惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

MyScale Blog
MyScale Blog
WordPress大学
WordPress大学
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
C
CXSECURITY Database RSS Feed - CXSecurity.com
I
Intezer
V
Visual Studio Blog
Cisco Talos Blog
Cisco Talos Blog
Microsoft Azure Blog
Microsoft Azure Blog
S
Securelist
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
N
News and Events Feed by Topic
Recorded Future
Recorded Future
Simon Willison's Weblog
Simon Willison's Weblog
G
GRAHAM CLULEY
酷 壳 – CoolShell
酷 壳 – CoolShell
L
Lohrmann on Cybersecurity
U
Unit 42
Hacker News: Ask HN
Hacker News: Ask HN
阮一峰的网络日志
阮一峰的网络日志
Vercel News
Vercel News
PCI Perspectives
PCI Perspectives
H
Help Net Security
C
Cisco Blogs
爱范儿
爱范儿
Recent Announcements
Recent Announcements
Google DeepMind News
Google DeepMind News
小众软件
小众软件
T
Tor Project blog
Exploit-DB.com RSS Feed
Exploit-DB.com RSS Feed
Schneier on Security
Schneier on Security
H
Hackread – Cybersecurity News, Data Breaches, AI and More
www.infosecurity-magazine.com
www.infosecurity-magazine.com
IT之家
IT之家
J
Java Code Geeks
人人都是产品经理
人人都是产品经理
Spread Privacy
Spread Privacy
T
The Blog of Author Tim Ferriss
Application and Cybersecurity Blog
Application and Cybersecurity Blog
AI
AI
S
Security @ Cisco Blogs
T
Tenable Blog
Security Archives - TechRepublic
Security Archives - TechRepublic
aimingoo的专栏
aimingoo的专栏
Cloudbric
Cloudbric
D
Docker
W
WeLiveSecurity
Hacker News - Newest:
Hacker News - Newest: "LLM"
F
Fortinet All Blogs
The Hacker News
The Hacker News
Help Net Security
Help Net Security

Wiz Blog | RSS feed

Meet Wiz for M365: Bringing SaaS into the Security Graph Bringing Security Visibility to Vercel with Wiz Axios NPM Distribution Compromised in Supply Chain Attack Tracking TeamPCP: Investigating Post-Compromise Attacks Seen in the Wild The Wiz Blue Agent, now Generally Available Beyond the Badge: What Achieving Microsoft’s Certified Software Designation Means for Your Cloud Security Introducing the Green Agent: AI-Powered Remediation for the Cloud Three’s a Crowd: TeamPCP trojanizes LiteLLM in Continuation of Campaign KICS GitHub Action Compromised: TeamPCP Strikes Again in Supply Chain Attack Introducing the Wiz Red Agent- AI-Powered Attacker Introducing Wiz AI Application Protection Platform (AI-APP) Introducing Wiz Agents & Workflows: Security at the Speed of AI AI Runtime Threat Detection: From Input to Real-World Impact Trivy Compromised: Everything You Need to Know about the Latest Supply Chain Attack It’s Official: Wiz Joins Google Understanding and Reducing AI Risk in Modern Applications Introducing Wiz Tenant Manager: Multi-Tenant Management for Federated Organizations The Agile FedRAMP Playbook, Part 4: Reactive Risk Management through Enriched Incident Response Wiz Achieves CPSTIC Certification in Spain Seeing AI Clearly: Building Visibility Across Modern AI Applications The Agile FedRAMP Playbook, Part 3: Preventative Risk Management by building Secure by Design Wiz Leads the 2026 Latio Application Security Report with awards in 4 categories Building an Agentic Cloud Security Ecosystem: A Reference Architecture with Wiz MCP and Infosys Cyber Next The Agile FedRAMP Playbook, Part 2: Proactive Risk Management with Continuous Monitoring Cloud-native Security for your Windows environment: Announcing the Wiz Runtime Sensor for Windows Would You Click ‘Accept’? Automatically detecting malicious Azure OAuth applications using LLMs Wiz Named a Leader in The Forrester Wave™: Cloud Native Application Protection Solutions, Q1 2026 From Detection to Remediation: It’s Time to Rethink AppSec Around Exploitability and Root Cause Fixes The Agile FedRAMP Playbook, Part 1: Why Risk is Your Best Starting Point Introducing AI Cyber Model Arena: A Real-World Benchmark for AI Agents in Cybersecurity Wiz + Spotify Backstage: Security at the Developer’s Desk Building AI Security Together: New Ways to Partner with Wiz for AI Security in 2026 Hacking Moltbook: The AI Social Network Any Human Can Control The Year in Wiz Research: 2025 Most Read Blogs WizExtend is Here: AI and Cloud Security Insights in Your Daily Workflow From Detection to Remediation: Wiz in Your JetBrains IDE Agentic Browser Security: 2025 Year-End Review CodeBreach: Infiltrating the AWS Console Supply Chain and Hijacking AWS GitHub Repositories via CodeBuild A 90-Day Action Plan to Turn Resolutions into Results with Wiz Introducing the Wiz Partner Alliance: A New Chapter for Partner Success Preparing for Post-Quantum Cryptography Wiz Recognized as a 2025 Customers’ Choice in the Gartner® Peer Insights™ Voice of the Customer for CNAPP Expanding the Zero Critical Club to set a new standard for AppSec and SecOps teams Snipping the Long Tail of Shai-Hulud 2.0 Protecting Against Zero-Day Vulnerabilities with SOC-Level ASM Alert MongoBleed (CVE-2025-14847) exploited in the wild: everything you need to know The Kenna Transition: Your Strategic Shift to Exposure Management From MCP to Vibe Coding: Full Endpoint Visibility in Wiz AI Security Bringing Oracle Cloud Identity to Wiz Zero‑Days in the Age of AI: Behind the Scenes of ZeroDay.cloud 2025, with a Record High of CVEs in Critical Cloud Infra Gogs 0-Day Exploited in the Wild Code to Cloud Attacks: From Github PAT to Cloud Control Plane Top AWS re:Invent Announcements for Security Teams in 2025 React2Shell: Technical Deep-Dive & In-the-Wild Exploitation of CVE-2025-55182 React2Shell (CVE-2025-55182): Everything You Need to Know About the Critical React Vulnerability Wiz Product Announcements at re:Invent 2025: Expanding Visibility from Code to Cloud Introducing Wiz SAST: Where Code Risk Meets Cloud Context Wiz Becomes Fastest Security ISV to Reach $1 Billion in AWS Marketplace Lifetime Sales It's Here! Wiz Exposure Management is Now GA Shai-Hulud 2.0 Aftermath: Trends, Victimology and Impact Service Catalog is Here: Expand Risk Visibility for Your Service and Its Dependencies, Simplify Issue Ownership WizOS: Powering Secured Image Adoption with AI 3 OAuth TTPs Seen This Month — and How to Detect Them with Entra ID Logs Mastering Software Governance with Hosted Technologies Inventory Shai-Hulud 2.0 Supply Chain Attack: 25K+ Repos Exposing Secrets Get Certified on Wiz Defend for Threat Detection and Response Blueprint for Security: A Guide to Code, Governance, and Response Frameworks Google Unified Security Recommended Program Names Wiz Among First 3 Strategic Partners Introducing Posture Issues: Transform Security Findings into Actionable Outcomes Empower and Accelerate Your SOC with the Blue Agent Exposure Report: 65% of Leading AI Companies Found with Verified Secret Leaks Wizdom 2025 Product Announcements: Extending the Cloud Operating Model When AI Becomes the Heart of Security: Powering a Future You Can Trust AI-Powered Wiz: From Agents to Everyday Intelligence Defend Agentless Workload Detection: Bringing Visibility to Blind Spots in Threat Detection Securing AI Agents with Wiz AI-SPM Introducing Wiz ASM: Context-Driven Attack Surface Management Securing Critical Infrastructure in the Cloud Era: A Policy and Technology Blueprint How CISOs Should Plan Security Budgets for 2026 Beyond the Checkbox: How Wiz Transforms SOC 2 into a Security Powerhouse Bringing Visibility to Kubernetes: Unified Inventory and Network Insight The Foundation Modern AppSec Is Still Missing: Code to Cloud, Rebuilt the Right Way Dismantling a Critical Supply Chain Risk in VSCode Extension Marketplaces Introducing HoneyBee: How We Automate Honeypot Deployment for Threat Research RediShell: Critical Remote Code Execution Vulnerability (CVE-2025-49844) in Redis, 10 CVSS score Defending against database ransomware attacks AI Security 101: Mapping the AI Attack Surface Introducing zeroday.cloud: First-of-its-kind cloud and AI hacking competition Unifying Cloud Risk and Network Defense: Wiz and Check Point The emerging use of malware invoking AI Wiz achieves FedRAMP High authorization Wiz + HCP Terraform: Close the IaC-to-Cloud Infrastructure Security Gap IMDS Abused: Hunting Rare Behaviors to Uncover Exploits Beyond CVEs: The Exploitation of Everyday Misconfigurations Wiz Research Discovers One in Five Organizations Exposed to Systemic Risks in Vibe-Coded Applications - Here's How to Secure Them Introducing Wiz Incident Response: Your Expert Partner for Cloud Security Incidents Shai-Hulud: Ongoing Package Supply Chain Worm Delivering Data-Stealing Malware DORA Compliance in the Cloud Era: Insights from Deloitte and Wiz How Wiz Customers like Brex and FICO See AI Changing Security Wiz Recognized as a Leader in the 2025 IDC MarketScape for ASPM
AI Threat Readiness Pillar 3: Perform AI Code Analysis Natively in Wiz
Salman Ladha, Sharon Ben Zeev · 2026-06-12 · via Wiz Blog | RSS feed

In the past two posts on AI Threat Readiness, we covered how to reduce critical exposures by validating what attackers can exploit in your environment and how to accelerate patching and response by closing the loop from detection to remediation.

Both pillars start with code that's already been written. AI is changing that, accelerating how fast code is produced and how exploitable it can become. The next move is closing the loop at the source.

Today, we are diving deep into Pillar 3: Perform AI Code Analysis. We will explore why traditional scanning must evolve, how to prioritize your most critical repositories, and how Wiz leverages native AI Code Scans, frontier models, and agentic workflows to ensure that fixing vulnerabilities is finally as fast as breaking the applications they were found in.

Why AI Code Scans Matter for AI Threat Readiness 

Traditional code security wasn’t built for AI-driven development. 

As highlighted in our recent State of SDLC Security 2026 report, AI’s primary impact isn't necessarily introducing entirely new risks. It's the amplification of existing ones through faster code generation, contributing to a wider attack surface area with less time for human review. 

Meanwhile, frontier models have collapsed the window between vulnerability discovery and exploitation. Because they can reason about application logic, they’re highly adept at uncovering complex flaws traditional Application Security solutions miss. 

For security teams, this shift surfaces three persistent challenges that existing tools weren't designed to solve:

  • Inconsistent coverage: Traditional SAST relies on predefined patterns and struggles to reason about application intent, data flows, and trust boundaries, allowing business logic flaws and authorization issues to slip through.

  • Alert fatigue: Code security findings often lack the runtime context needed to determine exploitability, leaving developers overwhelmed by alerts that may not matter in production.

  • Manual remediation workflows: Even when vulnerabilities are identified, assigning ownership, prioritizing fixes, and driving remediation remains heavily manual and difficult to scale.

How Wiz Supports Pillar 3: Perform AI Code Analysis 

Knowing Where and When to Scan with AI 

The first step is to understand where to deploy AI analysis across your environment. Since AI models can reason deeply about application logic, they’re highly resource intensive. For an enterprise managing hundreds or thousands of repositories, running AI code scans against every single file is slow, expensive, and complex to scale.

We need a systematic strategy to determine when and where to deploy AI analysis. The deepest, model-driven analysis must be focused exactly where the potential business impact is highest. But how do you pinpoint your most critical repositories?

Start from your cloud, before your code. Rather than looking at code repositories in a vacuum, organizations must understand their real-world runtime architecture. Using the Wiz Service Catalog and Code-to-Cloud mapping, teams can connect deployed resources directly to their source code.

This context makes scanning priorities clear. Repositories supporting customer-facing applications, internet-exposed APIs, and sensitive authentication services can be prioritized for advanced AI analysis, while lower-risk projects continue to benefit from cost-effective baseline scanning.

By combining runtime context with code analysis, organizations can focus AI resources where they deliver the greatest security impact.

Wiz’s Service Catalog showing resources in production environments with High and Critical Sensitive Data findings. This helps security teams prioritize resources for AI Code Scans.

A Layered Approach Using Traditional and AI Scans 

A common misconception is that frontier models will replace traditional scanners. In practice, running heavy AI analysis on every code commit across an enterprise is financially and operationally unsustainable.

Instead, the future of code security relies on highly efficient, lightweight models that deliver outsized value by operating continuously in the background. The effectiveness of this approach is already being validated across our industry.

To balance speed, cost, and depth, organizations need a layered approach to application security. One that balances 

  1. Ongoing, Rules Based SAST (Pattern Matching): Traditional SAST is highly adept at catching well-known, syntax-based flaws like SQL injections and Cross-Site Scripting (XSS). It remains a critical, fast, and cost-effective approach for all codebases and should be used as a form of ongoing security hygiene. Wiz’s Unified Policy Engine lets teams define security policies across IDEs, pull requests, CI/CD pipelines, and cloud environments as a continuous, low-cost baseline that catches common errors before they reach production.

  2. Continuous, AI Code Scans (Semantic Reasoning): AI Code Scans employ commercially available AI models to reason about application code the way a security researcher would. Run these on every major update to identify intent-dependent vulnerabilities like IDOR, business logic errors and broken function-level authorization. In Wiz, our native AI scans are developed around a purpose-built model harness that we’re constantly improving based on research, evolving cloud risks, and learnings from scans across our environment.  

  3. Periodic, Deep "X-Ray" Analysis (Frontier Models): For mission-critical applications, highly intensive architectural scans using advanced frontier models act as the ultimate validation layer to uncover multi-step, complex zero-days. These scans should run on a risk-based cadence, guided by application criticality and the organization’s tolerance for cost and review time.

Together, this approach delivers the best of every world: the speed and cost-efficiency of traditional SAST, the semantic depth of AI reasoning, and the thoroughness of frontier-grade analysis. Because this layered model is natively built and managed for you directly within the Wiz platform, it eliminates the complex infrastructure overhead usually required to spin up and maintain disconnected tools. 

Across all three layers, Wiz operates as an open platform. We offer native static and AI scanning capabilities, but also ingest findings from frontier models or external scanners your teams already use. Every finding, regardless of source, is enriched on the Wiz Security Graph so teams can operationalize AI Threat Readiness under a consistent workflow. 

Context is Queen in Application Security 

Once we have a list of findings, the next step is to enrich, correlate, and prioritize. Most exploitable vulnerabilities don't exist in isolation. They emerge when multiple weaknesses combine across code, identities, cloud resources, and external exposure.

This is where standalone scanners reach their limits. A code scanner can identify a vulnerability, but it cannot determine how that finding interacts with the rest of the environment or whether it contributes to a viable attack path.

The Wiz Security Graph connects relationships across code, cloud resources, identities, runtime activity, and external exposure to provide that missing context. But now, with AI we can go one step further and use adversarial validation to confirm whether or not a finding is truly exploitable. 

The Wiz Red Agent uses the context of AI Code Scans and autonomously tests them end-to-end against your live environment, so teams can not only identify vulnerabilities in code but also confirm their exploitability.    

The Wiz Security Graph can stitch context across several risk domains to surface attack paths for security teams to prioritize. In this case, a missing authentication weakness was mapped to an AI application which was validated by the Wiz Red Agent.

Machine-Speed Remediation at Scale 

Finding and validating a zero-day at machine speed provides limited value if it still takes human engineers weeks to patch it. In a post-AI world, fixing must be as fast as detecting.

When the Red Agent validates a critical attack path, the Wiz Green Agent immediately takes over to automate the remediation lifecycle. Using the full context of your code, pipeline, cloud, and runtime environment, the Green Agent creates a tailored remediation plan to address the root cause which goes beyond generic LLM guidance. It instantly identifies the exact ownership, down to the specific infrastructure, application, or individual developer, and formulates an optimal, step-by-step remediation strategy. It even provides mitigating controls while the code fix is being developed and best practices that improve the overall posture of your application.

It can also work alongside AI coding agents such as Claude Code and CodeMender to help automate the path from validated finding to implemented fix in a truly agentic workflow.

The Wiz Green Agent builds a comprehensive remediation plan including remediations in code.

This outcome is a continuous loop. One where discovery, validation, and remediation work together to help teams move faster without sacrificing security.

Governing the Full Lifecycle

Not every finding may map to an attack path. But, lower-severity findings still represent real risk if left unaddressed. Organizations need a way to track and govern these Posture Issues as ongoing security debt, with consistent ownership and remediation expectations over time.

Wiz helps assess coverage, define remediation SLAs, and measure speed of action and progress. Wiz orchestrates the entire program across environments so organizations can demonstrate risk reduction over time, maintain accountability across teams, and easily report progress to their board. 

The result is a single platform that manages the full lifecycle of a vulnerability, from discovery through governance.

Posture Policies help security teams manage the full lifecycle of individual findings to ensure security debt is being managed in accordance with organizational SLAs.

Practical Steps to Implement Today

Wiz customers looking to operationalize Pillar 3 of the AI Threat Readiness Framework can start building a layered defense today:

  1. Establish the Baseline Radar: Deploy continuous deterministic scanning across all repositories via Wiz Code and the unified policy engine to catch pattern-based vulnerabilities at scale.

  2. Start from Your Cloud, Not Your Code: Use the Wiz Service Catalog and Code-to-Cloud mapping to identify which repositories power your most exposed, sensitive, or privileged live services. Let runtime context drive your scanning priorities.

  3. Activate AI Code Scans on High-Value Repositories: Target customer-facing applications, internet-exposed APIs, and sensitive data flows for deep semantic analysis to surface intent-dependent flaws traditional SAST misses.

  4. Prioritize Risk Issues: Focus remediation efforts on findings that contribute to Red Agent validated attack paths.

  5. Remediate at Machine Speed: Enable the Green Agent to generate pull requests and route fixes directly to code owners and their coding agents, closing the loop without manual bottlenecks.

Securing Applications at Machine Speed

As AI accelerates both software development and vulnerability discovery, the gap between exposure and exploitation will only continue to shrink. Security teams need a continuous risk elimination loop and an operating model where AI-powered defense runs natively across code, cloud, and runtime.

The answer is a layered approach. Pattern matching for baseline hygiene, AI Code Scans for the intent-dependent flaws, and frontier-grade x-ray analysis for the most critical applications. Combined with context and our agents, security teams can operationalize AI Threat Readiness at enterprise scale. 

A core part of this is our native AI Code Scans. Now in private preview, AI Code Scans use agentic analysis to reason about code like a human security researcher, surfacing complex vulnerabilities that traditional pattern-matching engines miss. We designed it as a lightweight, high-value engine that is easy to operationalize, folding into the classic AppSec workflows your team already relies on. AI Code Scans will be included with Wiz Code Advanced, extending the value of the existing subscription with contextual code analysis for defenders.

Talk to a Wiz expert to learn how to operationalize the AI Threat Readiness Framework in your environment. And if you're already a Wiz Code Advanced customer, reach out to your account team to get started with AI Code Scans.