Qualys Brings Scanless Vulnerability Detection to AI-Speed Defense
AI-Speed Attacks Demand Faster Detection
Alan Shimel speaks with Kunal Modasiya, senior vice president of products at Qualys, during Techstrong TV’s Black Hat 2026 coverage. The conversation focuses on scanless vulnerability detection and the need to respond as attackers use AI to move faster. Modasiya explains that the window between vulnerability disclosure and exploitation has collapsed from weeks or months to days, hours or even less.
That change puts pressure on traditional vulnerability management programs. Security teams can no longer wait for signatures, scheduled scans and long remediation cycles. Qualys is responding with InstaScan, a new capability powered by Agent Insta. It is designed to use existing asset inventory, software telemetry and vendor advisories to identify exposure without waiting for a new scan.
InstaScan Turns Existing Telemetry Into Findings
Modasiya describes scanless vulnerability detection as a way to close the detection gap. Agent Insta listens for new advisories from vendors such as Microsoft, Red Hat and Dell. It then compares those advisories against the software and asset data Qualys already has for the customer environment. The goal is to show which systems are exposed almost immediately.
The interview compares that approach to knowing what software and versions are already installed before a new vulnerability is announced. Instead of sending scanners back through the environment, Qualys can use the known inventory to identify likely exposure. That matters in an AI frontier model era, where attackers can weaponize disclosures faster than manual processes can react.
Agent Sara Extends Detection Into Remediation
The discussion also covers remediation. Modasiya says Agent Sara works with Agent Insta to help organizations move from detection to action. That includes patching, mitigation, isolation and validation. In this model, scanless vulnerability detection is not only about finding issues faster. It is also about reducing the time required to prioritize and fix them.
Shimel notes that AI-scale vulnerability discovery requires AI-scale response. Modasiya agrees, pointing to a three-part vision: AI-speed detection, hyper-prioritization and zero-day remediation. The goal is to help defenders operate at machine speed rather than relying on ticket queues and 60- or 90-day patch windows.
TotalAI 2.0 Addresses Agentic AI Risk
Qualys is also expanding its focus on securing agentic AI. Modasiya discusses TotalAI 2.0, which is designed to help organizations discover, secure, monitor and govern AI agents, LLMs, MCPs, AI tools and AI code repositories. The platform is aimed at visibility, posture management, runtime monitoring and governance.
For Techstrong TV viewers, the takeaway is clear. Enterprises are moving quickly toward agentic AI, and attackers are moving just as fast. Qualys is positioning InstaScan, Agent Insta, Agent Sara and TotalAI 2.0 as a way to help security teams detect, prioritize, remediate and govern risk at AI speed.
Transcript
Hey everyone, welcome back to Techstrong TV. We are live in our secret location at Black Hat. We were here early today.
They wouldn't let us on the show floor, and so my friend, Kumal Odacia. Mordacia. Mordacia.
We grabbed him off the floor, brought him here into our location, and he's nice enough to meet with me. If you've watched any of the coverage we've done with Qualys over the years, Kumal's a staple. He always comes out.
He always has a lot to say. He's the SVP of products at Qualys, so if you want to know what's going on at Qualys, he's the guy to talk to. Kumal, how are you, man?
It's good to see you. Good to see you, Alan, again, and as always, I appreciate the partnership that we have. Oh, yeah.
Absolutely. And thank you for inviting me and giving me the opportunity to talk to your audience. You know what?
You're one of the nicest people to interview, and you carry the water to tell you the truth, so it's an easy interview for me. Thank you. So a big announcement today from Qualys here at Black Hat.
I don't want to steal your thunder. Tell the people about the announcement. No, thank you so much.
First of all, and it's exciting, Black Hat with the 110 Fahrenheit outside, so if you just step outside, you will get- It's hot ... roasted, right? Yes.
It's very, very hot. But in the hot market, in the hot city, we made it further hot by announcing two interesting capabilities, brand new. So one is the Insta Scan.
So first I'll talk about that, and the second one is the agentic AI security, which is equally hot topic, right? So we are making Vegas further hot from 110 Fahrenheit to 150 Fahrenheit. So let's talk about the first one, Insta Scan.
So Alan, if you look at in the industry over the last three, six months, the frontier AI model, like Mythos and others. So as they have started doing this scanning and finding the issues and all of that new disclosure which are coming at the machine speed now. Now, as the disclosures are coming at a machine speed, but you see the approach that security team has, which is a very traditional, outdated approach, which was not built for the AI frontier model era, where they would actually wait for a vendor like a Qualys to write the signature detection, CVE, et cetera, and then we push it out, then they take a week to scan it and find the detection.
Now, with the AI frontier model era, the disclosures are happening, and then at the same speed, attackers are taking the advantage of those disclosure and writing the exploit. And even before the vendor like a Qualys and others could write the detection, attackers are actually launching the attack. And that's the crux of it, right?
The window from discovery to exploit has moved from weeks and months to days and hours. Days, hours. Practically in hours, right?
We have seen that. That's a sea change. And as you saw recently, the HuggingFace example, oh my God, right?
I mean- Well, not just HuggingFace, and then whether you believe it was PR or not, a week later, anything they could do, the other one does better, right? So free. It could be that angle as well.
Right. Yeah. But the fact is that the attackers have that undue or unfair advantage now.
Always. Right? So now the traditional approach of waiting for a signature and all of that is not going to scale.
So what Qualys, we saw this opportunity, and we have launched this new capability called Insta Scan, which is part of our enterprise true risk management, which is part of our ROC, risk operations center- Sure ... platform. Now, what it does is a multiple thing.
First, and then as a part of that capability, we have Agent Insta, which is our agentic AI agent- Sure ... which is autonomously listening to the different vendors, say Dell, Red Hat, Microsoft, all of those vendors, software vendors' advisory. Mm-hmm.
So as soon as the new disclosure happens, the Agent Insta picks up those advisory. Now, as a part of our ETM product, we already have a snapshot of all of the assets inventory, all of the software, all of the version of the software that we already have it. So now when the disclosure happens from the vendor, our Agent Insta picks up them, straight away goes into your environment, and tells you which critical attacks- Without scanning ...
without scanning. You nailed it. And that's why we are calling it as a scanless scanning.
You now- So Kumal, let me explain something here. Oh, yeah. Please.
If you don't mind. Oh, no, of course. Of course.
So I wasn't always on this side of the camera. I was a security person. I ran a security company.
20 years ago, we had what we called NAC, network access control. Yes, I know. You remember.
And this is exactly what we used to do. We would have a copy of your registry, so I knew what programs you were running, what versions of the programs you were running, and once we put a particular program or version on the gold list, it was okay. 1X.
I know that. I have done the network access control in the past, right? Sure.
I know this. So this, to me, sounds a lot like that. Very, very similar in the concept, where moment the advisory comes, our agentic AI agent, Insta, finds them in your environment.
It shows you that, hey, here are the disclosures that are in your environment. Mm-hmm. These are the ones that are on the machine which are business critical, which are part of your production environment.
And as a part of that, we have Agent Sara, which is also the new announcement that we are doing, which is a remediation agent. Aha. It is also showing you the remediation option that, hey- How are you doing?
do you want to patch it? Do you want to mitigate? Do you want to isolate?
So now you think about it from disclosure to detection to remediation. And that's the missing piece. That's always been the missing piece.
That's always been the missing piece. So her name is... It's not her.
Excuse me. But the agent's name is Sara. The agent name is Sara for the remediation, and the Agent Insta is the one which is finding those zero day disclosure into your environment in an instant scan.
We are calling it as Agent Insta, and we call it as scanless scanning. You do not have to scan your environment to find where those disclosures are. You already know they're there.
They are already there. Here they are, and this is how you fix them, with Agent Sara. I love it.
So super excited to launch. Look, here's my take. And again, I've been doing this a long time, too.
The problem that Mythos and these things, the similar frontier models brought, is they're bringing AI scale to vulnerability finding. You can't respond to that if you're not doing it at AI scale. Not at all.
Humans are never going to do it at this scale. Indeed. At the speed and the breadth of it.
100% agree, and as a part of this AI frontier model era, we have a three vision that we have rolled out to the market, what you need at, to your point, AI speed detection, hyper prioritization in terms of what you want to prioritize, and then zero-day remediation. Gone are those days when you are creating the ticket and waiting for a 60 days, 90 days patch window. Yeah.
No. It's not going to scale. No.
Not at all. Right? The whole game has changed.
Whole game has changed, and we are super proud to announce yesterday, as of actually, we announced it today morning, the Agent Insta, the scanless scanning. Right. With the Agent Sara, both of them together, very, very exciting announcement.
We have our customers loving the capability. I could see why, without a doubt. Let me ask you a question.
Any concern about these agents themselves breaking containment? Let me be clear. Agents are not malicious by nature.
They're just doing their job. But any concern about them sort of breaking containment or the guardrails? Very good question, and that leads to my second announcement also that we made it, so thank you for- It's almost like I knew it was coming It was coming, right?
But, so I will answer in a twofold. First of all, our agents, which is the Agent Insta- And Sara ... Agent Sara, all of these agents are taken care and built with the security policy, with the guardrail in terms of what tools, what databases, what memory they are accessing it, and the customer have an option to assign those tools and task and everything.
So customer knows it's not like a full thing where they have a zero visibility, no. It's a fully transparent to them that they can configure the access, they can allow what kind of a tools that the Agent Insta or all of that. We will come up with our default, they could override.
So that's one, to secure our own agent. Okay? Now, coming to the industry-wide problem, that every vendor today is launching the agents.
Any industry you pick it, they are launching the agents to do the autonomous workflows. Yeah. Whether it is security workflow, IT workflow- Yeah, forget everything ...
manufacturing workflow. Yeah. Whatever it is, everybody's doing the autonomous agent.
And believe it or not, but over the next three year, every enterprise is going to be agentic enterprise. I guarantee you along three years later- I agree with you ... you, me, and Mitchell, we will be here at the same place.
I think agents will outnumber people at an average by 100 to 1. If not more. 100% agree.
We see in the same way. So what we did is that we had a product last year that we launched called Total AI. I remember.
So you remember, right? And you and I had chat about that. 0 version of the product called Total AI.
Okay. Now, that is doing a five different thing that is built for the agentic AI era. First of all, in order for a organization to discover or secure or protect the agents, they need to first know what are the agents running in their environment.
Absolutely. Where are the AI tools running in environment? What are the LLM, what are the MCPs they are accessing it?
What kind of a developers that they are using the dev tools, that AI tools, AI pipeline, AI code repository. So first step is to find out the agents, LLM, MCPs, AI code repo, AI tools like a ChatGPT, Claude, all of that we are using it. First thing is finding all of them.
Second is about securing them with a configuration setting. And to your question, that, hey, we got to define the guardrail, we have to define the policies around it. So what we do is the AISPM, which is a security posture management for their agent, and we make sure that the agents are configured properly.
That's the second step. Third, while those agents are running in the production environment, we are monitoring the traffic and all the activities that agents are doing it in terms of what are they talking to, who are they talking to, what kind of files, memories, database, tools that they are accessing it. We are doing this by looking into the eBPF kernel-based traffic and the uProb.
That's a new technology that has come out, especially for the agents, AI agents- Okay ... to track their activities. So we are leveraging those technology to monitor the traffic in the runtime production environment, the kind of activities that they are doing it.
Now, that gives me the-- and then we do the red teaming on those agents and LLM to test against various jailbreak prompt, OWASP attack, bias testing. Sure. All of that we do it.
So with that We are basically not only discovering them, but before those agents hit the production, we do the misconfiguration assessment with AISPM and make sure that those agents are configured correctly, all of the LLM MCPs are configured properly. Then in the runtime, we are constantly monitoring all of the activities. And as we see some behavioral issues or other thing that they are not supposed to do, we flag them.
Right? And the last part that the CISOs and the security team is asking us is the governance and compliance. Right?
EU Act, the NIST RMF, ISO 42001, all of this act now require CISOs to report the AI usage. Yes. Govern the AI usage, right?
So our, we have taken a very holistic approach when it comes to securing the agentic AI because we firmly believe every enterprise is going to be agentic enterprise. And just monitoring on a runtime is not sufficient. Just doing the misconfiguration assessment- Not sufficient ...
is not sufficient. You need that holistic approach, Alan. But I want to be clear.
Yes. There's a lot of companies, ServiceNow, SalesForce, who are making a play. They want to manage your agents.
They want to have the garage that your agents are parked in. That's not what you're talking about here. No.
You're talking truly, and when I say governance, I don't mean just compliance with statute. I mean governance in terms of governing the behavior of the agents, putting the guardrails in. Much like if platform engineers now, they build a platform with guardrails so that developers, DevOps, can go as fast as they need to go along the platform with guardrails.
You're doing the same thing now for agents. Very similar. Yes, sir.
You nailed it. This is exactly what we are doing it, that we are applying the guardrail as per the organization's policy and procedures. Yeah.
So all of that helps secure the governance. It's the governance part of it. It's the governance part of the- Right.
It's not about, you're not looking to be the super-duper manager of agents. You're looking to provide this governance layer which has been missing. Right?
Because in our rush to adopt agents- 100% ... you know how it always, security's always- Always behind, but this time we are helping them prepare- You're right there ... right there.
And look- I love it ... overall, those two announcement as a quick summary for our audience, right? So look, we are in AI frontier model era.
Attackers are gaining the access to the same technology that developers or a defender has it. So now as they are launching the attacks at the machine speed, we are helping organizations with the AI speed detection, which is our Insta Scan scanless scanning- Yeah ... powered by our Agent Insta, which is helping them.
Then you need a zero-day remediation. So right. For that, we have Agent Sarah that is helping them patching, mitigation, isolation, et cetera.
And finally, now everywhere there is AI, customers are upgrading their infrastructure to the AI infrastructure as they are deploying the agents, AI agents. 0 version- Who's it? works well for the organization.
I got one more quick thing. Please. I know you're not a financial analyst, and God knows I'm not.
And you know, but I did want to mention, you guys also reported earnings, a solid quarter. And as we were talking offline, I'm glad to see Qualys getting the recognition it deserves. It was a long due, and- Congratulations ...
we are innovating at a faster speed, all the patch management and the zero-day remediation. We came five years back when nobody was doing it. And now look, AI frontier model era is giving us a tailwind.
Good. So, and it is reflecting in our stock price. I can't speak much about stock, but hey, very happy to see- Always ...
earnings and the investor's trust on us. That's what, I mean the market's the market. The prices will fluctuate, but earnings mean something, right?
That means people are willing to write a check- Yes ... and buying your product, and that's what's important. Good correction, Alan.
Congratulations. Thank you so much- Always a pleasure ... for your time.
Pleasure meeting you. Hey, we're here at Black Hat. We've got more coming.
You've just watched Qualys here on Techstrong TV.