惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

G
Google Developers Blog
Apple Machine Learning Research
Apple Machine Learning Research
小众软件
小众软件
Recent Announcements
Recent Announcements
阮一峰的网络日志
阮一峰的网络日志
IT之家
IT之家
A
About on SuperTechFans
量子位
Engineering at Meta
Engineering at Meta
B
Blog
The Cloudflare Blog
博客园 - 【当耐特】
Hugging Face - Blog
Hugging Face - Blog
Y
Y Combinator Blog
J
Java Code Geeks
D
DataBreaches.Net
aimingoo的专栏
aimingoo的专栏
T
Tailwind CSS Blog
H
Help Net Security
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
V
V2EX
Stack Overflow Blog
Stack Overflow Blog
C
Check Point Blog
酷 壳 – CoolShell
酷 壳 – CoolShell

Wiz Blog | RSS feed

Meet Wiz for M365: Bringing SaaS into the Security Graph Bringing Security Visibility to Vercel with Wiz Axios NPM Distribution Compromised in Supply Chain Attack Tracking TeamPCP: Investigating Post-Compromise Attacks Seen in the Wild The Wiz Blue Agent, now Generally Available Beyond the Badge: What Achieving Microsoft’s Certified Software Designation Means for Your Cloud Security Introducing the Green Agent: AI-Powered Remediation for the Cloud Three’s a Crowd: TeamPCP trojanizes LiteLLM in Continuation of Campaign KICS GitHub Action Compromised: TeamPCP Strikes Again in Supply Chain Attack Introducing the Wiz Red Agent- AI-Powered Attacker Introducing Wiz AI Application Protection Platform (AI-APP) Introducing Wiz Agents & Workflows: Security at the Speed of AI AI Runtime Threat Detection: From Input to Real-World Impact Trivy Compromised: Everything You Need to Know about the Latest Supply Chain Attack It’s Official: Wiz Joins Google Understanding and Reducing AI Risk in Modern Applications Introducing Wiz Tenant Manager: Multi-Tenant Management for Federated Organizations The Agile FedRAMP Playbook, Part 4: Reactive Risk Management through Enriched Incident Response Wiz Achieves CPSTIC Certification in Spain Seeing AI Clearly: Building Visibility Across Modern AI Applications The Agile FedRAMP Playbook, Part 3: Preventative Risk Management by building Secure by Design Wiz Leads the 2026 Latio Application Security Report with awards in 4 categories Building an Agentic Cloud Security Ecosystem: A Reference Architecture with Wiz MCP and Infosys Cyber Next The Agile FedRAMP Playbook, Part 2: Proactive Risk Management with Continuous Monitoring Cloud-native Security for your Windows environment: Announcing the Wiz Runtime Sensor for Windows Would You Click ‘Accept’? Automatically detecting malicious Azure OAuth applications using LLMs Wiz Named a Leader in The Forrester Wave™: Cloud Native Application Protection Solutions, Q1 2026 From Detection to Remediation: It’s Time to Rethink AppSec Around Exploitability and Root Cause Fixes The Agile FedRAMP Playbook, Part 1: Why Risk is Your Best Starting Point Introducing AI Cyber Model Arena: A Real-World Benchmark for AI Agents in Cybersecurity
Wiz launches support for Google Workspace, helping organi...
Shaked Rotlevi, Yariv Ashkenazy, Ofer David · 2023-10-16 · via Wiz Blog | RSS feed

Cloud-native attacks are evolving fast and becoming increasingly more challenging to protect against. An attack path in the cloud is a combination of multiple risk factors that first lead to initial access to the cloud, and then to lateral movement, creating a path for attackers to reach crown jewels. With these new type of attack paths, identity has become the new perimeter in the cloud. Attackers attempt to assume the initial access to an environment via compromised credentials, like in the LAPSUS$ attack. Not only are identities used for initial access, but attackers also use misconfigured identities to find escalation paths and lateral movement that lead to the crown jewels. That is why organizations must protect their cloud identities and proactively remove identity risks that can lead to an attack path.

Identity and access management in Google Cloud Platform 
Many Google Cloud customers use Google Workspace for managing their GCP identities and permissions. Google Workspace, leveraging Google Cloud Identity, offers a comprehensive Identity Provider (IdP) solution for Google Cloud customers, allowing them to easily manage users, groups, domains, applications, and devices through a centralized Admin console. By integrating Google Workspace with GCP, customers can efficiently control authentication of users and their permissions to GCP, allowing them to scale their operations while maintaining a robust identity management framework. 

Secure your Google Cloud identities with the new Google Workspace modeling
We are excited to launch support for Google Workspace identity modeling as part of Wiz’s CIEM capabilities, helping Google Cloud customers protect their cloud identities. With the new Google Workspace modeling, Google Cloud customers gain visibility into their Google Cloud entitlements, identify identity misconfigurations in Google Cloud and Google Workspace, and proactively remove attack paths and harden their environment.  

This is how Wiz secures Google Cloud entitlements: 

Full visibility into Google Cloud identities
The first step in protecting identities and entitlements is gaining a centralized view of all your identities, across humans and services, and their permissions. With this launch, Wiz now provides complete visibility into Google Cloud identities that are managed in Google Workspace, with modeling on the Wiz Security Graph. This visibility enables customers to identify the groups in Google Workspace, the Users within the groups, and their permissions in their Google Cloud environment.

Identify Google Workspace Super Admin users 
Wiz now alerts you of Google Workspace users that have a Super Admin role. Google Workspace Super Admin users have access to all permissions in Google Workspace, such as creating additional admin roles, changing passwords, and inviting unmanaged users. A compromised Super Admin user can result in a critical risk to your Google Cloud environment. An attacker could use the Super Admin permissions to add a new user to a Google Workspace group that has Admin permissions in Google Cloud, and gain admin access to your environment. Now, you can quickly identify all users in your Google Workspace that have Super Admin permissions and proactively remove risk. 

Analyze effective permissions to identify high-privileges, admin, and excessive GCP permissions 
The next step after gaining visibility, is understanding the effective permissions of each identity in your environment. Wiz builds a map of effective access between all Google cloud principals and resources, taking into account advanced cloud-native mitigating controls such as boundaries. This helps you answer questions such as “who has access and to what resources?”. 

To help you enforce least privileges, Wiz automatically identifies and alerts of identities with high-privileges and admin permissions in your environment to ensure they are scoped properly. Wiz also identifies identities with excessive permissions and generates granular recommendations to right-size permissions that allow you to follow guided remediation steps to reduce access and revoke unused permissions. 

Detect IAM misconfigurations in GCP with built-in Wiz Controls 
Misconfigured IAM settings, for example a user with no MFA enabled, can lead to security risks such as unauthorized access. Wiz helps you identify Google Cloud misconfigured users with built-in controls extended to Google Workspace. Such misconfigurations include users with no MFA enabled, identity exposures, inactive users, and publicly exposed admin compute resources.

Proactively remove lateral movement paths 
To successfully protect and remove attack paths in your Google Cloud, you need to understand how an attacker can move laterally in your environment. With the new Google Workspace modeling, detect Google Cloud identities that can lead to lateral movement paths such as cross-account, by which an attacker can gain admin permission to your Google Cloud environment and takeover the account.

Detect Google Workspace threats in near real-time
Not only are we enabling Google Cloud customers to proactively remove identity risks in their environment, but we are also excited to enable them to detect threats in Google Workspace in near real-time. We released over 50 new threat detection rules for Google Workspace, helping customers identify and respond to threats quickly. The new rules include detection of suspicious Google Workspace login events, configuration changes such as disabling 2FA across the domain, creation of new users, and more. 

Let’s take a look at one of the new rules for Large number of failed logins followed by a successful login to Google Workspace by a high privileged user.   

Google Workspace events are correlated back to the GCP cloud context, allowing customers to understand the blast radius of a threat in their cloud environment. For this event, you can quickly understand context around the GCP user in scope and its permissions and look at the remediation guidance to scope down permissions and reduce blast radius. 

The new modeling for Google Workspace and the new threat detection rules enables customers to protect their Google Cloud identities from prevention to detection. Get started now with protecting your Google Cloud identities, you can learn more in the Wiz docs (login needed). If you prefer a live demo, we would love to connect with you.