Qualys has announced InstaScan, powered by Agent Insta, a new capability within Qualys Enterprise TruRisk Management (ETM) that closes the gap between vulnerability disclosure and detection by transforming the asset telemetry organizations already collect into continuous exposure visibility.
The industry's detection clock broke in 2025. In the first seven months of 2026, 46,048 CVEs were published nearly matching the total for all of 2025. For the first time, Verizon’s 2026 DBIR named vulnerability exploitation the leading breach entry point, accounting for 31% of breaches, and found that AI is compressing attacker timelines from months to hours. Qualys research shows the defender side: among KEV-linked vulnerability instances ultimately remediated, median detection-to-closure held at nine days, even as KEV-linked workload grew 78% year over year. Defenders’ nine days now meet attackers’ hours, while the queue grows faster than conventional, human-led programs can drain it. Waiting for the next scan window is no longer a delay. It is lost response time.
InstaScan introduces scanless scanning, an innovative, autonomous vulnerability management capability within Qualys ETM. Powered by Agent Insta, a cyber-risk agent leveraging AI to continuously monitor newly published vendor security advisories and threat intelligence from Qualys and trusted third-party sources, Agent Insta correlates emerging vulnerabilities with an organization's live inventory, telemetry and threat intelligence. It automatically identifies impacted assets and surfaces trusted detections within minutes.
Across its initial set of supported technologies, InstaScan covers 90 percent of detections within minutes. InstaScan powered by Agent Insta helps to:
· Detect at the speed of disclosure — New vulnerabilities become visible within minutes of advisory publication which closes the exposure window before attackers can exploit them.
· Outpace the AI-accelerated threat landscape — Detection is triggered by new advisories and asset changes rather than fixed scan schedules, keeping exposure data continuously current and enabling remediation to begin while legacy scan windows are still waiting to open.
· Power autonomous defense — AI-normalized, confidence-scored detections provide trusted signals that downstream prioritization, validation and remediation workflows can immediately act on, accelerating the path from vulnerability disclosure to risk reduction.
"The speed of vulnerability exploitation has fundamentally changed,” said Sumedh Thakar, president and CEO of Qualys. “A slow vulnerability management program is now the biggest vulnerability an organization has. We're entering a new era of vulnerability, one where detection is continuous – driven by live intelligence instead of scan cycles. Built on the Qualys platform, InstaScan helps organizations identify and reduce risk the moment new vulnerabilities are disclosed."
InstaScan is the intelligence layer that powers continuous vulnerability detection across the Qualys platform. It correlates newly published advisories with the platform’s existing inventory, exposure data and threat telemetry to deliver confidence-scored detections within minutes of disclosure. As the first step in a broader agent-driven detection-to-remediation workflow, InstaScan provides TruRisk with intelligence for more accurate prioritization, while giving validation and remediation workflows a trusted signal to act immediately. The result is a faster path from vulnerability disclosure to risk reduction.
See What’s Next in Tech With the Fast Forward Newsletter
Tweets From @varindiamag
Nothing to see here - yet
When they Tweet, their Tweets will show up here.




