惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

月光博客
月光博客
人人都是产品经理
人人都是产品经理
Hugging Face - Blog
Hugging Face - Blog
有赞技术团队
有赞技术团队
阮一峰的网络日志
阮一峰的网络日志
罗磊的独立博客
博客园_首页
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
大猫的无限游戏
大猫的无限游戏
博客园 - 司徒正美
S
SegmentFault 最新的问题
Jina AI
Jina AI
美团技术团队
酷 壳 – CoolShell
酷 壳 – CoolShell
小众软件
小众软件
WordPress大学
WordPress大学
爱范儿
爱范儿
博客园 - Franky
量子位
V
V2EX
Apple Machine Learning Research
Apple Machine Learning Research
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
雷峰网
雷峰网

Wiz Blog | RSS feed

Meet Wiz for M365: Bringing SaaS into the Security Graph Bringing Security Visibility to Vercel with Wiz Axios NPM Distribution Compromised in Supply Chain Attack Tracking TeamPCP: Investigating Post-Compromise Attacks Seen in the Wild The Wiz Blue Agent, now Generally Available Beyond the Badge: What Achieving Microsoft’s Certified Software Designation Means for Your Cloud Security Introducing the Green Agent: AI-Powered Remediation for the Cloud Three’s a Crowd: TeamPCP trojanizes LiteLLM in Continuation of Campaign KICS GitHub Action Compromised: TeamPCP Strikes Again in Supply Chain Attack Introducing the Wiz Red Agent- AI-Powered Attacker Introducing Wiz AI Application Protection Platform (AI-APP) Introducing Wiz Agents & Workflows: Security at the Speed of AI AI Runtime Threat Detection: From Input to Real-World Impact Trivy Compromised: Everything You Need to Know about the Latest Supply Chain Attack It’s Official: Wiz Joins Google Understanding and Reducing AI Risk in Modern Applications Introducing Wiz Tenant Manager: Multi-Tenant Management for Federated Organizations The Agile FedRAMP Playbook, Part 4: Reactive Risk Management through Enriched Incident Response Wiz Achieves CPSTIC Certification in Spain Seeing AI Clearly: Building Visibility Across Modern AI Applications The Agile FedRAMP Playbook, Part 3: Preventative Risk Management by building Secure by Design Wiz Leads the 2026 Latio Application Security Report with awards in 4 categories Building an Agentic Cloud Security Ecosystem: A Reference Architecture with Wiz MCP and Infosys Cyber Next The Agile FedRAMP Playbook, Part 2: Proactive Risk Management with Continuous Monitoring Cloud-native Security for your Windows environment: Announcing the Wiz Runtime Sensor for Windows Would You Click ‘Accept’? Automatically detecting malicious Azure OAuth applications using LLMs Wiz Named a Leader in The Forrester Wave™: Cloud Native Application Protection Solutions, Q1 2026 From Detection to Remediation: It’s Time to Rethink AppSec Around Exploitability and Root Cause Fixes The Agile FedRAMP Playbook, Part 1: Why Risk is Your Best Starting Point Introducing AI Cyber Model Arena: A Real-World Benchmark for AI Agents in Cybersecurity
Security Posture Management for GitHub: spotting and fixi...
Swaroop Sham, Arnon Trabelsi · 2024-03-29 · via Wiz Blog | RSS feed

A few months ago, Wiz introduced Wiz Code, a leap forward in enabling developers and security teams to shift security left — enabling positive security outcomes from the first lines of code through to production and bolstering cloud detection and response. That was just the beginning.

Today, Wiz is extending its approach to secure the very components that make up the software development lifecycle (SDLC) — and we're starting with the version control system (VCS). Customers can enhance the security of their development environments and reduce their attack surface by identifying and mitigating risks from misconfigured GitHub organizations, repositories, or branches.

As part of this release, customers can also proactively measure their posture against the Source Code Management Best Practices Guide by the Open-Source Security Foundation (OpenSSF). Wiz's security for VCS embraces a comprehensive approach that goes beyond traditional compliance assessment. Wiz takes a comprehensive view that includes the evaluation of multiple risk factors (misconfigurations, identity, and secrets), along with cloud context, to prioritize the most critical attack paths impacting your VCS and the cloud environment where your code is deployed. 

From backdoors to data leaks: why version control system security matters  

A version control system is like a second home to developers. It’s where distributed engineering teams contribute to code, perform reviews, automate testing, deploy workflows, and more.  

Traditionally, the security team’s focus has always been on the code itself; but this can cause potential security risks from misconfigurations in the VCS to be overlooked. Attackers, however, are increasingly shifting their attention to developers (seen as “overprivileged” users inside an organization) and the tools they use.

For example, a compromised developer account on GitHub can create opportunities for an attacker, such as exfiltrating source code. Attackers can then use this code to steal intellectual property or identify security flaws that help them plan their attack steps. Furthermore, attackers who gain access to hardcoded secrets in developer accounts can use those secrets to move from the VCS to cloud accounts.

In the absence of branch protection rules, or if a repository is configured to allow GitHub Actions workflows to automatically approve Pull Requests (PRs), attackers can also inject malicious code, driving a supply chain attack that may potentially reach all downstream users of an application.  

Given the crucial and sensitive role of the VCS in modern software development, the outcomes are always severe, regardless of the scenario. Recent high profile attacks have further highlighted the need for secure posture management for source code systems. 

Security posture management for GitHub  

Wiz takes a comprehensive approach to securing your GitHub instance by combining multiple risk factors — such as public exposure, lateral movement, and cloud context — to prioritize the most critical attack paths affecting your GitHub instances. It also takes account of who made changes and when, which team owns the project, and the cloud environment where the code is deployed.

For example, when Wiz identifies secrets in your repositories, it determines whether the repository is publicly exposed and what impact the leaking of that secret could have on your cloud environment. Then Wiz illustrates the potential attack path created by the leaked secret. 
 
An example of this is shown below, where Wiz provides a visualization of a public version control system repository with cleartext cloud keys granting high privileges. 

Additionally, customers can gauge their alignment with the OpenSSF’s Source Code Management Best Practices. These guidelines are designed to enhance the security and integrity of software development processes; they provide a framework for managing source code, ensuring secure coding practices, and safeguarding against potential misconfigurations. The framework covers various aspects of software development, including source code management posture, access controls, and audit trails. Wiz checks the individual settings of your GitHub organizations, repositories, and branches against 30+ configuration rules to help you assess and improve your development environment’s security posture.

Next steps

Securing the software development lifecycle (SDLC) is a multifaceted effort, and Wiz is just getting started. Wiz is extending its posture management capabilities beyond cloud apps to the infrastructure used to build cloud apps. Wiz is planning to expand coverage to other VCS platforms to ensure ongoing support for developer tools. 

These new capabilities will help Developers, DevOps, and Security teams detect and reduce the risk of misconfigured GitHub instances and remain compliant. To get started, understand how this feature works, and much more, read the latest Wiz docs and release notes. Questions? We’d love to hear from you. Reach out, and our team will be glad to assist.