Qualys
qualys.com
Imported from official source
Qualys — publications from its own official source.
- Type
- Company
- Scope
- US · national
- Website
- qualys.com
- Feed
- Atom
Publications 14
-
Autonomous Remediation Is Already Running at Enterprise Scale
The following is a guest blog by ITSPmagazine, based on their interview of Qualys President & CEO Sumedh Thakar at Black Hat USA 2026. Sumedh Thakar has watched the same clock compress for 23 y...
-
Lessons from Microsoft Patch KB5002907: Two Layers of Patch Control in Qualys TruRisk Eliminate
How reliability scoring keeps risky patches out of zero-touch jobs, and how one blocking rule stops a paused update across your environment. Executive Summary Microsoft has paused the rollout of KB...
-
The Developer is the New Perimeter: How Supply Chain Attacks Are Becoming Cloud Breaches
A routine package install can open the door to a cloud breach. Learn how attackers exploit developer credentials. Discover practical steps to contain exposure and protect your cloud environment.
-
CISA BOD 26-04 Timelines for Three Linux Kernel CVEs
Executive Summary CISA added three actively exploited Linux kernel vulnerabilities: CVE-2025-39682, CVE-2026-53266, and CVE-2025-39964 to its KEV Catalog on September 18, 2026, triggering a 3-day r...
-
The End of Point-in-Time Compliance: Why Continuous Audit Readiness Matters to You in the AI Era
AI-driven threats are outpacing traditional audits. Discover how continuous monitoring, automated evidence collection, and risk-based remediation help security teams close compliance gaps and maint...
-
The Autonomous Engine Behind Remediation, and What Finally Makes It Safe
Executive Summary Vulnerability exploitation now happens at a speed that manual, ticket-based remediation can’t match. Qualys’s Enterprise TruRisk Management Platform closes that gap with autonomou...
-
Oracle Critical Security Patch Update, September 2026 Review
Oracle released its September edition of Critical Security Patch Update. The update received patches for 673 security vulnerabilities. Some of the vulnerabilities addressed in this update impa...
-
Before You Patch. Why Patch Reliability Matters for Confident Deployment
Executive Summary Microsoft’s September 2026 security updates – KB5124008, KB5124012, and KB5123099 have been linked to significant issues, underscoring the operational risks associated with securi...
Cybersecurity 2 versions -
Automate Asset Isolation: Your Last Resort to Meet Remediation Deadlines
Executive Summary Remediation deadlines slip for reasons outside your control: a patch does not exist yet, a patch is delayed, or a remediation attempt fails. The outcome is the same either way: th...
-
What Is ISPM? How It Differs from IAM, PAM, IGA, and IDaaS
Key Takeaways Identity Security Posture Management (ISPM) is the continuous risk and posture layer of the identity stack not a replacement for Identity and Access Management (IAM), Privileged Acces...
-
The Models That Found 10,000 Zero-Days Broke Into Three Companies Using Weak Passwords
The question of whether a Frontier AI model could find vulnerabilities that no human researcher had found was settled in April. Claude Mythos Preview identified thousands of previously unknown flaw...
-
Microsoft and Adobe Patch Tuesday, September 2026 Security Update Review
Microsoft kicks off September with its monthly Patch Tuesday release, delivering fixes for security vulnerabilities affecting its products. The security updates are packed with security f...
-
4 Questions to Ask When Evaluating an Exposure Management Platform
Executive Summary Exposure management platforms are increasingly evaluated based on post-detection actions rather than detection itself. This piece sets out four questions to ask when evaluating on...
-
Anatomy of a Silent Domain Takeover
Key Takeaways Modern AD attacks use legitimate protocols end-to-end, no malware, no exploit, nothing for signature tools to fingerprint. The evidence is already in the logs; what is missing is the ...