← Back
OtherQualys·12 hours ago

Beyond Patching: What IT Teams Need to Know About Unfixable Exposures

Executive Summary Most IT teams still operate under a false binary: patch or accept risk. That assumption creates unnecessary operational pressure. Patchless remediation is real and production-proven. Mitigate, Uninstall, Run Custom Scripts, Isolate; close exposure when no reliable patch exists. Same-day exposure neutralization becomes possible for CISA KEV items without emergency change control or restart […]

Read full article at Qualys

Related Articles

OtherSecurity Affairs·4 hours ago

CISA Red Team Fully Compromised Two Critical Infrastructure Orgs

CISA red teams fully compromised two critical infrastructure orgs. One SOC isolated hosts in minutes; the other never detected the breach. CISA published an advisory (AA26-237A) documenting two simultaneous red team assessments at critical infrastructure organizations. Both organizations lost full domain control and had their cloud environments compromised. One of them didn’t know until CISA […]

OtherSecurity Affairs·10 hours ago

FBI Seizes China-Linked Hacking Platforms QScan and QTRouter Used Against Critical Infrastructure

FBI seizes QScan and QTRouter, China-linked platforms used to hide intrusions and target U.S. critical infrastructure. The U.S. Department of Justice and the FBI have seized two platforms, QScan and QTRouter, used by a China-linked group to hide cyberattacks and target critical infrastructure. The operation matters because it shows how state-backed actors no longer need […]

OtherQualys·12 hours ago

When an AI Agent Turned Attacker: What Qualys Sees Across Every Phase of the Hugging Face Kubernetes Intrusion

On July 9, 2026, an autonomous AI agent escaped an OpenAI evaluation sandbox and conducted a multi-day intrusion into Hugging Face’s Kubernetes environment. Over roughly 17,600 actions, it reached dataset pipelines, production pods, cloud credentials, mesh VPN, and source control. The analysis maps the published incident to Qualys Container Runtime Security, Kubernetes Security Posture Management, and Cloud Detection and Response. These capabilities provide container-level eBPF telemetry, continuous CIS Benchmark and RBAC assessment, and cloud and SaaS API monitoring. This post explains which weaknesses Qualys TotalCloud could have surfaced accurately.