Sign in

Qualys

@qualysofficial.bsky.social
54 followers 31 following 34 posts

The official Blue Sky channel for Qualys the leading provider of #cloud #security and #compliance solutions. www.qualys.com

PostsRepliesMedia
Qualys @qualysofficial.bsky.social · 11/03/2026
Our “Exploit, Don’t Trust” Cyber Risk Series will bring curated sessions from experts to discuss how to make better risk decisions and align security investments. Learn how to move beyond theoretical risk to measurable risk reduction. ▶️ Register now: qualys.brighttalk.com?utm_source=l...
000
Qualys @qualysofficial.bsky.social · 11/03/2026
Microsoft just released its March 2026 Patch Tuesday, addressing 93 vulnerabilities and two zero-day vulnerabilities. Read our full Security Update Review to get the full breakdown: 📝 bit.ly/4b0zH7G #CyberRisk
000
Qualys @qualysofficial.bsky.social · 10/03/2026
Less than 1% of “critical vulnerabilities” will be exploited in the wild, yet scanners treat them all as equally urgent. Download our newest whitepaper to learn how TruConfirm provides deterministic exploit validation so your teams can eliminate proven attack paths. bit.ly/4l4VRZX
000
Qualys @qualysofficial.bsky.social · 09/03/2026
We’re proud to announce that we are extending our partnership with the #SFUnicorns through 2027! 🦄 Read the full press release here: bit.ly/3P11tbw Go #SparkleArmy!
000
Qualys @qualysofficial.bsky.social · 11/02/2026
Microsoft’s February #PatchTuesday fixes 61 vulnerabilities, including 6 zero-days exploited in the wild. The Qualys TRU breaks down what to fix first &how Agent Sara cuts through the noise to surface real risk. Read the blog: bit.ly/4tr6jhU
000
Qualys @qualysofficial.bsky.social · 27/01/2026
Qualys named a Leader and Outperformer in the 2025 GigaOm Radar for CNAPP. What sets us apart? Our platform brings together hybrid cloud CNAPP, WebApp & API Security, & Compliance helping organizations achieve measurable results. Report: bit.ly/4sZMOgl #CloudSecurity
000
Qualys @qualysofficial.bsky.social · 14/01/2026
Microsoft’s January #PatchTuesday fixes 115 vulnerabilities, including 3 zero-days (1 actively exploited) and 8 critical issues. Learn how to assess vendor guidance & reduce risk with #Qualys Policy Compliance. Read the Threat Research Unit (TRU) blog: bit.ly/3NJiwy3
010
Qualys @qualysofficial.bsky.social · 05/01/2026
Cybersecurity leaders grapple with technology sprawl, expanding security stacks, & overwhelming telemetry volumes. TechObserver chats with #Qualys' Richard Seiersen on how to align security decisions with business value in 2026. .https://bit.ly/4qxFfLI #CyberSecurity #AI #CISO
000
Qualys @qualysofficial.bsky.social · 31/12/2025
To our customers, partners, and #TeamQualys: thank you for your trust, collaboration, and shared commitment to securing the digital world. We look forward to continuing to build, innovate & push the boundaries of cyber risk reduction—together. Happy New Year from #TeamQualys 🎉
010
Qualys @qualysofficial.bsky.social · 30/12/2025
CVE-2025-14847 demands immediate patching. A high-severity MongoDB Server flaw enables a pre-auth, unauthenticated remote memory disclosure via zlib message decompression. Read the blog for details: bit.ly/49uoL1f
000
Qualys @qualysofficial.bsky.social · 19/12/2025
Earlier this week, we warned about two zero-day WebKit flaws used in attacks. Apple has now released a critical iOS update to patch them. @Qualys’ Mayuresh Dani says the bugs were likely chained, a hallmark of spyware. Update your iPhone ASAP! bit.ly/4joLU8V via @forbes.com
000
Qualys @qualysofficial.bsky.social · 17/12/2025
Apple has issued security updates to fix 2 zero-day vulnerabilities in WebKit. Both CVEs have been exploited in the wild in highly targeted attacks and can be exploited by processing maliciously crafted web content. Get the details here: bit.ly/3YD2hVr #ThreatProtection
000
Qualys @qualysofficial.bsky.social · 13/12/2025
Google patched an actively exploited Chrome zero-day, the eighth one this year. Details remain limited, but exploitation has been confirmed and users are urged to update immediately. Read the blog for affected versions and mitigation guidance: bit.ly/48KQDOx
000
Qualys @qualysofficial.bsky.social · 09/12/2025
December’s @MsftSecIntel Patch Tuesday addresses 72 CVEs – 3 critical & 55 important. It also addresses 3 0-day CVEs, 1 exploited, 7 2 publicly disclosed. Details here: bit.ly/4oKVR1c Join our webinar 12/11 for expert insights from @Qualys TRU: bit.ly/4prS4XJ
000
Qualys @qualysofficial.bsky.social · 08/12/2025
React & Next.js fixed critical flaws in React Server Components & the Next.js App Router. Exploitation of the React Flight protocol could let attackers send crafted HTTP requests & execute code on servers. Learn more about affected versions & mitigations: bit.ly/48FnmDj
000
Qualys @qualysofficial.bsky.social · 15/11/2025
A critical Fortinet FortiWeb auth bypass (CVE-2025-64446) is being actively exploited, giving attackers full control of vulnerable devices. CISA has added it to the KEV with a Nov 21 deadline. Learn about the exploit, affected versions, & mitigation steps: bit.ly/4o0shEt
010
Qualys @qualysofficial.bsky.social · 23/10/2025
Oracle has issued its third Critical Patch Update of the year, addressing 374 vulnerabilities across its portfolio. Oracle Communications received the most fixes, followed by Communications Applications and Financial Services. Read the full analysis: bit.ly/4noXkd5
000
Qualys @qualysofficial.bsky.social · 21/10/2025
F5 has disclosed a long-term breach by a nation-state attacker involving stolen BIG-IP source code & unpatched vulnerabilities. With CISA warning of an imminent threat, organizations must quickly identify exposed assets & speed up remediation. Read more: bit.ly/4oy4nRG
001
Qualys @qualysofficial.bsky.social · 14/10/2025
Oracle addressed a high-severity vulnerability in its E-Business Suite. Exploitation could let an unauthenticated remote attacker compromise Oracle Configurator Runtime UI. Read the blog for affected versions and mitigation guidance: bit.ly/3W5B4cU #ThreatProtection
010
Qualys @qualysofficial.bsky.social · 14/10/2025
Expert-led cybersecurity training at #ROCon25. Here’s a glimpse as our instructor walks through the 5 Steps to TruRisk Reduction dashboard – demonstrating how to identify what truly needs your focus across complex vulnerability data. #RiskManagement
000
Qualys @qualysofficial.bsky.social · 14/10/2025
This month’s @MsftSecIntel Patch Tuesday fixes 193 vulnerabilities, including 9 Critical & 6 zero-days, with 4 actively exploited & 2 publicly disclosed. Get the details in this blog: bit.ly/48vQNcH. Join the @Qualys TRU webinar this Thursday: bit.ly/474T78a
000
Qualys @qualysofficial.bsky.social · 02/10/2025
Broadcom addressed a critical CVE in VMware’s guest service discovery features. Exploitation could allow an unprivileged user to escalate privileges to root on the same VM. Researchers confirmed that it has been exploited in the wild. Learn more: bit.ly/4mKu9Rq
000
Qualys @qualysofficial.bsky.social · 30/09/2025
Researchers discovered a malicious modification in the npm package postmark-mcp. By adding a blind copy to an external domain, attackers secretly exfiltrated email contents. This is the first known case of an MCP server exploited in the wild. Blog: bit.ly/474o8dy
000
Qualys @qualysofficial.bsky.social · 26/09/2025
SolarWinds fixed a critical CVE in its Web Help Desk software. Successful exploitation of the flaw could allow an unauthenticated attacker to execute arbitrary code on the target system. Learn more about the vulnerability, affected versions & mitigation: bit.ly/46yJPAZ
000
Qualys @qualysofficial.bsky.social · 26/09/2025
@Cisco patched a critical zero-day flaw in IOS & IOS XE Software. Exploitation could let low-privileged attackers cause DoS, while high-privileged attackers could execute code as root and fully compromise systems. Read the blog for mitigation details: bit.ly/3IChLok
000
Qualys @qualysofficial.bsky.social · 23/09/2025
Fortra released security updates for a critical flaw (CVE-2025-10035) in GoAnywhere MFT License Servlet. With a CVSS of 10, exploitation could allow unauthenticated remote code execution. Learn more in this blog: bit.ly/4nkBFDA #ThreatProtection #VulnerabilityManagement
000
Qualys @qualysofficial.bsky.social · 19/09/2025
Attackers exploited SharePoint ToolShell flaws to hit 145+ orgs, incl. US agencies. The campaign persisted even after patches with stealth tactics. Saeed Abbasi of @qualys.bsky.social says that when patching isn’t possible, use advanced remediation: bit.ly/3K6LbeU via @ismsonline.bsky.social
010
Qualys @qualysofficial.bsky.social · 19/09/2025
Google released security updates to fix a critical CVE in the Chrome browser. Successful exploitation of the type confusion flaw in the V8 JavaScript & WebAssembly engine, has already been observed in the wild by Google Threat Analysis Group. Learn more: bit.ly/42EBpa1
000
Qualys @qualysofficial.bsky.social · 17/09/2025
Over 400 npm packages have been compromised in in an ongoing supply chain attack. With 2.6B weekly downloads, thousands of apps are at risk, along with likelihood of further impact. No patches yes, users should uninstall the affected packages. Learn more: bit.ly/3IpDoZ3
000
Qualys @qualysofficial.bsky.social · 12/09/2025
Ivanti released its Sept security bulletin, addressing 13 CVEs across its popular products. There is currently no evidence of active exploitation. Get the details in this blog, including exploitation methods, affected versions, & detection steps: bit.ly/46kQWNs #VulnerabilityManagement
000
Qualys @qualysofficial.bsky.social · 23/08/2025
Apple addressed a critical CVE across its operating systems, including macOS & iOS. The flaw could be exploited through a malicious image file to cause memory corruption. The vulnerability is already being exploited in the wild. Learn more in this blog: bit.ly/3JlkzGJ #ThreatProtection
000
Qualys @qualysofficial.bsky.social · 10/08/2025
Big win at #DefCon33! Qualys Threat Research Unit (TRU) takes home Epic Achievement + Best RCE at the #PwnieAwards for: 🔹 CVE-2024-6387 (regreSSHion) — 1st pre-auth RCE in OpenSSH in 20 yrs 🔹 CVE-2025-26465 — MITM attack on OpenSSH client #vulnerabilityresearch #Qualys #TRU
031
Qualys @qualysofficial.bsky.social · 18/02/2025
The #Qualys Threat Research Unit (TRU) has identified and responsibly disclosed two vulnerabilities in OpenSSH: CVE-2025-26465 and CVE-2025-26466. TRU recommends upgrading to the lastest version of OpenSSH. Details at blog.qualys.com/vulnerabilit... #QualysThreatResearchUnit #Vulnerabilities
blog.qualys.com
Qualys TRU Discovers Two Vulnerabilities in OpenSSH: CVE-2025-26465 & CVE-2025-26466 | Qualys Security Blog
The Qualys Threat Research Unit (TRU) has identified two vulnerabilities in OpenSSH. The first, tracked as CVE-2025-26465, allows an active machine-in-the-middle attack on the OpenSSH client when the…
021
Qualys @qualysofficial.bsky.social · 02/02/2025
DeepSeek fails more than 50% of Jailbreak Tests by Qualys TotalAI: model failed 58% of jailbreak tests & 61% of security assessments. 🔎 Read the blog & learn how Qualys TotalAI helps secure AI models against threats. bit.ly/42Cubo0 #AI #CyberSecurity #LLMSecurity
bit.ly
DeepSeek Failed Over Half of the Jailbreak Tests by Qualys TotalAI | Qualys Security Blog
A comprehensive security analysis of DeepSeek’s flagship reasoning model reveals significant concerns for enterprise adoption. DeepSeek-R1, a groundbreaking Large Language Model recently released by a...
030
Reposted by Qualys
Joe Tidy BBC News @joetidy.bsky.social · 21/01/2025
Interesting research from Qualys here where they found a botnet that’s infected vulnerable AVTECH cameras and Huawei routers. 1500 IP addresses found to be in the bot army used to carry out further attacks. blog.qualys.com/vulnerabilit...
blog.qualys.com
Mass Campaign of Murdoc Botnet Mirai: A New Variant of Corona Mirai | Qualys Security Blog
The Qualys Threat Research Unit has uncovered a large-scale, ongoing operation within the Mirai campaign, dubbed Murdoc Botnet. This variant exploits vulnerabilities targeting AVTECH Cameras and…
052