Cybersecurity Research

Vendor Launches Real-Time Vulnerability Scanning as Attackers Exploit Flaws Within Hours

Wiz Research · 1 Sept 2026
Key Takeaway Australian small businesses should avoid relying solely on periodic vulnerability scans and instead prioritise faster patching processes for critical systems as soon as new vulnerabilities are disclosed.

Security researchers at Wiz have released a new approach called Continuous Vulnerability Assessment (CVA), aimed at addressing a growing problem: the time between a vulnerability being publicly disclosed and it being actively exploited is shrinking fast. Traditional vulnerability scanning runs on a schedule, often leaving organisations blind to new risks for days at a time. CVA instead updates its vulnerability catalog the moment a new flaw is discovered and immediately checks an organisation's exposure to it, rather than waiting for the next scan cycle.

According to Wiz, attackers are now exploiting newly published vulnerabilities within hours of disclosure, a pace driven largely by AI tools that let threat actors identify vulnerable targets and build working exploits far faster than manual methods allow. This narrow window between disclosure and exploitation is exactly what attackers rely on, and it is also where most organisations are most exposed. The report positions this shift as part of a broader industry move towards Continuous Threat Exposure Management (CTEM), a framework that replaces periodic security checks with an ongoing cycle of discovery, prioritisation and remediation.

The article notes that this shift is increasingly being reflected in regulation, with the US CISA's BOD 26-04 directive and subsequent FedRAMP guidance pushing organisations away from scheduled scanning towards continuous, exposure-based vulnerability management.

vulnerability management AI threats patch management exposure management cybersecurity trends

Summarised by CISO AI from Wiz Research. We link back to every original so you can read it yourself.