NSFOCUS

NSFOCUS Welcome to the company profile of NSFOCUS. Founded in 2000, NSFOCUS Information Technology Co., Ltd.
(1)

In June 2026, NSFOCUS Security Lab discovered a total of 28   attack activities. These activities were mainly distribute...
09/02/2026

In June 2026, NSFOCUS Security Lab discovered a total of 28 attack activities. These activities were mainly distributed in East Asia, South Asia, Eastern Europe, South America, and Central Asia.

3๏ธโƒฃ The most active APT groups in June were from East Asia, from South Asia. Other notably active groups included from East Asia and from Eastern Europe.
๐Ÿ˜ˆ 75% of the total attack incidents used spear email attack as the intrusion method. A small number of threat actors also utilized supply chain attacks (11%) and vulnerability exploitation (11%).
๐Ÿ‘ฅ The organizations or individuals were the primary targets in June, accounting for 29%, military institutions accounting for 25%.
๐Ÿ“Œ In June, key incidents include SideCopy launching โ€œOperation Xenofiscalโ€ targeting the Afghan government, and Gamaredon's continuous operations and evolution.

Learn more in ๐—ก๐—ฆ๐—™๐—ข๐—–๐—จ๐—ฆ ๐—”๐—ฃ๐—ง ๐—บ๐—ผ๐—ป๐˜๐—ต๐—น๐˜† ๐—ฏ๐—ฟ๐—ถ๐—ฒ๐—ณ๐—ถ๐—ป๐—ด:
https://nsfocusglobal.com/nsfocus-monthly-apt-insights-june-2026/



Regional APT Threat Situation In June 2026, the global threat hunting system of Fuying Lab detected a total of 28 APT attack activities. These activities were primarily concentrated in regions including East Asia, South Asia, Eastern Europe, South America, and Central Asia as shown in the figure bel...

๐Ÿฅ‡ We're proud to announce that NSFOCUS has just topped the ๐˜พ๐™ฎ๐™—๐™š๐™ง๐™‚๐™ฎ๐™ข Global Leaderboard, with a ๐Ÿต๐Ÿฑ.๐Ÿฌ๐Ÿฎ% success rate,  #1 ...
08/30/2026

๐Ÿฅ‡ We're proud to announce that NSFOCUS has just topped the ๐˜พ๐™ฎ๐™—๐™š๐™ง๐™‚๐™ฎ๐™ข Global Leaderboard, with a ๐Ÿต๐Ÿฑ.๐Ÿฌ๐Ÿฎ% success rate, #1 worldwide! ๐ŸŽ‰ ๐ŸŽ‰ ๐ŸŽ‰ https://lnkd.in/gKBXusfm

About CyberGym:
Introduced by the University of California, Berkeley, is a large-scale, high-quality cybersecurity evaluation framework designed to rigorously assess the capabilities of AI agents on real-world vulnerability analysis tasks, widely regarded as the most comprehensive and widely recognized practical AI security evaluation system in the world today.

NSFOCUS AI, our self-developed intelligent security agent built on Zhipu's ๐—š๐—Ÿ๐— -๐Ÿฑ.๐Ÿฏ, came out on top of the Level 1 leaderboard โ€” turning our accumulative offense&defense research into a computable workflow:
๐Ÿ”น Semantic constraint-based vulnerability hypothesis generation
๐Ÿ”น Debugger-assisted runtime evidence hardening (GDB)
๐Ÿ”น Constraint-guided directed fuzzing
๐Ÿ”น Closed-loop hypothesis correction

The result:
โœ”๏ธ 1,432 of 1,507 complex vulnerability discovery tasks completed
โœ”๏ธ 95.02% overall success rate (94.88% for ARVO and 96.40% for OSS-Fuzz)
โœ”๏ธ A 1.39 percentage point jump over the previous model generation, with the biggest gains on the hardest tasks

As AI accelerates both attack and defense, our philosophy stays the same: use AI to counter AI โ€” finding the unexpected state before adversaries do. ๐Ÿ‘ฟ

๐Ÿงท Read the full technical brief: https://lnkd.in/gNqYvvwb

๐ŸŽ‰ ๐Ÿฏ ๐—ฌ๐—ฒ๐—ฎ๐—ฟ๐˜€ in a Row! ๐Ÿ†NSFOCUS has once again been listed in the Gartnerยฎ Market Guide for Cloud Web Application and API P...
08/28/2026

๐ŸŽ‰ ๐Ÿฏ ๐—ฌ๐—ฒ๐—ฎ๐—ฟ๐˜€ in a Row! ๐Ÿ†

NSFOCUS has once again been listed in the Gartnerยฎ Market Guide for Cloud Web Application and API Protection ( )!

Protecting modern applications and APIs against increasingly sophisticated cyber threats requires continuous innovation and unwavering dedication. This recognition reinforces that we are moving in the right direction to provide top-tier protection for our customers globally. ๐Ÿ›ก๏ธ

๐Ÿงท Discover how NSFOCUS Cloud WAAP is shaping the future of web & API defense: https://nsfocusglobal.com/global-recognition-nsfocus-listed-in-gartner-market-guide-for-cloud-web-application-and-api-protection-for-three-consecutive-years/

Securing the date at GISEC GLOBAL 2026! ๐Ÿš€As   reshapes the threat landscape, modern cybersecurity demands smarter, faste...
08/25/2026

Securing the date at GISEC GLOBAL 2026! ๐Ÿš€

As reshapes the threat landscape, modern cybersecurity demands smarter, faster, and more proactive defenses. Join NSFOCUS at ๐—š๐—œ๐—ฆ๐—˜๐—– ๐—š๐—น๐—ผ๐—ฏ๐—ฎ๐—น ๐Ÿฎ๐Ÿฌ๐Ÿฎ๐Ÿฒ to explore how we are pioneering AI-powered security solutions to protect your digital transformation!

๐Ÿ—“๏ธ 16 - 18 September, 2026
๐Ÿ“ Dubai Exhibition Centre | ๐—•๐—ผ๐—ผ๐˜๐—ต ๐˜พ๐Ÿณ๐Ÿฌ
๐Ÿงท Register link: https://lnkd.in/gTAT5Ugs

Visit us at Booth C70 to experience our latest innovations across:

๐Ÿ”ธ ๐—œ๐—ป๐˜๐—ฒ๐—น๐—น๐—ถ๐—ด๐—ฒ๐—ป๐˜ ๐—ฆ๐—ฒ๐—ฐ๐˜‚๐—ฟ๐—ถ๐˜๐˜† ๐—ข๐—ฝ๐—ฒ๐—ฟ๐—ฎ๐˜๐—ถ๐—ผ๐—ป๐˜€: Leverage AI-driven automation to streamline threat detection and response.
๐Ÿ”ธ ๐—ก๐—ฒ๐˜๐˜„๐—ผ๐—ฟ๐—ธ & ๐—”๐—ฝ๐—ฝ๐—น๐—ถ๐—ฐ๐—ฎ๐˜๐—ถ๐—ผ๐—ป ๐—ฆ๐—ฒ๐—ฐ๐˜‚๐—ฟ๐—ถ๐˜๐˜†: Defend complex enterprise environments against sophisticated threats.
๐Ÿ”ธ ๐—”๐˜๐˜๐—ฎ๐—ฐ๐—ธ ๐—ฆ๐˜‚๐—ฟ๐—ณ๐—ฎ๐—ฐ๐—ฒ ๐— ๐—ฎ๐—ป๐—ฎ๐—ด๐—ฒ๐—บ๐—ฒ๐—ป๐˜: Gain continuous visibility to identify and remediate risks before exploitation.
๐Ÿ”ธ ๐—ฆ๐—ฒ๐—ฐ๐˜‚๐—ฟ๐—ถ๐˜๐˜† ๐—ฆ๐—ฒ๐—ฟ๐˜ƒ๐—ถ๐—ฐ๐—ฒ๐˜€: Partner with expert-managed services to elevate your overall security posture.

Let's connect, share insights, and redefine digital security for the AI era together!

๐ŸŒ NSFOCUS Log Audit System (๐™‡๐˜ผ๐™Ž) โ€” International Edition Now Available! https://lnkd.in/ghF2in5tAs digital business acce...
08/18/2026

๐ŸŒ NSFOCUS Log Audit System (๐™‡๐˜ผ๐™Ž) โ€” International Edition Now Available! https://lnkd.in/ghF2in5t

As digital business accelerates, IT environments are growing more complex by the day. Massive volumes of multi-source, heterogeneous logs are piling up faster than ever, making it harder for security teams to consolidate critical information, pinpoint hidden risks, and support effective security analysis. This has become a defining challenge for security operations worldwide. ๐Ÿ“Œ

๐—ก๐—ฆ๐—™๐—ข๐—–๐—จ๐—ฆ ๐—Ÿ๐—”๐—ฆ is now available, bringing core capabilities in centralized log collection, unified management, efficient retrieval, intelligent analysis, and security auditing to a global audience. https://lnkd.in/gmsZDPiw

Scattered logs โžก๏ธ Unified insight
Complex retrieval โžก๏ธ Efficient analysis
Risk detection โžก๏ธ Guided response

Built for diverse business environments and security operations scenarios, LAS is designed to turn massive log data into something truly understandable, analyzable, and ๐™–๐™˜๐™ฉ๐™ž๐™ค๐™ฃ๐™–๐™—๐™ก๐™š. ๐Ÿ”

AI Security Alert: ๐™ƒ๐™ค๐™ฌ ๐™– ๐˜ฟ๐™ค๐™˜๐™ช๐™ข๐™š๐™ฃ๐™ฉ ๐™’๐™ค๐™ง๐™ข ๐˜ผ๐™˜๐™๐™ž๐™š๐™ซ๐™š๐™จ ๐™Ž๐™š๐™ก๐™›-๐™๐™š๐™ฅ๐™ก๐™ž๐™˜๐™–๐™ฉ๐™ž๐™ค๐™ฃ ๐™ซ๐™ž๐™– ๐™ˆ๐™ž๐™˜๐™ง๐™ค๐™จ๐™ค๐™›๐™ฉ ๐™’๐™ค๐™ง๐™™ ๐˜พ๐™ค๐™ฅ๐™ž๐™ก๐™ค๐™ฉ? ๐Ÿšจ As enterprise adoption of...
08/05/2026

AI Security Alert: ๐™ƒ๐™ค๐™ฌ ๐™– ๐˜ฟ๐™ค๐™˜๐™ช๐™ข๐™š๐™ฃ๐™ฉ ๐™’๐™ค๐™ง๐™ข ๐˜ผ๐™˜๐™๐™ž๐™š๐™ซ๐™š๐™จ ๐™Ž๐™š๐™ก๐™›-๐™๐™š๐™ฅ๐™ก๐™ž๐™˜๐™–๐™ฉ๐™ž๐™ค๐™ฃ ๐™ซ๐™ž๐™– ๐™ˆ๐™ž๐™˜๐™ง๐™ค๐™จ๐™ค๐™›๐™ฉ ๐™’๐™ค๐™ง๐™™ ๐˜พ๐™ค๐™ฅ๐™ž๐™ก๐™ค๐™ฉ? ๐Ÿšจ

As enterprise adoption of AI assistants rapidly accelerates, threat actors are finding new ways to exploit the trust and autonomy granted to LLM-powered tools. Any system that integrates into a trusted workflow must recognize a default risk: once external content enters the model context, there is a certain probability of causing harm.

๐Ÿง Our research team delves into an emerging vector of a recent AI security incident: the attack exploits a hint injection vulnerability in Microsoft for Word, allowing malicious instructions to self-replicate and spread in normal document workflows, forming a new type of document-based AI worm.

๐Ÿ‘‡ Read the full technical breakdown:
https://nsfocusglobal.com/ai-security-incident-case-document-worm-achieves-self-replication-and-propagation-via-word-copilot/

Overview On July 28, 2026, security researcher Hรฅkon Mรฅlรธy publicly disclosed a new attack technique called โ€œAI Worming through Wordโ€. The attack exploits a hint injection vulnerability in Microsoft Copilot for Word, allowing malicious instructions to self-replicate and spread in normal docum...

๐Ÿšจ The first fully autonomous AI cyberattack has happened โ€” and it hit Hugging Face, one of the world's largest AI platfo...
07/30/2026

๐Ÿšจ The first fully autonomous AI cyberattack has happened โ€” and it hit Hugging Face, one of the world's largest AI platforms.

It was a ๐—บ๐˜‚๐—น๐˜๐—ถ-๐˜€๐˜๐—ฎ๐—ด๐—ฒ, ๐—ฐ๐—ฟ๐—ผ๐˜€๐˜€-๐˜€๐˜†๐˜€๐˜๐—ฒ๐—บ attack exploiting code-injection flaws in the data pipeline and a 0-day in the package management agent โš ๏ธ A critical security guardrail was deliberately disabled during testing, and let the model escaped containment in the first place.

We call this a "๐˜พ๐™๐™š๐™ง๐™ฃ๐™ค๐™—๐™ฎ๐™ก ๐™ข๐™ค๐™ข๐™š๐™ฃ๐™ฉ" for software supply chain security: not because of the scale of damage done, but because of what it reveals. As AI agents get folded into more of the supply chain, incidents like this are a preview of the threat landscape ahead.

Read our insight of the attack chain and what it means for AI/software supply chain security ๐Ÿ‘‡
https://lnkd.in/gqnw7_HK

๐™’๐™๐™–๐™ฉ ๐™๐™–๐™ฅ๐™ฅ๐™š๐™ฃ๐™จ ๐™ฌ๐™๐™š๐™ฃ ๐™–๐™ฃ ๐™–๐™™๐™ซ๐™–๐™ฃ๐™˜๐™š๐™™ ๐˜ผ๐™„ ๐™ˆ๐™ค๐™™๐™š๐™ก ๐™—๐™ง๐™š๐™–๐™ ๐™จ ๐™ค๐™ช๐™ฉ ๐™ค๐™› ๐™ž๐™ฉ๐™จ ๐™จ๐™–๐™ฃ๐™™๐™—๐™ค๐™ญ?Hugging Face recently experienced a multi-stage intrusi...
07/28/2026

๐™’๐™๐™–๐™ฉ ๐™๐™–๐™ฅ๐™ฅ๐™š๐™ฃ๐™จ ๐™ฌ๐™๐™š๐™ฃ ๐™–๐™ฃ ๐™–๐™™๐™ซ๐™–๐™ฃ๐™˜๐™š๐™™ ๐˜ผ๐™„ ๐™ˆ๐™ค๐™™๐™š๐™ก ๐™—๐™ง๐™š๐™–๐™ ๐™จ ๐™ค๐™ช๐™ฉ ๐™ค๐™› ๐™ž๐™ฉ๐™จ ๐™จ๐™–๐™ฃ๐™™๐™—๐™ค๐™ญ?

Hugging Face recently experienced a multi-stage intrusion originated from advanced AI models under internal testing by OpenAI. The breach revealed critical vulnerabilities across the chain:
๐Ÿ”ธ Code injection flaws in Hugging Face's data pipeline
๐Ÿ”ธ Zero-day vulnerabilities in package management agents
๐Ÿ”ธ Security guardrails were intentionally turned off during network capacity testing, granting the model unfiltered network capabilities.

The more far-reaching impact of this attack goes far beyond the Hugging Face platform:
๐Ÿค– Autonomous Offensive AI is Here: Agents are capable of executing complex, multi-stage attacks dynamically.
โš ๏ธ The Asymmetry Crisis: Defenders are constrained by security policies; untethered AI agents are not.
โ˜ ๏ธ Revisiting Defense Speed: When an agent generates thousands of heuristics per second, static "Trust โ†’ Verify" protocols fail instantly.

๐Ÿ” Read our analysis: https://nsfocusglobal.com/ai-security-incident-case-openai-models-independently-break-through-test-boundaries-and-exploit-vulnerabilities-to-invade-hugging-face/

Overview In July 2026, the AI open source community and collaboration platform Hugging Face publicly disclosed a special security incident: the platformโ€™s production infrastructure suffered an intrusion activity. The attacker poisoned a dataset in order to run codes on processing workers, ultimate...

Earlier this month, Sysdig disclosed the   ransomware attack. From reconnaissance, credential theft, lateral movement, a...
07/08/2026

Earlier this month, Sysdig disclosed the ransomware attack. From reconnaissance, credential theft, lateral movement, and privilege escalation to the final file encryption, the entire attack process was completed autonomously by AI agent. ๐Ÿค–

๐Ÿ‘ฟ This marks the first documented case of a fully AI-agent-driven, end-to-end ransomware attack, signaling a new stage of autonomous and intelligent ransomware operations.

Ransomware is no longer the exclusive tool of highly skilled individuals. In the age of agentic attacks, security architectures must incorporate AI agent behaviors into threat models to build an effective line of defense. ๐Ÿ›ก๏ธ

๐Ÿ”— Read our recap: https://nsfocusglobal.com/ai-security-incident-jadepuffer-ransomware-leverages-ai-agent-to-automate-attacks/

In early July 2026, security firm Sysdig publicly disclosed a new type of ransomware attack. After gaining initial access by exploiting a Langflow vulnerability (CVE-2025-3248), the JadePuffer ransomware leveraged a Large Language Model (LLM) agent to automatically execute the entire attack chain. F...

Address

690 N. McCarthy Boulevard, Suite 170
Milpitas, CA
95035

Alerts

Be the first to know and let us send you an email when NSFOCUS posts news and promotions. Your email address will not be used for any other purpose, and you can unsubscribe at any time.

Shortcuts

Share