The OWASP Top 10 2025 update -- what you need to know:
- Categories reshuffled.
- API attack surfaces expanded.
- New threat vectors added that most AppSec programs aren't accounting for yet.
Read the full breakdown: https://t.co/kEGrJUXDAR https://t.co/EV8KpXOpjj
Qualys’ CEO & President Sumedh Thakar: Prevent doing “dashboard tourism” by just creating more dashboards.
In this N2K CyberWire interview, Sumedh joins David Bittner of CyberWire Daily to explain how attackers are outpacing traditional patching timelines and why organizations must shift to autonomous remediation to close the growing gap between detection and response.
📢 Listen to the full podcast here:
#CyberSecurity #AutonomousRemediation #AI
Less than 1% of "critical" vulnerabilities in the average enterprise are actually exploitable. The other 99% consume engineer hours and were never going to hurt anyone. Inside Qualys's bet that most of cybersecurity has been chasing the wrong list.
Part of our editorial partnership series with @qualys -
https://t.co/vL4r9PEDNY
The @VerizonBusiness 2026 Data Breach Investigations Report (#DBIR) has been published, and the Qualys Threat Research Unit (#TRU) is proud to have served as a research partner. Our four-year CISA KEV survival curve analysis anchors the Survival of the Vulnerable section on page 18, where the DBIR cites our full report. We're grateful to the DBIR team for the collaboration.
The analysis draws on more than one billion anonymized vulnerability remediation records across four DBIR reporting cycles.
The finding: defenders are running harder than ever and still losing ground. KEV-linked vulnerability instances grew 7.7x in four years, from 68.7M to 527.3M. Median time-to-close held steady at 9 days. Yet at Day 28, the open backlog grew from 31 million instances to 184 million. The patching engine did not slow. The load outran it.
What closes the gap is an architectural shift: machine-speed pipelines that route validated, environment-confirmed exposures into autonomous remediation. We call it the Risk Operations Center (ROC).
Read our extended analysis, four-year cohort breakdowns, and proactive-defense data in our updated report, The Broken Physics of Remediation: https://t.co/TCLKLm8lt2
#Cybersecurity #VulnerabilityManagement #RiskOperationsCenter
How do you know your #AppSec program is hitting its breaking point?
Watch the full "Modern AppSec Is Broken" webinar here: https://t.co/bHtDfCLvH9 https://t.co/kpKNFiyFcY
Claude Mythos is the new elephant in the room when it comes to modern day cybersecurity.
Qualys’ Shailesh Athalye penned this comprehensive article on Mythos and the new landscape of threat remediation for @aidatainsider.
Learn why Mythos is the defining security challenge of 2026 and how you can combat AI-powered attackers with a Risk Operations Center (ROC) model.
https://t.co/CkBRJFebsY
#CyberSecurity #VulnerabilityManagement #ClaudeMythos #AI
Panel at Qualys' ROCon 26 ... Sir Ian Andrews, vice chair, National Preparedness Commission: hates obfuscatory word "cybersecurity"; our focus should be on risk as such.
And Qualys CEO Sumedh Thakar contended mainly that business risk management should govern cybersecurity thinking, not patching per se -- not the be all and end all; not all vulns will be ubiquitously exploitable. He was also funny.
The old days of #VM are over. To manage #RiskOperations at scale for partners, @Qualys is introducing the managed #RiskOperationsCenter (#mROC) Portal, providing a unified view of risk to our customers. Learn more below. https://t.co/60kYuDiGNj
Researchers at @qualys have issued an alert after discovering a set of nine vulnerabilities in Linux's built-in security layer, AppArmor, that affect millions of enterprise systems around the world.
The "CrackArmor" flaws allow unprivileged local users to circumvent kernel protections, escalate to root privileges, and weaken container isolation.
Notably, these flaws have existed since 2017 and affect more than 12.6 million enterprise Linux instances - any organization running Ubuntu, Debian, or SUSE will be affected, according to Qualys.
https://t.co/o5d2JmCOgk
Qualys Threat Research Unit (TRU) discovered CrackArmor: 9 AppArmor flaws impacting 12M+ Linux systems since 2017. These enable root access & container breakouts.
Patch your kernels now! Details: https://t.co/frznetHzYJ
#Linux#Cybersecurity#CrackArmor"
Last year, we made history as the first major cybersecurity company to sponsor a professional cricket team in the US.
Today, we’re proud to announce that we are extending our partnership with the @SFOUnicorns through 2027! Here’s to more wicked wickets and another great season together. 🦄 Go #SparkleArmy!
Read here: https://t.co/DrIvq8feXL
#QualysxUnicorns #SFUnicorns #Cricket #Cybersecurity