惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Apple Machine Learning Research
Apple Machine Learning Research
Google DeepMind News
Google DeepMind News
小众软件
小众软件
GbyAI
GbyAI
酷 壳 – CoolShell
酷 壳 – CoolShell
F
Fortinet All Blogs
博客园 - 三生石上(FineUI控件)
B
Blog
量子位
B
Blog RSS Feed
Vercel News
Vercel News
Blog — PlanetScale
Blog — PlanetScale
Last Week in AI
Last Week in AI
博客园 - 叶小钗
MongoDB | Blog
MongoDB | Blog
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
爱范儿
爱范儿
Jina AI
Jina AI
C
Check Point Blog
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
IT之家
IT之家
H
Hackread – Cybersecurity News, Data Breaches, AI and More
云风的 BLOG
云风的 BLOG

Wiz Blog | RSS feed

Meet Wiz for M365: Bringing SaaS into the Security Graph Bringing Security Visibility to Vercel with Wiz Axios NPM Distribution Compromised in Supply Chain Attack Tracking TeamPCP: Investigating Post-Compromise Attacks Seen in the Wild The Wiz Blue Agent, now Generally Available Beyond the Badge: What Achieving Microsoft’s Certified Software Designation Means for Your Cloud Security Introducing the Green Agent: AI-Powered Remediation for the Cloud Three’s a Crowd: TeamPCP trojanizes LiteLLM in Continuation of Campaign KICS GitHub Action Compromised: TeamPCP Strikes Again in Supply Chain Attack Introducing the Wiz Red Agent- AI-Powered Attacker Introducing Wiz AI Application Protection Platform (AI-APP) Introducing Wiz Agents & Workflows: Security at the Speed of AI AI Runtime Threat Detection: From Input to Real-World Impact Trivy Compromised: Everything You Need to Know about the Latest Supply Chain Attack It’s Official: Wiz Joins Google Understanding and Reducing AI Risk in Modern Applications Introducing Wiz Tenant Manager: Multi-Tenant Management for Federated Organizations The Agile FedRAMP Playbook, Part 4: Reactive Risk Management through Enriched Incident Response Wiz Achieves CPSTIC Certification in Spain Seeing AI Clearly: Building Visibility Across Modern AI Applications The Agile FedRAMP Playbook, Part 3: Preventative Risk Management by building Secure by Design Wiz Leads the 2026 Latio Application Security Report with awards in 4 categories Building an Agentic Cloud Security Ecosystem: A Reference Architecture with Wiz MCP and Infosys Cyber Next The Agile FedRAMP Playbook, Part 2: Proactive Risk Management with Continuous Monitoring Cloud-native Security for your Windows environment: Announcing the Wiz Runtime Sensor for Windows Would You Click ‘Accept’? Automatically detecting malicious Azure OAuth applications using LLMs Wiz Named a Leader in The Forrester Wave™: Cloud Native Application Protection Solutions, Q1 2026 From Detection to Remediation: It’s Time to Rethink AppSec Around Exploitability and Root Cause Fixes The Agile FedRAMP Playbook, Part 1: Why Risk is Your Best Starting Point Introducing AI Cyber Model Arena: A Real-World Benchmark for AI Agents in Cybersecurity
Wiz + Spotify Backstage: Security at the Developer’s Desk
Or Tzabary, Bandhna Bedi, Omer Mesika, Omer Rosenblit · 2026-02-06 · via Wiz Blog | RSS feed

Every developer has a mental map of their services. You know what you own. You know what’s on fire. You know what used to be on fire but someone swears is “fine now.” And when something breaks, you usually know where to look first.

Security issues don’t always show up on that same map. A risk pops up somewhere else, described in a different language, detached from the services, projects, and ownership models developers actually use. Now the first question isn’t how to fix it—it’s whether it even belongs to you.

That’s why we’re excited to announce the Wiz and Spotify Backstage plugin, now in General Availability. The plugin surfaces Wiz Issues and Vulnerabilities directly in the Spotify Backstage portal by mapping Wiz projects to Backstage components. 

For each component, developers can search findings by rule, resource, or CVE, and quickly see vulnerability counts and severity at a glance. When it’s time to take action - whether that’s remediation, investigation, or guidance - developers can jump straight from Backstage into Wiz with full context.

How Wiz maps risk to ownership

The Wiz plugin for Backstage works to solve the age old problem of unclear ownership in security. At the core of this is the Service Catalog, giving developers the context they need to see risk in action, understand impact, and know exactly which services they own. 

Services in Wiz provide the horizontal view, showing developers the resources that make up an application or microservice across environments. Services can also be combined with Wiz Projects, which sit above services vertically and define boundaries, access, and governance across teams and accounts -- like by business unit or geographic team. Together, they make ownership clear so developers can act quickly, without wading through dashboards or filling out tickets. 

How Projects and Services Work Together

The Wiz and Spotify Backstage plugin brings this ownership-first model into the developer portal. Risk is mapped by Project and surfaced next to the Backstage components developers already use every day, so findings show up where developers are reasoning about their systems and each developer sees the right findings for the systems they own.

For example, a developer might open a Backstage component representing a public-facing website. The plugin shows that this component has multiple vulnerable resources in Wiz, and by exploring the Wiz platform, they can see that these resources are running on an internet-exposed load balancer visualized in the Wiz Security Graph. The developer can immediately assess the risk and, with one click, jump into Wiz to understand impact and start remediation—without leaving Backstage.

Bringing Security to the Development Desk

The Wiz plugin for Backstage further democratizes security by bringing findings directly into the tools developers know and use daily:

  • See Issues and Vulnerabilities by Component: Each Backstage component defines how Wiz pulls Issues and Vulnerabilities from its associated Projects in Wiz. The plugin then shows all related issues and vulnerabilities right next to the component, giving developers an instant view of the risks affecting the components they own.

  • Search and Filter Issues: Inside the Backstage portal, developers can search by rule, resource, or CVE, making it easy to identify and focus on remediating the Issues and vulnerabilities most relevant to their work.

  • Understand impact quickly: The plugin shows a total count of vulnerabilities per component, along with their severity, the Issues they’re related to, remediation status, and when the vulnerability was first and last detected - helping teams prioritize without leaving Backstage.

  • Remediate and Respond Seamlessly: To investigate Issues and vulnerabilities deeper, or when remediation is needed, one click takes developers into Wiz with full context, remediation guidance, and the code-to-cloud pipeline to understand impact, triage, and remediate quickly.

Wiz plugin for Backstage in action

By bringing security closer to developer workflows and aligning Issues and Vulnerabilities to the projects developers care about and own, the Wiz plugin for Backstage makes security an enabler, keeping momentum with the pace of development.

Install the Wiz plugin for Backstage today, to bring security into your developer portal. Joint customers can follow the guide in the Wiz Docs (login required) to get started.