Vendor Launches Real-Time Vulnerability Scanning as Attackers Exploit Flaws Within Hours
Security researchers at Wiz have released a new approach called Continuous Vulnerability Assessment (CVA), aimed at addressing a growing problem: the time between a vulnerability being publicly disclosed and it being actively exploited is shrinking fast. Traditional vulnerability scanning runs on a schedule, often leaving organisations blind to new risks for days at a time. CVA instead updates its vulnerability catalog the moment a new flaw is discovered and immediately checks an organisation's exposure to it, rather than waiting for the next scan cycle.
According to Wiz, attackers are now exploiting newly published vulnerabilities within hours of disclosure, a pace driven largely by AI tools that let threat actors identify vulnerable targets and build working exploits far faster than manual methods allow. This narrow window between disclosure and exploitation is exactly what attackers rely on, and it is also where most organisations are most exposed. The report positions this shift as part of a broader industry move towards Continuous Threat Exposure Management (CTEM), a framework that replaces periodic security checks with an ongoing cycle of discovery, prioritisation and remediation.
The article notes that this shift is increasingly being reflected in regulation, with the US CISA's BOD 26-04 directive and subsequent FedRAMP guidance pushing organisations away from scheduled scanning towards continuous, exposure-based vulnerability management.