惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

量子位
Recent Announcements
Recent Announcements
D
Docker
V
V2EX
阮一峰的网络日志
阮一峰的网络日志
Vercel News
Vercel News
Microsoft Security Blog
Microsoft Security Blog
The GitHub Blog
The GitHub Blog
U
Unit 42
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
月光博客
月光博客
腾讯CDC
B
Blog
博客园_首页
罗磊的独立博客
D
DataBreaches.Net
IT之家
IT之家
酷 壳 – CoolShell
酷 壳 – CoolShell
L
LangChain Blog
aimingoo的专栏
aimingoo的专栏
MongoDB | Blog
MongoDB | Blog
GbyAI
GbyAI
Stack Overflow Blog
Stack Overflow Blog
M
MIT News - Artificial intelligence

Wiz Blog | RSS feed

Meet Wiz for M365: Bringing SaaS into the Security Graph Bringing Security Visibility to Vercel with Wiz Axios NPM Distribution Compromised in Supply Chain Attack Tracking TeamPCP: Investigating Post-Compromise Attacks Seen in the Wild The Wiz Blue Agent, now Generally Available Beyond the Badge: What Achieving Microsoft’s Certified Software Designation Means for Your Cloud Security Introducing the Green Agent: AI-Powered Remediation for the Cloud Three’s a Crowd: TeamPCP trojanizes LiteLLM in Continuation of Campaign KICS GitHub Action Compromised: TeamPCP Strikes Again in Supply Chain Attack Introducing the Wiz Red Agent- AI-Powered Attacker Introducing Wiz AI Application Protection Platform (AI-APP) Introducing Wiz Agents & Workflows: Security at the Speed of AI AI Runtime Threat Detection: From Input to Real-World Impact Trivy Compromised: Everything You Need to Know about the Latest Supply Chain Attack It’s Official: Wiz Joins Google Understanding and Reducing AI Risk in Modern Applications Introducing Wiz Tenant Manager: Multi-Tenant Management for Federated Organizations The Agile FedRAMP Playbook, Part 4: Reactive Risk Management through Enriched Incident Response Wiz Achieves CPSTIC Certification in Spain Seeing AI Clearly: Building Visibility Across Modern AI Applications The Agile FedRAMP Playbook, Part 3: Preventative Risk Management by building Secure by Design Wiz Leads the 2026 Latio Application Security Report with awards in 4 categories Building an Agentic Cloud Security Ecosystem: A Reference Architecture with Wiz MCP and Infosys Cyber Next The Agile FedRAMP Playbook, Part 2: Proactive Risk Management with Continuous Monitoring Cloud-native Security for your Windows environment: Announcing the Wiz Runtime Sensor for Windows Would You Click ‘Accept’? Automatically detecting malicious Azure OAuth applications using LLMs Wiz Named a Leader in The Forrester Wave™: Cloud Native Application Protection Solutions, Q1 2026 From Detection to Remediation: It’s Time to Rethink AppSec Around Exploitability and Root Cause Fixes The Agile FedRAMP Playbook, Part 1: Why Risk is Your Best Starting Point Introducing AI Cyber Model Arena: A Real-World Benchmark for AI Agents in Cybersecurity
From MCP to Vibe Coding: Full Endpoint Visibility in Wiz ...
Snegha Ramnarayanan, Guy Weiss · 2025-12-22 · via Wiz Blog | RSS feed

Introduction 

Everywhere AI is being adopted, new application endpoints appear. From Vibe Coding tools to large-scale model APIs and pipelines, these endpoints are the front doors into your AI usage — and the first places attackers probe.

The problem? Most organizations have no consolidated way to see them all.

That’s why Wiz AI Security now includes a new Application Endpoints widget, powered by the Wiz Attack Surface Scanner. It surfaces live, validated endpoints across the entire AI spectrum: AI Security, AI as a Service, AI Tools, AI Pipelines, AI Frameworks & Toolkits, and AI Models.

What You Can See (and Why It Matters)

The new widget doesn’t just show you a list of open services — it reveals the actual entry points into your AI adoption. These are endpoints that represent the real attack surface:

  • AI Developer Tools : AI-driven coding workflows that may introduce helper APIs or services outside formal review. (Vibe Coding)

  • AI Pipelines: Endpoints that move data in and out of training and deployment pipelines.

  • AI as a Service: Cloud AI platform APIs integrated directly into environments.

  • AI Frameworks & Toolkits: Developer libraries that expose default endpoints.

  • AI Models: Direct model-serving endpoints where sensitive data flows.

  • AI Security: Guardrail or governance services that themselves expose endpoints.

  • MCP Endpoints: Model Context Protocol interfaces that manage agent/server communication.

Unlike a basic scan that says “service exists,” Wiz validates whether these endpoints are live, exposed, and reachable in runtime — then ties them into the Security Graph so you can see what data, identities, and workloads they touch.

From Visibility to Action

The new widget goes beyond visibility — it helps teams take action right from within AI-SPM:

  • Explore endpoints directly: Visit each surfaced endpoint through a link in the widget to its IP address to investigate exposure in real time.

  • Trace to the underlying workload: See which workload hosts the technology, review related issues or misconfigurations, and remediate them — closing the loop from discovery to fix.

  • End-to-end response: Move from visibility to investigation to remediation, all in one place.

Real-World Examples

To make this concrete, here are two scenarios Wiz surfaces today:

  • MCP Endpoint Exposure
    An MCP endpoint left open to the internet is flagged by Wiz. The Security Graph shows it connects into sensitive data stores, turning what looks like an overlooked configuration into a potential breach path.

MCP endpoint flagged with connected attack path
  • Vibe Coding Endpoint in Production
    A developer experimenting with Vibe Coding spins up a test API for iteration. Wiz surfaces it as live, shows it ties into a pipeline, and highlights that it’s handling sensitive customer data. What started as a helper service could expose critical assets if left unseen.

Vibe Coding endpoint tied to a pipeline in the Security Graph

Why Wiz, Why Now

Most tools capture only one slice of the AI picture — cloud APIs, SaaS plugins, or isolated model endpoints. Wiz is delivers end-to-end AI endpoint visibility in a single place, dynamically validated and fully contextualized across your entire cloud environment.

This gives security teams a true single source of truth for AI endpoints — from Vibe Coding tools to MCP — and the ability to prioritize exposure based on what actually matters: sensitive data access, risky connections, and real attack paths.

AI endpoints are where innovation meets risk. They are the real-world access points into AI tools, services, pipelines, and models — showing what is actually exposed, not just what exists. Endpoints reveal how sensitive data flows, where shadow AI is being adopted, and how AI connects back into the broader cloud environment.

Wiz continuously validates these endpoints and connects them to identities, data, permissions, and infrastructure in the Security Graph, turning raw exposure into actionable, prioritized risk that teams can act on immediately.

Grounded in AI Security Best Practices

Wiz continuously aligns its AI-SPM capabilities with leading security frameworks such as the OWASP Top 10 for LLMs. These guidelines inform how Wiz prioritizes risks, identifies vulnerable endpoints, and helps teams follow a consistent approach to securing their AI environments.