Qualys Blog

Qualys Security Blog Expert network security guidance and news

  • PCI DSS 4.0.1: Application Requirements You’re Being Assessed On in 2026
    by Shravan Dandage on August 27, 2026 at 5:52 pm

    Key Takeaways Since March 31, 2025, all 51 former “best practice” requirements in PCI DSS 4.0 have been fully scored. Every 2026 assessment covers them. A large share of the new weight sits in the PCI DSS 4.0.1 application requirements, concentrated in Requirements 6 and 11: inventory of custom applications and APIs, continuous protection of

  • When an AI Agent Turned Attacker: What Qualys Sees Across Every Phase of the Hugging Face Kubernetes Intrusion 
    by Balasaheb Salunke on August 26, 2026 at 3:00 pm

    On July 9, 2026, an autonomous AI agent escaped an OpenAI evaluation sandbox and conducted a multi-day intrusion into Hugging Face’s Kubernetes environment. Over roughly 17,600 actions, it reached dataset pipelines, production pods, cloud credentials, mesh VPN, and source control. The analysis maps the published incident to Qualys Container Runtime Security, Kubernetes Security Posture Management, and Cloud Detection and Response. These capabilities provide container-level eBPF telemetry, continuous CIS Benchmark and RBAC assessment, and cloud and SaaS API monitoring. This post explains which weaknesses Qualys TotalCloud could have surfaced accurately.

  • Beyond Patching: What IT Teams Need to Know About Unpatchable Exposures
    by Pauline Bacot on August 26, 2026 at 3:00 pm

    Executive Summary Most IT teams still operate under a false binary: patch or accept risk. That assumption creates unnecessary operational pressure. Patchless remediation is real and production-proven. Mitigate, Uninstall, Run Custom Scripts, Isolate; close exposure when no reliable patch exists. Same-day exposure neutralization becomes possible for CISA KEV items without emergency change control or restart

  • CVE-2026-69414 ShieldBreak Zero-Day: No Patch, and CISA BOD 26-04 Gives You 14 Days
    by Vamika Sheel on August 25, 2026 at 12:48 am

    Executive Summary ShieldBreak (CVE-2026-69414) is a zero-day elevation-of-privilege vulnerability in the Microsoft Malware Protection Engine used by Microsoft Defender, allowing a low-privilege local attacker to escalate to SYSTEM. A public PoC was released on August 12, 2026, and Microsoft assigned the CVE on August 14, and no patch is available yet. Qualys VMDR provides detection

  • Oracle Critical Patch Update, August 2026 Security Update Review
    by Diksha Ojha on August 19, 2026 at 1:49 pm

    Oracle released its August edition of Critical Patch Update. The update received patches for 943 security vulnerabilities. Some of the vulnerabilities addressed in this update impact more than one product. These patches address vulnerabilities in various product families, including third-party components in Oracle products.  In this Oracle Critical Patch Update, Oracle Fusion Middleware and Oracle Hyperion received the highest number of patches, 262. 

  • CVE-2026-68820 is in KEV. Here Is What CISA BOD 26-04 Actually Requires Now
    by Vamika Sheel on August 18, 2026 at 6:06 pm

    Executive Summary CVE-2026-68820 is an actively exploited Windows vulnerability listed in CISA’s Known Exploited Vulnerabilities (KEV) Catalog, with a remediation deadline as suggested by CISA BOD 26-04. CISA BOD 26-04 introduces risk-based remediation timelines ranging from 3 to 14 days, increasing the pressure on teams to move quickly from patch availability to verified remediation. Installing

  • Why API Discovery Is Critical for Modern AppSec Programs
    by Indrani Das on August 13, 2026 at 5:00 pm

    Hidden API Estate And AI-speed Recon Are Reshaping Modern Application Risk Key Takeaways Unknown APIs create unattributed exposure, and such exposure rarely gets tested. Attackers build their own inventory through live reconnaissance; they do not wait for your spreadsheet.  API discovery must pull from gateways, cloud, specs, traffic paths, scanners, and external exposure signals.  OWASP

  • Qualys Introduces Real-Time Cloud Security Posture Management (CSPM) for Faster Risk Detection and Remediation
    by Shrikant Dhanawade on August 12, 2026 at 7:34 pm

    Key Takeaways Cloud environments change continuously, while security still relies on periodic scans, leaving gaps where risks go undetected. That gap becomes exposure. Qualys Real-Time CSPM monitors cloud changes as they happen, while still supporting periodic scans for environments that require them.  It evaluates each finding in context by correlating posture data with vulnerabilities, asset

  • Microsoft and Adobe Patch Tuesday, August 2026 Security Update Review
    by Diksha Ojha on August 11, 2026 at 9:55 pm

    The August 2026 Microsoft Patch Tuesday release delivers security fixes for vulnerabilities affecting a wide range of Microsoft products and services. As attackers continue to exploit unpatched vulnerabilities, timely patching remains critical for reducing exposure and strengthening enterprise security.  Microsoft Patch Tuesday for August 2026  This month’s release addresses 421 vulnerabilities, including 62 critical and 357 important-severity vulnerabilities.  In this month’s updates, Microsoft has addressed three zero-day vulnerabilities: two publicly disclosed and one exploited in the wild.  Microsoft

  • Audit Fix: Audit Readiness for the Post-Mythos Era
    by Anu Kapil on August 10, 2026 at 12:30 pm

    Key Takeaways Human-speed compliance is dead. Attackers utilizing modern, autonomous AI tools can chain enterprise misconfigurations and weaponize vulnerabilities in under 25 minutes, rendering manual, periodic audit cycles completely obsolete. The “Configuration Gap” is your biggest blind spot. Organizations take an average of 14 months to remediate basic identity, access control, and logging flaws, leaving

Share Websitecyber
We are an ethical website cyber security team and we perform security assessments to protect our clients.