Please turn JavaScript on
Qualys Security Blog icon

Qualys Security Blog

Subscribe to Qualys Security Blog’s news feed.

Click on “Follow” and decide if you want to get news from Qualys Security Blog via RSS, as email newsletter, via mobile or on your personal news page.

Subscription to Qualys Security Blog comes without risk as you can unsubscribe instantly at any time.

You can also filter the feed to your needs via topics and keywords so that you only receive the news from Qualys Security Blog which you are really interested in. Click on the blue “Filter” button below to get started.

Website title: Qualys Security Blog | Expert network security guidance and news

Is this your feed? Claim it!

Publisher:  Unclaimed!
Message frequency:  0.47 / day

Message History

Key Takeaways Identity Security Posture Management (ISPM) is the continuous risk and posture layer of the identity stack not a replacement for Identity and Access Management (IAM), Privileged Access Management (PAM), Identity Governance and Administration (IGA), or Identity-as-a-Service (IDaaS), but the layer that continuously assesses the exposure those systems create. IAM au...

Read full story

The question of whether a Frontier AI model could find vulnerabilities that no human researcher had found was settled in April. Claude Mythos Preview identified thousands of previously unknown flaws across every major o...


Read full story

Microsoft kicks off September with its monthly Patch Tuesday release, delivering fixes for security vulnerabilities affecting its products. The security updates are packed with security fixes, providing organizations with important updates to help protect their environments from emerging threats.

This Patch Tuesday is Microsoft’s largest security update ever, marki...


Read full story
Executive Summary

Exposure management platforms are increasingly evaluated based on post-detection actions rather than detection itself. This piece sets out four questions to ask when evaluating one: whether it narrows vulnerabilities to the exploitable using environment context rather than severity scores; whether it validates exploitability continuously rather t...


Read full story
Key Takeaways Modern AD attacks use legitimate protocols end-to-end, no malware, no exploit, nothing for signature tools to fingerprint. The evidence is already in the logs; what is missing is the narrative linking five benign-looking Windows events into a single attack. A full domain takeover can be completed in 54 minutes, from the first password spray to the forged G...

Read full story