Blog

Multiple Security Vulnerabilities Alerts of VMware vRealize Log Insight

fevereiro 1, 2023 | NSFOCUS

Overview Recently, NSFOCUS CERT found that VMware has officially fixed multiple security vulnerabilities in VMware vRealize Log Insight. Under default configuration conditions, unauthenticated attackers exploit the following key vulnerabilities in combination, and finally achieve arbitrary code execution with ROOT privileges on the target system. These vulnerabilities have been successfully verified by international security teams, and […]

Technical Framework of Software Supply Chain Security

janeiro 31, 2023 | NSFOCUS

NSFOCUS Security Labs is keeping an eye out for the trends in supply chain security and is pleased to share observations and thoughts with our blog readers. You will see the links for more posts we published about software supply chain security at the end of the article. In this post, we are going to […]

NSFOCUS Recognized Again by Forrester as a Sample Vendor for Its Next-Generation WAF

janeiro 26, 2023 | NSFOCUS

Santa Clara, Calif. January 26, 2023 – NSFOCUS, a global provider of intelligent hybrid security solutions, announced today that it has been selected by Forrester as a sample vendor for its next-generation Web Application Firewall (WAF) in the report The Forrester Tech Tide™: Zero Trust Threat Prevention, Q4 2022 published recently. The Forrester Tech TideTM […]

NSFOCUS Selected as a Representative Vendor in IDC Perspective: Unified Security Management as a Service (USMaaS), 2022

janeiro 24, 2023 | NSFOCUS

Santa Clara, Calif. January 19, 2023 – NSFOCUS, a global provider of intelligent hybrid security solutions, announced today that it has been selected by IDC as a representative vendor in the report IDC Perspective: Unified Security Management as a Service (USMaaS), 2022 released recently, and NSFOCUS T-ONE Cloud was selected as an excellent practice of […]

NSFOCUS Cloud DDoS Protection Service Summary of 2022

janeiro 19, 2023 | NSFOCUS

NSFOCUS published the Summary of Cloud DDoS Protection 2022 recently. This summary comes from DDoS attacks protected by NSFOCUS Cloud DDoS Protection Service (Cloud DPS) in the year 2022. The following service highlights can be found in the report: DDoS attack timeline, volume and attack type distribution collected from NSFOCUS Cloud DPS; Top 3 attacks […]

NSFOCUS Selected in Gartner’s Emerging Tech Impact Radar: Security

janeiro 17, 2023 | NSFOCUS

We are pleased to announce that NSFOCUS was selected by Gartner® as a sample vendor in the field of Deception as a Feature in the report Emerging Tech Impact Radar: Security (November 2022). According to the report, “This technology can significantly reduce the amount of time an attacker gets to spend in a compromised environment […]

Bread Crumbs of Threat Actors (Dec 19, 2022 – Jan 1, 2023)

janeiro 12, 2023 | NSFOCUS

From December 19, 2022 to Jan 1, 2023, NSFOCUS Security Labs found activity clues of 61 APT groups, 3 malware families (Zbot botnet, SpicyHotPot Trojan, and Banload Trojan), and 490 threat actors targeting critical infrastructure. APT Groups Among the 61 APT groups discovered, the APT28 affected the most significant number of hosts from December 19 […]

Analysis of Cyber Attack of APT Organization Confucius against Pakistan’s Intelligence-Based Operation

janeiro 12, 2023 | NSFOCUS

Overview Affected by many factors, Pakistan has long suffered from serious local terrorism threats. The country has also taken counter-terrorism as an important national security strategy. In the second half of 2022, the Pakistani security forces carried out many intelligence-based operations (IBO) in Baluchistan, Khyber and North Waziristan, and killed many terrorists. Pakistan’s recent high-profile […]

Relationship Between Security Concept and Security Assessment for Software Supply Chain

janeiro 5, 2023 | NSFOCUS

The three concepts, transparency of software supply chain, assessable capabilities of software supply chain security, and trusted software supply chain, are closely related to the ability of end users to conduct security checks and assessments for the software supply chain, including: 1. Basic assessment of software composition security Upstream and downstream companies can provide end […]

Security Concept for Software Supply Chain (Part 3) – Building Trusted Software Supply Chain

dezembro 28, 2022 | Adeline Zhang

A crop of multi-level upstream and downstream security problems makes software supply chain (SSC) security more complex.  It is difficult to assess and control the security of the whole chain only depending on companies, but it is necessary to strengthen the security supervision of the supply chain products, provide companies SBOM hosting and trusted certification […]