Qualys Security Blog Expert network security guidance and news
- Extending EOL/EOS Software Intelligence Across Containers, Kubernetes, and Modern Workloadsby Abhinav Mishra on May 28, 2026 at 4:00 pm
Key Takeaways Software inventory used to stop at the server. Modern application delivery erased that boundary. In cloud-native environments, software now moves continuously through container images, registries, CI/CD pipelines, and Kubernetes clusters, often reaching production faster than traditional governance models can track it. A single outdated base image or unsupported runtime no longer stays contained
- CVE-2026-46333: Local Root Privilege Escalation and Credential Disclosure in the Linux Kernel ptrace Pathby Saeed Abbasi on May 20, 2026 at 3:40 pm
The Qualys Threat Research Unit (TRU) has discovered and published the full advisory for CVE-2026-46333, a logic flaw in the Linux kernelâs __ptrace_may_access() function that permits an unprivileged local user to disclose sensitive files and execute arbitrary commands as root on default installations of several major distributions. The bug has resided in mainline Linux since
- Inside the 2026 Verizon DBIR: What One Billion Records Revealed About Vulnerability Remediationby Saeed Abbasi on May 19, 2026 at 4:27 pm
The Verizon 2026 Data Breach Investigations Report has been published. Qualys is proud to have served as a research partner and contributor, contributing analysis of more than one billion anonymized vulnerability remediation records across four consecutive DBIR reporting cycles of CISA Known Exploited Vulnerabilities (KEV) data. The DBIR described the picture our data painted in
- Achieve FedRAMP High M365 Security: Governing with Qualys SSPM and SCuBAby Shrikant Dhanawade on May 14, 2026 at 4:00 pm
Qualys SaaS Security Posture Management (SSPM) introduces native support for the Secure Cloud Business Applications (SCuBA) compliance framework, bringing CISAâs toughest M365 security benchmarks directly into your continuous posture monitoring workflow. Key Takeaways What Is SCuBA and Why Does It Matter for Enterprise Security The Secure Cloud Business Applications (SCuBA) project is a cybersecurity initiative
- Stop Chasing Threats: Top 3 Insights from the SANS Attack Surface Management Surveyby Lisa Bilawski on May 14, 2026 at 3:00 pm
Executive Summary The 2025 SANS ASM Survey highlights a clear shift in cybersecurity operations. Organizations are moving beyond fragmented, alert-driven security approaches toward unified, automated, and business-aligned risk operations. Continuous visibility, intelligent automation, and business-contextual prioritization are becoming essential for managing modern attack surfaces at scale. The findings reinforce the growing need for operational models
- FedRAMP High Authorized: Qualys TotalCloud CNAPP â From Compliance to Defense by Shrikant Dhanawade on May 14, 2026 at 12:45 pm
Qualys TotalCloud⢠has achieved FedRAMP High Authorization, marking a major milestone in delivering validated cloud security and compliance assurance for high-impact federal and regulated environments. Key Takeaways Cloud security and compliance expectations have fundamentally shifted. Organizations are no longer evaluated based on whether controls exist; theyâre evaluated on whether those controls are continuously enforced, validated, and measurable under real-world conditions. FedRAMP
- Microsoft and Adobe Patch Tuesday, May 2026 Security Update Reviewby Diksha Ojha on May 12, 2026 at 7:50 pm
May 2026âs Patch Tuesday arrives with Microsoft addressing a fresh set of vulnerabilities across its ecosystem, reinforcing the ongoing need for timely patching in an increasingly threat-heavy landscape. Hereâs a quick breakdown of what you need to know. Microsoft Patch Tuesday for May 2026 This monthâs release addresses 137 vulnerabilities, including 30 critical and 103 important-severity vulnerabilities. In this monthâs updates, Microsoft has not addressed any publicly disclosed zero-day vulnerability. Microsoft has addressed 128 vulnerabilities in Microsoft Edge (Chromium-based)
- Bringing AI Code Security into Qualys ETMby Vinay Sridhara on May 11, 2026 at 2:00 pm
A first-class data model for the next generation of findings AI-driven code security is becoming a real category. Anthropicâs Claude Code Security and OpenAIâs Codex Security are the leading examples, and more will follow. These tools reason about source code at a depth that traditional SAST cannot reach, surfacing logic flaws, broken authentication patterns, hardcoded
- Dirty Frag: Using the Page Caches as an Attack Surfaceby Mayuresh Dani on May 9, 2026 at 7:22 am
Dirty Frag is a Linux local privilege escalation (LPE) chain published on May 7, 2026. It combines two previously unknown kernel vulnerabilities can allow an unprivileged local user to escalate to root on many major Linux distributions. As of May 8, 2026, CVE-2026-43284 had been patched in mainline Linux, while public reporting indicated that CVE-2026-43500
- Before the Breach, There Was a Test Environmentby Amit Patil on May 6, 2026 at 4:00 pm
Key Takeaways The Problem with Calling QA âNon-Productionâ Most security conversations begin at the wrong end of the problem. We start with the breach, the alert, the investigation, and the inevitable question: how did it happen? Attention moves to production because that is where consequences become visible. But production is rarely where the story begins.













