Sign in

Wiz io

@wiz.io
133 followers 9 following 133 posts

Secure everything you build and run in the cloud

PostsRepliesMedia
Wiz io @wiz.io · 25/08/2026
🐶 WE ACTUALLY DID IT. We built a Magical Dog Bus. 🚌 Meet the real security pack behind the magic at Wiz. Every morning, they hop on the bus, roll into work, and protect everything you run, build & fetch. 🐾 Happy Dog Day from Wiz and our very best threat sniffers. 💙
010
Wiz io @wiz.io · 17/08/2026
🚨 BREAKING: Our AI Red Agent autonomously accessed Snowflake's Jira via a flaw written by GitHub's AI bot. Red Agent learned, exploited & extracted creds with 0 human help. Kudos to Snowflake for swiftly addressing the issue 👏 Technical breakdown → wiz.io/blog/red-agent-snowflake-copilot-cicd-bug
022
Wiz io @wiz.io · 30/07/2026
🚨 CosmosEscape: We found a single key that unlocked every database in Azure CosmosDB One key >> Platform-wide impact. Microsoft fully remediated the issue. ✅ Read the full research and see how Wiz uncovered CosmosEscape: www.wiz.io/blog/cosmose...
030
Wiz io @wiz.io · 29/07/2026
🚨 Wiz Red Agent is GA! AI-powered continuous pentesting that finds what traditional scanners miss: logic flaws, hidden APIs, auth bypasses & exploitable risks. 10K+ critical risks found in preview 🔥 wiz.io/blog/wiz-red...
020
Wiz io @wiz.io · 27/07/2026
🧠 Meet Atlas: our AI vulnerability researcher. It found 200+ previously unknown vulnerabilities, ranked #1 on CyberGym (90.9%), and is helping power Wiz Code with continuous AI-powered security. 🏆 www.wiz.io/blog/atlas-a...
010
Wiz io @wiz.io · 26/05/2026
🚨 SDLC Security '26 report is here! Wiz Research analyzed real dev envs, repos & prod telemetry on SDLC risk shifting upstream. 50% GH Actions reuse risk clusters 86% macOS AI amplifies risk Full report ↓ www.wiz.io/reports/sdlc...
000
Wiz io @wiz.io · 04/05/2026
The secret's out.🤫 Introducing THE ZERODAY.CLOUD COMMUNITY 👾 Inside: • 0-day vulnerability deep dives from Xint, Moritz Sanft, Paul Gerste & more... • Access to events & a network of world-class hackers • CTFs with prizes Join now :)
000
Wiz io @wiz.io · 28/04/2026
We responsibly disclosed the issue to GitHub, who deployed a fix on GitHub.com the same day (!) and released patches for all supported GHES versions. GitHub Enterprise Server customers are strongly encouraged to update immediately.
100
Wiz io @wiz.io · 28/04/2026
🚨 BREAKING: Wiz Research discovered Remote Code Execution on GitHub.com with a single git push. The flaw in @github.com allowed unauthorized access to millions of repositories belonging to other users and organizations 🤯
140
Wiz io @wiz.io · 30/03/2026
NEW CTF: AWS turned 20 🎉 So we built our monthly CTF challenge to celebrate: packed with challenges inspired by the last two decades of cloud ☁️ Oh, and… we made sure AI can't solve it 😅 So no prompts this time. Ready to play? www.cloudsecuritychampionship.com
000
Wiz io @wiz.io · 11/03/2026
🎉 IT'S OFFICIAL: wiz joins Google to secure the AI era. This is a massive moment for our customers and our team. Thank you to every customer, partner, and Wizard who made this moment possible 💙 We can't wait to share what's next. wiz.io/blog/google-...
030
Wiz io @wiz.io · 12/02/2026
How good is AI at hacking? We built a benchmark to find out. 🧪 Introducing the Offensive AI Benchmark, the framework that tests AI agents on 250+ real-world offensive security challenges. Check it out → www.wiz.io/cyber-model-...
000
Wiz io @wiz.io · 15/01/2026
🚨 CodeBreach: Wiz Research identified a critical repository-hijacking vulnerability that abused a CodeBuild Regex flaw to compromise core AWS GitHub repos, including a core lib running at the heart of the cloud's most critical interface - the #AWS Console.
100
Wiz io @wiz.io · 29/12/2025
🧠 Just in time for a new year, a NEW CTF drop! Think you know Terraform inside out? State of Affairs (challenge 7) might change your mind... This challenge uncovers an overlooked #Terraform risk and proves IaC tools are part of your supply chain. www.cloudsecuritychampionship.com/challenge/7
000
Wiz io @wiz.io · 11/12/2025
Day 2 at zeroday.cloud, let’s roll. 👾 👀 Didn’t register? No panic. Walk-ins are welcome for the onsite CTF and all the action happening on the floor. Flags are hidden. Only the sharp survive.
010
Wiz io @wiz.io · 11/12/2025
Day 1 of zeroday.cloud = PURE EXPLOIT ENERGY 👾 From crowd shots 👀 to researchers buried deep in terminals 💻 From first checks being claimed To live container escapes blowing minds in real time. See you tomorrow!
000
Wiz io @wiz.io · 11/12/2025
Day 1 at zeroday.cloud didn’t come to play 😈 New vulns dropped in Grafana, Linux Kernel, 3 Redis, and 2 PostgreSQL - and every. single. one. worked 🤯 100% success rate for day one. Let’s see what we find tomorrow 👀
000
Wiz io @wiz.io · 09/12/2025
Zeroday.cloud 2025 kicks off TOMORROW! 💻 London, brace yourself - IDEs open. Exploits cooking. 13 zero-days are on the line 💣 Don't miss it. Here's the schedule ahead ⬎
000
Wiz io @wiz.io · 09/12/2025
🎧 Your age after React2Shell... 𝟴𝟴. Cloud Security Wrapped 2025 is HERE ↓ Check out our exclusive insights from our Wiz Research team! Spotify, are we doing it right? 🎵
000
Wiz io @wiz.io · 08/12/2025
🚨 React2Shell (CVE‑2025‑55182) in‑the‑wild exploitation & deep‑dive analysis. Critical RCE across React 19, Next.js & all RSC frameworks. Patch now. www.wiz.io/blog/nextjs-...
010
Wiz io @wiz.io · 02/12/2025
🎉 This is not a dream 💤 OUR WizZZZ BOOTH IS NOW OPEN. Behold the ULTIMATE cloud security booth! Games, demos, swag, naps… and the coziest cloud security playground in history 🛏️ Come see why CISOs are finally sleeping through the night 😴
000
Wiz io @wiz.io · 06/11/2025
New CTF challenge ($20,000 IN PRIZES) 💥 We're running "Operation Cloudfall" - a live CTF during BlackHat & zeroday.cloud on December 10-11. Get your free pass to the event today: zeroday.cloud/operation-cloudfall See you in London 🇬🇧
000
Wiz io @wiz.io · 27/10/2025
🎃 Something spooky's brewing in the cloud... Introducing a new CTF challenge - "Game of Pods" 🕸️ 💀 Written by top Azure researcher & worth 30 points, it's our BIGGEST challenge yet! Get your skills ready for zeroday.cloud: cloudsecuritychampionship.com
000
Wiz io @wiz.io · 23/10/2025
Need a partner to finish that exploit chain for ZERODAY.CLOUD? We just launched our Research Collaboration Center at zeroday.cloud/collab to connect researchers, combine skills, and meet the deadline. 🤝 The clock is ticking... ⏱️
000
Wiz io @wiz.io · 16/10/2025
Our biggest reminder yet. ZERODAY.CLOUD. A first-of-its-kind, open-source cloud hacking competition. Find vulnerabilities in the critical open-source software that powers the cloud, and compete for your share of a $4.5M prize pool. ➡️ www.zeroday.cloud
010
Wiz io @wiz.io · 16/10/2025
🎁 We're giving away 2,000 SHIFT LEFT keyboards ↓ Want one on your desk? Fill out the form >> redeem.reachdesk.com/lp/wiz/shift... That's it! The keyboard is on its way 📦 Why are we doing this? 👀 A secret game is coming… and the whole world is invited.
000
Wiz io @wiz.io · 30/09/2025
Introducing ZERODAY.CLOUD🕵️‍♀️ Be the first to participate in the first-of-its-kind cloud hacking competition. 🤝 WIN HUGE PRIZES from our up to 4.5 million dollar prize pool. 💰🏆 Join us to help make the cloud a safer place. Register your exploit now >> zeroday.cloud
011
Wiz io @wiz.io · 30/09/2025
@fortune.com JUST DROPPED A FEATURE ON Wiz 🔥 If you've been following the Wiz story, this one's for you. HUGE shoutout to everyone who made this story worth telling. You helped build something Fortune couldn't ignore 💙 fortune.com/article/wiz-...
020
Wiz io @wiz.io · 16/09/2025
🚨 #Shai-Hulud: Major npm supply chain attack. 100+ packages weaponized with stolen GitHub tokens, stealing secrets, hijacking repos, and auto-propagating like a worm. Guidance + detections inside www.wiz.io/blog/shai-hu...
032
Wiz io @wiz.io · 09/09/2025
🚨 Major npm hijack: Attackers took over Qix's account (chalk, debug & more). Malicious versions briefly hit npm, injecting browser code to hijack crypto transactions. DuckDB ecosystem is also affected.
100
Wiz io @wiz.io · 02/09/2025
🚨 Your Cloud DFIR Desk Mat is here! A first-ever poster mapping MITRE ATT&CK to key AWS, Azure & GCP log sources and API events. 📥 Get your copy: threats.wiz.io/cloud-dfir-p...
000
Wiz io @wiz.io · 28/08/2025
🚨 New CTF: Azure APT 🏆 Step into the shoes of an attacker targeting Azure. Use a malicious OAuth app, bypass restrictions, and capture the flag. Can you solve all 12 CTF's and WIN our belt? Test your skills with this month's CTF by Lior Sonntag 👉 www.cloudsecuritychampionship.com/challenge/3
000
Wiz io @wiz.io · 21/08/2025
🚨 New keys just dropped… and they're already leaking. #AWS introduced Bedrock API keys, both long-term and short-term. On the surface, they look like just another way to authenticate. But here's the twist ⬇️
110
Wiz io @wiz.io · 19/08/2025
🤖 AI agents are everywhere now. So we put together a practical security guide that actually maps out what's happening in the wild. 👇 No fluff. Just the stuff security teams need to know. Save this cheat sheet 💾
000
Wiz io @wiz.io · 19/08/2025
🤖 AI agents are everywhere now. So we put together a practical security guide that actually maps out what's happening in the wild. 👇 No fluff. Just the stuff security teams need to know. Save this cheat sheet 💾
000
Wiz io @wiz.io · 14/08/2025
Introducing Wizmojis.com >> Our cloud security emojis for your Slack & WhatsApp that finally get YOU. 💬 Some favorites: * blame-the-intern * cve-part * phishing-season ⬇️ Comment below — What emoji do you need on Slack? The best ideas might just make it into the next pack of Wizmojis.
000
Wiz io @wiz.io · 04/08/2025
🚨 Wiz Research found a vulnerability chain in NVIDIA's open-source Triton Inference Server What started as a small error message turned into something big: A path to full remote code execution, no creds, no user interaction.
120
Wiz io @wiz.io · 31/07/2025
🏆 Can you escape a container & become THE ULTIMATE CLOUD SECURITY CHAMPION? This month's scenario was crafted by Sagi Tzadik to explore container escape techniques, the same kinds of risks we'll be diving into at #BlackHat next week! Challenge #2 👉 cloudsecuritychampionship.com/challenge/2
020
Wiz io @wiz.io · 29/07/2025
Wiz Research just found a critical vulnerability in the popular vibe coding platform Base44, recently acquired by Wix, that could have allowed anyone to access private applications.
100
Wiz io @wiz.io · 29/07/2025
🚨 We found a critical vulnerability in the popular Vibe Coding Platform Base44: No password. No invite. Full access.
100
Wiz io @wiz.io · 28/07/2025
🚨 TraderTraitor: North Korea's cyber "traitor" inside the crypto world. This hacking crew hijacks dev workflows, poisons open-source, and compromises cloud environments — all to steal billions in crypto. Here's how they do it 🧵 www.wiz.io/blog/north-k...
100
Wiz io @wiz.io · 23/07/2025
🚨 New research: A cryptomining campaign is hijacking exposed PostgreSQL, hiding payloads in fake 404 pages, and abusing legit infra. Multiplatform, stealthy, and still active 👉 www.wiz.io/blog/soco404...
000
Wiz io @wiz.io · 17/07/2025
🧱 With just three lines of code, attackers can escape containers and gain full root access to the host. That's your models, data, and GPU workloads — exposed. NVIDIA rated it 9.0. We think it's a sign: AI infra needs stronger walls. 🛠️ Full technical breakdown 👉 www.wiz.io/blog/nvidia-...
000
Wiz io @wiz.io · 17/07/2025
🚨 NEW RESEARCH: #NVIDIAscape AI vulnerability uncovered! Wiz Research discovered a critical vulnerability (CVE-2025-23266) in the NVIDIA Container Toolkit, the glue connecting containers to GPUs across major cloud providers.
110
Wiz io @wiz.io · 08/07/2025
WOOHOO! We are #1 in over 130 reports on #G2 this summer!☀️🍉 Huge G2 moment, and it's all thanks to you 💙 THANK YOU to our amazing Wizards and customers for your continued trust, feedback, and partnership. 🪄 www.wiz.io/lp/g2-grid-r...
000
Wiz io @wiz.io · 18/06/2025
🚨 We scanned GitHub and found *hundreds* of valid secrets, 4 of the top 5 were AI-related: HuggingFace, Azure OpenAI, Weights & Biases, and Groq. Read more: www.wiz.io/blog/leaking...
031
Wiz io @wiz.io · 15/05/2025
Over 14,500 have joined #ExfilCola's cloud IR CTF to track a fizzing breach 🥤 1,400+ solved challenge 1, 350+ beat it all, players from 48+ countries. Still time to join: cloudhuntinggames.com
000
Wiz io @wiz.io · 12/05/2025
📊 NEW REPORT: Wiz analyzed 150,000+ cloud accounts to uncover eye-opening insights on misconfigurations & vulnerabilities. Stay ahead with #DSPM to protect sensitive cloud data. Learn more: www.wiz.io/blog/cloud-d...
010
Wiz io @wiz.io · 06/05/2025
🔍IT'S HERE: #ExfilCola, our cloud IR security CTF challenge!🥤 Your mission: - Investigate the cloud environment logs - Research the compromised machines - Secure the files and save the day ⏰ The Cloud Hunting Games are live >> www.cloudhuntinggames.com
011
Wiz io @wiz.io · 05/05/2025
🚨 OH NOOOO! Someone stole the secret recipe of ExfilCola. We need your help tomorrow to get it back. Set your clocks for 9 a.m. ET ⏰ You'll need curiosity, cloud IR skills, and a taste for solving mysteries. 🧠 Do you think you can crack it?
001