Blogs
Artifactory Under Attack: In-the-Wild Exploitation of CVE-2026-42016, CVE-2026-42018 & CVE-2026-82329
A preview is not available. Open the original article to keep reading.
Wiz achieves GovRAMP High Authorization
A preview is not available. Open the original article to keep reading.
Off Guard: Breaking LiteLLM from authentication bypass to cloud compromise
A preview is not available. Open the original article to keep reading.
How Developers Prevent Production Risk at the Source
A preview is not available. Open the original article to keep reading.
Introducing Continuous Vulnerability Assessment: Real-Time Defense for the AI Threat Era
A preview is not available. Open the original article to keep reading.
JetBrains Cadence Compromised via Exploitation of TeamCity Vulnerability (Incident)
A preview is not available. Open the original article to keep reading.
Coder Module Registry Compromise Leads to Credential-Stealing Malware Distribution (Incident)
A preview is not available. Open the original article to keep reading.
@7nohe/openapi-react-query-codegen Compromised in Supply Chain Attack (Campaign)
A preview is not available. Open the original article to keep reading.
Inside 90 days of attacks on AI infrastructure
A preview is not available. Open the original article to keep reading.
From Concept to Context Engine: How Wiz Built AI-Powered Data Discovery
A preview is not available. Open the original article to keep reading.
Version Control DFIR: a Cheatsheet to GitHub, GitLab, Bitbucket, and Azure DevOps
A preview is not available. Open the original article to keep reading.
Democratizing FinOps with Wiz: Driving Cost Attribution with the Wiz Service Catalog
A preview is not available. Open the original article to keep reading.
The State of Cloud Risk 2026: Most Security Findings Aren’t Real Attacker Opportunities
A preview is not available. Open the original article to keep reading.
Rust Supply Chain Attack on arrayref: Significant Overlap with DPRK Campaigns
A preview is not available. Open the original article to keep reading.
arrayref and Other Rust Crates Hijacked in Supply Chain Attack (Campaign)
A preview is not available. Open the original article to keep reading.
Wiz Penetration Test Findings is now GA
A preview is not available. Open the original article to keep reading.
How to Spot and Stop Rogue Device Joins
A preview is not available. Open the original article to keep reading.
Announcing the 2026 Wiz Partner Alliance Award Winners
A preview is not available. Open the original article to keep reading.
Wiz Red Agent Finds Its Way Into Snowflake’s Internal Jira Due to an AI-Generated GitHub Copilot “Autofix”
A preview is not available. Open the original article to keep reading.
The Closed Loop Remediation Playbook with Wiz
A preview is not available. Open the original article to keep reading.
Wiz on Wiz: How the Wiz FinOps Team Uses Wiz Cloud Cost
A preview is not available. Open the original article to keep reading.
Securing Data in the AI era
A preview is not available. Open the original article to keep reading.
How to Investigate GitHub PAT Compromise: Lessons From a Multi-Organization Campaign
A preview is not available. Open the original article to keep reading.
Closing the Blind Spot: Securing Personal Repositories in the Software Supply Chain
A preview is not available. Open the original article to keep reading.
Inside the Metabase SQLi: Exploited in the Wild
A preview is not available. Open the original article to keep reading.
Payroll Pirates Phishing Campaign Targets Microsoft 365 Financial Workflows (Campaign)
A preview is not available. Open the original article to keep reading.
Cloud Threat Highlights: H1 2026
A preview is not available. Open the original article to keep reading.
Wiz Brings Automated DISA STIG Assessment to Amazon Linux 2023 and Windows Server 2025
A preview is not available. Open the original article to keep reading.
Wiz at Black Hat 2026: Driving AI Threat Readiness
A preview is not available. Open the original article to keep reading.
keyv and cacheable npm Package Hijacked in Supply Chain Attack
A preview is not available. Open the original article to keep reading.
keyv and cacheable npm Package Hijacked in Supply Chain Attack (Campaign)
A preview is not available. Open the original article to keep reading.
Introducing the Wiz Sensor for Developer Workstations to Protect Endpoints in the AI Era
A preview is not available. Open the original article to keep reading.
S3 Clones in the Neoclouds
A preview is not available. Open the original article to keep reading.
CaptiveCrunch: Midnight Blizzard Hospitality Network AiTM Campaign (Campaign)
A preview is not available. Open the original article to keep reading.
Rethinking scanning for the AI era: Wiz’s Agentic Code Security System
A preview is not available. Open the original article to keep reading.
CosmosEscape: Taking Over Every Database in Azure Cosmos DB
A preview is not available. Open the original article to keep reading.
Wiz’s First 6 Months as Part of Google
A preview is not available. Open the original article to keep reading.
The Wiz Red Agent is Now Generally Available
A preview is not available. Open the original article to keep reading.
The risk hiding behind exposed MCP servers
A preview is not available. Open the original article to keep reading.
Accelerating CISA BOD 26-04 Vulnerability and Triage Activities through Wiz
A preview is not available. Open the original article to keep reading.
Atlas: Wiz's autonomous AI Agent for vulnerability research, ranked #1 on CyberGym
A preview is not available. Open the original article to keep reading.
Opening the Black Box: Agentless Threat Detection for Virtual Appliances
A preview is not available. Open the original article to keep reading.
Cl0p Exploitation of PTC Windchill and FlexPLM Vulnerability (Campaign)
A preview is not available. Open the original article to keep reading.
Agentless Visibility: Uncovering Cloud Blind Spots
A preview is not available. Open the original article to keep reading.
300 WINtegrations Strong: An Open Security Ecosystem Built for the Speed of AI
A preview is not available. Open the original article to keep reading.
Exploitation in the Wild of wp2shell
A preview is not available. Open the original article to keep reading.
SleeperGem: RubyGems Supply Chain Attack Targets Dormant Maintainer Accounts (Campaign)
A preview is not available. Open the original article to keep reading.
NadMesh: Autonomous AI-Focused Botnet Targeting Cloud and AI Infrastructure (Campaign)
A preview is not available. Open the original article to keep reading.
CVE-2025-54068 Exploited in Large-Scale Laravel Livewire Credential Theft Campaign (Campaign)
A preview is not available. Open the original article to keep reading.
The Red Agent POV: The One Boolean That Broke a B2B Platform’s Credit System
A preview is not available. Open the original article to keep reading.
M-Red-Team: AsyncAPI Supply Chain Compromise via GitHub Actions
A preview is not available. Open the original article to keep reading.
AsyncAPI Supply Chain Compromise via GitHub Actions (Campaign)
A preview is not available. Open the original article to keep reading.
Why IaC Coverage Belongs on Your Security Dashboard
A preview is not available. Open the original article to keep reading.
Cryptomining campaign targeting Linux SSH servers (Campaign)
A preview is not available. Open the original article to keep reading.
Jscrambler npm Package Compromised in Supply Chain Attack (Campaign)
A preview is not available. Open the original article to keep reading.
How ProdSec uses Wiz
A preview is not available. Open the original article to keep reading.
Wiz in the Verizon DBIR: How AI Acceleration and Cloud Sprawl Impact Modern Defense
A preview is not available. Open the original article to keep reading.
Compromised Injective SDK npm Package Exfiltrates Cryptocurrency Wallet Keys (Campaign)
A preview is not available. Open the original article to keep reading.
GhostApproval: A Trust Boundary Gap in AI Coding Assistants
A preview is not available. Open the original article to keep reading.
Wiz ASM for any environment, any risk, everywhere
A preview is not available. Open the original article to keep reading.
Coordinated GitHub API Enumeration and Access Token Abuse (Campaign)
A preview is not available. Open the original article to keep reading.
FAQs from the Field: Is Wiz a Runtime Security Tool?
A preview is not available. Open the original article to keep reading.
Build AI Security Agents with Wiz MCP
A preview is not available. Open the original article to keep reading.
Breaking Down the White House’s Actions on Post-Quantum Cryptography Readiness
A preview is not available. Open the original article to keep reading.
Start Secure in the AI Era: Accelerating AI Threat Readiness with WizOS
A preview is not available. Open the original article to keep reading.
Bridging the Visibility Gap: A Unified Security Operating Model for Hybrid Cloud Teams
A preview is not available. Open the original article to keep reading.
The Borderless Attack Surface: Securing Public Sector Hybrid Environments
A preview is not available. Open the original article to keep reading.
The Red Agent POV: Exploiting Broken Object-Level Authorization in an Airline GraphQL API
A preview is not available. Open the original article to keep reading.
MCP Auto-Execution: From Git Clone to Cloud Compromise in Amazon Q VS Code Extension
A preview is not available. Open the original article to keep reading.
Uncovering Hidden Attack Paths in Cloud Environments Using Runtime Signals
A preview is not available. Open the original article to keep reading.
Cryptojacking Campaign Targeting K8s Clusters (Campaign)
A preview is not available. Open the original article to keep reading.
How AI Is Rewriting the SecOps Playbook
A preview is not available. Open the original article to keep reading.
AI Threat Readiness Pillar 4: Detect and contain threats in real-time
A preview is not available. Open the original article to keep reading.
Cloud-native Security for your Windows environment: Announcing the Wiz Runtime Sensor for Windows
A preview is not available. Open the original article to keep reading.
The President’s Executive Actions on AI Have a Lot to Say on Cybersecurity
A preview is not available. Open the original article to keep reading.
Klue Supply Chain Breach Leads to Salesforce Data Exfiltration (Incident)
A preview is not available. Open the original article to keep reading.
The Red Agent POV: How it Reasoned its Way to SSRF
A preview is not available. Open the original article to keep reading.
Introducing the Red Agent POV Series
A preview is not available. Open the original article to keep reading.
Mastra Packages Trojanized with Malicious Dependency (Campaign)
A preview is not available. Open the original article to keep reading.
Wiz Exposure Management Dashboard: Your CTEM Command Center
A preview is not available. Open the original article to keep reading.
FortiBleed: Credential Compromise Campaign Targeting Fortinet Devices (Campaign)
A preview is not available. Open the original article to keep reading.
Atomic Arch: AUR Package Supply Chain Compromise Using Malicious npm Package (Campaign)
A preview is not available. Open the original article to keep reading.
AI Threat Readiness Pillar 3: Perform AI Code Analysis Natively in Wiz
A preview is not available. Open the original article to keep reading.
AI Threat Readiness Pillar 2: Accelerate Patching and Response
A preview is not available. Open the original article to keep reading.
ServiceNow Unauthenticated Access Incident (Incident)
A preview is not available. Open the original article to keep reading.
Introducing Wiz Cloud Cost: Powering Cost Management and Optimization with Context
A preview is not available. Open the original article to keep reading.
TeamPCP adds Malware to Multiple Microsoft-Linked GitHub Projects (Campaign)
A preview is not available. Open the original article to keep reading.
AI Threat Readiness Pillar 1: Reduce Critical Exposures & Scan with AI
A preview is not available. Open the original article to keep reading.
Binding.gyp Supply Chain Attack Enables CI/CD Worm Propagation Across npm Packages (Campaign)
A preview is not available. Open the original article to keep reading.
From Posture to Runtime: A Unified Approach to OpenShift Security
A preview is not available. Open the original article to keep reading.
Eliminate Critical API Attack Paths with Wiz API SPM
A preview is not available. Open the original article to keep reading.
Miasma: Supply Chain Attack Targeting RedHat npm Packages
A preview is not available. Open the original article to keep reading.
Miasma: Supply Chain Compromise in RedHat npm Packages (Campaign)
A preview is not available. Open the original article to keep reading.
State of Post Quantum Cryptography
A preview is not available. Open the original article to keep reading.
Evidence at the Moment of Attack. Answers at AI Speed.
A preview is not available. Open the original article to keep reading.
Commit to Compromise: A New Threat Actor Targeting the Cryptocurrency Industry's Software Development Infrastructure
A preview is not available. Open the original article to keep reading.
Defending at Machine-Speed: Building AI Threat Readiness with Wiz
A preview is not available. Open the original article to keep reading.
JINX-0164 Targeting Cryptocurrency Development Infrastructure (Campaign)
A preview is not available. Open the original article to keep reading.
State of SDLC Security 2026: How Risk Scales in Modern Development
A preview is not available. Open the original article to keep reading.