#qualys — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #qualys, aggregated by home.social.
-
If you try to set a password between 41 and 50 characters you get an error:
> Your password must not exceed 40 characters (or fewer multibyte characters) in length. You typed 41 bytes.
If you enter more than 50 characters:
> The new password and confirmed password don't match. Enter the same password in both fields for successful authentication.
-
Huch?
Mehrere #letsencryt Zertifikate, die am 2026-05-20 ausgestellt wurden, sind widerrufen worden. #Firefox meldet entsprechend ein "Sicherheitsproblem", Chrome-basierte Browser rennen einfach drüber und scheren sich nicht drum.
#Qualys bzw. #SSLLabs liefert auch entsprechend ein "F" mit Hinweis, dass dem Zertifikat nicht vertraut wird.
Ich hab nix gefunden dazu - weiß jemand mehr?
Update: @testssl läuft durch, meldet KEIN Problem!
Update: Konkrete URLs/Web-Server absichtlich nicht angegeben.
Update^2: Zugriff durch renew-certificate wieder hergestellt, angegebener Grund im Revoke "cessationOfOperation" - Hintergrund weiterhin unklar.
Gerne retrööt!
-
SSL Labs checks the TLS-config of servers for PQC (post-quantum cryptography) key exchanges now.
https://www.ssllabs.com/ssltest/
#SSLlabs #SSLtest #qualys #pqc #tls #postQuantumCryptography #infosec
-
A serious Ubuntu vulnerability (CVE-2026-3888) allows local users to gain full root access. If you run Ubuntu 24.04 or later, you should update your system right now.
More details here: https://ostechnix.com/ubuntu-snapd-privilege-escalation-cve-2026-3888-fix/
-
CrackArmor: Multiple vulnerabilities in #AppArmor "Bypassing Ubuntu's user-namespace restrictions
AppArmor + Sudo + Postfix = root
Kernel vulnerabilities". https://seclists.org/oss-sec/2026/q1/303 #infosec #qualys -
#CrackArmor: Multiple vulnerabilities in #AppArmor
Advisory: https://cdn2.qualys.com/advisory/2026/03/10/crack-armor.txt
These vulnerabilities allow a local attacker to bypass the security normally provided by AppArmor. Also, in some situations, it allows privilege escalation to root by selectively blocking specific syscalls.
-
How board members think about cyber risk and what CISOs should tell them https://www.helpnetsecurity.com/2025/11/26/cybersecurity-metrics-for-boards-video/ #securitymetrics #cybersecurity #Don'tmiss #boardroom #cyberrisk #strategy #Qualys #Video #video #News #CISO
-
Qualys, Tenable Latest Victims of Salesloft Drift Hack – Source: www.infosecurity-magazine.com https://ciso2ciso.com/qualys-tenable-latest-victims-of-salesloft-drift-hack-source-www-infosecurity-magazine-com/ #rssfeedpostgeneratorecho #InfoSecurityMagazine #InfosecurityMagazine #CyberSecurityNews #Qualys
-
ScamAgent shows how AI could power the next wave of scam calls https://www.helpnetsecurity.com/2025/08/28/scamagent-ai-threats-scam-calls/ #Artificialintelligence #cybercrime #Don'tmiss #Features #Hotstuff #research #Qualys #scams #News #CISO
-
Kolejne podatności w sudo, tym razem moduły uwierzytelniania PAM
O tym, że sudo (czytane su-du) to krytyczny komponent systemu operacyjnego, z punktu widzenia nie tylko użyteczności ale przede wszystkim – bezpieczeństwa, przekonywaliśmy nie raz. Ostatnio opisywaliśmy ciekawe podatności dotyczące przełączników –host oraz –chroot. Tym razem, przyjrzymy się dwóm podatnościom z kategorii błędów logicznych – CVE-2025-6018 oraz CVE-2025-6019. Luki zostały...
#WBiegu #Linux #Opensuse #Qualys #Security #Sudo
https://sekurak.pl/kolejne-podatnosci-w-sudo-tym-razem-moduly-uwierzytelniania-pam/
-
Microsoft fixes critical wormable Windows flaw (CVE-2025-47981) https://www.helpnetsecurity.com/2025/07/09/microsoft-fixes-critical-wormable-windows-flaw-cve-2025-47981/ #MicrosoftEdge #WindowsServer #PatchTuesday #SharePoint #TrendMicro #Don'tmiss #Hotstuff #MSOffice #Tenable #Windows #Ivanti #Qualys #News
-
Innovator Spotlight: Qualys – Source: www.cyberdefensemagazine.com https://ciso2ciso.com/innovator-spotlight-qualys-source-www-cyberdefensemagazine-com/ #rssfeedpostgeneratorecho #cybersecurityplatform #compliancevisibility #cyberdefensemagazine #cyberdefensemagazine #executivereporting #Securityleadership #CyberSecurityNews #governancetools #auditreadiness #CISOStrategy #policyaudit #cyberrisk #Spotlight #Qualys
-
#Patches kommen:
Zwei Lücken verleihen #Angreifern #Root-Rechte unter #Linux
Durch Verkettung der beiden Lücken lassen sich #Linux-Systeme vollständig kompromittieren. Admins sollten so bald wie möglich patchen.
#Sicherheitsforscher von #Qualys haben zwei gefährliche #Sicherheitslücken aufgedeckt, mit denen Angreifer auf #Linux-Systemen einen #Root-Zugriff erlangen können.
-
Chaining two LPEs to get “root”: Most Linux distros vulnerable (CVE-2025-6018, CVE-2025-6019) https://www.helpnetsecurity.com/2025/06/18/chaining-two-lpes-to-get-root-most-linux-distros-vulnerable-cve-2025-6018-cve-2025-6019/ #vulnerability #Don'tmiss #Hotstuff #openSUSE #Debian #Fedora #Qualys #Ubuntu #Linux #News
-
#Qualys TRU Uncovers Chained LPE: SUSE 15 PAM to Full Root via libblockdev/udisks
-
Neue #Linux #Sicherheitslücken: #Race #Conditions bedrohen sensible Daten.
Zwei neu entdeckte Schwachstellen gefährden aktuell bestimmte #Linux- #Distributionen. Die #Sicherheitsforscher von #Qualys haben Race Conditions in den Komponenten apport und systemd-coredump identifiziert. Sie wurden unter den CVE-Nummern CVE-2025-5054 und CVE-2025-4598 veröffentlicht und ermöglichen es lokalen Angreifern, auf Speicherabzüge privilegierter Prozesse zuzugreifen.
-
Photos: Infosecurity Europe 2025, part 2 https://www.helpnetsecurity.com/2025/06/04/infosecurity-europe-2025-photo/ #BytesSoftwareServices #RootshellSecurity #VeeamSoftware #ManageEngine #PushSecurity #Bitdefender #conferences #DarkInvader #AbnormalAI #AttackIQ #iStorage #Sonatype #Garner #Qualys #News
-
Two information disclosure flaws have been identified in #apport and #systemd-coredump, the core dump handlers in #Ubuntu, #RedHat Enterprise #Linux, and #Fedora, according to the #Qualys Threat Research Unit (TRU).
Tracked as CVE-2025-5054 and CVE-2025-4598, both #vulnerabilities are race condition bugs that could enable a local attacker to obtain access to access sensitive information. Tools like Apport and systemd-coredump are designed to handle crash reporting and core dumps in Linux systems.
https://thehackernews.com/2025/05/new-linux-flaws-allow-password-hash.html
-
Linux Crash Reporting Flaws (CVE-2025-5054, 4598) Expose Password Hashes https://hackread.com/linux-crash-reporting-flaws-expose-password-hashes/ #systemdcoredump #Cybersecurity #Vulnerability #Security #Password #Apport #Hashes #Qualys #Linux
-
Closing security gaps in multi-cloud and SaaS environments https://www.helpnetsecurity.com/2025/05/20/kunal-modasiya-qualys-cloud-saas-security-strategy/ #cloudsecurity #collaboration #cybersecurity #Don'tmiss #Features #Hotstuff #strategy #Qualys #cloud #News #SaaS
-
🎙️ Ready for a mindset shift? 🤯
In this On Location Briefing from #RSAC2025, we catch up with one of the industry’s leading voices on risk-based security, Richard Seiersen, for an insightful discussion you won’t want to miss!
🚀 New Briefing from #RSAC 2025: This Is What Happens When Security Stops Chasing Threats and Starts Managing Risk
At RSA Conference 2025, Sean Martin, CISSP caught up with Rich Seiersen, Chief Risk Technology Officer at Qualys, to talk about why simply chasing threats isn’t enough — and why risk-based security is the future.
🔐 How can organizations rethink their priorities to focus on what truly matters in cybersecurity?
Find out how Qualys is helping companies shift from reactive defense to proactive, risk-driven security strategies.
🎙️ Watch, listen, or read the full conversation here:
👉 https://www.itspmagazine.com/their-stories/this-is-what-happens-when-security-stops-chasing-threats-and-starts-managing-risk-a-brand-story-with-rich-seiersen-from-qualys-an-on-location-rsac-conference-2025-brand-story📌 Learn more about Qualys’ work:
👉 https://www.itspmagazine.com/directory/qualys🛰️ See all our RSAC 2025 coverage:
👉 https://www.itspmagazine.com/rsac25🌟 Discover more Brand Stories and Briefings from innovative companies:
👉 https://www.itspmagazine.com/brand-story🎥🎙️ This is just one of the many incredible conversations we recorded On Location in San Francisco, as Sean Martin and Marco Ciappelli covered the event as official media partners for the 11th year in a row.
Stay tuned for more Brand Stories, Briefings, and candid conversations from RSAC 2025!
🎤 Looking ahead:
If your company would like to share your story with our audiences On Location, we’re gearing up for Infosecurity Europe in June and Black Hat USA in August!⚡ RSAC 2025 sold out fast — we expect the same for these next events.
🎯 Reserve your full sponsorship or briefing now: https://www.itspmagazine.com/purchase-programs#cybersecurity #infosec #infosecurity #technology #tech #society #business #riskmanagement #riskbasedsecurity #securitystrategy #qualys
-
#Qualys needs to update their TLS client test to support the new signature algorithms and named groups. There are a fair number of "unknown" entries with #OpenSSL 3.5. https://clienttest.ssllabs.com:8443/ssltest/viewMyClient.html
-
Infosec products of the month: February 2025 https://www.helpnetsecurity.com/2025/02/28/infosec-products-of-the-month-february-2025/ #PaloAltoNetworks #LegitSecurity #VeeamSoftware #SealSecurity #SafeBreach #1Password #Dynatrace #Privacera #Fortinet #Netwrix #Trustmi #Pangea #Qualys #Satori #Socure #Armor #BigID #News #Nymi
-
Powershell Qualys Authentication Part 1 http://dlvr.it/TJ3zpb via PlanetPowerShell #PowerShell #Qualys #VulnerabilityManagement #API
-
Critical OpenSSH Vulnerabilities Expose Users to MITM and DoS Attacks – Source:hackread.com https://ciso2ciso.com/critical-openssh-vulnerabilities-expose-users-to-mitm-and-dos-attacks-sourcehackread-com/ #1CyberSecurityNewsPost #CyberSecurityNews #cybersecurity #Vulnerability #Hackread #security #OpenSSH #Qualys #MITM #DoS