惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Vercel News
Vercel News
博客园 - 司徒正美
C
Check Point Blog
G
Google Developers Blog
The GitHub Blog
The GitHub Blog
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
有赞技术团队
有赞技术团队
P
Proofpoint News Feed
IT之家
IT之家
B
Blog
博客园_首页
量子位
MongoDB | Blog
MongoDB | Blog
博客园 - Franky
J
Java Code Geeks
H
Help Net Security
A
About on SuperTechFans
Apple Machine Learning Research
Apple Machine Learning Research
Jina AI
Jina AI
D
DataBreaches.Net
Y
Y Combinator Blog
大猫的无限游戏
大猫的无限游戏
云风的 BLOG
云风的 BLOG
Google DeepMind News
Google DeepMind News

Wiz Blog | RSS feed

Meet Wiz for M365: Bringing SaaS into the Security Graph Bringing Security Visibility to Vercel with Wiz Axios NPM Distribution Compromised in Supply Chain Attack Tracking TeamPCP: Investigating Post-Compromise Attacks Seen in the Wild The Wiz Blue Agent, now Generally Available Beyond the Badge: What Achieving Microsoft’s Certified Software Designation Means for Your Cloud Security Introducing the Green Agent: AI-Powered Remediation for the Cloud Three’s a Crowd: TeamPCP trojanizes LiteLLM in Continuation of Campaign KICS GitHub Action Compromised: TeamPCP Strikes Again in Supply Chain Attack Introducing the Wiz Red Agent- AI-Powered Attacker Introducing Wiz AI Application Protection Platform (AI-APP) Introducing Wiz Agents & Workflows: Security at the Speed of AI AI Runtime Threat Detection: From Input to Real-World Impact Trivy Compromised: Everything You Need to Know about the Latest Supply Chain Attack It’s Official: Wiz Joins Google Understanding and Reducing AI Risk in Modern Applications Introducing Wiz Tenant Manager: Multi-Tenant Management for Federated Organizations The Agile FedRAMP Playbook, Part 4: Reactive Risk Management through Enriched Incident Response Wiz Achieves CPSTIC Certification in Spain Seeing AI Clearly: Building Visibility Across Modern AI Applications The Agile FedRAMP Playbook, Part 3: Preventative Risk Management by building Secure by Design Wiz Leads the 2026 Latio Application Security Report with awards in 4 categories Building an Agentic Cloud Security Ecosystem: A Reference Architecture with Wiz MCP and Infosys Cyber Next The Agile FedRAMP Playbook, Part 2: Proactive Risk Management with Continuous Monitoring Cloud-native Security for your Windows environment: Announcing the Wiz Runtime Sensor for Windows Would You Click ‘Accept’? Automatically detecting malicious Azure OAuth applications using LLMs Wiz Named a Leader in The Forrester Wave™: Cloud Native Application Protection Solutions, Q1 2026 From Detection to Remediation: It’s Time to Rethink AppSec Around Exploitability and Root Cause Fixes The Agile FedRAMP Playbook, Part 1: Why Risk is Your Best Starting Point Introducing AI Cyber Model Arena: A Real-World Benchmark for AI Agents in Cybersecurity
Secure non-human identities with Wiz’s newest CIEM dashboard
Shaked Rotlevi, Yariv Ashkenazy · 2024-02-02 · via Wiz Blog | RSS feed

Many organizations think of their IAM users when implementing their cloud identity and entitlement strategy. However, to effectively use the cloud you need to trust non-human identities, such as machines and other services, to perform necessary tasks and access specific data in your environment. Such identities include service accounts used by applications, services, and third-party vendors.

For example, Wiz uses a service account in your cloud environment to provide CNAPP security capabilities. Other non-human identities include serverless functions that need an identity associated to perform the task assigned, or data stores and machines. As organizations go through digital transformation, they often adopt more tools and automation practices to grow their cloud environment. This results in the exponential growth of non-human identities, and it becomes challenging to manage and secure them at scale. Security teams often lack visibility into where those identities even exist, let alone monitor them in a multi-cloud and evolving environment. 

In recent years, there has been a consistent rise in supply chain attacks that exploit access granted to third-party apps and services. These attacks act as a concealed gateway to compromise a company's valuable assets. Inadequate security measures for non-human identities pose significant risks: a breach in one of these identities can serve as a gateway into your cloud environment, potentially leading to dangerous exposure. The Wiz Research team found that 42% of organizations have a non-human identity that belongs to a machine in their environment that has high privileges, is exposed to the internet, and has a vulnerability. This means it can enable an attacker to move laterally in the environment. 

Introducing the new Non-Human Identities Dashboard

Organizations wanting to secure their cloud identities against such risks adopt a CIEM (Cloud Infrastructure Entitlement Management) tool into their cloud security strategy to help them follow IAM security best practices and proactively remove identity risks. With the rise in non-human identities, it is important for a comprehensive CIEM solution to provide full support not only for user identities, but also for non-human ones. Today, we are excited to launch Wiz’s new Non-Human Identities Dashboard, providing customers visibility into their non-human identities with a holistic view into identity-related risks.

The dashboard makes it easy for security teams to quickly identify the non-human identities in their environment. They can also quickly detect risky service accounts, such as service accounts with admin or high privileges. Furthermore, to ensure that you're meeting your local regulatory requirements, Wiz detects service account activity in your environment and creates a visualization map representing all activity by country. The dashboard provides exact prioritization of non-human identity risks to allow security teams to quickly focus on the most critical. This also helps teams running in multi-cloud environments to bridge the skill gap needed to understand IAM across the different clouds and allow any security engineer or developer to understand multi-cloud IAM risks without becoming an expert in each cloud. 

Wiz combines visibility into non-human identities with the power of our attack path analysis to provide customers with the ability to detect risky service accounts, particularly those that can access sensitive data in your environment. The dashboard also helps you identify accounts that can lead to lateral movement paths and escalate to other roles in your environment. For example, Wiz can detect a service account that can be assumed by all users and has access to sensitive data, allowing an attacker to abuse the role and reach your sensitive data. 

Start protecting your non-human identities with Wiz now to gain consistent visibility into your environment and stay ahead of identity risks. Learn more Wiz’s CIEM in the docs (login required). If you prefer a live demo, we would love to connect with you.