How Security Tool Misuse Is Reshaping Cloud Compromise

2026-03-04T21:30:26Z2aab162420295ec67a3f9e3d53faf18a4b54488e5bf4bbcb06f10b96aa195246
CVE-2018-14634Active DirectoryCNAPPCTEMROCcloud compromisecredential misuseidentity and access managementpass-the-hashpass-the-ticketpatch managementpatch reliabilitypublic container registriessoftware supply chainvulnerability validationzero-day

What happened

Collection of Qualys blog posts (Jan–Feb 2026) covering rising cloud compromise trends driven by credential and identity misuse, abuse of legitimate security tools, and risks from public container registries; new product features for patch reliability scoring and autonomous exploit validation (TruConfirm); Active Directory attack techniques (Pass‑the‑Hash/Pass‑the‑Ticket) and enterprise mitigation guidance; Microsoft Patch Tuesday Feb 2026 addressing 61 vulnerabilities (including six zero‑days); and a retrospective on CVE‑2018‑14634 (Mutagen Astronomy) being added to CISA’s KEV catalog. The合集*

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
qualys_blog
Record identifier
2aab162420295ec67a3f9e3d53faf18a4b54488e5bf4bbcb06f10b96aa195246
Enrichment time
2026-03-04T21:30:26Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · How Security Tool Misuse Is Reshaping Cloud Compromise · Baitaphish