{"id":3242,"date":"2020-12-23T11:38:55","date_gmt":"2020-12-23T11:38:55","guid":{"rendered":"https:\/\/www.intelligentcio.com\/north-america\/?p=3242"},"modified":"2021-01-05T11:27:22","modified_gmt":"2021-01-05T11:27:22","slug":"qualys-offers-free-vulnerability-management-service-following-solarwinds-breach","status":"publish","type":"post","link":"https:\/\/www.intelligentcio.com\/north-america\/2020\/12\/23\/qualys-offers-free-vulnerability-management-service-following-solarwinds-breach\/","title":{"rendered":"Qualys offers free vulnerability management service following SolarWinds breach"},"content":{"rendered":"\n<p><strong><em>Qualys is offering a free 60-day integrated Vulnerability Management, Detection and Response service to help organizations quickly&nbsp;assess&nbsp;devices impacted by SolarWinds Orion vulnerabilities, SUNBURST Trojan detections and FireEye Red Team tools.<\/em><\/strong><\/p>\n\n\n\n<p>Qualys, a leading provider of cloud-based security and compliance solutions,&nbsp;has announced its research team, using the Qualys Cloud Platform, has identified 7.54\u202fmillion\u202fvulnerabilities related to\u202fFireEye\u202fRed Team assessment tools and compromised versions of SolarWinds Orion, tracked as Solorigate or SUNBURST, across its 15,700 member customer base.<\/p>\n\n\n\n<p>Of the vulnerabilities identified, researchers noted that across 5.29 million unique assets most are related to the FireEye Red Team tools. These findings highlight the scope of the potential attack surface if these tools are misused. The research team further identified that 99.84% of the seven million vulnerability instances are from eight vulnerabilities in Microsoft software that have patches available. &nbsp;<\/p>\n\n\n\n<p>To help mitigate risk and exposure from this breach, Qualys is providing IT and security teams free 60-day access to its integrated Vulnerability Management, Detection and Response service, which leverages the power of the Qualys Cloud Platform.<\/p>\n\n\n\n<p>More information can be found on the Qualys advisory blog at <a href=\"https:\/\/www.qualys.com\/solarwinds-fireeye-advisory-blog-post\">qualys.com\/solarwinds-fireeye-advisory-blog-post<\/a>.<\/p>\n\n\n\n<p>\u201cThe Qualys free solution provides much-needed visibility and response&nbsp;in a single app&nbsp;that many need at a time when IT and security organizations around the world are scrambling to shore up their systems,\u201d said Frank Dickson, Program Vice President, Security and Trust at IDC. \u201cQualys&#8217; solution draws from its native security and compliance platform to deliver vulnerability management, detection and response, the ability to detect malware, and the integrity of files. It is a great solution, easy to use and deploy,&nbsp;and it\u2019s hard to beat as it is free.\u201d<\/p>\n\n\n\n<p>\u201cThe scope of this nation-state attack is massive, as overnight a widely used and trusted piece of software turned into known malware,\u201d said Sumedh Thakar, President and Chief Product Officer at Qualys. \u201cSince its discovery, Qualys teams have been actively researching the issue and helping customers assess their environments. The good news is that nearly all of the CVEs are patchable, and we\u2019ve made this solution available to the industry so they can immediately work to protect themselves&nbsp;from being exploited by these vulnerabilities.\u201d<\/p>\n\n\n\n<p>Qualys is offering a fully functional license free for 60 days. The license enables full situational awareness, detection and remediation to reduce risk and exposure from the SolarWinds and FireEye breaches. It includes:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Real-time, up-to-date inventory and automated organization of all assets, applications, and services running across the hybrid-IT environment<\/li><\/ul>\n\n\n\n<ul class=\"wp-block-list\"><li>Continuous view of all critical vulnerabilities and their prioritization based on real-time threat indicators and attack surface<\/li><\/ul>\n\n\n\n<ul class=\"wp-block-list\"><li>Automatic correlation of applicable patches for identified vulnerabilities<\/li><\/ul>\n\n\n\n<ul class=\"wp-block-list\"><li>Patch deployment via Qualys Cloud Agents with zero impact to VPN bandwidth<\/li><\/ul>\n\n\n\n<ul class=\"wp-block-list\"><li>Security configuration hygiene assessment to apply as compensating controls to reduce vulnerability risk<\/li><\/ul>\n\n\n\n<ul class=\"wp-block-list\"><li>Unified dashboards that consolidate all insights for management visualization via a single pane of glass<\/li><\/ul>\n\n\n\n<p>\u201cAs our teams assessed the very sophisticated SolarWinds\/FireEye nation-state attack, we realized that we could help the industry through our very powerful unified Cloud Platform. The integrated security solution provides real-time visibility across the entire global and hybrid IT environment allowing it to detect and prioritize critical vulnerabilities, identify malware and effectively respond all from one single pane of glass,\u201d said Philippe Courtot, Chairman and CEO of Qualys.<\/p>\n\n\n\n<p>To sign up for the free&nbsp;60-day&nbsp;service visit <a href=\"https:\/\/www.qualys.com\/solarhack\/\">www.qualys.com\/solarhack\/.<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Qualys is offering a free 60-day integrated Vulnerability Management, Detection and Response service to help organizations quickly&nbsp;assess&nbsp;devices impacted by SolarWinds Orion vulnerabilities, SUNBURST Trojan detections and FireEye Red Team tools. Qualys, a leading provider of cloud-based security and compliance solutions,&nbsp;has announced its research team, using the Qualys Cloud Platform, has identified 7.54\u202fmillion\u202fvulnerabilities related to\u202fFireEye\u202fRed Team [&hellip;]<\/p>\n","protected":false},"author":18,"featured_media":3243,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[17,511,34,514],"tags":[217,1378,1376,1276,1377,1379],"class_list":["post-3242","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-enterprise-security","category-intelligent-technology-newsletter","category-more-news","category-used","tag-fireeye","tag-free","tag-qualys","tag-solarwinds","tag-solarwinds-breach","tag-vulnerability-management"],"acf":[],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/posts\/3242","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/users\/18"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/comments?post=3242"}],"version-history":[{"count":6,"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/posts\/3242\/revisions"}],"predecessor-version":[{"id":3272,"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/posts\/3242\/revisions\/3272"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/media\/3243"}],"wp:attachment":[{"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/media?parent=3242"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/categories?post=3242"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/tags?post=3242"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}