Exim Remote Code Execution Vulnerability (CVS 2023-42115) Notification

outubro 10, 2023 | NSFOCUS

Overview Recently, NSFOCUS CERT detected an Exim remote code execution vulnerability (CVE-2023-42115). When external authentication is enabled, due to improper user input verification, an unauthenticated attacker can remotely exploit this vulnerability by writing data beyond the bounds, ultimately executing arbitrary code on the target server. At present, the details of the vulnerability have been disclosed. […]

NSFOCUS Receives CNVD Outstanding Contribution Award for Original Vulnerability Submission

outubro 5, 2023 | NSFOCUS

The CNVD (China National Vulnerability Database) platform recently initiated the 2022 annual technical group support unit’s capability assessment. A comprehensive assessment was conducted across six capability domains, including vulnerability collection, vulnerability discovery, big data analysis of vulnerability threat risks, vulnerability technical analysis, major vulnerability incident response, and collaborative teamwork. NSFOCUS was awarded the Outstanding Contribution […]

Mirai Botnet’s New Wave: hailBot,kiraiBot, catDDoS, and Their Fierce Onslaught

outubro 3, 2023 | NSFOCUS

I. Abstract In September 2023, NSFOCUS global threat hunting system monitored several new botnet variant families developed based on Mirai, among which hailBot, kiraiBot and catDDoS are the most active, are accelerating their spread, and are widely deployed, which has constituted a considerable threat. Through this article, we will disclose the technical details of these […]

Google Chrome Heap Buffer Overflow Vulnerability (CVE-2023-5217) Notification

outubro 1, 2023 | NSFOCUS

Overview Recently, NSFOCUS CERT found that Google officially fixed a zero-day exploit (CVE-2023-5217), which was caused by the heap buffer overflow in the VP8 encoding of the open source libvpx video codec library. An attacker could use this vulnerability to execute arbitrary code on the target system. At present, this vulnerability has been exploited in […]

Uma imagem que ilustra o que são bots.

O que são bots? Conheça os tipos e como se precaver

setembro 29, 2023 | Eduardo Guerra

Os bots, uma abreviação para robôs, tornaram-se uma parte essencial do nosso mundo digital. Eles desempenham várias funções, desde automatizar tarefas simples até realizar atividades complexas na internet.  Neste artigo, vamos conhecer melhor o mundo dos bots, como eles funcionam, os diferentes tipos e como você pode proteger sua empresa contra bots maliciosos. Continue a […]

JumpServer Multiple Security Vulnerabilities Notification

setembro 28, 2023 | NSFOCUS

Overview Recently, NSFOCUS CERT monitored that JumpServer officially issued a notice to fix multiple security vulnerabilities. The vulnerabilities are detailed below. JumpServer Reset Password Vulnerability (CVS 2023-42820): There is a password reset vulnerability in JumpServer, as third-party libraries expose random seed numbers to APIs, which may cause random verification codes to be replayed. Unauthenticated remote […]

Google LibWebP Arbitrary Code Execution Vulnerability (CVE-2023-5129) Notification

setembro 27, 2023 | NSFOCUS

Overview Recently, NSFOCUS CERT found that Google officially fixed a heap buffer overflow vulnerability (CVE-2023-4863). Due to a flaw in the WebP module, an attacker triggered the vulnerability by inducing users to visit a malicious website, which ultimately led to arbitrary code execution on the target system. At present, it has been detected that the […]

Warning: Newly Discovered APT Attacker AtlasCross Exploits Red Cross Blood Drive Phishing for Cyberattack

setembro 25, 2023 | NSFOCUS

I. Abstract NSFOCUS Security Labs recently discovered a new attack process based on phishing documents in their daily threat-hunting operations. Delving deeper into this finding through extensive research, they confirmed two new Trojan horse programs and many rare attack techniques and tactics. NSFOCUS Security Labs believes that this new attack process comes from a new […]

Apple Multiple Product Security Vulnerabilities Notification

setembro 22, 2023 | NSFOCUS

Overview Recently, NSFOCUS CERT has detected that Apple has officially fixed three zero-day exploit in multiple products. These vulnerabilities exist in the wild. Affected users should take protective measures as soon as possible. The details of the vulnerability are as follows: Apple WebKit Arbitrary Code Execution Vulnerability (CVS 2023-41993): There is an arbitrary code execution […]

Unlocking the Future of Cybersecurity: Meet Us at GovWare 2023

setembro 22, 2023 | NSFOCUS

Today’s ever-evolving digital landscape presents unparalleled opportunities alongside formidable cybersecurity challenges, making the security of organizations’ networks and applications more crucial. As a global network and cyber security leader, we’re excited to invite you to join us at GovWare 2023, a pivotal event held at the Sands Expo and Convention Centre in Singapore from October […]

Procurar