Newsroom

UK Media Coverage

Imperva analysis demonstrates the importance of crowd-sourced threat intelligence

Research just published by Imperva claims to show that crowd-sourced threat intelligence is a key method by which business can raise the bar on their security defences. Read more

Apr 25, 2013

Qualys and FireMon enable real-time network risk visibility and remediation

Qualys, Inc. and FireMon have announced the integration of QualysGuard Vulnerability Management (VM) and FireMon Security Manager with Risk Analyzer in FireMon’s upcoming Version 7.0 release. Read more

Apr 24, 2013

InfoSec 2013: Government Promises £500,000 Cyber Aid For SMBs

SMBs are getting battered and the government wants to help with little pots of money Read more

Apr 23, 2013

Browsers pose the greatest threat to enterprise, Microsoft reports

Committed to Internet Explorer, Microsoft is experimenting with an architecture to replace the browser Read more

Apr 22, 2013

The Security Skills Gap

The UK’s National Audit Office (NAO) released a report in February this year (The UK cyber security strategy: Landscape review) that concluded that a lack of skilled workers is hampering the UK's fight against cybercrime.  Read more

Apr 22, 2013

Live on-stand interviews & wine: What we're up to at Infosecurity Europe...

Well, it's our last day in the office before we all go on site for Infosecurity Europe next week. There's a lot of excitement (and panic!) in the air...A few bits of news about what myself and the rest of team Infosecurity will be up to at the event next week... Read more

Apr 19, 2013

IT supply-chain security standard aims to prevent counterfeits, tampering

The danger of counterfeit and tampered IT products is well known, and to fight it, the Open Group has published a technical security standard aimed at supply-chain safety. Read more

Apr 17, 2013

Oracle addresses 120+ vulnerabilities in massive April patch update

Oracle has published two critical security updates, along with the Oracle Critical Patch Update (CPU) – all in all fixing 42 and 120+ vulnerabilities, respectively. Read more

Apr 17, 2013

Oracle plugs 42 Java flaws in critical update

Oracle is issuing 170 security patches – with 42 for Java alone – in a set of critical updates for its products. Read more

Apr 17, 2013

Topical Tuesday: 12 is the new 8 when it comes to password length

Wolfgang Kandek, Qualys’ chief technology officer, explains how his daughter’s emailaccount started generating spam – and why two-factor authentication and longer passwords are the answer… Read more

Apr 16, 2013

Microsoft eyes ditching browser for secure Web apps

Microsoft researchers have developed the prototype of a client-side architecture that would replace the Web browser with a much more secure virtualized environment that isolates Web applications. Read more

Apr 15, 2013

Problems with Patch Tuesday's MS13-036 bulletin

One of the patches pushed out by Microsoft has been withdrawn following reports of problems, including the infamous Blue Screen of Death Read more

Apr 15, 2013

If you haven’t yet, do not install Patch Tuesday’s MS13-036 bulletin

One of the patches pushed out by Microsoft this Patch Tuesday has been withdrawn following reports of problems, including the infamous Blue Screen of Death (BSOD). Read more

Apr 15, 2013

Microsoft Repairs Botched Patch Tuesday Update

Microsoft has repaired its botched Patch Tuesday update after it caused a number of problems for end-users Read more

Apr 15, 2013

Microsoft releases nine bulletins, but no Pwn2Own fixes

Microsoft issued nine bulletins to fix 14 vulnerabilities this week; however it left several known flaws unpatched. Read more

Apr 11, 2013

Widely used wireless IP cameras open to hijacking over the Internet, researchers say

Wireless IP cameras from Foscam and other vendors have serious security issues, researchers said at Hack in the Box Read more

Apr 11, 2013

Patch Tuesday: Microsoft releases patches to fix 14 vulnerabilities

Software leader Microsoft released 9 bulletins for various software on Tuesday as part of its regular ‘Patch Tuesday’ cycle of updates. Read more

Apr 10, 2013

Critical Internet Explorer Fix In Patch Tuesday Update

IT pros urged to take immediate action for all supported versions of the Microsoft browser Read more

Apr 10, 2013

Patch Tuesday leaves Internet Explorer zero day untouched

There are only two Critical security bulletins this month, but a recently discovered Internet Explorer zero day remains vulnerable. Read more

Apr 10, 2013

Patch Tuesday Lands With Critical Internet Explorer Fix

All supported versions of IE affected as IT pros urged to take action Read more

Apr 9, 2013

Security updates likely to keep admins busy in April

Security updates from Microsoft, Oracle and PostGreSQL are likely to keep security administrators busy in April. Read more

Apr 8, 2013

Microsoft's next Patch Tuesday to fix nine flaws

Microsoft will patch nine vulnerabilities in next week's Patch Tuesday, with two of the fixes rated critical. Read more

Apr 5, 2013

Patch Tuesday preview: April 2013

Next week’s Microsoft Patch Tuesday comprises nine bulletins.  Read more

Apr 5, 2013

Microsoft tackles Windows 8 security flaw with latest Patch Tuesday

Microsoft has released details of April's Patch Tuesday update, with critical vulnerabilities in Windows and Internet Explorer being addressed. Read more

Apr 5, 2013

Microsoft to slap 9 patches on Windows junkies on Tuesday

Microsoft is lining up nine patches - two critical - as part of the April edition of its regular Patch Tuesday update cycle. Read more

Apr 5, 2013

Microsoft quietly patches first Modern app for Windows 8, RT

Microsoft earlier this week quietly issued its first security update for one of its Windows 8 apps, patching a link-spoofing vulnerability in Mail. Read more

Mar 29, 2013

Who Owns Application Security, Patching In Your Business?

Too many organizations lack a formal security plan, leaving applications vulnerable to exploits, warns SANS Institute. Read more

Mar 22, 2013

Security pros pan and praise Microsoft's plans on updating Modern apps in Windows 8, RT

Experts like the on-the-fly updating of apps, but the alerts ... not so much Read more

Mar 14, 2013

Java's security problems 'unlikely to be resolved soon'

Security experts think Oracle should have acted sooner to strengthen Java against attacks Read more

Mar 14, 2013

Scary flaw makes your USB ports a major security risk

Microsoft released seven new security bulletins for the March Patch Tuesday Read more

Mar 13, 2013

Java's security problems unlikely to be resolved soon, researchers say

Security experts think Oracle should have acted sooner to strengthen Java against attack Read more

Mar 13, 2013

Microsoft issues seven bulletins for Patch Tuesday, but nothing for Pwn2Own vulnerability

Microsoft released seven bulletins last night, containing four patches rated as critical, to fix 20 vulnerabilities. Read more

Mar 13, 2013

Microsoft issues four critical updates for Patch Tuesday

Could allow remote code execution via a 'specially crafted' webpage in IE Read more

Mar 13, 2013

Black Tuesday patchfest: A lot of digits plug security dykes

Adobe joins Redmond in game of vuln Twister Read more

Mar 13, 2013

Microsoft reverses IE10's Flash blocking in Windows 8, RT

Browser now shows Flash by default, leverages edge over iOS, say analysts Read more

Mar 12, 2013

Microsoft releases four critical security updates

Microsoft is to release four “critical” patches in its monthly Patch Tuesday security update according to the Advance Notice. Read more

Mar 11, 2013

Apple plugs App Store HTTPS omission 6 months later

It took Apple 6 months to plug a hole in the App Store that could have lead to various security issues Read more

Mar 11, 2013

Microsoft Readies Four Critical Fixes For Patch Tuesday

IE10 flaw uncovered by VUPEN during PWN2OWN not addressed in latest update Read more

Mar 11, 2013

The 4 security controls your business should take now

Security experts have defined the 20 most important security controls any organization should make now. Start with these four. Read more

Mar 9, 2013

March 2013 Patch Tuesday preview

This month’s Patch Tuesday will include seven security bulletins from Microsoft: four are critical and three are important; three require reboots, three may require a reboot, and one does not. Both businesses and consumers will likely be affected. Read more

Mar 8, 2013

IE flaw in Windows 8 to be patched next week

Microsoft will release seven fixes in next week's Patch Tuesday, four of them patching critical vulnerabilities. Read more

Mar 8, 2013

Microsoft to release four critical patches among seven fixes next week

Microsoft is to release seven bulletins on next week's Patch Tuesday, four of which are rated as critical. Read more

Mar 8, 2013

Microsoft preps UPDATE EVERYTHING patch batch

Microsoft plans to deliver seven bulletins next week, four critical, and three important, as part of the March edition of its regular Patch Tuesday update cycle. Read more

Mar 8, 2013

Microsoft Patch Tuesday targets Internet Explorer drive-by attacks

Prepare for a busy time after the weekend Read more

Mar 7, 2013

Java security woes to stay with businesses for a long time

Zero-day vulnerabilities, delays in receiving patches and continuous cyberattacks are enough to make any large company want to toss the buggy Java plug-in from browsers. But that seemingly simple solution is not possible for the majority of businesses, which still use the platform for running Web-based Java applications, experts say Read more

Mar 6, 2013

Qualys beefs up security tool for Amazon Cloud users

New QualysGuard connector conducts vulnerability scans of virtual servers in Amazon Cloud. Read more

Feb 28, 2013

New security tool serves Amazon Cloud users

The new QualysGuard connector conducts vulnerability scans of virtual servers in the Amazon Cloud. Read more

Feb 27, 2013

RSA Conference: Age of internet of things is upon us

The challenge of hyper-connected devices and the 'internet of things' will see billions of devices connected by the end of this decade, and all need to be secured. Read more

Feb 27, 2013

Adobe springs emergency Flash update, says hackers hitting Firefox

Second 'out-of-band' patch this month, fourth fix overall in 2013 Read more

Feb 26, 2013

Chrome 25 stable channel released ahead of Pwn2Own

Google’s Chrome 25 browser has now been promoted from beta to the full stable channel, fixing nine high severity vulnerabilities in the process. Chrome, Firefox and Internet Explorer have now all had major security overhauls during February. Read more

Feb 25, 2013

Qualys streamlines vulnerability scanning of Amazon cloud instances

Qualys launches Amazon AWS API data connectors for QualysGuard Read more

Feb 25, 2013

Oracle, Apple Issue Java Security Patches

Oracle updates Java 7 and issues the final-ever public update for Java 6, while Apple releases its own Java 6 update for OS X users. Read more

Feb 20, 2013

Mozilla toughens up on CA certificate abuse

Sub-CA certificates will need technical constraints or be publicly disclosed and audited. Read more

Feb 20, 2013

Apple FINALLY fills gaping Java hole that pwned its own devs

Zero-day vuln also downed Facebook staff and other Mac users Read more

Feb 20, 2013

New Certificate Authorities group promotes web security standards

Certificate Authority Security Council will raise awareness about OCSP stapling Read more

Feb 18, 2013

Certificate Authorities form group to push for better revocation checking

Newly formed Certificate Authority Security Council will raise awareness about OCSP stapling Read more

Feb 15, 2013

New Certificate Authorities group promises better revocation checking

Certificate Authority Security Council will raise awareness about OCSP stapling Read more

Feb 15, 2013

Microsoft unleashes a Patch Tuesday to make your head spin

Microsoft isn't showing IT admins much love this Valentine's Day week with 12 new security bulletins. Read more

Feb 13, 2013

Microsoft fixes 57 vulnerabilities on Patch Tuesday

Microsoft released 12 bulletins, five of which were rated as critical, to address 57 vulnerabilities on Patch Tuesday. Read more

Feb 13, 2013

Microsoft issues 57 critical patches for February Patch Tuesday

Microsoft releases patches on the second Tuesday of every month, and this February Patch Tuesday saw it issue 12 bulletins addressing 57 vulnerabilities across the firm's software. Read more

Feb 13, 2013

Get up, shake off the hangover: These 57 Microsoft holes won't fix themselves

A bumper Microsoft Patch Tuesday has rolled out 12 security bulletins that collectively address a hefty 57 vulnerabilities. Read more

Feb 13, 2013

How to find the most vulnerable systems on your internal network

Data from a large number of penetration tests in recent years show most corporate networks share common vulnerabilities. Many of these problems could be mitigated by appropriate education in “hacker thinking” for technical staff. Read more

Feb 12, 2013

Patch Tuesday preview: February 2013

February’s Patch Tuesday will comprise 12 Microsoft security bulletins covering some 57 vulnerabilities. Read more

Feb 8, 2013

Internet Explorer flaws fixed by Microsoft Patch Tuesday updates

Microsoft says Internet Explorer versions 6 through 10 are subjects of two critical Patch Tuesday updates for February that could address recent Java woes. Read more

Feb 8, 2013

Microsoft to deliver 12 patches next week, with five rated as critical

Microsoft is to release 12 bulletins next Tuesday, including five critical patches, to cover 57 vulnerabilities. Read more

Feb 8, 2013

Every single Internet Explorer at risk of drive-by hacks until Patch Tuesday

Microsoft has lined up a bumper Patch Tuesday this month to snap shut a backbreaking 57 security vulnerabilities in its products. Read more

Feb 8, 2013

Lucky 13 – a new attack against SSL/TLS

A flaw discovered in the design of the SSL protocol Read more

Feb 7, 2013

Researchers devise new attack techniques against SSL

The new 'Lucky Thirteen' attacks can be used to decrypt SSL/TLS and DTLS data if certain conditions are met Read more

Feb 6, 2013

New attack techniques against SSL revealed

The new 'Lucky Thirteen' attacks can be used to decrypt SSL/TLS and DTLS data if certain conditions are met Read more

Feb 6, 2013

SC Magazine Awards Europe 2013 - shortlist announced

The finalists for this year's SC Magazine Awards Europe have been announced. Read more

Feb 5, 2013

Lesson learned in cyberattack on The New York Times

Qualys comment on New York Times cyberattack Read more

Feb 1, 2013

Irish security VAR Integrity intensifies UK assault

Qualys mention as 'big' security vendor Read more

Jan 31, 2013

Big Data means big security

David Lacey blog post-CSO Interchange - mentions possibility of event attendees creating a voluntary Code of Practice for Big Data use Read more

Jan 26, 2013

Can Big Data be tapped for security purposes?

Article follows on from briefing with Peter Wood following CSO Interchange Read more

Jan 24, 2013

How to prevent 'zombie accounts' from haunting your digital identity

Comment from Wolfgang Kandek regarding password management Read more

Jan 24, 2013

Top tips for staying safe online

Coverage from top tips for staying safe online Read more

Jan 22, 2013

Oracle to issue Java patch following US Homeland Security warning

Review of security update for zero day flaw in Java Read more

Jan 14, 2013

Microsoft flings out emergency patch for Iatest gaping IE hole

Coverage of Microsoft's plans to release an out-of-band patch Read more

Jan 14, 2013

Oracle Rushes Out Java Patch But ‘Serious’ Flaws Left Open

Review of Java patch Read more

Jan 14, 2013

First Java zero-day of 2013 implemented into exploit kits

Coverage of zero-day threat to Java Read more

Jan 11, 2013

UK cyber-hygiene in need of a good scrub up

Qualys comment on Defence Select Committee report into the state of cyber security in the military Read more

Jan 10, 2013

Security experts stress urgency of patching Windows XML flaw

Microsoft released seven new security bulletins for the first Patch Tuesday of 2013--the most urgent being a patch for a flaw in XML. Read more

Jan 9, 2013

Shocking and scaring into awareness?

Qualys comment on Defence Select Committee report into the state of cyber security in the military Read more

Jan 9, 2013

Microsoft releases seven bulletins with two critical patches

Microsoft released seven bulletins on its first patch Tuesday of 2013, addressing 12 vulnerabilities in Windows, Office, Developer Tools and Windows Server. Read more

Jan 9, 2013

Hellish XML demon exorcised from Windows, IE bug stays

Patch Tuesday Microsoft released two "critical" patches and five "important" security updates on Tuesday - but none of the fixes address a zero-day vulnerability in Internet Explorer discovered two weeks ago. Read more

Jan 9, 2013

Microsoft to release seven bulletins next week, but no fix for Internet Explorer

Microsoft is to release seven bulletins next week, but will not patch the zero-day vulnerability in Internet Explorer. Read more

Jan 4, 2013

Microsoft Patch Tuesday offers no easy start to 2013

The first Microsoft monthly security update for 2013 does not offer an easy start to the year for IT administrators with seven bulletins covering a wide variety of software. Read more

Jan 4, 2013

Microsoft Patch Tuesday: Two critical fixes, many affected Windows users

Microsoft is issuing two critical fixes on this month's Patch Tuesday, one of them affecting its most popular operating system -- Windows 7 -- in conjunction with Windows Server 2008 R2. Read more

Jan 4, 2013

Microsoft Delivers Two Critical Fixes On First 2013 Patch Tuesday

The first Patch Tuesday of 2013 includes two critical bulletins and another five issues for IT teams to address. Read more

Jan 4, 2013

January 2013 Patch Tuesday preview

The first Microsoft Patch Tuesday for 2013 contains: 7 security bulletins, five of them ‘important’, but two of them ‘critical.’ Bulletins 1 and 2 will be the ones to watch. Read more

Jan 4, 2013

Microsoft to patch Windows 8, but stays mum on IE zero-day fix

Microsoft today said it will release seven security updates next week -- including one rated critical for Windows 8 and Windows RT -- to patch 12 vulnerabilities in Windows, Office, SharePoint Server and the company's website design software. Read more

Jan 3, 2013

Microsoft Patch Tuesday: Just two critical fixes but they affect a lot of Windows systems

Microsoft is issuing two critical fixes on this month's Patch Tuesday, one of them affecting its most popular operating system -- Windows 7 -- in conjunction with Windows Server 2008 R2. Read more

Jan 3, 2013

Stay Connected with Qualys
Free Tools & Trials
Qualys Community