News
Top 5 Compliance Audit Software Tools for 2026 | Risk-Based Compliance
19+ hour, 42+ min ago (1557+ words) AI moves faster than your audit cycle. Compliance monitoring software closes that gap by locating assets, mapping controls, prioritizing what actually matters, automating remediation, and keeping audit-ready evidence current at all times. In a machine-speed threat environment, point-in-time compliance is…...
OWASP Top 10 2025 Coverage Map: Is Your AppSec Program Ready?
2+ week, 17+ hour ago (803+ words) If you’ve read What Changed in OWASP Top 10 2025 and Recommendations for Each Category, you already know what the 2025 update changed and what OWASP recommends for each of the 10 categories. This post is the practitioner’s guide to implementing recommendations in real-world…...
Turning Millions of Risks Into One Actionable List
1+ mon, 1+ week ago (403+ words) Every security leader walks into Monday morning with the same question. The findings are there. The dashboards are running. But out of the thousands of critical vulnerabilities on that list, which ones can an attacker actually use against this organization…...
Microsoft and Adobe Patch Tuesday, June 2026 Security Update Review
1+ mon, 1+ week ago (435+ words) The law states that we can store cookies on your device if they are strictly necessary for the operation of this site. For all other types of cookies we need your permission. There were also a massive 360 Microsoft Edge/Chromium…...
Advancing Cybersecurity in the Age of Frontier AI: Qualys Steps into Project Glasswing
1+ mon, 2+ week ago (597+ words) The cybersecurity industry has spent much of the last two years debating how attackers might use AI. That debate matters, but it misses a larger point: defenders now have an opportunity to change the economics of cyber risk. For me,…...
CVE-2026-46333: Local Root Privilege Escalation and Credential Disclosure in the Linux Kernel ptrace Path
2+ mon, 12+ hour ago (125+ words) The primitive is reliable and turns any local shell into a path to root or to sensitive credential material. To characterize impact across real systems, TRU built four exploits against widely deployed userland targets: You can find the technical details…...
Achieve Federal-Grade M365 Security: Governing with Qualys SSPM and SCuBA
2+ mon, 6+ day ago (638+ words) Unlike generic benchmarks, SCuBA baselines are built to counter real-world attack patterns, including the nation-state tactics that compromised federal agencies in high-profile breaches. They’re being rapidly adopted not only by federal civilian agencies but also by regulated industries, including finance,…...
Bringing AI Code Security into Qualys ETM
2+ mon, 1+ week ago (710+ words) AI-driven code security is becoming a real category. Anthropic’s Claude Code Security and OpenAI’s Codex Security are the leading examples, and more will follow. These tools reason about source code at a depth that traditional SAST cannot reach, surfacing logic…...
Dirty Frag: Using the Page Caches as an Attack Surface
2+ mon, 1+ week ago (367+ words) Dirty Frag is a Linux local privilege escalation (LPE) chain published on May 7, 2026. It combines two previously unknown kernel vulnerabilities can allow an unprivileged local user to escalate to root on many major Linux distributions. As of May 8, 2026, CVE-2026-43284 had…...
Qualys TotalAI Achieves FedRAMP Moderate Authorization
2+ mon, 2+ week ago (1153+ words) Most agencies struggle to meet these requirements because their existing security tools lack the necessary FedRAMP-authorized, AI-specific oversight. The goal is to gain end-to-end visibility, reduce risk, and produce audit-ready evidence from a single platform built for the entire AI…...