* * * #### Executive Summary _Knowing what’s exploitable is only half the battle. P2P patch distribution turns your endpoints into a delivery net...
#### **Key Takeaways** * HazyBeacon (CL-STA-1020) targets Southeast Asian government networks by abusing AWS Lambda Function URLs configured wit...
#### Key Takeaways * Unsupported software increasingly exists inside container images and Kubernetes workloads, not just traditional infrastruct...
The Qualys Threat Research Unit (TRU) has discovered and published the full advisory for CVE-2026-46333, a logic flaw in the Linux kernel's __ptrac...
The Verizon 2026 Data Breach Investigations Report has been published. Qualys is proud to have served as a research partner and contributor, contri...
**Qualys SaaS Security Posture Management (SSPM) introduces native support for the Secure Cloud Business Applications (SCuBA) compliance framework,...
**Qualys TotalCloud has achieved FedRAMP High Authorization, marking a major milestone...
May 2026's Patch Tuesday arrives with Microsoft addressing a fresh set of vulnerabilities across its ecosystem, reinforcing the ongoing need for ti...
### _A first-class data model for the next generation of findings_ AI-driven code security is becoming a real category. Anthropic's Claude Code Se...
Dirty Frag is a Linux local privilege escalation (LPE) chain published on May 7, 2026. It combines two previously unknown kernel vulnerabilities ca...
AI-powered asset discovery, dark web monitoring, CVE alerting, and vulnerability scanning — all in one platform.