惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Cyberwarzone
Cyberwarzone
Help Net Security
Help Net Security
L
LINUX DO - 最新话题
Security Archives - TechRepublic
Security Archives - TechRepublic
A
About on SuperTechFans
www.infosecurity-magazine.com
www.infosecurity-magazine.com
Attack and Defense Labs
Attack and Defense Labs
K
KPMG report finds enterprise disconnect between AI and its ROI | CIO
The GitHub Blog
The GitHub Blog
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
Webroot Blog
Webroot Blog
T
Tenable Blog
C
Cyber Attacks, Cyber Crime and Cyber Security
Microsoft Security Blog
Microsoft Security Blog
人人都是产品经理
人人都是产品经理
Simon Willison's Weblog
Simon Willison's Weblog
D
Docker
爱范儿
爱范儿
AI
AI
宝玉的分享
宝玉的分享
PCI Perspectives
PCI Perspectives
The Register - Security
The Register - Security
Project Zero
Project Zero
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
IT之家
IT之家
S
Securelist
Scott Helme
Scott Helme
B
Blog
Forbes - Security
Forbes - Security
Google DeepMind News
Google DeepMind News
T
The Blog of Author Tim Ferriss
月光博客
月光博客
P
Proofpoint News Feed
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
F
Fortinet All Blogs
H
Help Net Security
Last Week in AI
Last Week in AI
N
News and Events Feed by Topic
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
MyScale Blog
MyScale Blog
I
InfoQ
P
Privacy International News Feed
V
V2EX
有赞技术团队
有赞技术团队
G
Google Developers Blog
阮一峰的网络日志
阮一峰的网络日志
腾讯CDC
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
S
Schneier on Security
T
Tailwind CSS Blog

Wiz Blog | RSS feed

Meet Wiz for M365: Bringing SaaS into the Security Graph Bringing Security Visibility to Vercel with Wiz Axios NPM Distribution Compromised in Supply Chain Attack Tracking TeamPCP: Investigating Post-Compromise Attacks Seen in the Wild The Wiz Blue Agent, now Generally Available Beyond the Badge: What Achieving Microsoft’s Certified Software Designation Means for Your Cloud Security Introducing the Green Agent: AI-Powered Remediation for the Cloud Three’s a Crowd: TeamPCP trojanizes LiteLLM in Continuation of Campaign KICS GitHub Action Compromised: TeamPCP Strikes Again in Supply Chain Attack Introducing the Wiz Red Agent- AI-Powered Attacker Introducing Wiz AI Application Protection Platform (AI-APP) Introducing Wiz Agents & Workflows: Security at the Speed of AI AI Runtime Threat Detection: From Input to Real-World Impact Trivy Compromised: Everything You Need to Know about the Latest Supply Chain Attack It’s Official: Wiz Joins Google Understanding and Reducing AI Risk in Modern Applications Introducing Wiz Tenant Manager: Multi-Tenant Management for Federated Organizations The Agile FedRAMP Playbook, Part 4: Reactive Risk Management through Enriched Incident Response Wiz Achieves CPSTIC Certification in Spain Seeing AI Clearly: Building Visibility Across Modern AI Applications The Agile FedRAMP Playbook, Part 3: Preventative Risk Management by building Secure by Design Wiz Leads the 2026 Latio Application Security Report with awards in 4 categories Building an Agentic Cloud Security Ecosystem: A Reference Architecture with Wiz MCP and Infosys Cyber Next The Agile FedRAMP Playbook, Part 2: Proactive Risk Management with Continuous Monitoring Cloud-native Security for your Windows environment: Announcing the Wiz Runtime Sensor for Windows Would You Click ‘Accept’? Automatically detecting malicious Azure OAuth applications using LLMs Wiz Named a Leader in The Forrester Wave™: Cloud Native Application Protection Solutions, Q1 2026 From Detection to Remediation: It’s Time to Rethink AppSec Around Exploitability and Root Cause Fixes The Agile FedRAMP Playbook, Part 1: Why Risk is Your Best Starting Point Introducing AI Cyber Model Arena: A Real-World Benchmark for AI Agents in Cybersecurity Wiz + Spotify Backstage: Security at the Developer’s Desk Building AI Security Together: New Ways to Partner with Wiz for AI Security in 2026 Hacking Moltbook: The AI Social Network Any Human Can Control The Year in Wiz Research: 2025 Most Read Blogs WizExtend is Here: AI and Cloud Security Insights in Your Daily Workflow From Detection to Remediation: Wiz in Your JetBrains IDE Agentic Browser Security: 2025 Year-End Review CodeBreach: Infiltrating the AWS Console Supply Chain and Hijacking AWS GitHub Repositories via CodeBuild A 90-Day Action Plan to Turn Resolutions into Results with Wiz Introducing the Wiz Partner Alliance: A New Chapter for Partner Success Preparing for Post-Quantum Cryptography Wiz Recognized as a 2025 Customers’ Choice in the Gartner® Peer Insights™ Voice of the Customer for CNAPP Expanding the Zero Critical Club to set a new standard for AppSec and SecOps teams Snipping the Long Tail of Shai-Hulud 2.0 Protecting Against Zero-Day Vulnerabilities with SOC-Level ASM Alert MongoBleed (CVE-2025-14847) exploited in the wild: everything you need to know The Kenna Transition: Your Strategic Shift to Exposure Management From MCP to Vibe Coding: Full Endpoint Visibility in Wiz AI Security Bringing Oracle Cloud Identity to Wiz Zero‑Days in the Age of AI: Behind the Scenes of ZeroDay.cloud 2025, with a Record High of CVEs in Critical Cloud Infra Gogs 0-Day Exploited in the Wild Code to Cloud Attacks: From Github PAT to Cloud Control Plane Top AWS re:Invent Announcements for Security Teams in 2025 React2Shell: Technical Deep-Dive & In-the-Wild Exploitation of CVE-2025-55182 React2Shell (CVE-2025-55182): Everything You Need to Know About the Critical React Vulnerability Wiz Product Announcements at re:Invent 2025: Expanding Visibility from Code to Cloud Introducing Wiz SAST: Where Code Risk Meets Cloud Context Wiz Becomes Fastest Security ISV to Reach $1 Billion in AWS Marketplace Lifetime Sales It's Here! Wiz Exposure Management is Now GA Shai-Hulud 2.0 Aftermath: Trends, Victimology and Impact Service Catalog is Here: Expand Risk Visibility for Your Service and Its Dependencies, Simplify Issue Ownership WizOS: Powering Secured Image Adoption with AI 3 OAuth TTPs Seen This Month — and How to Detect Them with Entra ID Logs Mastering Software Governance with Hosted Technologies Inventory Shai-Hulud 2.0 Supply Chain Attack: 25K+ Repos Exposing Secrets Get Certified on Wiz Defend for Threat Detection and Response Blueprint for Security: A Guide to Code, Governance, and Response Frameworks Google Unified Security Recommended Program Names Wiz Among First 3 Strategic Partners Introducing Posture Issues: Transform Security Findings into Actionable Outcomes Empower and Accelerate Your SOC with the Blue Agent Exposure Report: 65% of Leading AI Companies Found with Verified Secret Leaks Wizdom 2025 Product Announcements: Extending the Cloud Operating Model When AI Becomes the Heart of Security: Powering a Future You Can Trust AI-Powered Wiz: From Agents to Everyday Intelligence Defend Agentless Workload Detection: Bringing Visibility to Blind Spots in Threat Detection Securing AI Agents with Wiz AI-SPM Introducing Wiz ASM: Context-Driven Attack Surface Management Securing Critical Infrastructure in the Cloud Era: A Policy and Technology Blueprint How CISOs Should Plan Security Budgets for 2026 Beyond the Checkbox: How Wiz Transforms SOC 2 into a Security Powerhouse Bringing Visibility to Kubernetes: Unified Inventory and Network Insight The Foundation Modern AppSec Is Still Missing: Code to Cloud, Rebuilt the Right Way Dismantling a Critical Supply Chain Risk in VSCode Extension Marketplaces Introducing HoneyBee: How We Automate Honeypot Deployment for Threat Research RediShell: Critical Remote Code Execution Vulnerability (CVE-2025-49844) in Redis, 10 CVSS score Defending against database ransomware attacks AI Security 101: Mapping the AI Attack Surface Introducing zeroday.cloud: First-of-its-kind cloud and AI hacking competition Unifying Cloud Risk and Network Defense: Wiz and Check Point The emerging use of malware invoking AI Wiz achieves FedRAMP High authorization Wiz + HCP Terraform: Close the IaC-to-Cloud Infrastructure Security Gap IMDS Abused: Hunting Rare Behaviors to Uncover Exploits Beyond CVEs: The Exploitation of Everyday Misconfigurations Wiz Research Discovers One in Five Organizations Exposed to Systemic Risks in Vibe-Coded Applications - Here's How to Secure Them Introducing Wiz Incident Response: Your Expert Partner for Cloud Security Incidents Shai-Hulud: Ongoing Package Supply Chain Worm Delivering Data-Stealing Malware DORA Compliance in the Cloud Era: Insights from Deloitte and Wiz How Wiz Customers like Brex and FICO See AI Changing Security Wiz Recognized as a Leader in the 2025 IDC MarketScape for ASPM
A Framework for AI Threat Readiness
Alon Schindel, Raaz Herzberg · 2026-05-09 · via Wiz Blog | RSS feed

Recent and continued advancements in AI models have fundamentally changed how vulnerabilities are found and exploited. Published research, including our own AI cyber model arena, has shown that frontier models can now autonomously discover zero-day vulnerabilities, generate working exploits, and chain multiple weaknesses together –  changing the scale and speed at which risk emerges.

The pace is still accelerating: more vulnerabilities will be discovered and disclosed, and the time between discovery and exploitation will continue to shrink. In the short term, exploit development accelerates. In the medium term, the volume of AI-discovered vulnerabilities increases. Over time, security must adapt to continuous, AI-driven discovery and exploitation.

We believe this is ultimately a very positive shift for security, and that it will lead to software becoming more secure than ever. For example, after scanning with Mythos, the Firefox team fixed more security bugs in April than they had in the entire previous year.

At the same time, this also creates a new world and a new dynamic of risk that organizations need to prepare for. As vulnerability discovery accelerates, organizations will need to move faster in how they assess exposure, prioritize what matters, and remediate issues before they can be exploited.

A Practical Model for AI Threat Readiness

AI readiness is driven by two factors: speed of action and breadth of visibility.

As AI increases the speed of both software development and vulnerability discovery, the gap between exposure and exploitation is shrinking. Security programs need to continuously reduce the time between identification, validation, and remediation across code, infrastructure, and runtime.

Breadth of visibility requires coverage across the full environment, including cloud, code, private infrastructure, SaaS, and the software supply chain. It also requires different levels of analysis, from baseline detection to deeper, AI-driven analysis of complex and exploitable risk. This applies across each layer of the environment.

The following framework is our suggestion for how organizations can think through next steps and evolve their strategy as they navigate a broader shift in the threat landscape. It is built on four key pillars – each of which organizations can start to apply today.

1. Eliminate Critical Risk, Reduce Exposure and Scan for Any Exposure with AI

As more vulnerabilities are discovered and exploitation accelerates, the first priority is to reduce unnecessary exposure. Sensitive assets should not be reachable from the internet or exposed to untrusted paths, regardless of patch status. The goal is not only to fix known critical issues, but to reduce what is reachable, validate what can actually be exploited, and make sure new risk does not depend on manual triage.

From there, organizations need to understand how quickly they can patch and respond across exposed technologies. As the number of CVEs increases and exploitation windows shrink, teams need clear ownership, prioritization, and execution paths before the next urgent vulnerability appears on an exposed technology. Any exposed application, service, or technology should be prioritized based on reachability, exploitability, and business impact, with a clear and fast process to route the issue to the right owner and drive remediation.

Finally, you must scan every exposure with AI. Attacks are increasingly moving up the stack from exposed infrastructure to applications, APIs, business logic, and identity flows. Traditional ASM helps identify what is exposed, but AI-driven analysis is needed to continuously scan every exposure, determine whether it can be exploited, and understand what it would enable an attacker to do. This makes exposure reduction, fast patching, and continuous AI-driven validation critical parts of the same operating model.

This risk is already measurable. Our data shows that 30% of cloud environments have at least one high-impact machine running software that is exposed externally. Even if that software is not exploitable today, the pace of AI-driven vulnerability discovery means it is likely only a matter of time before it becomes exploitable.

While direct exposure of sensitive data is less common, indirect risk is not. Only 2% of organizations have exposed software running on machines that also host sensitive data. However, 19% of organizations have exposed software on systems with IAM privileges that grant access to sensitive internal assets. In 6% of organizations, exposed software sits on machines with paths to administrative privileges, meaning a single vulnerability could provide attackers with full control of the environment.

“Exposed Versioned Tech” = compute ASM confirmed is exposing versioned software that may contain vulnerabilities.

Crucially, in addition to the above data, the public preview of the Wiz Red Agent, which is an external AI attacker, offers a massive, real-world experiment in large-scale, AI-driven vulnerability exploitation. Since it launched, this AI-powered attacker has been continuously learning and refining its adversarial capabilities across an ever-expanding dataset of over 150,000 production web applications and APIs scanned weekly.

The agent analyzed application logic, processing 100B+ tokens weekly across hundreds of enterprise environments, leading to rapid optimization of its multi-step attack patterns. The improvement is quantified by the results: the agent has matured from identifying basic structural vulnerabilities to consistently uncovering more than 3,000 high and critical exploitable logic flaws weekly, the "un-findable" risks that manual and traditional scanning methods routinely miss. 

Key steps

  1. Continuous Discovery and Mapping

    • Continuously discover and inventory internet-facing assets, APIs, and services

    • Use AI-powered discovery to identify shadow APIs that may not be documented or visible through traditional scanning

    • Map legacy applications, dependencies, and ownership gaps across environments

  2. Exposure Control and Mitigation

    • Reduce unnecessary internet exposure and continuously monitor for newly exposed assets as environments change

    • Segment or isolate unpatchable and high-risk systems

    • Ensure sensitive assets and privileged access paths are not exposed, regardless of patch status

  3. AI-driven Risk Analysis and Validation

    • Continuously analyze every exposed application, API, service, and identity flow with AI to identify application-layer weaknesses

    • Validate which exposures are actually exploitable, not just reachable.

    • Simulate attacker behavior to uncover end-to-end attack paths across application and infrastructure layers

  4. Establishing Remediation Processes

    • Define remediation playbooks so new critical issues are routed and resolved quickly

Automation playbooks

  • Continuously scan exposed applications and APIs with AI

  • Continuously remediate AI-validated, high-confidence risks

  • Monitor across exposed services

  • Remove unused or orphaned assets

Measure

  • ASM coverage: % of known external assets continuously monitored

  • AI exposure coverage: % of exposed apps/APIs scanned with AI

  • % of known external assets hosting sensitive data or impactful permissions (the goal is to get  to 0)

  • % of exposed assets mapped to owner/service/repo/cloud resources

  • % of exposure findings converted into remediation actions

  • Risk MTTR (time from when the exposure is discovered to remediation)

  • Reduction in externally reachable attack surface

  • Reduction in externally exposed critical risks

2. Accelerate Patching and Response

As the time between discovery and exploitation shrinks, response windows are growing smaller – patching speed and zero-day response become critical. Advanced models are already capable of rapidly identifying and exploiting vulnerabilities, compressing the window available to respond.

Delays between identification and remediation leave systems exposed, underscoring the need to move from ad hoc fixes to continuous, automated remediation. 

This requires distinguishing between a vulnerability in third-party software, such as a CVE, an instance of that vulnerability in your environment, and a vulnerability in first-party code. Each requires a different approach to detection, prioritization, and remediation.

At the same time, organizations should reduce the total volume of vulnerable components in the environment. This includes moving to hardened base images, minimizing unnecessary packages and dependencies, standardizing approved images, and continuously removing outdated or unsupported components. The less vulnerable software teams carry by default, the faster they can respond when a new CVE or zero-day emerges.

Key steps

  1.  Define Ownership and Remediation Flows

    • Review high-exposure technologies to identify where risk is most likely to concentrate and ensure you have clear patching flow and ownership

    • Map ownership and trace issues to their source in code or configuration to enable faster remediation and clear accountability

    • Use AI-driven analysis to identify ownership and impacted systems and auto-remediate back in code when possible

  2. Proactive Hardening and Prevention

    • Standardize on hardened components and base images to reduce constant patching where possible

    • Enforce guardrails to prevent known risky patterns and vulnerable components from reaching production

  3. Zero-Day Response

    • Establish response workflows for newly disclosed vulnerabilities so zero-day issues can be triaged and addressed quickly

Automation playbooks

  • Prioritize vulnerabilities using exploitability, known exploitation, external exposure, runtime usage, asset criticality, identity privileges, and data sensitivity; assign SLAs based on exposure and exploitability

  • Automatically route issues to likely owners using AI-driven context

  • Use AI to decide on the fastest safe action: patch host, upgrade package, rebuild image, update application code, change cloud config, remove exposure, disable feature, or apply compensating control

Measure

  • Vulnerability scan coverage across hosts, containers, cloud assets, applications, and packages

  • Time from disclosure to impacted asset inventory

  • Patch MTTR (time from vulnerability being identified to remediated)

  • % of issues remediated at source vs. downstream

  • % of vulnerable assets with owner mapping

  • % of vulnerabilities prioritized with AI-assisted context

  • % of vulnerabilities with AI-recommended remediation path

3. Perform Deep AI Code Analysis

Advanced frontier AI models are already being applied to security code analysis, enabling the identification of more complex issues. In the Wiz Cyber Model Arena benchmark, frontier models completed almost half of the challenges. These capabilities reflect a new class of model-driven analysis that goes beyond traditional SAST. Advanced AI code analysis identifies complex logic flaws (like IDOR) and insecure behavior across application flows, dependencies, APIs, and trust boundaries. It also determines how low-to-medium severity vulnerabilities can be chained into exploitable paths. AI's growing capabilities are also reducing the complexity of discovering critical vulnerabilities in binary code, as shown in the recent GitHub RCE vulnerability (CVE-2026-3854).

Because this level of analysis requires deeper reasoning across large codebases and produces more complex findings to investigate and validate, organizations need to prioritize which applications and services should be scanned first. The focus should start with the most critical code components: customer-facing applications, internet-exposed services, sensitive data flows, authentication and authorization logic, and other business-critical systems. Broader code coverage should continue through continuous baseline scanning, while the deepest model-driven analysis focuses on where the potential impact is highest.

This also requires building workflows to validate and remediate the findings. Model-driven analysis will surface complex issues that need to be confirmed, prioritized, routed to the right engineering owner, and fixed at the source. The goal is not only to find more issues, but to create a lifecycle where high-impact findings can move quickly from detection to validation to remediation.

As advanced models are applied more broadly, how they are used in practice is still evolving. Teams are starting to explore how to apply the most cost-effective model for each task, which codebases to prioritize, and how to use these approaches alongside existing traditional SCA and SAST scanners.

Key steps

  • Prioritize code to be scanned with advanced AI models based on code source, exposure, and business criticality

  • Analyze complex, customer-facing code using advanced models to identify logic flaws, chained vulnerabilities, and insecure application flows

  • Build a continuous AI-driven lifecycle for detection, triage, validation, and remediation

Automation playbooks

  • Build mechanism for code bases to be prioritized for advanced model scanning based on runtime and exposure changes

  • Automate validation and prioritization for code findings

  • Automate remediation workflows for eligible code issues through the organization’s AI coding agents 

Measure

  • AI-powered code scanning coverage

  • Code issue MTTR (time from identification to fix in code)

  • AI finding validation time 

  • Number of critical code findings in internet-exposed services

4. Detect and Respond to Threats in Real Time 

Even with strong prevention, some risk can materialize to an active threat in runtime. In the AI era, the speed of development, deployment, and exploitation means detection and response can no longer depend on manual investigation alone. Security teams need to move from alert review to automated response workflows that can quickly investigate a suspicious identified behavior, understand its context, and take action quickly to limit impact.

This requires full context across code, cloud, runtime, identity, network, workload, and data. Without that context, security operations teams are left with isolated alerts that require manual correlation. With context, detection can become more precise, investigations can be automated, and response can be routed or triggered based on the actual risk and blast radius.

Containment also needs to become faster and more standardized. For high-fidelity runtime threats, organizations should define automated playbooks that can isolate workloads, revoke risky permissions, block suspicious communication, rotate secrets, open incidents, notify owners, and preserve forensic evidence. Human approval can still be required for sensitive actions, but the investigation and recommended response should not start from scratch every time.

Detection and response in the AI era should be measured by whether teams can detect meaningful attacker behavior, investigate with full context, and contain threats quickly enough to reduce business impact.

Key steps

  • Achieve comprehensive real-time visibility across all environments by ingesting cloud and workload telemetry, including runtime telemetry for enriched context and runtime detection. This allows teams to understand how applications behave at runtime, how cloud identities are used, what data is being accessed, and how infrastructure is controlled. Guidance on which signals to prioritize should be based on the ability to trace these behaviors across environments.

    • Baseline visibility should include identity provider logs (such as Entra, Okta, and Google Workspace audit logs)

    • Ingest cloud audit logs (such as CloudTrail, Azure Activity Logs, and GCP Cloud Audit Logs)

    • Include version control system audit logs and granular telemetry for data access, secrets usage, and network activity to provide additional context for detection and investigation

  • Use AI to automatically investigate each threat by following multiple investigation steps to finally render a verdict (e.g., malicious, security test, undetermined)

  • Use AI to establish a baseline of regular behaviour and continuously recommend fine-tuning recommendations to reduce noise, and focus on high-fidelity, actionable threats

  • Enhance agent accuracy by adding environment-specific context and memory consisting of previously investigated data sets 

Automation playbooks

  • Automate response and remediation at the source through automatic assignment of ownership based on code-to-cloud context

  • For high-fidelity malicious threats, automate containment and response workflows where applicable and according to a sensitivity of actions (e.g. isolate workload, revoke data access, revoke identity access, block process)

Measure

  • Threat MTTR (time from detection to threat resolution) 

  • Agentic threat triage coverage (% of alerts investigated by AI with clear and accurate verdict)

  • Agentic threat containment coverage (% of alerts led to containment by AI)

  • Continuously validate detection efficacy and response speed through attack simulation to stress-test technology, process and people

Build and Manage the Readiness Program

As exposure and response cycles accelerate, it helps to establish a consistent way to operate over time. This includes defining ownership, setting expectations, and tracking progress against clear outcomes.

What to do

  • Establish governance and clear ownership, including a defined committee, roles, and decision-making processes

  • Define outcomes and key metrics to track progress and report to executive stakeholders

  • Create policies, SLAs, and exception processes to ensure risk is addressed consistently

Helpful metrics include SLA adherence, exception volume, coverage across assets and environments, and progress against defined security outcomes.

How Wiz Helps 

As AI accelerates how vulnerabilities are discovered and exploited, organizations need a security operating model that can continuously reduce exposure, validate real risk, and respond faster than attackers can adapt. At its core, this becomes a continuous operational flywheel: continuously discover exposure, validate exploitability, prioritize real operational risk, and remediate at machine speed as environments and exploitability evolve over time.

Wiz combines the contextual understanding of the Wiz Security Graph with purpose-built AI agents to help organizations reduce risk across modern cloud and AI-native environments. With context across code, cloud, and runtime, Wiz helps teams continuously validate exposure, prioritize real operational risk, and accelerate remediation.

Horizontal agentic security built for the AI era

1. Eliminate critical risk and scan any exposure with AI

  • AI Application Protection Platform (AI APP) helps secure AI applications across modern cloud and AI-native environments by connecting risk context across code, cloud, and runtime

  • Wiz Attack Surface Management (ASM) continuously discovers exposed applications, infrastructure, APIs, identities, and runtime environments so teams can reduce unnecessary exposure

  • Red Agent uses AI-powered, context-aware attack simulation to identify and validate complex exploitable attack paths, including application-layer and identity-driven risk traditional testing often misses

2. Accelerate patching and zero-day response

  • Green Agent helps identify the fastest and safest remediation path across code, infrastructure, runtime, and AI application context

  • Workflows and integrations help operationalize remediation and zero-day response across development and security teams

  • Preventative controls and hardened baselines such as Wiz OS help reduce vulnerable components and start secure by default

3. Perform deep AI code analysis

  • Findings from advanced AI model scans can be brought into the Wiz Security Graph to correlate cloud and application context for prioritization and remediation (Preview)

  • Advanced AI-driven code and application analysis scans applications, APIs, dependencies, and runtime environments to identify complex vulnerabilities, insecure application flows, and high-risk attack paths (Preview)

4. Detect and contain threats in real time

  • Wiz Defend provides runtime visibility and threat detection across workloads, cloud environments, Kubernetes, identities, and AI runtime activity

  • Blue Agent investigates threats and suspicious behavior using the broader context of the Wiz Security Graph to determine which risks are actively being exercised

  • Automated response workflows help contain threats and operationalize response at machine speed

Build and operationalize the readiness program

Organizations can operationalize this framework with clear ownership, governance, SLAs, and measurable outcomes. As exploitability changes and new risk is introduced, teams need visibility into exposure, validation, remediation speed, runtime coverage, and operational readiness across the environment.

We are continuing to learn and work with customers on this journey - expanding and building on this framework as we go.