Critical Security Fixes from Adobe, Microsoft

Adobe has released updates to fix at least 67 vulnerabilities in its Acrobat, Reader and Flash Player software. Separately, Microsoft today issued patches to plug 48 security holes in Windows and other Microsoft products. If you use Windows or Adobe products, it’s time once again to get your patches on.

More than two dozen of the vulnerabilities fixed in today’s Windows patch bundle address “critical” flaws that can be exploited by malware or miscreants to assume complete, remote control over a vulnerable PC with little or no help from the user. According to Microsoft, none of flaws in August’s Patch Tuesday are being actively exploited in the wild, although Bleeping Computer notes that three of the bugs were publicly detailed before today’s patch release. Continue reading Critical Security Fixes from Adobe, Microsoft

Qualys CISO on making everything visibile and secure

In this podcast recorded at Black Hat USA 2017, Mark Butler, CISO at Qualys, talks about his role, streamlining security and compliance solutions, building security into digital transformation initiatives, end-to-end IT security, keeping your teams in sync, and compliance for all your assets. Here’s a transcript of the podcast for your convenience. Hi, my name is Mark Butler, I’m the Chief Information Security Officer at Qualys, and I want to tell you a little bit … More Continue reading Qualys CISO on making everything visibile and secure

Qualys CloudView to deliver continuous security of public cloud infrastructure

Qualys announced CloudView, a new app framework in the Qualys Cloud Platform for comprehensive and continuous protection of cloud infrastructure, delivering InfoSec and DevSecOps teams a “single pane of glass” view of security and compliance across cloud infrastructures. CloudView delivers to customers topological visibility and insight about the security and compliance posture of their complete public cloud infrastructure for major providers including Amazon Web Services (AWS), Microsoft Azure and Google Cloud. The first two apps … More Continue reading Qualys CloudView to deliver continuous security of public cloud infrastructure

Qualys at Black Hat USA 2017: Best practices and case study presentations

There will be no lack of interesting content from Qualys at Black Hat next week. Depending on you interests, you might want to make time for some of these talks and presentations at booth #899. Wednesday, July 26 10:20 AM – Achieving 2-Second Visibility with Qualys Cloud Agent Jimmy Graham, Director of Product Management, Qualys This talk focuses on how to use the Qualys Cloud Agent to enable instant, global visibility of IT assets including … More Continue reading Qualys at Black Hat USA 2017: Best practices and case study presentations

Adobe, Microsoft Push Critical Security Fixes

It’s Patch Tuesday, again. That is, if you run Microsoft Windows or Adobe products. Microsoft issued a dozen patch bundles to fix at least 54 security flaws in Windows and associated software. Separately, Adobe’s got a new version of its Flash Player available that addresses at least three vulnerabilities. Continue reading Adobe, Microsoft Push Critical Security Fixes

GDPR: 12 steps businesses can use to prepare right now

In this podcast, Darron Gibbard, Chief Technical Security Officer, EMEA, Qualys, talks about preparing for the GDPR and provides a good basis to start your program and understand what departments you need to be working with, and how you should be engaging with your respective businesses. Here’s a transcript of the podcast for your convenience. Hello, my name is Darron Gibbard, I’m the Chief Technical Security Officer for Qualys based in the EMEA region. I’m … More Continue reading GDPR: 12 steps businesses can use to prepare right now

Stack Clash bug could give root privileges to attackers on Unix, Linux systems

Qualys researchers have unearthed a serious privilege escalation bug affecting a wide variety of Unix and Unix-based operating systems, and has been working with vendors to develop patches since May. As the patches have been pushed out, Qualys went public with the information, and urged users to implement them as soon as possible. The vulnerability (CVE-2017-1000364) The vulnerability has been dubbed Stack Clash, because it is triggered when the attackers forces an application’s stack to … More Continue reading Stack Clash bug could give root privileges to attackers on Unix, Linux systems

Stack Clash Vulnerability in Linux, BSD Systems Enables Root Access

Patches are available for a newly discovered Linux, BSD and Solaris vulnerability called Stack Clash that bypasses stack guard-page mitigations and enables root access. Continue reading Stack Clash Vulnerability in Linux, BSD Systems Enables Root Access