{"slug": "introducing-continuous-vulnerability-assessment-real-time-defense-for-the-ai-era", "title": "Introducing Continuous Vulnerability Assessment: Real-Time Defense for the AI Threat Era", "summary": "Wiz has launched Continuous Vulnerability Assessment (CVA), a new scanning model that updates its vulnerability catalog in real time and reassesses exposure immediately upon a new vulnerability's publication, eliminating the need for scheduled scans. The move responds to the accelerating exploitation of vulnerabilities by AI-assisted attackers and aligns with regulatory shifts, including CISA BOD 26-04 and new FedRAMP guidance mandating continuous exposure-based approaches. CVA integrates with Wiz's Green Agent for automated remediation, aiming to reduce mean time to detect and mean time to remediate.", "body_md": "We are excited to introduce Wiz's Continuous Vulnerability Assessment (CVA) - a fundamentally new operating model for vulnerability scanning that helps teams keep up in the AI Threat Era. Today, the window between \"vulnerability published\" and \"actively exploited\" is shrinking fast - and teams that rely on scheduled scanning are left exposed.\n\nWiz CVA solves this by providing real-time visibility into your exposure to vulnerabilities as soon as they are published. Wiz now updates our vulnerability catalog the moment a new vulnerability is discovered, and immediately reassesses your exposure to it- without having to wait for the next scheduled scan.\n\nCVA ensures findings are available in near-real-time, enabling teams to detect exposure, prioritize with context, and remediate on the same day a vulnerability is published, not days later.\n\nThe Challenge: Exploitation Is Moving Faster Than Ever\n\nAttackers are exploiting newly published vulnerabilities faster than ever before - in many cases within hours of public disclosure. AI has accelerated this significantly, enabling threat actors to identify affected targets and develop working exploits at a speed that was not possible by humans alone. The most critical window attackers look to exploit is precisely this gap - between the moment a vulnerability is published and the moment an organization finds the exposure and removes it. For security teams, this means they need to act fast: teams need to know where they are exposed as close to the moment of disclosure as possible, with a clear path to remediation from day one.\n\nCVA and CTEM: Continuous Exposure Management in Practice\n\nContinuous Threat Exposure Management (CTEM) is the security industry's answer to this challenge - a framework that moves organizations from periodic, point-in-time assessments to a continuous cycle of discovery, prioritization, and remediation. At its core, CTEM requires that your exposure picture is always current, not days or weeks stale - and increasingly, it is also the foundation for AI threat readiness: if your detection and response capabilities can't operate at the speed AI-assisted attacks move, you're already behind. This shift is now being mandated at the regulatory level: following CISA BOD 26-04, FedRAMP released new guidance requiring organizations to move away from scheduled scanning toward a continuous, exposure-and-threat-based approach to vulnerability detection and remediation.\n\nWiz has been building toward a complete CTEM solution across the platform - from cloud and code risk discovery, extending to on-prem with UVM, ASM validation enhanced with the Red Agent, and Green Agent accelerating response. CVA completes the picture for vulnerability management: it is the mechanism that ensures the \"Discovery\" phase of CTEM operates continuously, not on a schedule.\n\nFor teams adopting or maturing a CTEM program, CVA is the operational foundation that makes continuous exposure management real.\n\nFrom Real-Time Detection to Remediation\n\nSurfacing a vulnerability quickly is the first step, but responding fast and knowing how to act is the key. Once CVA surfaces a finding, Wiz's Green Agent (the Resolution Agent) extends remediation to machine-speed. It provides the remediation guidance, ownership context, and root cause context needed to move from finding to fix efficiently, without having to track down asset owners or piece together generic patch documentation.\n\nThe Impact of CVA\n\nTogether, CVA and the Wiz platform deliver measurable improvements across the metrics that matter most:\n\nReduced MTTD - Mean Time to Detect aligned with vulnerability publication, in near-real-time\n\nReduced MTTR - Right owners get the context and guided remediation they need to act immediately, with Wiz Workflows automating response at scale\n\nStronger AI threat readiness and CTEM posture - Continuous detection closes the exposure window that fast-moving, AI-assisted attacks rely on\n\nGet Started with Wiz CVA\n\nContinuous Vulnerability Assessment is available now in Public Preview. Learn more in the Wiz Docs (Login Required) or book a live demo with our team.\n\nWiz honeypots uncover active campaigns targeting LiteLLM, MCP servers, and AI frameworks through RCE, blind prompt injection, and memory credential theft.", "url": "https://wpnews.pro/news/introducing-continuous-vulnerability-assessment-real-time-defense-for-the-ai-era", "canonical_source": "https://www.wiz.io/blog/introducing-cva", "published_at": "2026-09-01 10:54:43+00:00", "updated_at": "2026-09-01 11:24:10.677630+00:00", "lang": "en", "topics": ["ai-safety", "ai-policy", "ai-products"], "entities": ["Wiz", "CISA", "FedRAMP", "Green Agent", "Red Agent", "UVM", "ASM"], "alternates": {"html": "https://wpnews.pro/news/introducing-continuous-vulnerability-assessment-real-time-defense-for-the-ai-era", "markdown": "https://wpnews.pro/news/introducing-continuous-vulnerability-assessment-real-time-defense-for-the-ai-era.md", "text": "https://wpnews.pro/news/introducing-continuous-vulnerability-assessment-real-time-defense-for-the-ai-era.txt", "jsonld": "https://wpnews.pro/news/introducing-continuous-vulnerability-assessment-real-time-defense-for-the-ai-era.jsonld"}}