惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Jina AI
Jina AI
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
有赞技术团队
有赞技术团队
罗磊的独立博客
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
U
Unit 42
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
Recent Announcements
Recent Announcements
Y
Y Combinator Blog
Vercel News
Vercel News
Martin Fowler
Martin Fowler
V
V2EX
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
L
LangChain Blog
云风的 BLOG
云风的 BLOG
H
Hackread – Cybersecurity News, Data Breaches, AI and More
aimingoo的专栏
aimingoo的专栏
G
Google Developers Blog
The GitHub Blog
The GitHub Blog
N
Netflix TechBlog - Medium
Google DeepMind News
Google DeepMind News
雷峰网
雷峰网
阮一峰的网络日志
阮一峰的网络日志
F
Fortinet All Blogs

Wiz Blog | RSS feed

Meet Wiz for M365: Bringing SaaS into the Security Graph Bringing Security Visibility to Vercel with Wiz Axios NPM Distribution Compromised in Supply Chain Attack Tracking TeamPCP: Investigating Post-Compromise Attacks Seen in the Wild The Wiz Blue Agent, now Generally Available Beyond the Badge: What Achieving Microsoft’s Certified Software Designation Means for Your Cloud Security Introducing the Green Agent: AI-Powered Remediation for the Cloud Three’s a Crowd: TeamPCP trojanizes LiteLLM in Continuation of Campaign KICS GitHub Action Compromised: TeamPCP Strikes Again in Supply Chain Attack Introducing the Wiz Red Agent- AI-Powered Attacker Introducing Wiz AI Application Protection Platform (AI-APP) Introducing Wiz Agents & Workflows: Security at the Speed of AI AI Runtime Threat Detection: From Input to Real-World Impact Trivy Compromised: Everything You Need to Know about the Latest Supply Chain Attack It’s Official: Wiz Joins Google Understanding and Reducing AI Risk in Modern Applications Introducing Wiz Tenant Manager: Multi-Tenant Management for Federated Organizations The Agile FedRAMP Playbook, Part 4: Reactive Risk Management through Enriched Incident Response Wiz Achieves CPSTIC Certification in Spain Seeing AI Clearly: Building Visibility Across Modern AI Applications The Agile FedRAMP Playbook, Part 3: Preventative Risk Management by building Secure by Design Wiz Leads the 2026 Latio Application Security Report with awards in 4 categories Building an Agentic Cloud Security Ecosystem: A Reference Architecture with Wiz MCP and Infosys Cyber Next The Agile FedRAMP Playbook, Part 2: Proactive Risk Management with Continuous Monitoring Cloud-native Security for your Windows environment: Announcing the Wiz Runtime Sensor for Windows Would You Click ‘Accept’? Automatically detecting malicious Azure OAuth applications using LLMs Wiz Named a Leader in The Forrester Wave™: Cloud Native Application Protection Solutions, Q1 2026 From Detection to Remediation: It’s Time to Rethink AppSec Around Exploitability and Root Cause Fixes The Agile FedRAMP Playbook, Part 1: Why Risk is Your Best Starting Point Introducing AI Cyber Model Arena: A Real-World Benchmark for AI Agents in Cybersecurity
Introducing Wiz Service Catalog: Democratize Cloud Securi...
Or Tzabary, Omer Mesika · 2025-05-29 · via Wiz Blog | RSS feed

For years, cloud security has centered around infrastructure. Tools surface risk in terms of resources, clusters, subscriptions, and accounts. That lens is powerful — it gives security teams visibility into the full blast radius of an issue. But it misses important context into the applications and services that development teams actually build and own. 

Modern cloud applications are made up of distributed microservices, APIs, containers, and ephemeral components. When security findings are tied to infrastructure, it’s hard for developers to understand and manage the security posture of services they own, and hard for security to identify the right owners for fixes. That disconnect creates friction across teams: 

  • Developers are on the hook for remediation, but ownership is unclear 

  • The same security issue shows up on dozens of resources with no clear grouping, leading to duplicate work 

  • Teams are overwhelmed with noise –ephemeral resources, duplicate issues, false priorities—instead of seeing patterns and root causes 

What’s been missing is a shared view of risk that aligns security to the way applications are built and maintained. 

That’s where the Wiz Service Catalog comes in. 

Get a service-centric view of cloud risk 

The Wiz Service Catalog gives security teams, platform teams, and developers a shared view into cloud risk — organized by the services they own.  

It works by automatically grouping related cloud resources into services: logical units that reflect how teams build and run applications. Each service includes the resources it depends on, the environment it runs in, who owns it, and all the relevant security findings tied to it. 

This means developers get a complete picture of their service’s security posture and can proactively monitor and address risk.  

A service can include: 

  • Cloud resources (VMs, containers, storage) 

  • Environment tags (like staging or production) 

  • Ownership metadata 

  • Linked issues and vulnerabilities 

Developers can visualize a service in the security graph to see relationships between the resources, risks, and attack paths for the service they own. 

Define once, scale everywhere 

You can use Wiz’s built-in service discovery rules to automatically detect services based on best practices tagging convention and support for tools like Helm and ArgoCD. Or, define custom service discovery rules using tags, annotations, or patterns that match your internal taxonomy. 

Once set, Wiz scales those definitions, identifying services across your entire environment. Suggested services are automatically surfaced for review, making it easy to accept and add them to service catalog. Services can even span across projects while inheriting the right environment context.  

Democratize security ownership 

When ownership is clear, remediation gets faster. Service Catalog makes it easier for cloud security and platform teams to identify the service owner for an issue, so they know exactly who to assign for a fix.  

What’s more, developers can proactively take charge of the security posture of the services they own and maintain. With a unified view of all issues and vulnerabilities for their service, they can self-serve to understand and resolve issues — no back-and-forth needed with the security team. They can automate how they are notified about issues related to their service so that they can get tickets or messages in their own workflows. Everyone sees the same picture of the service, minimizing friction between teams. 

Minimize noise and focus on what matters  

Wiz helps teams spot patterns across resources by automatically grouping repeated issues into a single service issue. Instead of fixing the same misconfiguration 20 times, you fix it once — at the source. 

This approach: 

  • Shows how widespread an issue is 

  • Helps teams address root causes 

  • Keeps the service issue open until it’s fully resolved across the board 

Wiz takes a similarly developer-friendly approach to vulnerabilities, grouping them by component. Developers can see all the vulnerabilities associated with a component, the number of resources that use the component, and the update version required for a fix. This enables developers to prioritize updates for the most vulnerable and widely used components in their service. 

The result: less noise, smarter remediation, and no wasted effort. 

Lay the foundation for a new approach to cloud security 

Wiz Service Catalog lays the foundation for an application and service-centric approach to cloud security. This approach democratizes security by empowering developers to own the security posture of the services they are responsible for.  

In the coming months, we plan to enhance the service catalog with new features that will further enable this approach at scale. These include: 

  1. Related resources: Automatically discover new resources related to your services, so you can easily keep services up to date. 

  2. Service Ownership: Automatic service owner suggestions based on code and cloud ownership context and 3rd party integrations. 

  3. Code to cloud service visibility: Expand the graph view for each service to map relationships between services, infrastructure, and the underlying application code.  

Available today 

Wiz Service Catalog is now in public preview for all customers. No extra licensing or setup required — just log in and start defining services to see your environment in a new light.