Recent Advisories

Severity ID Title Vendor Product Date Type
NONE QUALYSBLOG:B347...

ROC vs. CTEM: How a Risk Operations Center Evolves Beyond Continuous Threat Exposure Management in 2026_QUALYSBLOG:B347FEC1692869AB921514C713F3F9DC

## **Key Takeaways: The Essentials of ROC vs. CTEM** * **What is a ROC?** A risk operations center (ROC) is a centralized command hub that unifi...

N/A N/A QUALYSBLOG
NONE QUALYSBLOG:38D7...

Top 10 Cloud Compliance Tools for Enterprise Security and Audit Readiness in 2026_QUALYSBLOG:38D744DC8EDE9A4FB8C3821F654093C2

##### **Key Takeaways** * Cloud compliance has shifted from periodic audits to a continuous operating requirement as hybrid and multi-cloud envi...

N/A N/A QUALYSBLOG
NONE QUALYSBLOG:B9A3...

Cybersecurity Predictions for 2026 Signal the Maturation of Risk-First Security Models_QUALYSBLOG:B9A30CF74D953D82560D3840E32455FA

### Key Takeaways * **Cyber risk management gets operationalized in 2026.** Leading organizations move beyond visibility and frameworks to gover...

N/A N/A QUALYSBLOG
NONE QUALYSBLOG:4CD8...

Why Serverless Risk Demands Identity-Aware Security at Cloud Scale_QUALYSBLOG:4CD8AB8318C32E025DC00350BC3423F3

**Key Takeaways** * Serverless shifts security risk from infrastructure to identity, permissions, and configuration, where small design choice...

N/A N/A QUALYSBLOG
NONE QUALYSBLOG:CBA7...

Your VMDR Year in Review: Making Security Progress Visible and Actionable_QUALYSBLOG:CBA72A2A7949BF1E74A12097679C5205

## **Security Teams Rarely Stop to Reflect** When a security program is working well, very little seems to happen. That is by design. There is no ...

N/A N/A QUALYSBLOG
HIGH 8.4 QUALYSBLOG:1053...

Microsoft Patch Tuesday, January 2026 Security Update Review_QUALYSBLOG:1053341D368ED2E4ED9E02643CA3532F

Starting the year on a security-first note, Microsoft's January 2026 Patch Tuesday resolves several vulnerabilities that could impact enterprise en...

N/A N/A QUALYSBLOG
NONE QUALYSBLOG:DA7D...

Cloud Agent in 2025: A Year of Scale, Security, and Smarter Visibility_QUALYSBLOG:DA7D874D2EBCC98228423C4613538ECF

As we move into 2026, 2025 stands out as a defining year for the Qualys Cloud Agent. In 2025, Cloud Agent delivered **_deeper visibility into runni...

N/A N/A QUALYSBLOG
NONE QUALYSBLOG:E591...

Your Guide to PCI DSS 4.0.1 Web Application & API Controls—and a Simplified Path to Compliance_QUALYSBLOG:E5911A657F4DA6D267E4643F26D18F52

## **Executive Summary** **PCI DSS 4.0.1 compliance** mandates stricter security controls for web applications and APIs. Key updates include maint...

N/A N/A QUALYSBLOG
NONE QUALYSBLOG:DFBA...

ShadyPanda: The Silent Browser Takeover Threat and How Qualys TruRisk Eliminate Helps You Stop It_QUALYSBLOG:DFBA459B23CBBC98D1D1C2A2B05E0F37

## **Executive Summary** ShadyPanda has exploited trusted browser extensions to compromise millions of users, illustrating how legitimate software...

N/A N/A QUALYSBLOG
NONE QUALYSBLOG:4ED6...

Navigating Change: Evolving Your Exposure Management Strategy in a Post-Kenna World with Qualys_QUALYSBLOG:4ED63D6E8A7709CE43981EE048F5C6DC

**Key Takeaways** > * Cisco is ending support for it vuln management product (formerly Kenna Security) by June 2028 > * Risk-based vulnerabili...

N/A N/A QUALYSBLOG