Sign in

Wiz io

@wiz.io
133 followers 9 following 133 posts

Secure everything you build and run in the cloud

PostsRepliesMedia
Wiz io @wiz.io · 24/09/2026
Announcing Scan for Good! Powered by Wiz Red Agent & @googledeepmind.zpravobot.news.ap.brid.gy's Gemini 3.8 Flash Cyber, we help healthcare, nonprofits & public services find and fix security gaps before attackers do. Submit an application or learn more here >> www.wiz.io/blog/scan-fo...
wiz.io
Scan for Good: Finding Critical Exposures with AI | Wiz Blog
Wiz launches Scan for Good, using AI to help critical infrastructure, public services, and nonprofits find and remediate critical internet exposure.
010
Wiz io @wiz.io · 23/09/2026
Wiz Research presents ZERODAY.CLOUD 2026! 🕵️‍♀️ Our open-source cloud hacking competition is back at @blackhatevents.bsky.social Europe with @awscloud.bsky.social , @msftresearch.bsky.social & @googlecloudsec.bsky.social . Hunt vulns for a $6.5M prize pool! 💰🏆 www.zeroday.cloud/2026-competi...
zeroday.cloud
2026 Competition | ZeroDay.cloud
Join ZeroDay.cloud 2026, the cloud hacking competition at Black Hat Europe. Find zero-days in core open-source software, demonstrate live in London, and compete for prizes from a $6.5M pool.
000
Wiz io @wiz.io · 10/09/2026
We built a Cyber Arena to find out how good AI really is at hacking. 🧪 We tested AI like an attacker would (For science) with over 300 real-world offensive AI challenges! 🤖 This gives defenders real data & a clearer view of what AI can do today. www.wiz.io/cyber-model-...
wiz.io
Cyber Model Arena | Wiz
Evaluating AI agents across real-world security challenges
011
Wiz io @wiz.io · 25/08/2026
🐶 WE ACTUALLY DID IT. We built a Magical Dog Bus. 🚌 Meet the real security pack behind the magic at Wiz. Every morning, they hop on the bus, roll into work, and protect everything you run, build & fetch. 🐾 Happy Dog Day from Wiz and our very best threat sniffers. 💙
010
Wiz io @wiz.io · 17/08/2026
🚨 BREAKING: Our AI Red Agent autonomously accessed Snowflake's Jira via a flaw written by GitHub's AI bot. Red Agent learned, exploited & extracted creds with 0 human help. Kudos to Snowflake for swiftly addressing the issue 👏 Technical breakdown → wiz.io/blog/red-agent-snowflake-copilot-cicd-bug
022
Wiz io @wiz.io · 12/08/2026
🔍 What do threat researchers really talk about when they're not hunting zero-days? We put merav and Dan on the hot seat for Wiz Autocomplete Confessions --> and let's just say… they had a LOT to say. 👀 🎥 Watch the full video ↓ youtube.com/watch?v=VaPDXL7jt1k&feature=youtu.be&themeRefresh=1
youtube.com
Wiz Autocomplete Confessions | Threat Researchers Answer the Web's Most Asked Cyber and AI Questions
YouTube video by Wiz
020
Wiz io @wiz.io · 30/07/2026
🚨 CosmosEscape: We found a single key that unlocked every database in Azure CosmosDB One key >> Platform-wide impact. Microsoft fully remediated the issue. ✅ Read the full research and see how Wiz uncovered CosmosEscape: www.wiz.io/blog/cosmose...
030
Wiz io @wiz.io · 29/07/2026
🚨 Wiz Red Agent is GA! AI-powered continuous pentesting that finds what traditional scanners miss: logic flaws, hidden APIs, auth bypasses & exploitable risks. 10K+ critical risks found in preview 🔥 wiz.io/blog/wiz-red...
020
Wiz io @wiz.io · 27/07/2026
🧠 Meet Atlas: our AI vulnerability researcher. It found 200+ previously unknown vulnerabilities, ranked #1 on CyberGym (90.9%), and is helping power Wiz Code with continuous AI-powered security. 🏆 www.wiz.io/blog/atlas-a...
010
Wiz io @wiz.io · 21/07/2026
🎊 300 WIN INTEGRATIONS. WHAT. A. MILESTONE. 🎊 Times Square is glowing Wiz today! 🗽 To the 300+ partners who built, tested, and scaled alongside us in the past 3 years: This milestone is yours. www.wiz.io/blog/wiz-int...
wiz.io
Wiz Integration Network Hits 300 Partner Integrations | Wiz Blog
The Wiz Integration Network hits 300 partner integrations, connecting developer tools, CI/CD, and threat intel so security moves at AI speed.
010
Wiz io @wiz.io · 26/05/2026
🚨 SDLC Security '26 report is here! Wiz Research analyzed real dev envs, repos & prod telemetry on SDLC risk shifting upstream. 50% GH Actions reuse risk clusters 86% macOS AI amplifies risk Full report ↓ www.wiz.io/reports/sdlc...
000
Wiz io @wiz.io · 04/05/2026
The secret's out.🤫 Introducing THE ZERODAY.CLOUD COMMUNITY 👾 Inside: • 0-day vulnerability deep dives from Xint, Moritz Sanft, Paul Gerste & more... • Access to events & a network of world-class hackers • CTFs with prizes Join now :)
000
Wiz io @wiz.io · 28/04/2026
🚨 BREAKING: Wiz Research discovered Remote Code Execution on GitHub.com with a single git push. The flaw in @github.com allowed unauthorized access to millions of repositories belonging to other users and organizations 🤯
140
Wiz io @wiz.io · 06/04/2026
🚨 500+ malicious PRs. One campaign. Wiz Research traced 6 waves of prt-scan starting 3 weeks earlier. AI-powered, automated attacks exploiting pull_request_target. Low success rate—but real npm + cloud creds hit. Full story: www.wiz.io/blog/six-acc...
wiz.io
prt-scan: AI-Powered GitHub Actions Supply Chain Attack | Wiz Blog
Wiz Research traces six waves of pull_request_target exploitation to one actor, starting three weeks before public disclosure. 500+ malicious PRs, 10% success.
031
Wiz io @wiz.io · 30/03/2026
NEW CTF: AWS turned 20 🎉 So we built our monthly CTF challenge to celebrate: packed with challenges inspired by the last two decades of cloud ☁️ Oh, and… we made sure AI can't solve it 😅 So no prompts this time. Ready to play? www.cloudsecuritychampionship.com
000
Wiz io @wiz.io · 11/03/2026
🎉 IT'S OFFICIAL: wiz joins Google to secure the AI era. This is a massive moment for our customers and our team. Thank you to every customer, partner, and Wizard who made this moment possible 💙 We can't wait to share what's next. wiz.io/blog/google-...
030
Wiz io @wiz.io · 25/02/2026
🚨New CTF Alert: Got trust issues? Ever wondered what it's like to investigate a real data leak? Now's your chance. 🕵️ Your mission: 1) Investigate the compromised machine 2) Figure out how the attacker exfiltrated the data 3) Find the flag 🔗 Start here: cloudsecuritychampionship.com
cloudsecuritychampionship.com
The Ultimate Cloud Security Championship | 12 Months × 12 Challenges
Join our monthly cloud security CTF challenge, built by top Wiz researchers. Solve real-world scenarios and rise to the top of the leaderboard.
000
Wiz io @wiz.io · 12/02/2026
How good is AI at hacking? We built a benchmark to find out. 🧪 Introducing the Offensive AI Benchmark, the framework that tests AI agents on 250+ real-world offensive security challenges. Check it out → www.wiz.io/cyber-model-...
000
Wiz io @wiz.io · 15/01/2026
🚨 CodeBreach: Wiz Research identified a critical repository-hijacking vulnerability that abused a CodeBuild Regex flaw to compromise core AWS GitHub repos, including a core lib running at the heart of the cloud's most critical interface - the #AWS Console.
100
Wiz io @wiz.io · 29/12/2025
🧠 Just in time for a new year, a NEW CTF drop! Think you know Terraform inside out? State of Affairs (challenge 7) might change your mind... This challenge uncovers an overlooked #Terraform risk and proves IaC tools are part of your supply chain. www.cloudsecuritychampionship.com/challenge/7
000
Wiz io @wiz.io · 28/12/2025
🚨 CRITICAL: MongoBleed (CVE-2025-14847). MongoDB bug leaks in-memory data pre-auth and is exploited in the wild. 42% of clouds vulnerable, ~87K exposed. Atlas patched. Self-hosted: patch now or disable zlib. www.wiz.io/blog/mongobl...
wiz.io
MongoBleed (CVE-2025-14847) exploited in the wild | Wiz Blog
Detect and mitigate CVE-2025-14847, an unauthenticated information leak vulnerability in MongoDB. Exploitation has been observed in the wild.
010
Wiz io @wiz.io · 11/12/2025
Day 2 at zeroday.cloud, let’s roll. 👾 👀 Didn’t register? No panic. Walk-ins are welcome for the onsite CTF and all the action happening on the floor. Flags are hidden. Only the sharp survive.
010
Wiz io @wiz.io · 11/12/2025
Day 1 of zeroday.cloud = PURE EXPLOIT ENERGY 👾 From crowd shots 👀 to researchers buried deep in terminals 💻 From first checks being claimed To live container escapes blowing minds in real time. See you tomorrow!
000
Wiz io @wiz.io · 11/12/2025
Day 1 at zeroday.cloud didn’t come to play 😈 New vulns dropped in Grafana, Linux Kernel, 3 Redis, and 2 PostgreSQL - and every. single. one. worked 🤯 100% success rate for day one. Let’s see what we find tomorrow 👀
000
Wiz io @wiz.io · 09/12/2025
Zeroday.cloud 2025 kicks off TOMORROW! 💻 London, brace yourself - IDEs open. Exploits cooking. 13 zero-days are on the line 💣 Don't miss it. Here's the schedule ahead ⬎
000
Wiz io @wiz.io · 09/12/2025
🎧 Your age after React2Shell... 𝟴𝟴. Cloud Security Wrapped 2025 is HERE ↓ Check out our exclusive insights from our Wiz Research team! Spotify, are we doing it right? 🎵
000
Wiz io @wiz.io · 08/12/2025
🚨 React2Shell (CVE‑2025‑55182) in‑the‑wild exploitation & deep‑dive analysis. Critical RCE across React 19, Next.js & all RSC frameworks. Patch now. www.wiz.io/blog/nextjs-...
010
Wiz io @wiz.io · 02/12/2025
🎉 This is not a dream 💤 OUR WizZZZ BOOTH IS NOW OPEN. Behold the ULTIMATE cloud security booth! Games, demos, swag, naps… and the coziest cloud security playground in history 🛏️ Come see why CISOs are finally sleeping through the night 😴
000
Wiz io @wiz.io · 27/11/2025
It’s time to bust some malware! 🦠 Challenge #6 “Malware Busters” is LIVE. Built by Gili Tikochinski for the reverse‑engineering pros - dive into assembly and uncover what’s hidden inside. Think you can crack it? cloudsecuritychampionship.com/challenge/6
cloudsecuritychampionship.com
The Ultimate Cloud Security Championship | 12 Months × 12 Challenges
Join our monthly cloud security CTF challenge, built by top Wiz researchers. Solve real-world scenarios and rise to the top of the leaderboard.
021
Wiz io @wiz.io · 24/11/2025
🚨 New Shai-Hulud-style npm attack hitting 25k+ repos and growing fast. Devs & CI/CD exposed via malicious preinstall. Wiz Research has detection + mitigation. Details: www.wiz.io/blog/shai-hu...
wiz.io
Shai-Hulud 2.0: Ongoing Supply Chain Attack | Wiz Blog
Detect and mitigate malicious npm packages linked to the recent Shai-Hulud-style campaign. Over 25,000 affected repositories across ~350 unique users.
052
Wiz io @wiz.io · 10/11/2025
🤖 65% of Forbes AI 50 companies leaked secrets on GitHub. Shay from our research team revealed how AI speed without security = leaks waiting to happen. Full Wiz Research report 👉 www.wiz.io/blog/forbes-...
wiz.io
65% of Startups from Forbes AI 50 Leaked Secrets on GitHub | Wiz Blog
A Wiz investigation into the Forbes AI 50 reveals 65% of leading AI startups had leaked secrets. See real examples, leak types, and how to prevent this.
000
Wiz io @wiz.io · 06/11/2025
New CTF challenge ($20,000 IN PRIZES) 💥 We're running "Operation Cloudfall" - a live CTF during BlackHat & zeroday.cloud on December 10-11. Get your free pass to the event today: zeroday.cloud/operation-cloudfall See you in London 🇬🇧
000
Wiz io @wiz.io · 05/11/2025
🕹️ Meet Path-Man: Your new favorite game. 👾👾👾 Our 1-minute Wiz ASM game has arrived! 🤔 Here's the challenge: Navigate the attack surface to reach exploitable risk before the attackers get you. Think you've got the skills? wiz.io/path-man
wiz.io
Path-Man | Wiz
Find exploitable exposures before hackers do
010
Wiz io @wiz.io · 27/10/2025
🎃 Something spooky's brewing in the cloud... Introducing a new CTF challenge - "Game of Pods" 🕸️ 💀 Written by top Azure researcher & worth 30 points, it's our BIGGEST challenge yet! Get your skills ready for zeroday.cloud: cloudsecuritychampionship.com
000
Wiz io @wiz.io · 23/10/2025
Need a partner to finish that exploit chain for ZERODAY.CLOUD? We just launched our Research Collaboration Center at zeroday.cloud/collab to connect researchers, combine skills, and meet the deadline. 🤝 The clock is ticking... ⏱️
000
Wiz io @wiz.io · 16/10/2025
Our biggest reminder yet. ZERODAY.CLOUD. A first-of-its-kind, open-source cloud hacking competition. Find vulnerabilities in the critical open-source software that powers the cloud, and compete for your share of a $4.5M prize pool. ➡️ www.zeroday.cloud
010
Wiz io @wiz.io · 16/10/2025
🎁 We're giving away 2,000 SHIFT LEFT keyboards ↓ Want one on your desk? Fill out the form >> redeem.reachdesk.com/lp/wiz/shift... That's it! The keyboard is on its way 📦 Why are we doing this? 👀 A secret game is coming… and the whole world is invited.
000
Wiz io @wiz.io · 15/10/2025
🚨 Wiz Research uncovered 100+ leaked VSCode publisher tokens that could let attackers push malicious updates to 185K+ installs. We partnered with Microsoft to secure tokens and protect the ecosystem.
wiz.io
Supply Chain Risk in VSCode Extension Marketplaces | Wiz Blog
Wiz Research uncovered 500+ leaked secrets in VSCode and Open VSX extensions, exposing 150K installs to risk. Learn what happened and how it was fixed.
021
Wiz io @wiz.io · 09/10/2025
🤖 We're witnessing something unprecedented with AI agents: Malware that literally prompts ChatGPT, Claude, and other LLMs to write its own attack code. Live. On victim machines.
wiz.io
Emerging Threat: AI-Powered Malware Attacks | Wiz Blog
From LameHug to s1ngularity, attackers are invoking AI directly in malware payloads.
100
Wiz io @wiz.io · 30/09/2025
Introducing ZERODAY.CLOUD🕵️‍♀️ Be the first to participate in the first-of-its-kind cloud hacking competition. 🤝 WIN HUGE PRIZES from our up to 4.5 million dollar prize pool. 💰🏆 Join us to help make the cloud a safer place. Register your exploit now >> zeroday.cloud
011
Wiz io @wiz.io · 30/09/2025
@fortune.com JUST DROPPED A FEATURE ON Wiz 🔥 If you've been following the Wiz story, this one's for you. HUGE shoutout to everyone who made this story worth telling. You helped build something Fortune couldn't ignore 💙 fortune.com/article/wiz-...
020
Wiz io @wiz.io · 16/09/2025
🚨 #Shai-Hulud: Major npm supply chain attack. 100+ packages weaponized with stolen GitHub tokens, stealing secrets, hijacking repos, and auto-propagating like a worm. Guidance + detections inside www.wiz.io/blog/shai-hu...
032
Wiz io @wiz.io · 09/09/2025
🚨 Major npm hijack: Attackers took over Qix's account (chalk, debug & more). Malicious versions briefly hit npm, injecting browser code to hijack crypto transactions. DuckDB ecosystem is also affected.
100
Wiz io @wiz.io · 09/09/2025
Meet WizOS 💥 Public Preview! Secure, minimal container images with near-zero CVEs. Less patching, more speed, swap images right in your CI/CD & IDEs. www.wiz.io/blog/wizos-t...
wiz.io
WizOS Is Here: Container Security from the Image Up | Wiz Blog
WizOS is now in public preview: minimal, secured container images built by Wiz with near-zero CVEs. Join now to access the Secured Image Catalog.
000
Wiz io @wiz.io · 08/09/2025
🚨 One leaked #AWS key fueled a global phishing campaign. Wiz traced the attack, stopped it with Defend alerts, and added protections so one key never opens every door. Full story 👉 www.wiz.io/blog/wiz-dis...
wiz.io
Wiz Uncovers SES Abuse Campaign Using Stolen AWS Access Keys | Wiz Blog
From leaked AWS access keys to large-scale spam: Wiz Research uncovered a live Amazon SES abuse campaign, turning insights into early-warning detections.
000
Wiz io @wiz.io · 02/09/2025
🚨 Your Cloud DFIR Desk Mat is here! A first-ever poster mapping MITRE ATT&CK to key AWS, Azure & GCP log sources and API events. 📥 Get your copy: threats.wiz.io/cloud-dfir-p...
000
Wiz io @wiz.io · 28/08/2025
🚨 New CTF: Azure APT 🏆 Step into the shoes of an attacker targeting Azure. Use a malicious OAuth app, bypass restrictions, and capture the flag. Can you solve all 12 CTF's and WIN our belt? Test your skills with this month's CTF by Lior Sonntag 👉 www.cloudsecuritychampionship.com/challenge/3
000
Wiz io @wiz.io · 27/08/2025
🚨 hashtag#s1ngularity: a supply chain attack hiding in the Nx npm package Malicious versions stole hashtag#GitHub tokens, SSH keys, wallets, and secrets, even hijacking AI CLI tools to help exfiltrate data.
wiz.io
s1ngularity: supply chain attack leaks secrets on GitHub: everything you need to know | Wiz Blog
Detect and mitigate a critical supply chain compromise affecting the Nx NPM Package. Organizations should act urgently.
100
Wiz io @wiz.io · 21/08/2025
🚨 New keys just dropped… and they're already leaking. #AWS introduced Bedrock API keys, both long-term and short-term. On the surface, they look like just another way to authenticate. But here's the twist ⬇️
110
Wiz io @wiz.io · 19/08/2025
🤖 AI agents are everywhere now. So we put together a practical security guide that actually maps out what's happening in the wild. 👇 No fluff. Just the stuff security teams need to know. Save this cheat sheet 💾
000