惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

P
Proofpoint News Feed
云风的 BLOG
云风的 BLOG
Apple Machine Learning Research
Apple Machine Learning Research
Hugging Face - Blog
Hugging Face - Blog
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
Google DeepMind News
Google DeepMind News
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
雷峰网
雷峰网
B
Blog
月光博客
月光博客
博客园 - 【当耐特】
WordPress大学
WordPress大学
Microsoft Azure Blog
Microsoft Azure Blog
I
InfoQ
The GitHub Blog
The GitHub Blog
Engineering at Meta
Engineering at Meta
Jina AI
Jina AI
博客园 - Franky
MyScale Blog
MyScale Blog
H
Hackread – Cybersecurity News, Data Breaches, AI and More
Last Week in AI
Last Week in AI
B
Blog RSS Feed
H
Help Net Security

Wiz Blog | RSS feed

Meet Wiz for M365: Bringing SaaS into the Security Graph Bringing Security Visibility to Vercel with Wiz Axios NPM Distribution Compromised in Supply Chain Attack Tracking TeamPCP: Investigating Post-Compromise Attacks Seen in the Wild The Wiz Blue Agent, now Generally Available Beyond the Badge: What Achieving Microsoft’s Certified Software Designation Means for Your Cloud Security Introducing the Green Agent: AI-Powered Remediation for the Cloud Three’s a Crowd: TeamPCP trojanizes LiteLLM in Continuation of Campaign KICS GitHub Action Compromised: TeamPCP Strikes Again in Supply Chain Attack Introducing the Wiz Red Agent- AI-Powered Attacker Introducing Wiz AI Application Protection Platform (AI-APP) Introducing Wiz Agents & Workflows: Security at the Speed of AI AI Runtime Threat Detection: From Input to Real-World Impact Trivy Compromised: Everything You Need to Know about the Latest Supply Chain Attack It’s Official: Wiz Joins Google Understanding and Reducing AI Risk in Modern Applications Introducing Wiz Tenant Manager: Multi-Tenant Management for Federated Organizations The Agile FedRAMP Playbook, Part 4: Reactive Risk Management through Enriched Incident Response Wiz Achieves CPSTIC Certification in Spain Seeing AI Clearly: Building Visibility Across Modern AI Applications The Agile FedRAMP Playbook, Part 3: Preventative Risk Management by building Secure by Design Wiz Leads the 2026 Latio Application Security Report with awards in 4 categories Building an Agentic Cloud Security Ecosystem: A Reference Architecture with Wiz MCP and Infosys Cyber Next The Agile FedRAMP Playbook, Part 2: Proactive Risk Management with Continuous Monitoring Cloud-native Security for your Windows environment: Announcing the Wiz Runtime Sensor for Windows Would You Click ‘Accept’? Automatically detecting malicious Azure OAuth applications using LLMs Wiz Named a Leader in The Forrester Wave™: Cloud Native Application Protection Solutions, Q1 2026 From Detection to Remediation: It’s Time to Rethink AppSec Around Exploitability and Root Cause Fixes The Agile FedRAMP Playbook, Part 1: Why Risk is Your Best Starting Point Introducing AI Cyber Model Arena: A Real-World Benchmark for AI Agents in Cybersecurity
Introducing new Amazon Q Developer plugin for Wiz
Shaked Rotlevi, Annam Iyer, Nadav Tzuker · 2024-11-14 · via Wiz Blog | RSS feed

Traditional cloud security tools are typically catered to security teams, making it challenging to scale and democratize security to other teams in organizations. At Wiz, our goal is to help organizations democratize security so they can innovate faster in the cloud. The Wiz Security Graph already simplifies cloud security and makes it more accessible to other teams developing in the cloud, with over 50% of our active users being developers. We wanted to make it even simpler for AWS builders to quickly gain insights into their cloud security posture and risks. Many developers typically work in the AWS Management Console and are assigned security tickets in other tools. Developers may need to jump between the ticketing system, AWS, and the security tool to see the issues they need to remediate. Wiz together with AWS brings security to the forefront of the build process to make it simple for AWS users to gain security insights. 

As an AWS Security Competency Partner, we are excited to extend our partnership with AWS to Amazon Q to make it easier for customers to secure everything they build and run in the cloud. By leveraging generative AI with the new Amazon Q Developer plugin for Wiz, we can enable organizations to simplify security operations and bring it directly to their AWS console

Oron Noah, Vice President of Product Extensibility & Partnerships at Wiz

We are excited to make security even more accessible for AWS developers with a new Wiz plugin from Amazon Q Developer that brings the power of Wiz Cloud-Native Application Protection Platform (CNAPP) directly to their AWS console. Amazon Q Developer helps builders with all of their tasks— from coding, testing, and upgrading, to troubleshooting, optimizing AWS resources, and creating data engineering pipelines.  

This integration makes it easier for developers to ask questions about the security posture in AWS using human-language and gain immediate insights into any risks in their environment. 

Amazon Q Developer makes it easier for developers to uphold security best practices so that they can focus on innovating, and we are continuing this work with Wiz. By extending Amazon Q Developer’s abilities to access Wiz's CNAPP capabilities, developers can more seamlessly and deeply incorporate security into their daily workflows and build with confidence.

Deepak Singh, Vice President of Next Generation Developer Experience at AWS

For example, a user can ask Amazon Q: “What are my critical severity issues in Wiz?” and get a list of the most pressing risks they need to focus on. Wiz prioritizes risks that result in attack paths in the environment by combining multiple risk factors across misconfigurations, vulnerabilities, identities, data, secrets, and more on the Wiz Security Graph. These types of critical attack paths allow an attacker to reach crown jewels in the environment or escalate permissions to admin and need to be prioritized and remediated. For example, in the below screenshot, we can see the critical risks that Wiz flags down. 

When a developer asks Amazon Q for the most critical issues in their environment, they know they are focusing their time on the risks that matter and effectively increasing their security posture

Another example where you could explore the security posture of your environment without needing to leave AWS is to assess the posture of your AWS resources. By asking Amazon Q “What is the riskiest asset I have in my AWS environment?” you could get a list of all the resources that need your attention now. This allows you to prioritize your remediation efforts on a resource that will make the greatest impact on your security posture.  By giving you the tools to assess the security posture of your resources without needing to leave AWS, you can effectively focus your efforts and reduce operational overhead. 

With the new Amazon Q Developer plugin, organizations can: 

  • Improve security posture in AWS: gain immediate security insights directly in the AWS console to remove risks quickly 

  • Democratize security to developers: scale security across the organization by making it accessible for developers to quickly understand security posture 

  • Reduce operational overhead: leverage the same console already used for building on AWS to understand the security posture and reduce time it takes to switch platforms   

Get started now with the new plugin here. To learn more about this integration, you can visit the Wiz Docs (login required) or Amazon Q Developer docs