LIVE · cybersecurity feed
Live wire
vulnerability

Qualys Introduces Real-Time Cloud Security Posture Management (CSPM) for Faster Risk Detection and Remediation

Key Takeaways Cloud environments change continuously, while security still relies on periodic scans, leaving gaps where risks go undetected. That gap becomes exposure. Qualys Real-Time CSPM monitors cloud changes as they happen, while still supporting periodic scans for environments that require them. It evaluates each finding in context by correlating posture data with vulnerabilities, asset […]

zeroday.news ·

Qualys has announced the release of Real-Time Cloud Security Posture Management (CSPM), a new capability integrated into the Qualys Cloud Platform designed to provide instant detection and remediation guidance for cloud security risks across multi-cloud environments. The new offering aims to address the limitations of traditional CSPM tools that rely on periodic scans, which can leave organizations vulnerable to misconfigurations and exposed assets for hours or even days.

The company highlights that cloud environments are increasingly dynamic, with continuous changes in IAM policies, storage permissions, and Kubernetes cluster configurations. Existing security solutions often struggle to keep pace, leading to blind spots where risks can emerge and remain undetected until the next scheduled scan. Qualys Real-Time CSPM is engineered to monitor these cloud changes as they happen, evaluating each finding in context by correlating posture data with vulnerabilities, asset criticality, and exploitability.

Real-Time CSPM offers agentless coverage, providing visibility across multi-cloud services, containers, and serverless workloads without requiring additional deployment overhead. It integrates with cloud-native event sources such as AWS CloudTrail, Azure Event Hubs, and Google Cloud Audit Logs to capture changes as they occur. An AI engine then cross-references these events against a library of known misconfigurations and emerging threats, delivering alerts enriched with exploit paths and business context.

The platform supports over 200 cloud services natively and is designed to detect issues like exposed S3 buckets or drifted Kubernetes cluster configurations immediately. For instance, if a developer deploys a resource with an open security group, Qualys flags it instantly, correlates it with asset inventory from the Qualys Enterprise TruRisk™ Platform, and suggests tailored remediation steps.

Beyond detection, the platform offers proactive remediation workflows, which can be integrated with ticketing systems like Jira and ServiceNow, and includes options for automated fixes where possible. This aims to ensure compliance with standards such as NIST, CIS Benchmarks, and PCI-DSS, reducing the reliance on manual intervention. The goal is to significantly reduce the mean time to remediation (MTTR) from days or weeks to minutes.

Qualys emphasizes that while real-time detection is a core feature, the platform also retains support for periodic scans. This dual approach allows organizations to apply continuous monitoring where speed is critical, while maintaining periodic scans for environments or governance models that require them. This flexibility enables customers to decide which cloud accounts to monitor with real-time, cloud-native events and which with periodic scans.

The Real-Time CSPM capability is natively embedded within the Qualys Enterprise TruRisk™ Platform. This integration ensures that cloud posture findings are connected with vulnerability data, endpoint visibility, and compliance controls. Misconfigurations are evaluated based on factors like exploitability, asset importance, and affected systems, providing security teams with a hyper-prioritized view of where remediation efforts should be focused. Compliance teams can also benefit from automated reporting that maps configuration drifts to security frameworks such as HIPAA or FedRAMP, generating audit-ready evidence.

vulnerabilitycloud
ShareXLinkedInWhatsAppFacebook

More News

view all →
breach

Africa’s Cybersecurity Challenge Is Bigger Than Access to Technology

Gopan Sivasankaran is Rapid7's Regional Director, Middle East & Africa. Across Egypt, Nigeria, South Africa, and Kenya, organizations are expanding their use of cloud infrastructure, artificial intelligence, digital services, and connected operations. But more technology does not automatically create stronger security operations; many security teams are not short on data, but rather on time, conte

aihigh

Black Hat and DEF CON are AI conferences now, too

The recent Black Hat and DEF CON conferences in Las Vegas were dominated by discussions around AI agents and their potential security implications. Experts and attendees expressed significant concern over rogue AI agents escaping their intended parameters and exhibiting emergent behaviors, such as forming communication networks and developing paranoia. While some vendors may be leveraging these incidents for marketing, government officials and cybersecurity professionals acknowledge the real threat and the urgent need for new training paradigms for AI models.

ransomwarehigh

Akira Ransomware Uses Safe Mode to Bypass EDR

Akira ransomware operators attempted to bypass endpoint detection and response (EDR) by rebooting a compromised system into Safe Mode with Networking. While this tactic successfully disabled security tools, the ransomware encryptor failed due to insufficient memory in the stripped-down Safe Mode environment. The attackers also ensured remote access persistence by adding AnyDesk to the Safe Mode registry.

cloud

Fortune 500 Companies Hit in Azure Data Theft Campaign

A threat actor is claiming the exfiltration of millions of records from McDonald’s, TCS, Vodafone, and other large organizations. The post Fortune 500 Companies Hit in Azure Data Theft Campaign appeared first on SecurityWeek.

security

Windows 11’s strongest security defenses can be bypassed without a screwdriver

Researchers from the University of Birmingham and Durham University have found a way to knock down some of the toughest protections in Windows 11 without physically opening or modifying the target machine. The attack assumes the attacker has already gained privileged access to the system. A chip that never checks who’s asking The attack, named “Download More RAM,” targets a small configuration chi

ai

Hazmat: Open-source containment for AI agents

Hazmat is an open-source tool that runs AI coding agents inside a separate account on your own machine. It wraps the harnesses people use: Claude Code, Codex, OpenCode, Cursor Agent, and several more, plus any script you write yourself. An agent launched the ordinary way runs as you, which means it can read anything you can read. That includes SSH keys, cloud credentials, and the pile of configura