NSFOCUS

NSFOCUS Welcome to the company profile of NSFOCUS. Founded in 2000, NSFOCUS Information Technology Co., Ltd.
(1)

To accurately analyze the evolving landscape of global Advanced Persistent Threats ( ) and bolster defenses for digital ...
06/03/2026

To accurately analyze the evolving landscape of global Advanced Persistent Threats ( ) and bolster defenses for digital security and critical information infrastructure, NSFOCUS has released the ๐Ÿฎ๐Ÿฌ๐Ÿฎ๐Ÿฑ ๐—”๐—ฃ๐—ง ๐—”๐—ป๐—ป๐˜‚๐—ฎ๐—น ๐—Ÿ๐—ฎ๐—ป๐—ฑ๐˜€๐—ฐ๐—ฎ๐—ฝ๐—ฒ ๐—ฅ๐—ฒ๐—ฝ๐—ผ๐—ฟ๐˜, combining robust cybersecurity monitoring and advanced threat hunting capabilities.

๐Ÿ“œ This report conducts an in-depth analysis of APT activities across 2025 and decodes cutting-edge attack techniques, delivering actionable guidance to defend against APT activities.

In 2025, we recorded 308 APT incidents throughout the year, representing a YoY increase of 4%. Global APT activities showed the characteristics of "technical sophistication, tactical complexity, and frequent vulnerabilities". ๐Ÿ‘ฟ Driven by new attack strategies and new productivity tools, APT groupsโ€™ attack techniques and tactics continued to upgrade, and their attack accuracy and destructive power have been significantly improved.

๐Ÿ‘‰ Download the full report: https://nsfocusglobal.com/resources/2025-apt-annual-landscape-report/

05/29/2026

LLMs represented by ๐— ๐˜†๐˜๐—ต๐—ผ๐˜€ have greatly reduced the cost and skill threshold for discovering and exploiting vulnerabilities, making advanced cyber attack capabilities that previously required national resources within reach.

โš ๏ธ The structural shift is real: the time from vulnerability disclosure to weaponization is being compressed to near-zero. Defenders relying on traditional response timelines are already at a systemic disadvantage.

We've published a report analyzing the AI threat landscape following the next-gen LLMs capable of autonomous vulnerability discovery and exploitation.

What should enterprises do?
โœ… Build AI + Blue Army platforms for normalized attack-defense drills
โœ… Embed AI security agents directly into CI/CD pipelines
โœ… Establish SBOM/AIBOM inventories for real-time 0-day impact assessment
โœ… Shift focus from perimeter defense to limiting blast radius after breach
โœ… Deploy AI-driven XDR platforms for machine-speed threat detection and response

The era of ๐˜ผ๐™„ ๐Ÿ†š ๐˜ผ๐™„ ๐™ž๐™ฃ ๐™˜๐™ฎ๐™—๐™š๐™ง๐™จ๐™š๐™˜๐™ช๐™ง๐™ž๐™ฉ๐™ฎ is here. Read the full report to understand the threat landscape and our recommended response framework.

๐Ÿ”—https://nsfocusglobal.com/wp-content/uploads/2026/05/Security-Plan-for-AI-Threats.pdf

In March 2026, NSFOCUS Security Lab discovered a total of 31   attack activities. These activities were mainly distribut...
05/28/2026

In March 2026, NSFOCUS Security Lab discovered a total of 31 attack activities. These activities were mainly distributed in South Asia, Eastern Europe, and the Middle East.

3๏ธโƒฃ The most active groups in March were from South Asia and based in Eastern Europe, while other relatively active groups included from the Middle East and from South Asia.
๐Ÿ˜ˆ 87% of the total attack incidents used spear email attack as the intrusion method. A small number of threat actors also utilized vulnerability exploitations (10%) and watering hole attacks for infiltration (3%).
๐Ÿช– Military institutions were the primary targets in March, accounting for 33%, followed by government agencies (30%).
๐Ÿ“Œ In March, key incidents include orchestrating the Axios supply chain poisoning campaign, a vulnerability in products being escalated to a RCE severity, and leveraging OpenClaw-related GitHub repositories to distribute malware.

Learn more in ๐—ก๐—ฆ๐—™๐—ข๐—–๐—จ๐—ฆ ๐—”๐—ฃ๐—ง ๐—บ๐—ผ๐—ป๐˜๐—ต๐—น๐˜† ๐—ฏ๐—ฟ๐—ถ๐—ฒ๐—ณ๐—ถ๐—ป๐—ด:
๐Ÿ”— https://nsfocusglobal.com/nsfocus-monthly-apt-insights-march-2026/



Regional APT Threat Situation In March 2026, the global threat hunting system of Fuying Lab detected a total of 31 APT attack activities. These activities were primarily concentrated in regions including South Asia, Eastern Europe, and the Middle East, as shown in the figure below. Regarding the act...

In 2025, the   ecosystem is experiencing accelerated fragmentation: while established threat actors continue to consolid...
05/22/2026

In 2025, the ecosystem is experiencing accelerated fragmentation: while established threat actors continue to consolidate their dominance, emerging groups are rising swiftly by leveraging automation and intelligent capabilities, making the overall threat landscape increasingly complex.

Powered by long-term monitoring from NSFOCUS Fuying Labโ€™s Global Threat Hunting System, the newly released ๐Ÿฎ๐Ÿฌ๐Ÿฎ๐Ÿฑ ๐—š๐—น๐—ผ๐—ฏ๐—ฎ๐—น ๐——๐——๐—ผ๐—ฆ ๐—”๐˜๐˜๐—ฎ๐—ฐ๐—ธ ๐—Ÿ๐—ฎ๐—ป๐—ฑ๐˜€๐—ฐ๐—ฎ๐—ฝ๐—ฒ ๐—ฅ๐—ฒ๐—ฝ๐—ผ๐—ฟ๐˜ provides a systematic breakdown of current DDoS trends.

๐Ÿ“ฅ Download the full report to decode the trends and safeguard your infrastructure: https://nsfocusglobal.com/resources/2025-global-ddos-landscape-report/

05/20/2026

To overcome bottlenecks of AI models, including low performance and high memory usage in encrypted traffic detection, NSFOCUS and Intel jointly introduced ๐™๐™–๐™จ๐™ฉ๐™Ÿ๐™ค๐™ฎ, a next-generation, open-source traffic feature analysis framework. ๐Ÿ˜‰

Powered by Intel's hardware acceleration, VPP data-processing engine, and Intelยฎ oneAPI Toolkit, is integrated into the NSFOCUS Unified Threat Sensor ( ) to deliver:

โœ… Higher detection throughput at scale
โœ… Real-time threat identification โ€” without the memory overhead
โœ… Lower device costs across gateway security deployments
โœ… Extensible AI detection across NSFOCUS's broader product portfolio

We've just published a joint whitepaper detailing how this Intel-optimized pipeline โ€” from hardware acceleration to AI model deployment โ€” is redefining what's possible in encrypted traffic detection.

๐Ÿ“– Download a copy:https://nsfocusglobal.com/wp-content/uploads/2026/05/NSFOCUS-and-Intel-Achieve-High-Performance-Encrypted-Traffic-Detection-Through-Fastjoy.pdf

๐ŸŽ‰ Exciting news: NSFOCUS has been included in the Visionaries in the 2026 Gartnerยฎ Magic Quadrantโ„ข for ๐—–๐˜†๐—ฏ๐—ฒ๐—ฟ๐˜๐—ต๐—ฟ๐—ฒ๐—ฎ๐˜ ๐—œ๐—ป๐˜๐—ฒ๐—น...
05/15/2026

๐ŸŽ‰ Exciting news: NSFOCUS has been included in the Visionaries in the 2026 Gartnerยฎ Magic Quadrantโ„ข for ๐—–๐˜†๐—ฏ๐—ฒ๐—ฟ๐˜๐—ต๐—ฟ๐—ฒ๐—ฎ๐˜ ๐—œ๐—ป๐˜๐—ฒ๐—น๐—น๐—ถ๐—ด๐—ฒ๐—ป๐—ฐ๐—ฒ ๐—ง๐—ฒ๐—ฐ๐—ต๐—ป๐—ผ๐—น๐—ผ๐—ด๐—ถ๐—ฒ๐˜€!

For us, this is more than a milestone โ€” it's a reflection of our commitment to turning threat intelligence into real, business-relevant action. ๐Ÿง‘โ€๐Ÿ’ป

From AI-powered intelligence workflows, APT attribution research to our ThreatLens platform, we're focused on one thing: establish a full-spectrum threat intelligence product system spanning strategic, tactical, and technical levels. By deeply embedding threat intelligence into business contexts, we help enterprises advance their security operations from reactive response to proactive anticipation.

๐Ÿ”— Read more:

SANTA CLARA, Calif., May 13, 2026 โ€“ On May 4, 2026, Gartnerยฎ published the Gartnerยฎ Magic Quadrantโ„ข for Cyberthreat Intelligence Technologies report (hereinafter referred to as โ€œthe Reportโ€). NSFOCUS was included in the Visionaries quadrant. We believe, this recognition reflects the intern...

In 2025, fueled by the rapid evolution of AI agents and LLMs,   attacks are undergoing a paradigm shift from traditional...
05/13/2026

In 2025, fueled by the rapid evolution of AI agents and LLMs, attacks are undergoing a paradigm shift from traditional volumetric, bandwidth-heavy confrontations to intelligent warfare centered on cognitive speed, strategic precision, and decision-making efficiency.

๐Ÿ“ˆ Attack methodologies have evolved from blunt traffic suppression to highly targeted precision strikes, resulting in a marked increase in both stealth and destructive impact.

๐ŸŽฏ The overall threat landscape is increasingly complex. As cyber and physical worlds become more deeply coupled, DDoS is evolving into a strategic geopolitical tool.

๐™„๐™จ ๐™ฎ๐™ค๐™ช๐™ง ๐™™๐™š๐™›๐™š๐™ฃ๐™จ๐™š ๐™จ๐™ฉ๐™ง๐™–๐™ฉ๐™š๐™œ๐™ฎ ๐™ง๐™š๐™–๐™™๐™ฎ ๐™›๐™ค๐™ง ๐™ฉ๐™๐™š ๐˜ผ๐™„ ๐™š๐™ง๐™–?

๐Ÿ“ฅ Download the full report to decode the trends and safeguard your infrastructure:

THANK YOU FOR YOUR INTEREST IN NSFOCUS REPORTSโ€‹ 2025 Global DDoS Attack Landscape Report In 2025, fueled by the rapid evolution of AI agents and LLMs, DDoS attacks are undergoing a paradigm shift from traditional volumetric, bandwidth-heavy confrontations to intelligent warfare centered on cogniti...

โš ๏ธ Look out! A Linux kernel privilege escalation vulnerability (๐˜ฟ๐™ž๐™ง๐™ฉ๐™ฎ ๐™๐™ง๐™–๐™œ) was recently disclosed online. Attackers use...
05/08/2026

โš ๏ธ Look out! A Linux kernel privilege escalation vulnerability (๐˜ฟ๐™ž๐™ง๐™ฉ๐™ฎ ๐™๐™ง๐™–๐™œ) was recently disclosed online. Attackers use the logical defects of splice system calls in conjunction with xfrm-ESP or RxRPC protocol stacks to tamper with the page cache of any read-only file without race conditions to obtain system root permissions.

This vulnerability is highly stable and concealed. ๐Ÿ˜ˆ Attackers can accurately tamper with the page cache of any read-only file in the system by running simple scripts; because this exploitation process is triggered by deterministic logic, it does not rely on race conditions, and only tampers with memory data without destroying the original disk files, it is difficult for traditional security tools based on disk scanning to discover in real time.

๐Ÿ”— Read our analysis and mitigation advice:

Overview Recently, NSFOCUS CERT has detected a Linux kernel privilege escalation vulnerability (Dirty Frag) disclosed online. Attackers use the logical defects of splice system calls in conjunction with xfrm-ESP or RxRPC protocol stacks to tamper with the page cache of any read-only file without rac...

What if attackers could walk straight through your WAF โ€” and it would never know? ๐Ÿ˜ˆ  That's not a hypothetical. It's ๐™‚๐™๐™ค...
05/01/2026

What if attackers could walk straight through your WAF โ€” and it would never know? ๐Ÿ˜ˆ That's not a hypothetical. It's ๐™‚๐™๐™ค๐™จ๐™ฉ ๐˜ฝ๐™ž๐™ฉ๐™จ, disclosed at 2026.

The vulnerability exploits a subtle Java encoding behavior: when a 16-bit Unicode character is narrowed to a byte, the upper 8 bits are silently dropped. Attackers craft payloads that look benign to your security tools but are decoded as live attack code by the backend. The detection chain and the ex*****on chain see two completely different things.

The impact spans virtually every critical attack category โ€” SQL injection, RCE, file upload bypass, path traversal, authentication bypass, and SMTP injection. It even bypasses existing WAF rules protecting against known critical CVEs. No privileges needed.

๐Ÿ”ฅ Here's the difference that ๐—ก๐—ฆ๐—™๐—ข๐—–๐—จ๐—ฆ ๐—ช๐—”๐—™ makes:

โœ… Detection happens at the decoding layer โ€” not just pattern matching on surface strings
โœ… Both standard Unicode and Ghost Bits-modified payloads are semantically decoded and blocked
โœ… Protection was in place before the public disclosure: Actual interception with verifiable records

๐Ÿ“– Read the full technical breakdown to understand the attack chain and how our defense closes the gap:
๐Ÿ”— https://nsfocusglobal.com/waf-defense-in-crisis-nsfocus-locks-down-ghost-bits-attacks-in-advance/

Incident Review In April 2026, Black Hat Asia 2026 disclosed a systematic security threat named Ghost Bits, targeting underlying encoding flaws in the Java ecosystem that can render mainstream WAF/IDS defenses completely ineffective. The core of this risk lies in inconsistent encoding interpretation...

As the   ecosystem continues to surge in popularity, more customers are deploying and utilizing these AI agents on a lar...
04/30/2026

As the ecosystem continues to surge in popularity, more customers are deploying and utilizing these AI agents on a large scale. However, this growth has brought significant security challenges.

NSFOCUS LLM security assessment system ๐—”๐—œ-๐—ฆ๐—–๐—”๐—ก introduces specialized security scanning capabilities for OpenClaw and its derived ecosystems. ๐Ÿ›ก๏ธ New capabilities are coming soon in May:

โœ… Gateway Exposure Detection: Full visibility into public network risks
โœ… Credential Storage Detection: Preventing plaintext secret leaks
โœ… Memory Poisoning Detection: Ensuring AI agents remain non-hijackable
โœ… Supply Chain Security Detection: Multi-layer defense against malicious Skills

๐Ÿ’ก Stay tuned for the new AI-Scan defined by lightweight scanning, high-precision detection, and intelligent enhancement.

As the OpenClaw ecosystem continues to surge in popularity, more customers are deploying and utilizing these AI agents on a large scale. However, this growth has brought significant security challenges to the forefront, including over 33 documented CVE vulnerabilities, 288+ GHSA security advisories,...

Address

690 N. McCarthy Boulevard, Suite 170
Milpitas, CA
95035

Alerts

Be the first to know and let us send you an email when NSFOCUS posts news and promotions. Your email address will not be used for any other purpose, and you can unsubscribe at any time.

Share