惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

F
Full Disclosure
Recorded Future
Recorded Future
T
Tenable Blog
S
Securelist
C
CERT Recently Published Vulnerability Notes
T
Threatpost
S
Schneier on Security
A
Arctic Wolf
The Hacker News
The Hacker News
C
CXSECURITY Database RSS Feed - CXSecurity.com
Know Your Adversary
Know Your Adversary
P
Privacy International News Feed
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
The Register - Security
The Register - Security
Cisco Talos Blog
Cisco Talos Blog
AWS News Blog
AWS News Blog
K
Kaspersky official blog
T
True Tiger Recordings
T
Threat Research - Cisco Blogs
V
Vulnerabilities – Threatpost
P
Palo Alto Networks Blog
T
The Exploit Database - CXSecurity.com
小众软件
小众软件
B
Blog
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
Microsoft Azure Blog
Microsoft Azure Blog
Cyberwarzone
Cyberwarzone
C
Cybersecurity and Infrastructure Security Agency CISA
T
Tor Project blog
Spread Privacy
Spread Privacy
Malwarebytes
Malwarebytes
P
Proofpoint News Feed
F
Fox-IT International blog
F
Fortinet All Blogs
P
Privacy & Cybersecurity Law Blog
G
GRAHAM CLULEY
量子位
Latest news
Latest news
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
博客园 - 叶小钗
Project Zero
Project Zero
T
Tailwind CSS Blog
N
Netflix TechBlog - Medium
Martin Fowler
Martin Fowler
IntelliJ IDEA : IntelliJ IDEA – the Leading IDE for Professional Development in Java and Kotlin | The JetBrains Blog
IntelliJ IDEA : IntelliJ IDEA – the Leading IDE for Professional Development in Java and Kotlin | The JetBrains Blog
I
Intezer
博客园_首页
腾讯CDC
H
Hackread – Cybersecurity News, Data Breaches, AI and More
D
Darknet – Hacking Tools, Hacker News & Cyber Security

Wiz Blog | RSS feed

Defending at Machine-Speed: Building AI Threat Readiness with Wiz State of SDLC Security 2026: How Risk Scales in Modern Development Claude Enterprise Meets the Security Graph: Wiz Integrates with Anthropic's Compliance API durabletask: TeamPCP's Latest PyPi Compromise Introducing Runtime Threat Detection for Google Cloud Run The Worm That Keeps on Digging: TeamPCP Hits @antv in Latest Wave From Cryptographic Blind Spots to Post-Quantum Agility: Introducing Wiz for PQC Readiness Beyond Findings: Connecting Exploitable Risk to Cloud Context with Wiz and HackerOne Fragnesia: Linux Kernel Local Privilege Escalation via ESP-in-TCP Introducing Wiz Audit History: Track Every Change Across your Environment Mini Shai-Hulud Strikes Again: TanStack + more npm Packages Compromised Wiz at Wiz: Reducing Risk through Service Ownership A Framework for AI Threat Readiness See and Secure Everything at the Edge with Wiz and Akamai Dirty Frag: Linux Kernel Local Privilege Escalation via ESP and RxRPC Build Fast, Build Secure: Wiz findings are now in Lovable It's Time to Go After Achieving Zero Code Criticals The Jenkins Threat Landscape Critical Buffer Overflow Vulnerability in PAN-OS Exploited in-the-Wild Introducing Penetration Test Findings: Unified Offensive Security in Wiz Practical Package Security: The Unofficial Guide From Foundation to Force: Your Guide to Operationalizing Wiz at Scale Copy Fail: Universal Linux Local Privilege Escalation Vulnerability Red Agent and Claude Opus: Securing Production Targets at Scale The (In)security Landscape of AI-Powered GitHub Actions (Part 2/2) Key Takeaways from the 2026 State of AI in the Cloud Report Supply Chain Campaign Targets SAP npm Packages with Credential-Stealing Malware Wiz Code Week Recap: Securing AI Native Development Modern Defensible Architecture: Resilience for the Australian Federal Government Securing GitHub: Wiz Research uncovers Remote Code Execution in GitHub.com and GitHub Enterprise Server (CVE-2026-3854) NIST NVD Update: What it Means For Vulnerability Management Wiz at Google Next: Machine-Speed Defense for Any Cloud, Any Platform, Any AI Closing the Security Gap in the Age of Agentic Coding Mapping Your API Ecosystem: Wiz Expands API Discovery with Apigee Context.ai OAuth Token Compromise Wiz and Databricks: Adding Databricks to the Wiz Security Graph From Code to Pipeline: Wiz Code Now Secures Your Build Environment Securing AI Applications From Inception to Deployment Securing the AI Edge: Wiz and Cloudflare Integrate for End-to-End AI Protection Introducing Shadow Data Detection: Reduce Cost and Risk Across Your Cloud Primer on GitHub Actions Security - Threat Model, Attacks and Defenses (Part 1/2) Claude Mythos: Preparing for a World Where AI Finds and Exploits Vulnerabilities Faster Than Ever Cloud Threats Retrospective 2026: What AI Changed (and What It Didn’t) Bringing Security Visibility to Vercel with Wiz Six Accounts, One Actor: Inside the prt-scan Supply Chain Campaign Axios NPM Distribution Compromised in Supply Chain Attack Tracking TeamPCP: Investigating Post-Compromise Attacks Seen in the Wild The Wiz Blue Agent, now Generally Available Beyond the Badge: What Achieving Microsoft’s Certified Software Designation Means for Your Cloud Security Introducing the Green Agent: AI-Powered Remediation for the Cloud Introducing Wiz Workflows: Your path to building a self healing cloud Three’s a Crowd: TeamPCP trojanizes LiteLLM in Continuation of Campaign KICS GitHub Action Compromised: TeamPCP Strikes Again in Supply Chain Attack Introducing the Wiz Red Agent- AI-Powered Attacker Introducing Wiz AI Application Protection Platform (AI-APP) Introducing Wiz Agents & Workflows: Security at the Speed of AI AI Runtime Threat Detection: From Input to Real-World Impact Trivy Compromised: Everything You Need to Know about the Latest Supply Chain Attack Twenty Years of Cloud Security Research It’s Official: Wiz Joins Google Understanding and Reducing AI Risk in Modern Applications Introducing Wiz Tenant Manager: Multi-Tenant Management for Federated Organizations The Agile FedRAMP Playbook, Part 4: Reactive Risk Management through Enriched Incident Response Wiz Achieves CPSTIC Certification in Spain Seeing AI Clearly: Building Visibility Across Modern AI Applications The Agile FedRAMP Playbook, Part 3: Preventative Risk Management by building Secure by Design Security Insights Where Work Happens: Notion Custom Agents + Wiz MCP Wiz Leads the 2026 Latio Application Security Report with awards in 4 categories Building an Agentic Cloud Security Ecosystem: A Reference Architecture with Wiz MCP and Infosys Cyber Next The Agile FedRAMP Playbook, Part 2: Proactive Risk Management with Continuous Monitoring Cloud-native Security for your Windows environment: Announcing the Wiz Runtime Sensor for Windows Would You Click ‘Accept’? Automatically detecting malicious Azure OAuth applications using LLMs Wiz Named a Leader in The Forrester Wave™: Cloud Native Application Protection Solutions, Q1 2026 From Detection to Remediation: It’s Time to Rethink AppSec Around Exploitability and Root Cause Fixes The Agile FedRAMP Playbook, Part 1: Why Risk is Your Best Starting Point Introducing AI Cyber Model Arena: A Real-World Benchmark for AI Agents in Cybersecurity Wiz + Spotify Backstage: Security at the Developer’s Desk Building AI Security Together: New Ways to Partner with Wiz for AI Security in 2026 Hacking Moltbook: The AI Social Network Any Human Can Control The Year in Wiz Research: 2025 Most Read Blogs AI Agents vs Humans: Who Wins at Web Hacking in 2026? Introducing the WIN Partner Index: The Integrations That Powered Modern Cloud Security in 2025 AI-Powered Forensics, at Cloud Speed Introducing SITF: The First Threat Framework Dedicated to SDLC Infrastructure WizExtend is Here: AI and Cloud Security Insights in Your Daily Workflow From Detection to Remediation: Wiz in Your JetBrains IDE Agentic Browser Security: 2025 Year-End Review CodeBreach: Infiltrating the AWS Console Supply Chain and Hijacking AWS GitHub Repositories via CodeBuild A 90-Day Action Plan to Turn Resolutions into Results with Wiz Introducing the Wiz Partner Alliance: A New Chapter for Partner Success Preparing for Post-Quantum Cryptography Wiz Recognized as a 2025 Customers’ Choice in the Gartner® Peer Insights™ Voice of the Customer for CNAPP Expanding the Zero Critical Club to set a new standard for AppSec and SecOps teams Snipping the Long Tail of Shai-Hulud 2.0 Protecting Against Zero-Day Vulnerabilities with SOC-Level ASM Alert MongoBleed (CVE-2025-14847) exploited in the wild: everything you need to know The Kenna Transition: Your Strategic Shift to Exposure Management From MCP to Vibe Coding: Full Endpoint Visibility in Wiz AI Security Bringing Oracle Cloud Identity to Wiz Zero‑Days in the Age of AI: Behind the Scenes of ZeroDay.cloud 2025, with a Record High of CVEs in Critical Cloud Infra
IaC Inventory: A Unified View Across Code, Deployments, and Cloud
2026-04-17 · via Wiz Blog | RSS feed

AI applications are changing what "infrastructure" means. Agents, model endpoints, vector databases, and the guardrails that govern them are now core cloud resources , defined and deployed through Infrastructure-as-Code (IaC). And with AI assisted development, more engineers are writing IaC directly, often without the security context that platform teams have historically owned.

That shift has a cost. Security misconfigurations are now #2 in the OWASP Top 10 . When infrastructure authorship moves faster and spreads wider, the blast radius of a single misconfiguration grows with it.

The deeper problem is that visibility hasn't kept up. IaC configurations live in code repositories. State lives in scattered backends. Resources run in the cloud. When something goes wrong, teams are forced to stitch context across tools just to answer basic questions: What created this resource? Who owns it? What else does it affect?

Prevention matters. But it doesn't eliminate what's already running in production.

Today, Wiz addresses both sides of that problem. Our new IaC Inventory gives security and platform teams a unified view of how code becomes cloud, connecting every module to every deployment it created and every live resource it manages. And with new Pulumi support, Wiz extends IaC scanning to developer-first languages putting infrastructure authorship in the hands of application teams across AWS, GCP, and Azure. meeting application teams where they already work across AWS, GCP, and Azure.

The IaC Inventory Modules tab gives teams a complete view of every IaC module across their estate, including source origin, platform, type, deployments, and resources.

Securing AI Resources from Code-to-Cloud 

Wiz approaches IaC security with a simple principle: the same policies that govern your cloud at runtime should apply to the code that defines it. In most environments, they don’t. Infrastructure is validated late, after deployment, when CSPM alerts surface issues that have already reached production. By that point, fixing them is slower, riskier, and often disconnected from the teams that introduced them. 

Wiz connects these worlds. With Wiz Code, policies are enforced directly in development using a unified policy engine. Teams can use Wiz's built-in best practice rules, for example "Bedrock Agent should be associated with Bedrock Guardrails," or create custom rules, and enforce it consistently across code, pipelines, and cloud. Critical misconfigurations are caught pre-deployment, not hours later by a CSPM alert.

For risks that are found in the cloud, Wiz simplifies remediation through code-to-cloud traceability. Every live resource is automatically mapped back to the exact module, file, line of code, and author that defined it. When a misconfiguration surfaces, Wiz identifies the owner and surfaces a targeted PR to fix it at the source.

A misconfigured AI Agent traced back through its full code-to-cloud pipeline,  from the IaC deployment that defined it to the live resource and its configuration findings.

IaC Inventory: A Unified View for Code, Deployments, and Cloud

Until now, even with scanning and traceability, there was no single place to see how your IaC actually maps to your cloud. This is especially critical as AI workloads like agents, models, datasets, guardrails  become first-class infrastructure resources defined and managed through IaC

The IaC Inventory changes that. Wiz uses state files as the bridge to automatically connect resources and modules declared in IaC to the live resources running in the cloud. This gives security, DevOps, and platform teams a unified view across their entire IaC estate without needing to manually cross-reference across disparate tools. 

The value is immediate across three workflows:

  • Scope risk instantly. When a vulnerable module is identified, whether it’s an AI training dataset or Bedrock Agent, the blast radius is no longer a mystery. See every deployment it backs and every live resource it manages in one click, turning hours of detective work into a single interaction.

The resources tab allows teams to surface AI resources, providing instant visibility into every AI workload defined and managed through IaC.
  • Govern your estate. Spot modules sourced from unapproved or ungoverned origins, surface unused modules as explicit technical debt, and identify deployments running outdated versions all without writing a query or enforcing tagging hygiene.

  • Catch drift and close the gap between code and runtime. When a resource drifts from its declared state, it sits outside your governance boundary, unreviewed and unprotected. The IaC Inventory surfaces drift explicitly so teams can catch and resolve them before they become incidents.

A drifted S3 bucket surfaces alongside its full code-to-cloud pipeline, connecting the live resource to the IaC deployment and code repository that defined it — and the configuration findings that need to be resolved.

Pulumi Support: Meeting Developers how they build 

Wiz already secures IaC across several frameworks such as Terraform, CloudFormation, and Bicep. Today, that coverage expands to include Pulumi. 

As infrastructure is increasingly authored in developer-first languages, and as LLMs generate more infrastructure code than ever before, the need for a guardrail that understands the context of that code has never been higher. This shift increases the surface area for misconfiguration, making automated oversight a necessity rather than a luxury.

With Wiz CLI support for native Pulumi scanning across AWS, GCP, and Azure, misconfigurations are caught before they ever reach production. Whether that is a developer inadvertently leaving public access enabled on a GCP storage bucket or an overly permissive IAM policy generated by an AI-assisted tool, Wiz catches it before it ships.

Closing the loop from visibility to remediation with agents 

Visibility is only valuable if it leads to action. And action is only as good as the context behind it.

Consider a common scenario. Your team uses a third-party Terraform module to provision AWS Bedrock Agents. The third-party maintainer is compromised and a new malicious version of the module introduces a misconfiguration that removes any Bedrock Guardrails that were applied, and on the next deployment, the change propagates silently across every environment using that module.

But some of those agents were designed not to have guardrails, and adding them blindly can break production. Now you need to act, but carefully. Where is this module used? What resources has it deployed? Which of them have drifted from their IaC configuration? Which of them are actually at risk? What will break if you change it?

Without IaC Inventory, answering these questions requires hours of manual investigation across repositories, state files, and cloud consoles. With it, the full context is immediately available. By connecting modules, deployments, and live resources, Wiz enables teams to understand not just where the issue exists, but how it propagates and where different behaviors are actually required.

This makes genuinely safe remediation possible. The problem is no longer finding the issue. It’s understanding its impact. Instead of a blanket fix that breaks legitimate use cases, teams can make informed architectural changes, reducing risk while preserving intended functionality. Our Green Agent orchestrates fixes by understanding the context of the code, cloud, and runtime environment. Developers know exactly where to make the change. Platform teams understand the full blast radius. Remediation workflows operate with precision and confidence.

This is how visibility turns into safe, scalable remediation.

Wiz Green Agent generates precise remediation steps for an overprivileged Bedrock Agent, with full context of the code, cloud, and runtime environment.

Get started

Existing Wiz Code customers can connect their repositories and IaC platforms to begin exploring IaC Inventory today. As part of Wiz Code, it gives security, DevOps, and platform teams a unified view of their entire IaC estate, connecting every module to every deployment it created and every live resource it manages, so teams can trace risk, catch drift, and remediate with confidence from code to cloud.

For a deep dive into how IaC Inventory works, visit the documentation (login required).

New to Wiz? Book a demo to see how the Security Graph connects your IaC estate to your runtime environment.