惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

博客园_首页
B
Blog
V
V2EX
T
Tailwind CSS Blog
Hugging Face - Blog
Hugging Face - Blog
博客园 - 【当耐特】
博客园 - 聂微东
博客园 - 叶小钗
博客园 - 三生石上(FineUI控件)
The Cloudflare Blog
J
Java Code Geeks
H
Help Net Security
雷峰网
雷峰网
Apple Machine Learning Research
Apple Machine Learning Research
H
Hackread – Cybersecurity News, Data Breaches, AI and More
Engineering at Meta
Engineering at Meta
F
Fortinet All Blogs
Martin Fowler
Martin Fowler
D
Docker
L
LangChain Blog
人人都是产品经理
人人都是产品经理
爱范儿
爱范儿
WordPress大学
WordPress大学
V
Visual Studio Blog

Wiz Blog | RSS feed

Meet Wiz for M365: Bringing SaaS into the Security Graph Bringing Security Visibility to Vercel with Wiz Axios NPM Distribution Compromised in Supply Chain Attack Tracking TeamPCP: Investigating Post-Compromise Attacks Seen in the Wild The Wiz Blue Agent, now Generally Available Beyond the Badge: What Achieving Microsoft’s Certified Software Designation Means for Your Cloud Security Introducing the Green Agent: AI-Powered Remediation for the Cloud Three’s a Crowd: TeamPCP trojanizes LiteLLM in Continuation of Campaign KICS GitHub Action Compromised: TeamPCP Strikes Again in Supply Chain Attack Introducing the Wiz Red Agent- AI-Powered Attacker Introducing Wiz AI Application Protection Platform (AI-APP) Introducing Wiz Agents & Workflows: Security at the Speed of AI AI Runtime Threat Detection: From Input to Real-World Impact Trivy Compromised: Everything You Need to Know about the Latest Supply Chain Attack It’s Official: Wiz Joins Google Understanding and Reducing AI Risk in Modern Applications Introducing Wiz Tenant Manager: Multi-Tenant Management for Federated Organizations The Agile FedRAMP Playbook, Part 4: Reactive Risk Management through Enriched Incident Response Wiz Achieves CPSTIC Certification in Spain Seeing AI Clearly: Building Visibility Across Modern AI Applications The Agile FedRAMP Playbook, Part 3: Preventative Risk Management by building Secure by Design Wiz Leads the 2026 Latio Application Security Report with awards in 4 categories Building an Agentic Cloud Security Ecosystem: A Reference Architecture with Wiz MCP and Infosys Cyber Next The Agile FedRAMP Playbook, Part 2: Proactive Risk Management with Continuous Monitoring Cloud-native Security for your Windows environment: Announcing the Wiz Runtime Sensor for Windows Would You Click ‘Accept’? Automatically detecting malicious Azure OAuth applications using LLMs Wiz Named a Leader in The Forrester Wave™: Cloud Native Application Protection Solutions, Q1 2026 From Detection to Remediation: It’s Time to Rethink AppSec Around Exploitability and Root Cause Fixes The Agile FedRAMP Playbook, Part 1: Why Risk is Your Best Starting Point Introducing AI Cyber Model Arena: A Real-World Benchmark for AI Agents in Cybersecurity
Wiz launches support for Google Cloud excessive access fi...
Shaked Rotlevi, Ofer David, Matika Lidgi · 2023-11-20 · via Wiz Blog | RSS feed

Editor’s note: In our first blog post for this series, we announced support for Google Workspace identity modeling in Wiz. In this blogpost, we are adding a capability to detect excessive access findings for GCP customers that don’t have IAM Recommender enabled.

As discussed in the first blogpost in this series, identity is the new perimeter in the cloud. Following the least privilege principle helps organizations reduce attack surface in the cloud, ensuring that users and services only have access to what they need to perform their tasks and minimizing the risk of unauthorized access or data breaches. Least-privilege also helps organizations prevent privilege escalation, where an attacker is able to elevate access permissions to gain deeper access to resources and data. 

Google’s IAM Recommender provides GCP customers with role recommendations based on excess permissions of principals, and Wiz leverages these findings by default in its product. It was recently announced that IAM Recommender will be available for customers with organization-level activations of Security Command Center (SCC), requiring the Premium pricing tier. To provide all GCP customers with consistent visibility into excessive permissions, regardless of their SCC pricing tier, Wiz is excited to add support for Excessive Access Findings based on Google audit logs. With this launch, all Wiz GCP customers can identify excessive permissions and understand how to scope them down. Wiz excessive access analysis makes it easy for organizations to ensure least-privilege by identifying permissions that have been over-provisioned, as well as inactive users and service-accounts, based on GCP cloud events. Wiz provides you with exact guidance on how to adjust these permissions to ensure that your environment enforces the principle of least-privilege access more effectively.  

You can easily view all the excessive access findings for all identities in your GCP and multi-cloud environment and drill down into the remediation guidance. 

Not only does Wiz detect excessive access, but it also identifies how identity misconfigurations can create a toxic combination that leads to an attack path in your environment. In this example below, Wiz identifies a publicly exposed GCP Compute Instance that has excessive permissions and high privileges, as well as a network vulnerability with a known exploit, creating an attack path for an attacker to exploit. 

All GCP customers can now benefit from consistent visibility into excessive permissions and understand how identity risks can lead to attack paths. Get started now with Wiz for CIEM, you can learn more in the Wiz docs (login needed). If you prefer a live demo, we would love to connect with you.