The Increasing Trend of Software Supply Chain Attacks

novembro 8, 2022 | NSFOCUS

Compared with traditional security threats, supply chain threats have a spreading influence. Vulnerabilities of upstream products will affect all downstream roles, causing security risks to spread along the supply chain and consequently expanding the attack area. In recent years, several influential supply chain attacks have taken place, involving open-source components, public code repositories, and cloud […]

NSFOCUS Partner Summit 2022

novembro 6, 2022 | NSFOCUS

NSFOCUS LATAM team held #PartnerSummit2022 in partnership with CLM, where we met with major partners and distributors to celebrate the success we have achieved throughout this year.We spent an amazing night fulfilled with good talks, laughter, exchange of experiences, wine tasting, raffle of gifts and awards for companies that stood out in 2022.

Spring Security Authentication Bypass Vulnerability (CVE-2022-31692) Notice

novembro 4, 2022 | Jie Ji

Overview Recently, NSFOCUS CERT found that the PoC of the Spring Security authentication bypass vulnerability (CVE-2022-31692) was publicly disclosed online. Due to improper authorization flaws, under certain conditions, an unauthenticated remote attacker can use FORWARD or INCLUDE for forwarding, thereby exploiting the vulnerability to bypass the authorization rules and ultimately achieve authentication bypass. At present, […]

OpenSSL Multiple Buffer Overflow Vulnerability Notice

novembro 2, 2022 | Jie Ji

Overview On November 2, 2022, NSFOCUS CERT detected that openssl officially released a security notice and fixed multiple buffer overflow vulnerabilities in OpenSSL. OpenSSL is an open source software library package. Applications can use this package to communicate securely, avoid eavesdropping, and confirm the identity of the other end of the connection. It is widely […]

Threats against Software Supply Chain Security

novembro 1, 2022 | NSFOCUS

In the last post of this series, we had an overview of software supply chain security and summarized some observations during the research. You can read the previous post here. In this post, we’re going to talk about the threats faced by the software supply chain.   Globalized economic development has brought more opportunities and […]

Google Chrome Remote Code Execution Vulnerability (CVE-2022-3723) Alert

outubro 31, 2022 | Jie Ji

Overview Recently, NSFOCUS CERT monitored that Google Chrome has officially released a security bulletin and fixed a remote code execution vulnerability in Chrome V8 (JavaScript engine). Due to a type confusion vulnerability in Chrome V8, a remote attacker could exploit the vulnerability to execute arbitrary code on the target system. At present, the official has […]

Stay Alert to Traps in Updates: A New Variant of Magniber Ransomware

outubro 26, 2022 | NSFOCUS

Overview The Magniber is a notorious ransomware. Unlike the common ransomware families such as Hive and LockBit that target companies, it is primarily used to blackmail individuals with a relatively low ransom around USD 2,500. The Magniber ransomware can neither be transmitted automatically nor used to upload user files, but encrypt files only. Here listed […]

GovWare Focus 2022

outubro 25, 2022 | NSFOCUS

GovWare 2022 went back in-person in Singapore from 18th to 20th Oct 2022. The conference & exhibition was held with the theme of “Fostering a safe and sustainable cyberspace amidst disruption.”  At the 3-day event, Richard, Hai Siang, Meng Kiat and Cindy were there to introduce our newly launched Cloud WAAP service, DDoS protection solution and hybrid intelligent […]

Apache Dubbo Remote Code Execution Vulnerability (CVE-2022-39198) Notification

outubro 22, 2022 | Jie Ji

Overview On October 19, NSFOCUS CERT found that Apache issued a security notice to fix a remote code execution vulnerability (CVE-2022-39198) in Dubbo. Due to a deserialization vulnerability in Dubbo’s hessian-lite, an attacker can exploit this vulnerability to remotely execute arbitrary code on the target system. Relevant users are requested to take measures to protect […]

Software Supply Chain Security: Overview

outubro 21, 2022 | NSFOCUS

Software supply chain security is one of the key considerations in modern supply chain security. NSFOCUS Security Labs has conducted long-term research on security of the software supply chain. We’d like to publish a series of posts to share our observations, explore security issues existing in the software supply chain, conclude the core concepts, technical […]

Procurar