Blog

AI Security Incident Case: OpenAI Models Independently Break Through Test Boundaries and Exploit Vulnerabilities to Invade Hugging Face

Overview In July 2026, the AI open source community and collaboration platform Hugging Face publicly disclosed a special security incident: the platform's production infrastructure suffered an intrusion activity. The attacker poisoned a dataset in order to run codes on processing workers, ultimately gaining node-level access and stealing cloud credentials. It...

O que é Privacidade de dados? Veja como proteger sua empresa

A era digital trouxe uma explosão no volume de dados gerados, coletados e armazenados diariamente. Esse cenário levanta questões críticas sobre a privacidade de dados, que se tornou um tópico central nas discussões empresariais e legislativas.  Neste artigo, exploraremos o mundo da privacidade de dados, sua importância, a relação com...

Fastjson 1.2.x Remote Code Execution Without Gadget Vulnerability Notice

Overview Recently, NSFOCUS CERT detected that a Fastjson 1.2.x remote code execution vulnerability without gadget was disclosed online; Due to the defects in the internal type parsing logic of Fastjson deserialization, unauthenticated attackers can construct specially crafted malicious JSON data to bypass the traditional autoType black and white list protection...

WordPress Remote Code Execution Vulnerability (CVE-2026-63030/CVE-2026-60137) Notice

Overview Recently, NSFOCUS CERT detected that WordPress issued a security bulletin to fix the WordPress remote code execution vulnerability (CVE-2026-63030/CVE-2026-60137), known as wp2shell; Unauthenticated attackers can bypass authentication through REST API batch requests, use SQL injection to obtain administrator password hashes, and use plug-in installation functions to implant WebShell to...

NSFOCUS Releases 2025 APT Group Research Annual Report

SANTA CLARA, Calif., July 20, 2026 – In 2025, geopolitical conflict and technological transformation have become deeply intertwined, and the iterative leaps in artificial intelligence (AI) have reshaped the landscape of cybersecurity offense and defense. Empowered by AI, Advanced Persistent Threats (APTs) now exhibit greater stealth and destructive power, becoming a...

Microsoft’s July Security Update of High-Risk Vulnerability Notice for Multiple Products

Overview On July 15, NSFOCUS CERT monitored that Microsoft released its July security update patch, fixing 622 security issues. These affect widely used products such as Windows, Microsoft Office, Microsoft SQL Server, Visual Studio Code, Microsoft Edge, Azure, etc., which include high-risk vulnerability types such as remote code execution vulnerabilities,...

NSFOCUS
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.