CISO Middle East Issue 03 | Page 12

AI moves from assistant to operator as cyberattacks accelerate
Qualys launches InstaScan to detect vulnerabilities

CISO news

AI moves from assistant to operator as cyberattacks accelerate

heck Point Software Technologies has published its Annual AI Security Report 2026, documenting a significant shift over

C the past 12 months: artificial intelligence has moved from assisting attackers to operating attacks. is used, secure the AI systems they now depend on, and defend at machine speed rather than human speed.”

Where AI once helped criminals prepare, it now runs live intrusions with minimal human direction, compressing the time defenders have to respond and opening new attack surfaces across the enterprise. The report also highlights how enterprise AI adoption is outpacing governance controls.
Grounded in real incidents, telemetry and original case studies from the past year, the report examines how AI is participating directly at every stage of the attack chain and what this means for defenders.
Lotem Finkelstein, Vice President, Check Point Research, said:“ A year ago we described AI as a force multiplier for attackers. What we documented this year is more significant: AI has crossed into the live attack chain and is now running operations as a sole operation, that once required a skilled team. The expertise barrier that separated capable attackers from the rest is disappearing, and defenders can no longer assume a human is setting the pace on the other side. The organizations that stay ahead will be the ones that govern how AI
Lotem Finkelstein, Vice President, Check Point Research

Qualys launches InstaScan to detect vulnerabilities

Q ualys has announced InstaScan, powered by Agent Insta, a new capability within Qualys Enterprise TruRisk Management( ETM) designed to close the gap between vulnerability disclosure and detection by transforming existing asset telemetry into continuous exposure visibility.

The announcement comes as the volume and speed of vulnerability exploitation continue to increase. In the first seven months of 2026, 46,048 CVEs were published, nearly matching the total for all of 2025. Verizon’ s 2026 DBIR identified vulnerability exploitation as the leading breach entry point, accounting for 31 % of breaches, and found that AI is compressing attacker timelines from months to hours.
InstaScan introduces scanless scanning, an autonomous vulnerability management capability within Qualys ETM. Powered by Agent Insta, a cyber risk agent that uses AI to continuously monitor newly published vendor security advisories and threat intelligence from Qualys and trusted third-party sources, the capability correlates emerging vulnerabilities with an organisation’ s live inventory, telemetry and threat intelligence.
Sumedh Thakar, president and CEO of Qualys
“ The speed of vulnerability exploitation has fundamentally changed,” said Sumedh Thakar, president and CEO of Qualys.“ A slow vulnerability management program is now the biggest vulnerability an organisation has. We’ re entering a new era of vulnerability, one where detection is continuous – driven by live intelligence instead of scan cycles. Built on the Qualys platform, InstaScan helps organisations identify and reduce risk the moment new vulnerabilities are disclosed.”
12 WWW. INTELLIGENTCISO. COM / MIDDLE-EAST