Blog

NSFOCUS Lua-based Anti-DDoS Solution

junho 6, 2023 | NSFOCUS

Limitations of Pre-configured DDoS Protection Policies Lots of organizations have realized that DDoS defense is critical to the availability of network infrastructure. But most Anti-DDoS solutions in the market still rely on pre-configured protection policies with multiple threshold options to offer multi-layered protection at different levels. However, this approach has some limitations: Considering these limitations, […]

NSFOCUS Listed in Gartner® 2023 Market Guide for Security Threat Intelligence Products and Services Again

junho 1, 2023 | NSFOCUS

Santa Clara, Calif. June 1, 2023 – We are proud to announce that NSFOCUS has been included in the Gartner®2023 Market Guide for Security Threat Intelligence Products and Services[1] as a representative vendor for 3 years in a row. According to this report published in May, “Security and risk management leaders struggle to know what […]

Apache RocketMQ Remote Code Execution Vulnerability (CVS 2023-33246)

junho 1, 2023 | NSFOCUS

Overview Recently, NSFOCUS CERT found that the PoC of Apache RocketMQ remote code execution vulnerability (CVE-2023-33246) was publicly disclosed online. Due to the lack of appropriate permission verification in some components such as NameServer, Broker, and Controller of RocketMQ, they were unintentionally exposed to the external network. In specific circumstances, attackers can execute commands or […]

An Insight into RSAC 2023: Cooperation is the Key to Strengthening Cybersecurity

maio 30, 2023 | NSFOCUS

“Stronger Together” is the theme of the RSA Conference this year. Under the trend that the cyber security industry not only deeply participates in international competition to ensure technological advancement, but also continues to strengthen independent innovation ability, this theme reflects the development vitality and unique confrontation characteristics of this industry and is in line […]

GitLab Arbitrary File Read Vulnerability (CVS 2023-2825)

maio 29, 2023 | NSFOCUS

Overview Recently, NSFOCUS CERT found that GitLab officially issued a security notice, fixing an arbitrary file reading vulnerability (CVE-2023-2825) in GitLab Community Edition (CE) and Enterprise Edition (EE). When there are attachments in public projects nested in at least five groups, unauthenticated remote attackers use the upload function to traverse the path, resulting in reading […]

Software Supply Chain Security Solution – Supply Chain Security Supervision (Part 2)

maio 25, 2023 | NSFOCUS

Continued from the previous post: Software Supply Chain Security Solution – Supply Chain Security Supervision (Part 1) II.  Open-source Software Risk Monitoring Driven by the open source community and the continuous development of open source, open source software is widely used in practical engineering projects, and the number is growing rapidly. The number of open […]

Software Supply Chain Security Solution – Supply Chain Security Supervision (Part 1)

maio 25, 2023 | NSFOCUS

NSFOCUS Security Labs is keeping an eye out for the trends in supply chain security and is pleased to share observations and thoughts with our blog readers. You will see the links for more posts we published about software supply chain security at the end of the article. In the next several posts, we are going to […]

Uma imagem que ilustra um cadeado aberto em forma de computação.

Cibersegurança: o que é e como se proteger das ameaças virtuais?

maio 24, 2023 | Eduardo Guerra

Cibersegurança: o que é e como se proteger das ameaças virtuais? Proteja seus dados e informações contra ameaças virtuais. Descubra o que é cibersegurança e como se proteger por meio de nossas dicas. Seja em casa ou no ambiente de trabalho, a segurança digital é essencial e abrange diversos aspectos, desde a segurança de rede […]

Pay Attention to New SLP Vulnerability That May Lead to Massive DDoS Amplification Attacks

maio 23, 2023 | NSFOCUS

A new reflective Distributed-Denial-of-Service (DDoS) amplification vulnerability was recently discovered in the Service Location Protocol (SLP), which allows attackers to achieve a high amplification factor of over 2,200 times. This vulnerability has been identified as CVE-2023-29552, potentially making it one of the largest amplification attacks ever recorded. SLP is a protocol that provides a dynamic […]

Linux Kernel Privilege Escalation Vulnerability (CVS 2023-32233) Notice

maio 18, 2023 | NSFOCUS

Overview Recently, NSFOCUS CERT found that the PoC of Linux Kernel privilege escalation vulnerability (CVE-2023-32233) was publicly disclosed online. There is a use-after-free vulnerability in Linux kernel’s subsystem Netfilter nf_tables, which can be exploited by authenticated local attackers to perform arbitrary read and write operations in kernel memory, ultimately elevating permissions to ROOT. The CVSS […]