STOCK TITAN

Qualys Launches InstaScan to Detect Vulnerabilities Within Minutes of Disclosure

(Moderate)
(Negative)
Tags

Qualys (NASDAQ: QLYS) introduced InstaScan, a new “scanless scanning” capability within Enterprise TruRisk Management (ETM) powered by Agent Insta. The solution continuously correlates newly published vendor security advisories and threat intelligence with organizations' live asset inventory, exposure data and telemetry to detect vulnerabilities within minutes of disclosure.

According to Qualys, InstaScan covers about 90% of detections within minutes across its initial supported technologies, providing AI-normalized, confidence-scored findings that can immediately feed prioritization, validation and remediation workflows. InstaScan is now available within ETM and will be showcased at Black Hat USA and via dedicated webinars and content.

Loading...
Loading translation...

Positive

  • 90% of detections within minutes across initial supported technologies, according to Qualys
  • AI-driven scanless scanning shifts detection from periodic scans to continuous advisory-triggered monitoring
  • Confidence-scored detections enable faster downstream prioritization, validation and remediation workflows

Negative

  • None.

Market reaction after InstaScan capability launch: QLYS +6.44%

+6.44% $154.07
15m delay
+6.44% Vs previous close
$154.07 Last Price
$146.38 $155.18 Day Range
$5.31B Market Cap
0.8x Rel. Volume

Following this news, QLYS has gained 6.44%, reflecting a notable positive market reaction. Our momentum scanner has triggered 37 alerts so far, indicating elevated trading interest and price volatility. The stock is currently trading at $154.07.

Data tracked by StockTitan Argus (15 min delayed). Upgrade to Gold for real-time data.

Market Context

Historical event 1057740 recorded a 0.27% 24-hour reaction, while event 1055041 recorded -1.41% afte...
Analysis

Historical event 1057740 recorded a 0.27% 24-hour reaction, while event 1055041 recorded -1.41% after Q1 results. For this launch, the platform record adds mixed precedent; watch adoption evidence and the documented insider net-selling signal.

Key Figures

CVEs published: 46,048 CVEs Breaches from vulnerability exploitation: 31% Median detection-to-closure: 9 days +2 more
5 metrics
CVEs published 46,048 CVEs First seven months of 2026
Breaches from vulnerability exploitation 31% Verizon 2026 DBIR
Median detection-to-closure 9 days Remediated KEV-linked vulnerability instances
KEV-linked workload growth 78% Year over year
Detection coverage within minutes 90% Initial set of supported technologies

Historical Context

5 past events · Latest: Jul 21 (Neutral)
Pattern 5 events
Date Event Sentiment 24h Move Catalyst
Jul 21 Earnings date notice Neutral -8.1% Qualys scheduled second-quarter 2026 results for August 4, followed by an 8.05% decline.
May 14 FedRAMP authorization Positive +0.3% TotalCloud achieved FedRAMP High Authorization for Qualys Government Platform.
May 11 Investor conference Neutral -2.9% Qualys announced management participation in William Blair's annual growth stock conference.
May 05 Q1 earnings report Positive -1.4% Qualys reported Q1 results and raised full-year 2026 revenue and EPS guidance.
May 05 Insurance partnership Positive -0.4% Qualys and Converge launched a joint cyber-risk offering for insurance underwriting.

24h Move is the share-price change in the day after each event; other market factors may also have contributed.

Pattern Detected

Recent positive Qualys announcements were followed by mixed-to-negative 24-hour reactions, including -1.41% after Q1 results and +0.27% after FedRAMP High Authorization.

Key Terms

cves, telemetry, threat intelligence
3 terms
cves technical
"46,048 CVEs were published nearly matching the total for all of 2025."
CVEs (Common Vulnerabilities and Exposures) are unique ID numbers assigned to publicly known security flaws in software or hardware, like a catalog entry that describes a specific weak spot. For investors, CVEs matter because they signal potential risks to a company’s systems and customer data—similar to a product recall number that warns of problems requiring fixes, which can lead to costs, downtime, regulatory scrutiny, or reputational damage.
telemetry technical
"asset, exposure and threat telemetry from Qualys and third-party sources"
Telemetry is the automatic collection and transmission of measurements from remote devices, systems, or patients to a central system for monitoring and analysis—like a car sending engine, speed and location data back to a dashboard. For investors it matters because telemetry provides real-time evidence of product performance, safety and user behavior, helping assess revenue potential, operational risk, regulatory compliance and whether a product is meeting market demand.
threat intelligence technical
"monitor newly published vendor security advisories and threat intelligence"
Threat intelligence is actionable information about cyber risks—who might attack, how they operate, and what systems or data are vulnerable—gathered from monitoring networks, software behavior, and public reports. For investors it matters because strong threat intelligence helps a company prevent disruptions, avoid costly breaches and fines, and protect reputation, much like a weather forecast and neighborhood watch help a community prepare for storms and deter crime.

AI-generated analysis. How Rhea-AI works. Not financial advice.

See more from StockTitan in Google Search and AI answers. Adds StockTitan as a preferred source · opens Google
Add on Google

Qualys Enterprise TruRisk Management's (ETM) "scanless scanning," powered by Agent Insta, continuously correlates new advisories with asset, exposure and threat telemetry from Qualys and third-party sources detecting vulnerabilities at AI speed

FOSTER CITY, Calif., Aug. 3, 2026 /PRNewswire/ -- Qualys, Inc. (NASDAQ: QLYS), a leading provider of disruptive cloud-based IT,security and compliance solutions, today announced InstaScan, powered by Agent Insta, a new capability within Qualys Enterprise TruRisk Management (ETM) that closes the gap between vulnerability disclosure and detection by transforming the asset telemetry organizations already collect into continuous exposure visibility.

InstaScan, powered by Agent Insta is a new capability within Qualys Enterprise TruRisk Management (ETM)

The industry's detection clock broke in 2025. In the first seven months of 2026, 46,048 CVEs were published nearly matching the total for all of 2025. For the first time, Verizon's 2026 DBIR named vulnerability exploitation the leading breach entry point, accounting for 31% of breaches, and found that AI is compressing attacker timelines from months to hours. Qualys research shows the defender side: among KEV-linked vulnerability instances ultimately remediated, median detection-to-closure held at nine days, even as KEV-linked workload grew 78% year over year. Defenders' nine days now meet attackers' hours, while the queue grows faster than conventional, human-led programs can drain it. Waiting for the next scan window is no longer a delay. It is lost response time.

"Qualys InstaScan moves threat intelligence from telling you what already happened to detect exposure the moment it emerges; that's true proactive detection," said Theresa Lanowitz, principal cybersecurity analyst, Omdia. "As threat intelligence becomes a core variable in how organizations quantify risk, InstaScan gives Qualys a direct way to feed that signal into the platform."

InstaScan introduces scanless scanning, an innovative, autonomous vulnerability management capability within Qualys ETM. Powered by Agent Insta, a cyber risk agent leveraging AI to continuously monitor newly published vendor security advisories and threat intelligence from Qualys and trusted third-party sources, Agent Insta correlates emerging vulnerabilities with an organization's live inventory, telemetry and threat intelligence. It automatically identifies impacted assets and surfaces trusted detections within minutes.

Across its initial set of supported technologies, InstaScan covers 90 percent of detections within minutes. InstaScan powered by Agent Insta helps to:

  • Detect at the speed of disclosure — New vulnerabilities become visible within minutes of advisory publication which closes the exposure window before attackers can exploit them.
  • Outpace the AI-accelerated threat landscape — Detection is triggered by new advisories and asset changes rather than fixed scan schedules, keeping exposure data continuously current and enabling remediation to begin while legacy scan windows are still waiting to open.
  • Power autonomous defense — AI-normalized, confidence-scored detections provide trusted signals that downstream prioritization, validation and remediation workflows can immediately act on, accelerating the path from vulnerability disclosure to risk reduction.

"The speed of vulnerability exploitation has fundamentally changed," said Sumedh Thakar, president and CEO of Qualys. "A slow vulnerability management program is now the biggest vulnerability an organization has. We're entering a new era of vulnerability, one where detection is continuous - driven by live intelligence instead of scan cycles. Built on the Qualys platform, InstaScan helps organizations identify and reduce risk the moment new vulnerabilities are disclosed."

InstaScan is the intelligence layer that powers continuous vulnerability detection across the Qualys platform. It correlates newly published advisories with the platform's existing inventory, exposure data and threat telemetry to deliver confidence-scored detections within minutes of disclosure. As the first step in a broader agent-driven detection-to-remediation workflow, InstaScan provides TruRisk with intelligence for more accurate prioritization, while giving validation and remediation workflows a trusted signal to act immediately. The result is a faster path from vulnerability disclosure to risk reduction.

Availability            
InstaScan is now available within Qualys ETM. Visit Qualys at Black Hat USA booth 2333 to experience InstaScan in action. Register for our webinar at brighttalk.com/webcast/11673/673558.

About Qualys 

Qualys, Inc. (NASDAQ: QLYS) is a leading provider of disruptive cloud-based security, compliance and IT solutions with more than 10,000 subscription customers worldwide, including a majority of the Forbes Global 100 and Fortune 100. Qualys helps organizations streamline and automate their security and compliance solutions onto a single platform for greater agility, better business outcomes, and substantial cost savings.

The Qualys Enterprise TruRisk Platform leverages a single agent to continuously deliver critical security intelligence while enabling enterprises to automate the full spectrum of vulnerability detection, compliance, and protection for IT systems, workloads and web applications across on premises, endpoints, servers, public and private clouds, containers, and mobile devices. Founded in 1999 as one of the first SaaS security companies, Qualys has strategic partnerships and seamlessly integrates its vulnerability management capabilities into security offerings from cloud service providers, including Oracle Cloud Infrastructure, Amazon Web Services, the Google Cloud Platform and Microsoft Azure, along with a number of leading managed service providers and global consulting organizations. For more information, please visit http://www.qualys.com.

Qualys, Qualys VMDR®, Qualys TruRisk and the Qualys logo are proprietary trademarks of Qualys, Inc. All other products or names may be trademarks of their respective companies. 

Media Contact:   
Rachel Yap Winship 
Qualys
Media@Qualys.com

Qualys, Inc., Redwood City, Calif.

Cision View original content to download multimedia:https://www.prnewswire.com/news-releases/qualys-launches-instascan-to-detect-vulnerabilities-within-minutes-of-disclosure-302840753.html

SOURCE Qualys, Inc.

FAQ

What is Qualys InstaScan and how does it work for QLYS customers?

Qualys InstaScan is a scanless vulnerability detection capability in Enterprise TruRisk Management. It uses Agent Insta and AI to continuously correlate new vendor advisories and threat intelligence with live asset telemetry, surfacing confidence-scored vulnerability detections for impacted assets within minutes of disclosure, according to Qualys.

How fast can Qualys InstaScan detect new vulnerabilities for QLYS users?

According to Qualys, InstaScan can detect most new vulnerabilities within minutes of advisory publication. The company states that across its initial supported technologies, InstaScan covers about 90% of detections within minutes by continuously monitoring advisories and correlating them with organizations’ existing inventory, exposure data and threat telemetry.

What problem does Qualys InstaScan aim to solve in 2026 for QLYS stakeholders?

InstaScan targets the widening gap between rapid vulnerability exploitation and slower detection cycles. Qualys cites attacker timelines compressing from months to hours and notes defenders’ median nine-day detection-to-closure, aiming for continuous, intelligence-driven detection instead of periodic scan windows to reduce exposure time and risk.

How does Qualys InstaScan differ from traditional vulnerability scanning tools?

InstaScan uses scanless scanning, triggering detection from new advisories and asset changes rather than fixed scan schedules. According to Qualys, this AI-driven approach keeps exposure data continuously current and delivers confidence-scored detections that downstream workflows can immediately act on, accelerating the path from disclosure to remediation.

Is Qualys InstaScan available now for Enterprise TruRisk Management (QLYS)?

Yes, InstaScan is currently available within Qualys Enterprise TruRisk Management. According to Qualys, customers can experience InstaScan at Black Hat USA booth 2333, through a dedicated BrightTALK webinar, blog posts, videos and other resources linked from the company’s ETM information pages and social channels.