities Threat Alert
Overview Microsoft released the January 2019 security patch on Tuesday that fixes 51 vulnerabilities ranging from simple spoofing attacks to remote code execution in various products, including .NET Framework, Adobe Flash Player, Android App, ASP.NET, Internet Explorer, Microsoft Edge, Microsoft Exchange Server, Microsoft JET Database Engine, Microsoft Office, Microsoft Office...
NSFOCUS Forms Strategic Partnerships in LATAM and Around the World
By: Andre Tristao e Mello, Vice President, Latin America & Caribbean, NSFOCUS At NSFOCUS, we are always looking for ways to better serve and work with our customers --- from innovative product updates to partnerships; we’re dedicated to helping and protecting our customers. Across the LATAM region, we focused...
IP Reputation Report-01112019
Top 10 countries in attack counts: The above diagram shows the top 10 regions with the most malicious IP addresses from the NSFOCUS IP Reputation databases at January 11, 2019. Top 10 countries in attack percentage: From the diagram above, we can see the region Palestinian Territory has the biggest...
Microsoft Exchange Server Arbitrary User Impersonation Vulnerability Handling Guide
1 Vulnerability Overview Recently, a security researcher released details of an arbitrary user impersonation vulnerability (CVE-2018-8581) in Microsoft Exchange Server (also known as Exchange Web Server, EWS for short), revealing that an authenticated attacker could exploit this vulnerability to impersonate arbitrary accounts or even gain privileges of the target user....





