Qualys reports that public-facing applications have become a primary vector for initial access in cyberattacks, representing a significant shift in threat landscape priorities. The finding underscores the importance of securing externally-accessible systems as organizations face increasing threats targeting web-based and cloud-connected infrastructure.