Lessons from Microsoft Patch KB5002907: Two Layers of Patch Control in Qualys TruRisk Eliminate

From the source: Qualys Blog

How reliability scoring keeps risky patches out of zero-touch jobs, and how one blocking rule stops a paused update across your environment. Executive Summary Microsoft has paused the rollout of KB5002907, an optional Microsoft 365 Apps update that left some Office 2016 and Office 2019 installations unlicensed or removed. When an update runs into trouble […]

Read the full story on Qualys Blog
Originally published by Qualys Blog on 29 Sept 2026. Techarda links to the original rather than republishing it. Read the full article →

Have you worked with this?

The story is what was announced. Nobody has discussed it yet, so if it touches your team, a short post about what you’ve seen helps the next reader.

Start the discussion

More from Qualys

Recent updates from Qualys, so you can tell whether this is a one-off or part of a pattern.

All Qualys news →
Security

Autonomous Remediation Is Already Running at Enterprise Scale

The following is a guest blog by ITSPmagazine, based on their interview of Qualys President & CEO Sumedh Thakar at Black Hat USA 2026. Sumedh Thakar has watched the same clock compress for 23 years. He joined Qualys as an early software engineer on the scanner, when organizations scanned once every 90 days and gave […]

Qualys·via Qualys Blog
Security

The Developer is the New Perimeter: How Supply Chain Attacks Are Becoming Cloud Breaches

A routine package install can open the door to a cloud breach. Learn how attackers exploit developer credentials. Discover practical steps to contain exposure and protect your cloud environment.

Qualys·via Qualys Blog
Security

CISA BOD 26-04 Timelines for Three Linux Kernel CVEs

Executive Summary CISA added three actively exploited Linux kernel vulnerabilities: CVE-2025-39682, CVE-2026-53266, and CVE-2025-39964 to its KEV Catalog on September 18, 2026, triggering a 3-day remediation deadline that passed on September 21. Under CISA BOD 26-04, a 3-day window applies to CVE-2025-39682 across all assets, and for the other two, the deadline is 3 days […]

Qualys·via Qualys Blog

More in Security

What other companies in Security are doing. The category page shows who’s active, side by side.

Compare companies in Security →
SecurityWhy it matters

Threat Actors Use Google Ads To Target Ledger Users

In August 2026, Zscaler ThreatLabz analyzed a phishing campaign that used fraudulent Google ads to target Ledger hardware wallet users. The ads redirected users through Google Cloud Storage and Vercel to a Google Sites page containing a phishing page impersonating Ledger in an iframe. During our analysis, the Vercel redirect appeared to change every 15-20 minutes. There, a fake…

Zscaler·via Zscaler ThreatLabz
Security

Using AI to chart a course for our post-quantum migration

We’re building CryptoLabe, an internal AI-powered tool that discovers cryptography across our codebase, surfaces dependencies, and helps us progress toward a full post-quantum migration by 2029. Here’s what we’ve learned so far.

Cloudflare·via Cloudflare Blog
SecurityVideo

Streamline: custom video pipelines with Cloudflare Stream and Workers

Streamline demonstrates how to build long-running, continuous video processing pipelines by pairing Cloudflare Workers and Durable Objects with a containerized media engine.

Cloudflare·via Cloudflare Blog
Security

Introducing Web Search API via AI Gateway

Cloudflare AI Gateway now supports native web search API integration in partnership with Ceramic.ai, Exa, and Linkup. Developers can now inject real-time web context into model inference calls via AI Gateway, REST APIs, or Workers bindings.

Cloudflare·via Cloudflare Blog