Qualys

qualys.com

Imported from official source

Qualys — publications from its own official source.

Type
Company
Scope
US · national
Website
qualys.com
Feed
Atom

Publications 14

  1. Autonomous Remediation Is Already Running at Enterprise Scale

    The following is a guest blog by ITSPmagazine, based on their interview of Qualys President & CEO Sumedh Thakar at Black Hat USA 2026. Sumedh Thakar has watched the same clock compress for 23 y...

  2. Lessons from Microsoft Patch KB5002907: Two Layers of Patch Control in Qualys TruRisk Eliminate

    How reliability scoring keeps risky patches out of zero-touch jobs, and how one blocking rule stops a paused update across your environment. Executive Summary Microsoft has paused the rollout of KB...

  3. The Developer is the New Perimeter: How Supply Chain Attacks Are Becoming Cloud Breaches 

    A routine package install can open the door to a cloud breach. Learn how attackers exploit developer credentials. Discover practical steps to contain exposure and protect your cloud environment.

  4. CISA BOD 26-04 Timelines for Three Linux Kernel CVEs

    Executive Summary CISA added three actively exploited Linux kernel vulnerabilities: CVE-2025-39682, CVE-2026-53266, and CVE-2025-39964 to its KEV Catalog on September 18, 2026, triggering a 3-day r...

  5. The End of Point-in-Time Compliance: Why Continuous Audit Readiness Matters to You in the AI Era 

    AI-driven threats are outpacing traditional audits. Discover how continuous monitoring, automated evidence collection, and risk-based remediation help security teams close compliance gaps and maint...

  6. The Autonomous Engine Behind Remediation, and What Finally Makes It Safe

    Executive Summary Vulnerability exploitation now happens at a speed that manual, ticket-based remediation can’t match. Qualys’s Enterprise TruRisk Management Platform closes that gap with autonomou...

  7. Oracle Critical Security Patch Update, September 2026 Review

    Oracle released its September edition of Critical Security Patch Update. The update received patches for 673 security vulnerabilities. Some of the vulnerabilities addressed in this update impa...

  8. Before You Patch. Why Patch Reliability Matters for Confident Deployment

    Executive Summary Microsoft’s September 2026 security updates – KB5124008, KB5124012, and KB5123099 have been linked to significant issues, underscoring the operational risks associated with securi...

    Cybersecurity 2 versions
  9. Automate Asset Isolation: Your Last Resort to Meet Remediation Deadlines

    Executive Summary Remediation deadlines slip for reasons outside your control: a patch does not exist yet, a patch is delayed, or a remediation attempt fails. The outcome is the same either way: th...

  10. What Is ISPM? How It Differs from IAM, PAM, IGA, and IDaaS

    Key Takeaways Identity Security Posture Management (ISPM) is the continuous risk and posture layer of the identity stack not a replacement for Identity and Access Management (IAM), Privileged Acces...

  11. The Models That Found 10,000 Zero-Days Broke Into Three Companies Using Weak Passwords

    The question of whether a Frontier AI model could find vulnerabilities that no human researcher had found was settled in April. Claude Mythos Preview identified thousands of previously unknown flaw...

  12. Microsoft and Adobe Patch Tuesday, September 2026 Security Update Review

    Microsoft kicks off September with its monthly Patch Tuesday release, delivering fixes for security vulnerabilities affecting its products. The security updates are packed with security f...

  13. 4 Questions to Ask When Evaluating an Exposure Management Platform

    Executive Summary Exposure management platforms are increasingly evaluated based on post-detection actions rather than detection itself. This piece sets out four questions to ask when evaluating on...

  14. Anatomy of a Silent Domain Takeover

    Key Takeaways Modern AD attacks use legitimate protocols end-to-end, no malware, no exploit, nothing for signature tools to fingerprint. The evidence is already in the logs; what is missing is the ...

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.