Blog

Imagem que ilustra a visibilidade de ataque externo.

The Undercurrent Behind the Rise of DeepSeek: DDoS Attacks in the Global AI Technology Game

janeiro 31, 2025 | NSFOCUS

Background The rise of DeepSeek is undoubtedly a milestone in the development of AI technology in China. As a representative AI enterprise, DeepSeek has not only made breakthrough progress in technological innovation and commercial application, but also demonstrated the outstanding strength and great potential of Chinese technology enterprises in the global AI competition. However, as […]

imagem que ilustra segurança da NSFOCUS em relação ao CTEM.

Security Risks of Low-altitude Economy

janeiro 28, 2025 | NSFOCUS

The low-altitude economy is becoming an important force to promote economic growth by virtue of its innovative ability and huge development potential. From UAV logistics distribution to urban air traffic, from emergency rescue to aerial photography and mapping, the application scenarios of low-altitude economy have been continuously expanded, and the market scale has been expanding […]

Uma imagem que ilustra um cadeado em cima de um teclado de notebook.

O que é Privacidade de dados? Veja como proteger sua empresa

janeiro 24, 2025 | Eduardo Guerra

A era digital trouxe uma explosão no volume de dados gerados, coletados e armazenados diariamente. Esse cenário levanta questões críticas sobre a privacidade de dados, que se tornou um tópico central nas discussões empresariais e legislativas.  Neste artigo, exploraremos o mundo da privacidade de dados, sua importância, a relação com a LGPD (Lei Geral de […]

Oracle WebLogic Server Remote Code Execution and Denial of Service Vulnerability (CVE-2025-21535/CVE-2025-21549)

janeiro 23, 2025 | NSFOCUS

Overview Recently, NSFOCUS CERT detected that Oracle has released a security announcement, in which the remote code execution and denial of service vulnerabilities of Oracle WebLogic Server have been fixed. Affected users should take protective measures as soon as possible. CVE-2025-21535: When the T3/IIOP protocol is enabled, an unauthenticated attacker sends a special request to […]

MongoDB Mongoose Search Injection Vulnerability (CVE-2025-23061)

janeiro 21, 2025 | NSFOCUS

Overview Recently, NSFOCUS CERT detected a security announcement issued by GitHub that fixed a search injection vulnerability (CVE-2025-23061) in Mongoose, which is an incomplete fix for CVE-2024-53900. Because Mongoose incorrectly handles the $where filter with match conditions in the populate() method, an unauthenticated attacker can manipulate a search injection when both queries are used, resulting […]

Rsync Buffer Overflow and Information Disclosure Vulnerability (CVE-2024-12084/CVE-2024-12085) Notification

janeiro 17, 2025 | NSFOCUS

Overview Recently, NSFOCUS detected that Rsync issued a security announcement and fixed the buffer overflow and information leakage vulnerabilities in Rsync (CVE-2024-12084/CVE-2024-12085). The combination of the two vulnerabilities can realize remote code execution. Please take measures to protect them as soon as possible. CVE-2024-12084: There is a heap buffer overflow vulnerability in the Rsync daemon. […]

Uma imagem que ilustra o ransomware.

O que é Ransomware? Definição, prevenção e remoção

janeiro 16, 2025 | Eduardo Guerra

O termo ransomware é um tema frequente nas discussões sobre segurança cibernética.  Trata-se de um tipo de malware que pode causar sérios danos a indivíduos e organizações, restringindo o acesso a dados vitais e sistemas inteiros.  Neste artigo, vamos entender o que é ransomware, mitigações e formas de assegurar sua exposição. Continue a leitura! O […]

Imagem que ilustra funcionários usando inteligência artificial na empresa.

Inteligência Artificial nas Empresas: Quais Cuidados Adotar?

janeiro 16, 2025 | Eduardo Guerra

A Inteligência Artificial (IA) tem se tornado uma ferramenta essencial no dia a dia das empresas, revolucionando processos, melhorando a eficiência e oferecendo soluções inovadoras. No entanto, a implementação dessa tecnologia não vem sem desafios. Embora a IA traga benefícios consideráveis, é crucial que as empresas adotem precauções para garantir que seu uso seja seguro, […]

Microsoft’s January Security Update of High-Risk Vulnerabilities in Multiple Products

janeiro 16, 2025 | NSFOCUS

Overview On January 14, NSFOCUS CERT detected that Microsoft released a security update patch for January, which fixed 159 security problems in widely used products such as Windows, Microsoft Office, Microsoft Visual Studio, Azure, Microsoft Dynamics, and Microsoft Edge. This includes high-risk vulnerabilities such as privilege escalation and remote code execution. Among the vulnerabilities fixed […]

Fortinet OS & FortiProxy Authentication Bypass Vulnerability (CVE-2024-55591) Notification

janeiro 16, 2025 | NSFOCUS

Overview Recently, NSFOCUS CERT detected that Fortinet has issued a security notification and fixed the identity authentication bypass vulnerability in FortiOS and FortiProxy (CVE-2024-55591). Unauthenticated attackers can bypass system identity authentication by sending special packets to the Node.js websocket module, thus obtaining super administrator permissions of the target system. The CVSS score is 9.8. At […]