Blog

Gitblit Authentication Bypass Vulnerability (CVE-2024-28080)

setembro 2, 2025 | NSFOCUS

Overview Recently, NSFOCUS CERT detected that Gitblit issued a security announcement and fixed the Gitblit authentication bypass vulnerability (CVE-2024-28080); Because Gitblit’s SSH service has defects in the public key authentication process, unauthenticated attackers can use the client’s public key to trigger signature verification failure and fall back to password-based authentication to complete SSH login with […]

NSFOCUS Recognized by Gartner® “Hype Cycle™ for APIs, 2025” for API Threat Protection

setembro 2, 2025 | NSFOCUS

Recently, Gartner released “Hype Cycle for APIs, 2025”, NSFOCUS was selected as a Representative vendor in API Threat Protection of Hype Cycle with its cloud-native API security solution. We believe, this recognition reflects NSFOCUS’s comprehensive strength in API security technology innovation research, and continuous accumulation and achievements in API security protection practices in cloud-native environments. With […]

NSFOCUS was Included Among Representative Vendors in “The Cloud Native Application Protection Solutions Landscape”

agosto 28, 2025 | NSFOCUS

Recently, Forrester released the 2025 “The Cloud Native Application Protection Solutions Landscape” report. NSFOCUS Cloud Native Application Protection Solution (hereinafter referred to as “NSFOCUS CNAPP”) has been selected among Representative vendors in the field of cloud native security, which NSFOCUS believes is due to its continuous innovation and prospective layout. The solution is an integrated, […]

Imagem que ilustra um vazamento de dados.

Prompt Injection: An Analysis of Recent LLM Security Incidents

agosto 26, 2025 | NSFOCUS

Overview With the widespread application of LLM technology, data leakage incidents caused by prompt word injections are increasing. Many emerging attack methods, such as inducing AI models to execute malicious instructions through prompt words, and even rendering sensitive information into pictures to evade traditional detection, are posing serious challenges to data security. At the same […]

Uma imagem que ilustra um hacker.

NSFOCUS Monthly APT Insights – July 2025

agosto 25, 2025 | NSFOCUS

Regional APT Threat Situation In July 2025, the global threat hunting system of Fuying Lab detected a total of 33 APT attack activities. These activities were primarily concentrated in regions including South Asia, East Asia, Southeast Asia, Eastern Europe, and West Asia, as shown in the following figure. Regarding the activity levels of different organizations, […]

US Officials Claim to Have Gained Control of the RapperBot

agosto 22, 2025 | NSFOCUS

Overview Recently, US officials claimed to have successfully gained control of RapperBot, effectively curbing this powerful source of DDoS attacks. The operation pinpointed the key figure behind the botnet, Ethan Foltz. According to the investigation, Foltz has been developing and operating RapperBot since 2021, with his residence in Eugene, Oregon, USA. Since its activity, the […]

Uma imagem que ilustra o que é EDR.

EDR Security: o que é Detecção e Resposta de Endpoint? 

agosto 21, 2025 | Eduardo Guerra

Em um mundo cada vez mais digital, a segurança cibernética já é uma necessidade. E uma das tecnologias emergentes nesse campo é a Detecção e Resposta de Endpoint (EDR). Por isso, criamos este conteúdo a fim de desmistificá-lo, explicando desde a sua definição até os principais recursos e como a tecnologia pode ser um diferencial […]

Microsoft’s August Security Update High-Risk Vulnerability Notice for Multiple Products

agosto 14, 2025 | NSFOCUS

Overview On August 13, NSFOCUS CERT detected that Microsoft released the August Security Update patch, which fixed 111 security issues involving widely used products such as Windows, Microsoft Office, Microsoft SQL Server, Visual Studio, and Microsoft Exchange Server. These include high-risk vulnerability types such as privilege escalation and remote code execution. Among the vulnerabilities fixed […]

Imagem que ilustra um vazamento de dados.

O que é Data Leakage? Veja como as empresas devem se prevenir

agosto 14, 2025 | Eduardo Guerra

A segurança da informação é um dos pilares essenciais para qualquer organização que lida com dados sensíveis. Se você trabalha com tecnologia, gestão de dados, compliance ou é responsável por processos de segurança digital, este conteúdo é para você. Saber o que é data leakage e como evitá-lo é fundamental para preservar a confidencialidade, integridade […]

Uma imagem que ilustra um hacker.

NSFOCUS Monthly APT Insights – June 2025

agosto 8, 2025 | NSFOCUS

Regional APT Threat Situation In June 2025, the global threat hunting system of Fuying Lab detected a total of 33 APT attack activities. These activities were mainly distributed in regions such as South Asia, East Asia, West Asia, Eastern Europe, and South America, as shown in the figure below. In terms of organizational activity, the […]