Blog

Apache Kafka Arbitrary File Read and SSRF Vulnerability (CVE-2025-27817)

junho 11, 2025 | NSFOCUS

Overview Recently, NSFOCUS CERT detected that Apache issued a security bulletin to fix the arbitrary file read and SSRF vulnerabilities in Apache Kafka (CVE-2025-27817); Because the Apache Kafka client does not strictly validate and restrict user input, an unauthenticated attacker can elevate the file system/environment/URL access rights of the REST API by constructing malicious configurations […]

NSFOCUS Releases 2024 Global DDoS Landscape Report

junho 9, 2025 | NSFOCUS

SANTA CLARA, Calif., June 9, 2025 – NSFOCUS, a global leader in cybersecurity solutions, announced the release of its annual report, the 2024 Global DDoS Landscape Report. The full report is packed with in-depth analysis and insights that can help organizations better understand the DDoS threat environment and formulate more effective countermeasures. Highlights of the […]

Multiple High-Risk Vulnerabilities in DataEase (CVE-2025-49001/CVE-2025-49002/CVE-2025-48999)

junho 9, 2025 | NSFOCUS

Overview Recently, NSFOCUS CERT has detected that DataEase has issued a security bulletin to fix multiple high-risk vulnerabilities in DataEase (CVE-2025-49001/CVE-2025-49002/CVE-2025-48999). Combined use can achieve unauthorized code execution. At present, the vulnerability details and PoC have been made public. Relevant users are requested to take measures to protect them as soon as possible. CVE-2025-49001: Due […]

Uma imagem que ilustra um teclado com uma tecla escrita ddos attack.

Quais as diferenças entre ataques DDoS na camada de aplicação e na camada de rede?

junho 6, 2025 | Eduardo Guerra

O mercado de serviços de proteção contra ataques de negação de serviço distribuídos, ou Anti-DDoS – possui um grande foco na mitigação de ataques direcionados à camada de rede da infraestrutura das empresas. Os ataques DDoS (Distributed Denial of Service) continuam sendo uma das maiores ameaças à disponibilidade de serviços online. Com o aumento da […]

Uma imagem que ilustra ataques ddos e um sistema de segurança.

Ataque DDoS: o que é, como funciona e como se proteger?

maio 29, 2025 | Eduardo Guerra

Ataques cibernéticos são cada vez mais frequentes, e entre os mais temidos está o ataque DDoS. Seja você um profissional de tecnologia, dono de um site ou empresa, ou apenas alguém interessado em segurança digital, é fundamental entender como esses ataques funcionam e o que fazer para se proteger. Neste artigo, você vai descobrir o […]

NSFOCUS Recognized by Forrester in The Network Analysis and Visibility (NAV) Solution Landscape

maio 28, 2025 | NSFOCUS

Santa Clara, Calif. May 28, 2025 – Recently, global research and advisory firm Forrester released The Network Analysis and Visibility (NAV) Solutions Landscape, Q2 2025, offering a comprehensive analysis of market dynamics, technology trends, and product capabilities. NSFOCUS has once again [1] been included in this report. Forrester’s reports on specific technical fields are highly recognized worldwide. […]

VMware vCenter Server Command Execution Vulnerability (CVE-2025-41225)

maio 21, 2025 | NSFOCUS

Overview Recently, NSFOCUS CERT detected that VMware issued a security bulletin to fix the command execution vulnerability (CVE-2025-41225) of VMware vCenter Server; Due to an authenticated command execution vulnerability in VMware vCenter Server, an attacker with permissions to create or modify alerts and run scripts can exploit this vulnerability to execute arbitrary commands on the […]

Ivanti Endpoint Manager Mobile Authentication Bypass and Remote Code Execution Vulnerability (CVE-2025-4427/CVE-2025-4428)

maio 16, 2025 | NSFOCUS

Recently, NSFOCUS CERT detected that Ivanti issued a security advisory to fix the authentication bypass and remote code execution vulnerabilities (CVE-2025-4427/CVE-2025-4428) in Ivanti Endpoint Manager Mobile (EPMM). At present, both 2 vulnerabilities have been found to be exploited in the wild. Please take measures to protect them as soon as possible. CVE-2025-4427: An authentication bypass […]

Imagem que ilustra um ataque cibernético em andamento.

O que é um ataque cibernético? Tipos e prevenção

maio 15, 2025 | Eduardo Guerra

A segurança digital se tornou uma prioridade inegociável. Com o avanço da tecnologia, surgem também novas ameaças digitais e uma das mais perigosas é o ataque cibernético. Empresas, governos e até mesmo usuários comuns estão constantemente na mira de criminosos digitais que buscam explorar vulnerabilidades. Mas afinal, o que é ataque cibernético, quais são os […]

NSFOCUS WAF Selected in the 2025 Gartner® Market Guide for Cloud Web Application and API Protection

maio 14, 2025 | NSFOCUS

Santa Clara, Calif. May 14, 2025 – Recently, Gartner released the “Market Guide for Cloud Web Application and API Protection”[1], and NSFOCUS was selected as a Representative Vendor with its innovative WAAP solution. We believe this recognition reflects the technical accumulation and practical capabilities of NSFOCUS WAF in the field of cloud native security protection. Its […]