The Autonomous Engine Behind Remediation, and What Finally Makes It Safe
Executive Summary Vulnerability exploitation now happens at a speed that manual, ticket-based remediation can’t match.
16 articles
Executive Summary Vulnerability exploitation now happens at a speed that manual, ticket-based remediation can’t match.
On July 9, 2026, an autonomous AI agent escaped an OpenAI evaluation sandbox and conducted a multi-day intrusion into Hugging Face’s Kubernetes environment. ...
Key Takeaways Cloud environments change continuously, while security still relies on periodic scans, leaving gaps where risks go undetected. That gap becomes...
Photo gallery from the Business Hall at Black Hat USA 2026. Interesting booths, demo stages, crowded aisles, and the moments in between.
Powered by TruConfirm — Exploit Validation That Now Runs on the Network and the Host Executive Summary Qualys TruConfirm now validates exploitability across ...
Key Takeaways AI adoption has outpaced enterprise controls, with AI and LLM workloads appearing faster than security teams can inventory or approve them. AI ...
Linux systems using the XFS filesystem suffer from a race condition that could enable an unprivileged local user to gain full root access. The flaw affects s...
A recently disclosed vulnerability in Ubuntu’s snap ecosystem, identified as CVE-2026-8933, presents a critical local privilege escalation flaw. This vulnera...
Qualys disclosed CVE-2026-8933, a high-severity Ubuntu flaw that lets local attackers gain root privileges through a race condition in snap-confine. Qualys h...
Executive summary Qualys Threat Research Unit (TRU) identified CVE-2026-64600, a race condition in the Linux kernel’s XFS filesystem copy-on-write path. An a...
The Qualys Threat Research Unit (TRU) has identified a Local Privilege Escalation (LPE) vulnerability in snap-confine (CVE-2026-8933). This flaw allows an un...
Executive Summary Manual audit preparation no longer scales across hybrid, cloud, endpoint, and application environments. Compliance monitoring software must...
Key Takeaways Identity-based attacks are among the fastest and most effective intrusion methods because valid credentials let attackers operate as trusted us...
Why Qualys joined the Athena coalition, and what it means for how you prioritize risk. Qualys is proud to have joined Athena, the industry coalition Chaingua...
Qualys finds nine-year-old Linux ptrace flaw exposing SSH keys and password hashes locally
In this article, we describe how we applied survival analysis to vulnerability management (VM) data from Qualys VMDR, using the Elastic Stack.