logo

Qualys Blog

ID: 238d9eda-62f4-519f-ad05-e8f31580e042

STIX ID: identity--238d9eda-62f4-519f-ad05-e8f31580e042

Feed Type: rss

Earliest post: 2023-11-27

Latest post: 2026-08-27

Threat research, vulnerability management insights, cloud & endpoint security guidance, and expert analysis from the Qualys cybersecurity team.

01/01/2020
08/28/2026
Title Date Published Describes IncidentAuthorVisible
PCI DSS 4.0.1: Application Requirements You’re Being Assessed On in 20262026-08-27TrueShravan DandageTrue
When an AI Agent Turned Attacker: What Qualys Sees Across Every Phase of the Hugging Face Kubernetes Intrusion 2026-08-26TrueBalasaheb SalunkeTrue
CVE-2026-69414 ShieldBreak Zero-Day: No Patch, and CISA BOD 26-04 Gives You 14 Days2026-08-25TrueVamika SheelTrue
CVE-2026-69414 ShieldBreak Zero-Day: No Patch, and CISA BOD 26-04 Gives You 14 Days2026-08-20TrueVamika SheelTrue
CVE-2026-68820 is in KEV. Here Is What CISA BOD 26-04 Actually Requires Now2026-08-18TrueVamika SheelTrue
Microsoft Patch Tuesday, August 2026 Security Update Review2026-08-11TrueDiksha OjhaTrue
The Sub-10-Minute Cloud Takeover: How Exposed IAM Keys, Misconfiguration and AI Are Rewriting the Rules of Cloud Breaches2026-07-27TrueSayali WarekarTrue
RefluXFS: A Linux Kernel Local Privilege Escalation to Root in XFS (CVE-2026-64600) 2026-07-22TrueSaeed AbbasiTrue
Oracle Critical Patch Update, July 2026 Security Update Review2026-07-22TrueDiksha OjhaTrue
CVE-2026-8933: Local Privilege Escalation in Set-Capabilities snap-confine2026-07-21TrueSaeed AbbasiTrue
Is Your Security Program Ready for AI-Speed Application Exploitation?2026-07-20TrueIndrani DasTrue
Microsoft and Adobe Patch Tuesday, July 2026 Security Update Review 2026-07-14TrueDiksha OjhaTrue
FortiBleed: Credential Reuse, Legacy Hashes, and the Risk of Internet-Exposed FortiGate Devices 2026-07-08TrueArun Pratap SinghTrue
CERT-In’s AI Vulnerability Blueprint: Why Indian CISOs Need Machine-Speed Risk Operations in the Post-Mythos Era 2026-06-24TrueIndrani DasTrue
Oracle Critical Patch Update, June 2026 Security Update Review2026-06-18TrueDiksha OjhaTrue
Microsoft and Adobe Patch Tuesday, June 2026 Security Update Review2026-06-09TrueDiksha OjhaTrue
From Operating Model to Product: How We Built the ROC for Detection-Speed Remediation2026-06-04TrueVivek BhandariTrue
The HazyBeacon Protocol – How Malware Weaponizes Amazon Web Services (AWS) Lambda Function URLs2026-06-02TrueAniket HarneTrue
CVE-2026-46333: Local Root Privilege Escalation and Credential Disclosure in the Linux Kernel ptrace Path2026-05-20TrueSaeed AbbasiTrue
Microsoft and Adobe Patch Tuesday, May 2026 Security Update Review2026-05-12TrueDiksha OjhaTrue
Dirty Frag: Using the Page Caches as an Attack Surface2026-05-09TrueMayuresh DaniTrue
Don’t Wait for a Patch. Mitigate RedSun Zero-Day Risk in Microsoft Defender Today 2026-04-22TrueMukesh ChoudharyTrue
Oracle Critical Patch Update, April 2026 Security Update Review2026-04-22TrueDiksha OjhaTrue
Microsoft and Adobe Patch Tuesday, April 2026 Security Update Review2026-04-14TrueDiksha OjhaTrue
Anatomy of an Autonomous AI Agent Risk: How Qualys ETM Connects the Dots on OpenClaw2026-04-13TrueViren ChaudhariTrue
CVE-2026-3888: Important Snap Flaw Enables Local Privilege Escalation to Root2026-03-17TrueSaeed AbbasiTrue
Countering Current Geopolitical Cyber Threats Based on CISA Intel With Qualys2026-03-17TrueAlex KreileinTrue
CrackArmor: Critical AppArmor Flaws Enable Local Privilege Escalation to Root2026-03-12TrueSaeed AbbasiTrue
Microsoft Patch Tuesday, March 2026 Security Update Review2026-03-10TrueDiksha OjhaTrue
How Security Tool Misuse Is Reshaping Cloud Compromise2026-02-19TrueSayali WarekarTrue
Microsoft and Adobe Patch Tuesday, February 2026 Security Update Review2026-02-10TrueDiksha OjhaTrue
Mutagen Astronomy: From Discovery to CISA Recognition—A Seven-Year Journey2026-02-02TrueSaeed AbbasiTrue
How Public Container Registries Have Become a Silent Risk Multiplier in a Modern Supply Chain2026-01-22TrueAmit GadhaveTrue
Why Serverless Risk Demands Identity-Aware Security at Cloud Scale 2026-01-15TrueSiddhant PatilTrue
Microsoft Patch Tuesday, January 2026 Security Update Review2026-01-13TrueDiksha OjhaTrue
ShadyPanda: The Silent Browser Takeover Threat and How Qualys TruRisk Eliminate Helps You Stop It2025-12-17TrueLavish JhambTrue
React2Shell: Decoding CVE-2025-55182 – The Silent Threat in React Server Components2025-12-11TrueKaustubh JagtapTrue
Microsoft and Adobe Patch Tuesday, December 2025 Security Update Review2025-12-09TrueDiksha OjhaTrue
Active Exploitation of 7-Zip RCE Vulnerability Shows Why Manual Patching is No Longer an Option 2025-12-04TrueMohd Anas KhanTrue
Unauthenticated Authentication Bypass in Fortinet FortiWeb (CVE-2025-64446) Exploited in the Wild2025-11-15TrueMayuresh DaniTrue
Microsoft Patch Tuesday, November 2025 Security Update Review2025-11-11TrueDiksha OjhaTrue
Inside an Automotive Giant’s Data Leak — A Cloud Misconfiguration Lesson for AWS Users2025-11-03TrueRahul PareekTrue
What Security Teams Need to Know as PHP and IoT Exploits Surge  2025-10-30TrueAmit GadhaveTrue
Oracle Critical Patch Update, October 2025 Security Update Review2025-10-23TrueDiksha OjhaTrue
A Strategic Response to the F5 BIG-IP Nation-State Breach2025-10-18TrueSaeed AbbasiTrue
Microsoft and Adobe Patch Tuesday, October 2025 Security Update Review2025-10-14TrueDiksha OjhaTrue
Patch Automation for Browsers with TruRisk™ Eliminate2025-09-24TrueMohd Anas KhanTrue
When Dependencies Turn Dangerous: Responding to the NPM Supply Chain Attack2025-09-10TrueAbhinav MishraTrue
Microsoft and Adobe Patch Tuesday, September 2025 Security Update Review2025-09-09TrueDiksha OjhaTrue
Fortifying Your Cloud Against Cross-Service Confused Deputy Attacks2025-07-24TrueNehal BaviskarTrue

1–50 of 128