惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

大猫的无限游戏
大猫的无限游戏
阮一峰的网络日志
阮一峰的网络日志
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
WordPress大学
WordPress大学
博客园 - 叶小钗
Hugging Face - Blog
Hugging Face - Blog
博客园 - 司徒正美
Last Week in AI
Last Week in AI
罗磊的独立博客
量子位
Jina AI
Jina AI
T
Tailwind CSS Blog
Apple Machine Learning Research
Apple Machine Learning Research
IT之家
IT之家
美团技术团队
雷峰网
雷峰网
爱范儿
爱范儿
S
SegmentFault 最新的问题
小众软件
小众软件
月光博客
月光博客
酷 壳 – CoolShell
酷 壳 – CoolShell
人人都是产品经理
人人都是产品经理
The Cloudflare Blog
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报

Wiz Blog | RSS feed

Meet Wiz for M365: Bringing SaaS into the Security Graph Bringing Security Visibility to Vercel with Wiz Axios NPM Distribution Compromised in Supply Chain Attack Tracking TeamPCP: Investigating Post-Compromise Attacks Seen in the Wild The Wiz Blue Agent, now Generally Available Beyond the Badge: What Achieving Microsoft’s Certified Software Designation Means for Your Cloud Security Introducing the Green Agent: AI-Powered Remediation for the Cloud Three’s a Crowd: TeamPCP trojanizes LiteLLM in Continuation of Campaign KICS GitHub Action Compromised: TeamPCP Strikes Again in Supply Chain Attack Introducing the Wiz Red Agent- AI-Powered Attacker Introducing Wiz AI Application Protection Platform (AI-APP) Introducing Wiz Agents & Workflows: Security at the Speed of AI AI Runtime Threat Detection: From Input to Real-World Impact Trivy Compromised: Everything You Need to Know about the Latest Supply Chain Attack It’s Official: Wiz Joins Google Understanding and Reducing AI Risk in Modern Applications Introducing Wiz Tenant Manager: Multi-Tenant Management for Federated Organizations The Agile FedRAMP Playbook, Part 4: Reactive Risk Management through Enriched Incident Response Wiz Achieves CPSTIC Certification in Spain Seeing AI Clearly: Building Visibility Across Modern AI Applications The Agile FedRAMP Playbook, Part 3: Preventative Risk Management by building Secure by Design Wiz Leads the 2026 Latio Application Security Report with awards in 4 categories Building an Agentic Cloud Security Ecosystem: A Reference Architecture with Wiz MCP and Infosys Cyber Next The Agile FedRAMP Playbook, Part 2: Proactive Risk Management with Continuous Monitoring Cloud-native Security for your Windows environment: Announcing the Wiz Runtime Sensor for Windows Would You Click ‘Accept’? Automatically detecting malicious Azure OAuth applications using LLMs Wiz Named a Leader in The Forrester Wave™: Cloud Native Application Protection Solutions, Q1 2026 From Detection to Remediation: It’s Time to Rethink AppSec Around Exploitability and Root Cause Fixes The Agile FedRAMP Playbook, Part 1: Why Risk is Your Best Starting Point Introducing AI Cyber Model Arena: A Real-World Benchmark for AI Agents in Cybersecurity
Wizards of security, casting spells on themselves for ult...
Tanya Wadhawan, Tomer Sabag · 2024-04-03 · via Wiz Blog | RSS feed

Navigating the complexities of cloud security, especially in expansive and dynamic environments, is a challenge. Wiz’s approach mitigates vulnerabilities and identifies potential threats from code to cloud, extending from the development process and CI/CD pipeline through to the production cloud infrastructure and services.  

Cloud security strategy: Wiz4Wiz

From the earliest days of the product and company, the Wiz security team has used an internal instance of Wiz, called Wiz4Wiz, as the cornerstone of its cloud security strategy. This has enabled Wiz to protect its most sensitive assets – the systems and services that support our own customers – and to empower our security, operations, and developer teams to collaborate efficiently. Wiz’s agentless approach ensures that our security teams can maintain complete visibility over our cloud resources as our development teams quickly build and scale the platform and its features, never having to worry about coverage gaps or performance issues. Maintaining visibility and securing our resources with the Wiz platform works as a preventative measure as well, building security into processes early rather than applying patches as issues arise.  

At a fast-growing startup, maintaining complete security tool coverage can be a challenge, but Wiz’s agentless design ensures that its cloud resources were secure from day one with minimal need for tuning, risk of coverage gaps, chance of performance or operational issues, etc. As a result, Wiz’s internal security team can spend more time testing features and providing feedback to product managers.

Enabling Wiz cloud security and innovation

Wiz’s back end is primarily hosted on AWS, but our platform also operates with connected customer cloud environments hosted on AWS, GCP, Azure, Oracle Cloud, Alibaba Cloud, and other providers. Wiz excels with diverse cloud platforms by abstracting certain cloud-specific features into universal security controls and detections, ensuring that security measures are applicable and effective across any cloud environment. Utilizing and normalizing all cloud environments simplifies multi-cloud complexity and enables building cloud security teams with diverse experiences across all cloud service providers. Aside from providing consistency, this also helps us quickly onboard new team members that may only have experience with one particular cloud service provider – enabling them to quickly map their knowledge and concepts to other providers. Additionally, Wiz primarily runs its workloads on containers that are managed and orchestrated through Kubernetes. Wiz supports Kubernetes as another cloud platform in and of itself and can surface Kubernetes-specific security risks and threats, regardless of the hosting platform. Wiz also enforces Kubernetes security policies.  
 
Prior to deploying any feature or upgrade to customers, rigorous testing is conducted in pre-production environments utilizing Wiz4Wiz, allowing us to dogfood our own product and enable Wiz to be customer zero of Wiz. Wiz4Wiz also enables our teams to innovate and test emerging product capabilities, refining them before they’re ready for broader rollout to customers, and ensuring they work across various cloud environments. This fosters a powerful cycle of continuous improvement and collaboration with Wiz’s research team, developers, and product team.  

Democratizing security across Wiz 

Wiz4Wiz serves as a shared platform for every team that builds and operates in our cloud environments. This encourages developers and DevOps team members to understand the security impact of their design and implementation decisions throughout their day-to-day work. When security works with teams to respond to events or mitigate vulnerabilities, everyone benefits from sharing the platform’s analysis of risks, toxic combinations, and attack paths. This fosters an environment where security is democratized and shifts the development process left – developers and DevOps are truly an extension of our security team. This increases efficiency, security, and the quality of our product. Through automation within Wiz4Wiz, and integrations with on call management and ticketing systems, security issues can be efficiently routed and escalated to the right teams for in-platform triage, avoiding bottlenecks and delays.