Security News

Drupal admins: Get ready for emergency out-of-band patch for critical vulnerability
2018-04-24 12:12

Drupal's first patch for the 'Drupalgeddon 2' apparently proved insufficient, prompting a timed release of another patch on Wednesday.

Expand vulnerability and risk management programs to eliminate security misconfigurations
2018-04-23 12:15

In this podcast recorded at RSA Conference 2018, Tim White, Director of Product Management, Policy Compliance at Qualys, discusses how expanding vulnerability and risk management programs can...

LinkedIn Vulnerability Allowed User Data Harvesting
2018-04-20 06:05

LinkedIn recently patched a vulnerability that could have been exploited by malicious websites to harvest data from users’ profiles, including private information. read more

iOS trustjacking vulnerability lets hackers steal iPhone data, install spy apps
2018-04-19 12:11

The flaw takes advantage of Wi-Fi syncing in iTunes, but requires a developer image to work properly.

Hackers Exploiting Drupal Vulnerability to Inject Cryptocurrency Miners
2018-04-18 10:03

The Drupal vulnerability (CVE-2018-7600), dubbed Drupalgeddon2 that could allow attackers to completely take over vulnerable websites has now been exploited in the wild to deliver malware...

Report: 100% of web apps have at least one security vulnerability
2018-04-16 20:16

Nearly all of the vulnerabilities detected in web apps were of a critical nature, with financial services sites the most at risk, according to a Positive Technologies report.

Illumio, Qualys Partner on Vulnerability-based Micro-Segmentation
2018-04-13 16:10

Vulnerability management has two major components: discovering vulnerabilities, and mitigating those vulnerabilities. The first component is pointless without the second component. So, for...

Hackers Start Exploiting Drupalgeddon2 Vulnerability
2018-04-13 14:01

Attempts to exploit a recently patched vulnerability in the Drupal content management system (CMS) were spotted by researchers shortly after someone published a proof-of-concept (PoC) exploit. read more

Illumio and Qualys integrate to deliver vulnerability-based micro-segmentation
2018-04-13 10:45

Illumio announced new global vulnerability mapping capabilities on its Adaptive Security Platform. Vulnerability and threat data from the Qualys Cloud Platform is integrated with Illumio...

Vulnerability in San Francisco’s Public Safety Warning Sirens Fixed
2018-04-10 19:01

A patched vulnerability in San Francisco’s public safety warning siren system suggests other radio-based platforms could also be hacked.