At the RSA Conference this year, researchers from Cyberason shared the topic of Container Escape: All You Need Is Cap (Capabilities), detailing three methods of using Cap permissions for container escape, hoping to make users pay attention to the permission allocation of Capabilities when using containers and maintain best practices....
Categoria: Blog
An Insight into RSAC 2023: Build Cloud-Native Security Base Based on Zero Trust
At the 2023 RSA conference, Tracy Walker, Senior Security Engineer from SUSE NeuVector, shared with us a transparent (business- and environment-neutral) approach to blocking 0-Day attacks in K8S environments – Zero Trust Principle and demonstrated it using an open source tool, NeuVector. Based on Tracy's zero-trust viewpoint and the SUSE...
VMware Aria Operations for Networks Remote Code Execution Vulnerability (CVS 2023-20887) Notification
Overview Recently, NSFOCUS CERT detected a remote code execution vulnerability in VMware Aria Operations for Networks. Due to a specific flaw in the createSupportBundle method, the string entered by the user is not properly validated when executing system calls. Unauthenticated remote attackers can exploit this vulnerability through command injection, ultimately...
An Insight into RSAC 2023: Convergence of Threat Intelligence and AI
I. Overview In cybersecurity, big data is transforming threat intelligence and artificial intelligence, providing security teams with the flexibility to respond to changing environments. At the 2023 RSAC, Microsoft Vice President John Lambert discussed the convergence of intelligence and AI at the intersection of data and threats. The topic focused...
Openfire Console Identity Authentication Bypass Vulnerability (CVS 2023-32315) Notification
Overview Recently, NSFOCUS CERT detected an identity authentication bypass vulnerability in the Openfire console (CVE-2023-32315). The Admin Console of Openfire is a web-based application that has been found to be vulnerable to path traversal attacks by setting up the environment. Unauthenticated attackers use the unauthenticated Openfire setting environment in a...
An Insight into RSAC 2023: Web Application and API Security Trend
At this year's RSA conference, Akamai Senior Vice President Rupesh Chokshi shared a topic entitled Spotlight on latest web application and API attack data, highlighting the latest web application vulnerabilities and API attack trends. This article will explore this topic, starting from the data trends of application vulnerabilities and API...



