惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

雷峰网
雷峰网
博客园 - 聂微东
酷 壳 – CoolShell
酷 壳 – CoolShell
宝玉的分享
宝玉的分享
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
罗磊的独立博客
Hugging Face - Blog
Hugging Face - Blog
T
Tailwind CSS Blog
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
IT之家
IT之家
博客园_首页
博客园 - 三生石上(FineUI控件)
博客园 - 叶小钗
Apple Machine Learning Research
Apple Machine Learning Research
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
量子位
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
人人都是产品经理
人人都是产品经理
美团技术团队
小众软件
小众软件
Jina AI
Jina AI
S
SegmentFault 最新的问题
博客园 - Franky
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com

Wiz Blog | RSS feed

Meet Wiz for M365: Bringing SaaS into the Security Graph Bringing Security Visibility to Vercel with Wiz Axios NPM Distribution Compromised in Supply Chain Attack Tracking TeamPCP: Investigating Post-Compromise Attacks Seen in the Wild The Wiz Blue Agent, now Generally Available Beyond the Badge: What Achieving Microsoft’s Certified Software Designation Means for Your Cloud Security Introducing the Green Agent: AI-Powered Remediation for the Cloud Three’s a Crowd: TeamPCP trojanizes LiteLLM in Continuation of Campaign KICS GitHub Action Compromised: TeamPCP Strikes Again in Supply Chain Attack Introducing the Wiz Red Agent- AI-Powered Attacker Introducing Wiz AI Application Protection Platform (AI-APP) Introducing Wiz Agents & Workflows: Security at the Speed of AI AI Runtime Threat Detection: From Input to Real-World Impact Trivy Compromised: Everything You Need to Know about the Latest Supply Chain Attack It’s Official: Wiz Joins Google Understanding and Reducing AI Risk in Modern Applications Introducing Wiz Tenant Manager: Multi-Tenant Management for Federated Organizations The Agile FedRAMP Playbook, Part 4: Reactive Risk Management through Enriched Incident Response Wiz Achieves CPSTIC Certification in Spain Seeing AI Clearly: Building Visibility Across Modern AI Applications The Agile FedRAMP Playbook, Part 3: Preventative Risk Management by building Secure by Design Wiz Leads the 2026 Latio Application Security Report with awards in 4 categories Building an Agentic Cloud Security Ecosystem: A Reference Architecture with Wiz MCP and Infosys Cyber Next The Agile FedRAMP Playbook, Part 2: Proactive Risk Management with Continuous Monitoring Cloud-native Security for your Windows environment: Announcing the Wiz Runtime Sensor for Windows Would You Click ‘Accept’? Automatically detecting malicious Azure OAuth applications using LLMs Wiz Named a Leader in The Forrester Wave™: Cloud Native Application Protection Solutions, Q1 2026 From Detection to Remediation: It’s Time to Rethink AppSec Around Exploitability and Root Cause Fixes The Agile FedRAMP Playbook, Part 1: Why Risk is Your Best Starting Point Introducing AI Cyber Model Arena: A Real-World Benchmark for AI Agents in Cybersecurity
AI Threat Readiness Pillar 1: Reduce Critical Exposures &...
Shaked Rotlevi · 2026-06-04 · via Wiz Blog | RSS feed

AI is changing how software is built, deployed, and secured. It is also changing how attackers operate.

The barrier to exploitation is getting lower as AI helps attackers move faster from vulnerability disclosure to working exploit. Vulnerabilities that once took days or weeks to weaponize can now be analyzed and exploited in hours. At the same time, the number of vulnerabilities continues to grow, making it increasingly difficult for security teams to determine which issues actually matter. The challenge has shifted from finding vulnerabilities, to identifying which ones actually matter.

To help organizations navigate this shifting landscape, we created the AI Threat Readiness Framework that outlines an operating model designed to help organizations prepare for the AI era. 

In this blog series, we'll explore each pillar of the framework, starting with Pillar 1: Reduce critical exposures & scan with AI.

Why reducing critical exposures matters for AI Threat Readiness 

Most organizations have more security findings than they can realistically address. Security teams are overwhelmed with alerts across cloud infrastructure, applications, SaaS platforms, APIs, identities, and AI services- yet not every vulnerability represents a meaningful risk. As exploitation timelines shrink, teams need to focus less on the volume of vulnerabilities and more on reducing the specific exposures attackers can actually use to impact the environment.

The first priority is reducing unnecessary exposure, which starts with visibility. Organizations need a unified view of their attack surface across cloud, SaaS, AI, and on-premises environments to understand what is exposed to the internet. Once identified, teams must evaluate assets across three key dimensions:

  • Reachability: Can an attacker access it?

  • Exploitability: Can it actually be compromised?

  • Business impact: What would happen if it were exploited?

Answering these questions requires more than an asset inventory. Security teams need an outside-in view to understand what is truly reachable and exploitable from an attacker's perspective, connected directly to business context-such as what data the asset can access, its permissions, ownership, and connected critical systems. Combining an outside-in attacker view with inside-out environmental context helps teams focus on exposures presenting real business risk.

At the same time, critical vulnerabilities are no longer limited to just CVEs. With the rapid rise of AI-assisted vibe-coding, logic flaws have become far more frequent and easier to exploit- as evidenced by the Moltbook, Base44, and DeepSeek flaws our research team recently discovered in the wild in the past year. Attackers increasingly target APIs, authentication mechanisms, authorization controls, business logic, and identity workflows- weaknesses that traditional signature-based scanning often misses.

To keep pace with AI-powered adversaries, organizations need to scan exposures with AI to uncover complex attack chains at a speed and scale impossible to achieve manually. By focusing on validated, exploitable attack paths, teams can cut through the noise, prioritize what matters most, and drive quick action through clear ownership and efficient remediation workflows.

The goals of this pillar are to:

  • Reduce unnecessary exposure

  • Validate what attackers can actually exploit

  • Continuously identify exploitable risks using AI

  • Prioritize based on real-world risk

  • Establish clear ownership and remediation workflows

How Wiz supports Pillar 1: Reduce Exposures & Scan with AI

Reducing the attack surface with Wiz ASM

Wiz Attack Surface Management (ASM) helps organizations identify and reduce critical exposures across cloud, SaaS, AI, and on-premises environments. Traditional attack surface scanners primarily operate from the outside, discovering internet-facing assets but lacking the context needed to understand their significance. Wiz ASM combines external visibility with internal cloud context to provide a complete view of an organization's attack surface.

Wiz ASM continuously discovers internet-facing assets including domains, IP addresses, APIs, cloud services, and SaaS applications. Discovery is enriched with data from cloud network configurations, API endpoints, code repositories, and runtime telemetry to uncover blind spots like unmanaged cloud services, shadow APIs, and rapidly created AI-generated or "vibe-coded" applications. Every potential exposure is validated from the outside to confirm it is reachable from the internet. Wiz then analyzes exposed technologies and validates exploitable risks such as vulnerabilities, misconfigurations, exposed secrets, and weak or default credentials.

AI-powered exploitation with the Red Agent 

Attackers increasingly target vulnerabilities that traditional scanners struggle to identify, including authorization flaws, business logic weaknesses, and complex API attack chains. Red Agent is Wiz's autonomous AI-powered attacker that continuously identifies complex exploitable risks at machine speed. It complements signature-based scanning with AI-powered exploitation that reasons about application behavior and adapts its approach based on observed responses.

Red Agent begins by mapping the complete API attack surface, aggregating endpoints from cloud APIs, Swagger and OpenAPI documentation, the Wiz Runtime Sensor, and its AI-powered web crawler. The crawler analyzes client-side code to uncover shadow APIs, forgotten test services, and undocumented endpoints. Once APIs are identified, Red Agent performs context-aware scanning to uncover hidden, logic-driven vulnerabilities. By analyzing API specifications, reasoning about application workflows, and dynamically adapting attack paths, it identifies risks such as broken authorization, improper authentication, business logic flaws, injection vulnerabilities, excessive data exposure, and multi-step attack chains in custom-built and AI-generated applications. Red Agent helps teams defend at machine-speed, finding exploitable risks continuously at scale in minutes that would take a human researcher weeks or months to uncover.

Prioritizing exposures with context

To effectively prioritize exposures and understand impact, teams need to determine which ones represent meaningful risk. Wiz takes a unique approach, mapping external risks to your environmental context. Wiz correlates validated findings from ASM and Red Agent with context from the Wiz Security Graph, connecting exposures to cloud infrastructure, identities, sensitive data, application ownership, and potential attack paths.

This allows security teams to prioritize based on reachability, exploitability, and business impact, focusing on the exposures that could realistically lead to data access, privilege escalation, lateral movement, or business disruption. By connecting external findings to internal context, Wiz helps organizations understand not only what is exposed, but what an attacker could actually achieve if that exposure were exploited.

Remediate at AI-speed with the Green Agent

Once critical exposures are identified, organizations need to move quickly to reduce risk. Wiz helps teams accelerate remediation through ownership mapping, workflow automation, and AI-powered guidance. Findings can be automatically routed to the appropriate application owner, infrastructure team, or developer, reducing the manual effort required to triage and assign work.

Teams can leverage Green Agent to identify the root cause of an exposure finding and receive context-aware remediation guidance. Green Agent synthesizes information from across the Wiz platform, including code-to-cloud relationships, ownership data, Security Graph context, and historical remediation patterns, helping teams resolve issues faster and with greater confidence. Combined with Wiz Workflows, organizations can establish repeatable remediation processes that continuously reduce exposure and improve response times.

Practical steps to implement today

Wiz customers looking to establish Pillar 1 of the AI Threat Readiness Framework should prioritize the following steps:

  • Enable Advanced ASM: Enable Advanced ASM to extend Wiz to any asset and get comprehensive external risk assessment.

  • Scan with the Red Agent: Activate the AI-attacker to continuously discover logic flaws and complex vulnerabilities across your applications and APIs.

  • Prioritize Validated External Risk Issues: First focus on the Validated External Risk Issues to remove proven exploitable attack paths before attackers can take adventage.

  • Automate remediation workflows with Green Agent: Establish clear organizational workflows that utilize Green Agent’s contextual root-cause guidance to deliver actionable fixes directly to resource owners.

Reducing critical exposures and continuously validating exploitability is the foundation of AI threat readiness. Organizations that can identify, prioritize, and remediate exploitable risk at machine speed will be better positioned to keep pace with AI-powered attackers.


Check out our next blog in this series to learn about Pillar 2: Accelerate Patching and Response

Ready to get started? Request a demo.