Technology

Qualys InstaScan Targets Faster Vulnerability Detection After New Disclosures

Bakhtawar Majid

By: Bakhtawar Majid

3 min read

The new capability uses existing security telemetry to help identify potentially affected systems as new vulnerabilities are disclosed. 

[For more news, click here]

Security teams are being asked to respond to newly disclosed vulnerabilities at a pace that scheduled scanning was not designed for. A flaw can become public long before an organization’s next scan establishes whether the affected software is running in its environment, leaving security teams to work out exposure while the clock is already running. 

Qualys is addressing that gap with InstaScan, a capability within Enterprise TruRisk Management that uses existing asset and security information to identify potential exposure when new vulnerability intelligence becomes available. Powered by Agent Insta, it continuously monitors vendor security advisories and threat intelligence and compares them with an organization’s asset inventory, exposure data, and security telemetry. The issue is becoming harder to ignore as attackers move more quickly after vulnerabilities are disclosed. Verizon’s 2026 Data Breach Investigations Report found that vulnerability exploitation accounted for 31% of breaches in its latest dataset, making it the leading initial access vector. Verizon also reported that attackers are using AI to accelerate exploitation of known vulnerabilities, giving defenders less time to establish whether a newly disclosed flaw affects them. Qualys says 46,048 CVEs were published during the first seven months of 2026, almost matching the number recorded throughout 2025. Its research also puts the median time from detection to closure at nine days for KEV-linked vulnerability instances that were eventually remediated. Rather than treating every new disclosure as something that must wait for the next scan cycle, the company is using the information already available about an environment to make that first check sooner. 

From New Advisory to Affected Asset 

Agent Insta is the part of the system that handles that matching. It monitors new vendor advisories and threat intelligence from Qualys and other sources, then compares those signals with current information about assets and their exposure. Changes to assets can also trigger detection, so the information being used is not limited to what was recorded during a previous scan. Qualys says the capability produces confidence scored detections within minutes and covers 90% of detections across its initial set of supported technologies.  The underlying asset information is also important because the system needs a current picture of what software and systems are present before it can identify a potential match. 

“Qualys InstaScan moves threat intelligence from telling you what already happened to detect exposure the moment it emerges; that's true proactive detection,” said Theresa Lanowitz, principal cybersecurity analyst, Omdia. “As threat intelligence becomes a core variable in how organizations quantify risk, InstaScan gives Qualys a direct way to feed that signal into the platform."  

Once a potential exposure is identified, the finding can move into Enterprise TruRisk Management for prioritization and then into validation and remediation workflows. The initial detection does not determine whether a vulnerability can actually be exploited or how urgently it should be addressed. Those decisions remain part of the work that follows, but the process can begin without waiting for another scan. 

"The speed of vulnerability exploitation has fundamentally changed,” said Sumedh Thakar, president and CEO of Qualys. “A slow vulnerability management program is now the biggest vulnerability an organization has. We're entering a new era of vulnerability, one where detection is continuous – driven by live intelligence instead of scan cycles. Built on the Qualys platform, InstaScan helps organizations identify and reduce risk the moment new vulnerabilities are disclosed."  

The capability is now available within ETM, with detections feeding into the platform’s existing prioritization, validation, and remediation workflows. Its initial coverage is limited to supported technologies, with Qualys saying it plans to extend the approach as part of its broader agent-driven vulnerability detection and remediation work. 


Related Articles 

Qualys Debuts Industry’s First AI Agent for Safe Exploit Validation 

Tenable and Anthropic Think Agentic AI Can Finally Close the Gap Between Cyber Discovery and Response 

The Case for Fewer Dashboards: Censys and the Push to Embed Intelligence Into Security Workflows 


 

Share this article

Related Articles