IT Brief Australia - Technology news for CIOs & IT decision-makers
Australia
Qualys launches InstaScan for faster vulnerability detection

Qualys launches InstaScan for faster vulnerability detection

Tue, 4th Aug 2026 (Today)
Joseph Gabriel Lagonsin
JOSEPH GABRIEL LAGONSIN News Editor

Qualys has launched InstaScan within its Enterprise TruRisk Management platform, saying the feature can detect newly disclosed vulnerabilities within minutes.

The launch targets a growing problem for security teams as reported software flaws increase and attackers move faster to exploit them. Qualys cited 46,048 CVEs published in the first seven months of 2026, close to the total for all of 2025.

InstaScan uses what Qualys calls "scanless scanning" through Agent Insta, which continuously monitors vendor advisories and threat intelligence, then matches that information against an organisation's existing asset inventory, exposure data and threat telemetry. The goal is to identify affected assets without waiting for a scheduled scan cycle.

The product is available now within Enterprise TruRisk Management and initially supports technologies that account for 90 per cent of detections within minutes, according to Qualys.

Faster detection

The announcement comes as vulnerability management faces pressure from both the pace of disclosure and the speed of exploitation. Verizon's 2026 Data Breach Investigations Report identified vulnerability exploitation as the leading breach entry point, accounting for 31 per cent of breaches, and found that artificial intelligence is shortening attacker timelines from months to hours.

Qualys said its research found that among KEV-linked vulnerability instances that were eventually remediated, the median time from detection to closure was nine days. Over the same period, KEV-linked workload rose 78 per cent year on year, suggesting defenders are managing a larger queue even as response windows shrink.

That gap between disclosure and action has become a central issue for security vendors trying to move customers away from periodic scanning models. Rather than waiting for the next scan window, Qualys is positioning InstaScan as a way to use existing telemetry to spot exposure as soon as a new advisory appears.

Theresa Lanowitz, principal cybersecurity analyst at Omdia, linked the launch to the growing role of intelligence in risk measurement.

"Qualys InstaScan moves threat intelligence from telling you what already happened to detect exposure the moment it emerges; that's true proactive detection," said Theresa Lanowitz, principal cybersecurity analyst at Omdia.

"As threat intelligence becomes a core variable in how organisations quantify risk, InstaScan gives Qualys a direct way to feed that signal into the platform," Lanowitz added.

Platform role

Qualys described InstaScan as the intelligence layer for continuous vulnerability detection across its wider platform. It combines newly published advisories with data already held in the platform to generate confidence-scored detections that can feed prioritisation, validation and remediation workflows.

In practical terms, the feature sits upstream of remediation work, supplying a signal on which assets may be exposed and which vulnerabilities should be addressed first. Qualys described this as the first step in a broader agent-driven workflow that connects detection to risk reduction.

The launch also reflects a broader push by cybersecurity suppliers to present artificial intelligence less as a standalone feature and more as a way to automate existing operational tasks. Here, the emphasis is on reducing dependence on fixed scanning schedules and speeding the hand-off from disclosure to detection.

Sumedh Thakar, president and CEO of Qualys, said the change in attacker behaviour had altered the economics of vulnerability management.

"The speed of vulnerability exploitation has fundamentally changed," said Sumedh Thakar, president and CEO of Qualys.

"A slow vulnerability management program is now the biggest vulnerability an organisation has. We're entering a new era of vulnerability, one where detection is continuous - driven by live intelligence instead of scan cycles. Built on the Qualys platform, InstaScan helps organisations identify and reduce risk the moment new vulnerabilities are disclosed," Thakar said.

Qualys has more than 10,000 subscription customers worldwide, including many large enterprises, and has built its business around cloud-based security, compliance and IT tools. Its platform already draws on telemetry from on-premises systems, endpoints, servers, public and private clouds, containers, web applications and mobile devices.

That installed base gives the company a large pool of customer telemetry to work with as it expands automation across the platform. The argument behind InstaScan is that this data can be reused for faster vulnerability detection, rather than relying only on conventional scans to build a fresh picture of exposure.

For customers, the main test is likely to be whether earlier detection produces faster remediation in practice, particularly in environments where patching still depends on internal approval, validation and change management processes. Qualys is seeking to address that by feeding a trusted detection signal into those downstream workflows as soon as an advisory is published.

InstaScan is now available within Qualys Enterprise TruRisk Management.