惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

www.infosecurity-magazine.com
www.infosecurity-magazine.com
Security Archives - TechRepublic
Security Archives - TechRepublic
TaoSecurity Blog
TaoSecurity Blog
Cloudbric
Cloudbric
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
N
News and Events Feed by Topic
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
S
Securelist
The Cloudflare Blog
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
D
DataBreaches.Net
S
Schneier on Security
L
LangChain Blog
Jina AI
Jina AI
M
MIT News - Artificial intelligence
Recent Announcements
Recent Announcements
T
Tenable Blog
B
Blog RSS Feed
V
Visual Studio Blog
Simon Willison's Weblog
Simon Willison's Weblog
G
Google Developers Blog
T
The Exploit Database - CXSecurity.com
Exploit-DB.com RSS Feed
Exploit-DB.com RSS Feed
WordPress大学
WordPress大学
W
WeLiveSecurity
I
InfoQ
The Hacker News
The Hacker News
雷峰网
雷峰网
月光博客
月光博客
P
Privacy & Cybersecurity Law Blog
O
OpenAI News
Hacker News: Ask HN
Hacker News: Ask HN
T
Threat Research - Cisco Blogs
GbyAI
GbyAI
The Last Watchdog
The Last Watchdog
P
Privacy International News Feed
Cyberwarzone
Cyberwarzone
S
SegmentFault 最新的问题
L
Lohrmann on Cybersecurity
人人都是产品经理
人人都是产品经理
V
V2EX
V
Vulnerabilities – Threatpost
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
C
Cybersecurity and Infrastructure Security Agency CISA
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
T
Troy Hunt's Blog
Application and Cybersecurity Blog
Application and Cybersecurity Blog
阮一峰的网络日志
阮一峰的网络日志
SecWiki News
SecWiki News
Microsoft Azure Blog
Microsoft Azure Blog

Wiz Blog | RSS feed

Meet Wiz for M365: Bringing SaaS into the Security Graph Bringing Security Visibility to Vercel with Wiz Axios NPM Distribution Compromised in Supply Chain Attack Tracking TeamPCP: Investigating Post-Compromise Attacks Seen in the Wild The Wiz Blue Agent, now Generally Available Beyond the Badge: What Achieving Microsoft’s Certified Software Designation Means for Your Cloud Security Introducing the Green Agent: AI-Powered Remediation for the Cloud Three’s a Crowd: TeamPCP trojanizes LiteLLM in Continuation of Campaign KICS GitHub Action Compromised: TeamPCP Strikes Again in Supply Chain Attack Introducing the Wiz Red Agent- AI-Powered Attacker Introducing Wiz AI Application Protection Platform (AI-APP) Introducing Wiz Agents & Workflows: Security at the Speed of AI AI Runtime Threat Detection: From Input to Real-World Impact Trivy Compromised: Everything You Need to Know about the Latest Supply Chain Attack It’s Official: Wiz Joins Google Understanding and Reducing AI Risk in Modern Applications Introducing Wiz Tenant Manager: Multi-Tenant Management for Federated Organizations The Agile FedRAMP Playbook, Part 4: Reactive Risk Management through Enriched Incident Response Wiz Achieves CPSTIC Certification in Spain Seeing AI Clearly: Building Visibility Across Modern AI Applications The Agile FedRAMP Playbook, Part 3: Preventative Risk Management by building Secure by Design Wiz Leads the 2026 Latio Application Security Report with awards in 4 categories Building an Agentic Cloud Security Ecosystem: A Reference Architecture with Wiz MCP and Infosys Cyber Next The Agile FedRAMP Playbook, Part 2: Proactive Risk Management with Continuous Monitoring Cloud-native Security for your Windows environment: Announcing the Wiz Runtime Sensor for Windows Would You Click ‘Accept’? Automatically detecting malicious Azure OAuth applications using LLMs Wiz Named a Leader in The Forrester Wave™: Cloud Native Application Protection Solutions, Q1 2026 From Detection to Remediation: It’s Time to Rethink AppSec Around Exploitability and Root Cause Fixes The Agile FedRAMP Playbook, Part 1: Why Risk is Your Best Starting Point Introducing AI Cyber Model Arena: A Real-World Benchmark for AI Agents in Cybersecurity Wiz + Spotify Backstage: Security at the Developer’s Desk Building AI Security Together: New Ways to Partner with Wiz for AI Security in 2026 Hacking Moltbook: The AI Social Network Any Human Can Control The Year in Wiz Research: 2025 Most Read Blogs WizExtend is Here: AI and Cloud Security Insights in Your Daily Workflow From Detection to Remediation: Wiz in Your JetBrains IDE Agentic Browser Security: 2025 Year-End Review CodeBreach: Infiltrating the AWS Console Supply Chain and Hijacking AWS GitHub Repositories via CodeBuild A 90-Day Action Plan to Turn Resolutions into Results with Wiz Introducing the Wiz Partner Alliance: A New Chapter for Partner Success Preparing for Post-Quantum Cryptography Wiz Recognized as a 2025 Customers’ Choice in the Gartner® Peer Insights™ Voice of the Customer for CNAPP Expanding the Zero Critical Club to set a new standard for AppSec and SecOps teams Snipping the Long Tail of Shai-Hulud 2.0 Protecting Against Zero-Day Vulnerabilities with SOC-Level ASM Alert MongoBleed (CVE-2025-14847) exploited in the wild: everything you need to know The Kenna Transition: Your Strategic Shift to Exposure Management From MCP to Vibe Coding: Full Endpoint Visibility in Wiz AI Security Bringing Oracle Cloud Identity to Wiz Zero‑Days in the Age of AI: Behind the Scenes of ZeroDay.cloud 2025, with a Record High of CVEs in Critical Cloud Infra Gogs 0-Day Exploited in the Wild Code to Cloud Attacks: From Github PAT to Cloud Control Plane Top AWS re:Invent Announcements for Security Teams in 2025 React2Shell: Technical Deep-Dive & In-the-Wild Exploitation of CVE-2025-55182 React2Shell (CVE-2025-55182): Everything You Need to Know About the Critical React Vulnerability Wiz Product Announcements at re:Invent 2025: Expanding Visibility from Code to Cloud Introducing Wiz SAST: Where Code Risk Meets Cloud Context Wiz Becomes Fastest Security ISV to Reach $1 Billion in AWS Marketplace Lifetime Sales It's Here! Wiz Exposure Management is Now GA Shai-Hulud 2.0 Aftermath: Trends, Victimology and Impact Service Catalog is Here: Expand Risk Visibility for Your Service and Its Dependencies, Simplify Issue Ownership WizOS: Powering Secured Image Adoption with AI 3 OAuth TTPs Seen This Month — and How to Detect Them with Entra ID Logs Mastering Software Governance with Hosted Technologies Inventory Shai-Hulud 2.0 Supply Chain Attack: 25K+ Repos Exposing Secrets Get Certified on Wiz Defend for Threat Detection and Response Blueprint for Security: A Guide to Code, Governance, and Response Frameworks Google Unified Security Recommended Program Names Wiz Among First 3 Strategic Partners Introducing Posture Issues: Transform Security Findings into Actionable Outcomes Empower and Accelerate Your SOC with the Blue Agent Exposure Report: 65% of Leading AI Companies Found with Verified Secret Leaks Wizdom 2025 Product Announcements: Extending the Cloud Operating Model When AI Becomes the Heart of Security: Powering a Future You Can Trust AI-Powered Wiz: From Agents to Everyday Intelligence Defend Agentless Workload Detection: Bringing Visibility to Blind Spots in Threat Detection Securing AI Agents with Wiz AI-SPM Introducing Wiz ASM: Context-Driven Attack Surface Management Securing Critical Infrastructure in the Cloud Era: A Policy and Technology Blueprint How CISOs Should Plan Security Budgets for 2026 Beyond the Checkbox: How Wiz Transforms SOC 2 into a Security Powerhouse Bringing Visibility to Kubernetes: Unified Inventory and Network Insight The Foundation Modern AppSec Is Still Missing: Code to Cloud, Rebuilt the Right Way Dismantling a Critical Supply Chain Risk in VSCode Extension Marketplaces Introducing HoneyBee: How We Automate Honeypot Deployment for Threat Research RediShell: Critical Remote Code Execution Vulnerability (CVE-2025-49844) in Redis, 10 CVSS score Defending against database ransomware attacks AI Security 101: Mapping the AI Attack Surface Introducing zeroday.cloud: First-of-its-kind cloud and AI hacking competition Unifying Cloud Risk and Network Defense: Wiz and Check Point The emerging use of malware invoking AI Wiz achieves FedRAMP High authorization Wiz + HCP Terraform: Close the IaC-to-Cloud Infrastructure Security Gap IMDS Abused: Hunting Rare Behaviors to Uncover Exploits Beyond CVEs: The Exploitation of Everyday Misconfigurations Wiz Research Discovers One in Five Organizations Exposed to Systemic Risks in Vibe-Coded Applications - Here's How to Secure Them Introducing Wiz Incident Response: Your Expert Partner for Cloud Security Incidents Shai-Hulud: Ongoing Package Supply Chain Worm Delivering Data-Stealing Malware DORA Compliance in the Cloud Era: Insights from Deloitte and Wiz How Wiz Customers like Brex and FICO See AI Changing Security Wiz Recognized as a Leader in the 2025 IDC MarketScape for ASPM
Wiz at Google Cloud Next: Machine-Speed AI Defense | Wiz Blog
https://www.wiz.io/authors/kelsey-nelson · 2026-04-22 · via Wiz Blog | RSS feed

Security teams have spent decades fighting the same ghosts: misconfigurations, over-privileged identities, and unpatched CVEs. But today, AI has given those ghosts a megaphone. By plugging AI into real-time data and autonomous agents, we’ve empowered these systems to pull levers in our most sensitive environments. A minor oversight is no longer a localized error; in a hyper-connected AI ecosystem, it’s a systemic vulnerability.

At Wiz, our goal has always been to help teams protect everything they build and run, from cloud providers like Amazon Web Services, Google Cloud, Microsoft Azure, and Oracle Cloud to software-as-a-service (SaaS) environments like OpenAI to even custom hosted environments. 

Last month at RSAC, we introduced the Wiz AI Application Protection Platform (AI-APP) to help security teams move from human speed to machine-speed defense. Wiz AI-APP secures the entire AI lifecycle and arms defenders with their own AI agents to autonomously investigate, prioritize, and remediate risks. Our trio of AI agents – Blue Agent (generally available), Green Agent (public preview), and Red Agent (launching today in public preview) – and Wiz Workflows can also come together to help security teams move even faster to respond to risks.

Now we’re taking this commitment further. Because the AI software lifecycle is evolving at incredible speed, we are continuing to push the boundaries of protection by announcing new capabilities that extend and deepen Wiz AI-APP coverage, from the first line of AI-generated code, through AI and agent studios, all the way to the edge of the cloud.

Expanding coverage across cloud and AI platforms

Organizations today are building and running applications across an increasingly complex mix of environments, from cloud, SaaS, PaaS, to on-prem infrastructure. That means the attack surface cannot be confined to a single place; it’s everywhere your business operates.

To keep up, security can’t be fragmented or reactive. It needs to be comprehensive, continuous, and built to span every layer of your environment. We’re committed to continuously investing in capabilities that help organizations secure everything they build and run, no matter the platform, environment, or architecture.

Our recent AI-APP launch extended the Wiz platform to secure AI applications from code to runtime, bringing the same depth of context and risk prioritization to AI applications. Today, we’re building on that commitment with new expansions across key areas:

  • Cloud platforms: Added support for Databricks, giving teams visibility into where sensitive data lives, how it’s classified and accessed, and how identities and infrastructure combine to create real, exploitable risk.

  • AI studios: Expanded coverage for platforms like AWS Agentcore, Gemini Enterprise Agent Platform, Microsoft Azure Copilot Studio, and Salesforce Agentforce, providing visibility into agents, models, and connected tools. AI studios reveal how interactions create new paths to data access and real-world impact.

  • Multi-cloud PaaS: Continued expansion across multicloud PaaS environments, including platforms like AgentCore, enabling teams to track workloads, identities, and exposures as infrastructure becomes more abstracted and distributed.

We are also excited to launch the Red Agent in Public Preview to help our customers stay ahead of attackers across this rapidly changing landscape, especially in the face of new advanced AI models like Mythos, making Zero-Day exploitation easier than ever. By reasoning about application behavior and adapting in real time, Red Agent acts as an AI-powered "intelligent attacker" that continuously and proactively discovers and validates complex, logic-driven vulnerabilities helping you stay one step ahead.

And we’re just getting started. 

In addition to expanding Wiz coverage, we’re bringing more visibility into the state of cloud and AI technology with our new Technology Intel Center. The Technology Intel Center aggregates and centralizes a feed of relevant new features releases, migration updates, and end-of-life notices across cloud and AI tech providers in the Wiz platform. Like the Threat Intel Center, Wiz will automatically show teams where they have affected resources and, for those organizations using Wiz Cloud Cost, if the update will result in an impact on their cloud spend.

The new Wiz Technology Intel Center centralizes relevant new features releases, migration updates, and end-of-life notices across cloud and AI tech providers

By unifying risk insights with the Tech Intel Center’s operational updates and cost data, Wiz transforms raw industry news into a personalized, actionable roadmap for your entire infrastructure. It’s no longer just about knowing what’s changing in the cloud. It’s about understanding exactly how those changes affect your deployment, its risk posture, and your bottom line before they even take effect. 

Securing the AI Development Lifecycle

AI-assisted coding is supercharging innovation at a breakneck pace. At Spotify, some of the best developers haven’t written a line of manual code in months thanks to AI, a trend that mirrors our own internal velocity here at Wiz. We’re also seeing new trends emerge in AI-assisted coding security: Wiz Research analyzed real applications built with AI-assisted coding tools and found 20% contained material security issues, including broken access controls and unprotected data endpoints. 

It’s the ultimate double-edged sword: AI doesn’t just accelerate your code; it accelerates your risk. For application security teams, the speed of creation was already outpacing the speed of security. To stay ahead now, we must move beyond developer speed to machine-speed risk mitigation, providing visibility across these new AI coding tools and models, enforcing guardrails at the point of code generation, and remediating where developers work.

To help address security concerns earlier in the AI-assisted software development lifecycle, we’re introducing three new capabilities into Wiz Code:

Wiz AI-BOM: Code and Shadow AI Visibility
Wiz has always started from a foundation of visibility and context: you can't protect what you can't see or don't fully understand. Vibe coding tools introduce two main visibility gaps for security teams. First, because AI-assisted coding tools are so easy to use, they allow both developers and non-technical employees to bypass standard IT/security reviews, creating a new Shadow AI attack surface. Second, when these teams start to build with AI tools, security teams often have no way to see what AI frameworks, models, or extensions are active in their environment or contributing to their codebase.

To help with these challenges, Wiz’s dynamic AI-Bill of Materials (AI-BOM) can now automatically inventory AI frameworks (like LangChain), models, and IDE extensions, including Gemini Code Assist, GitHub Copilot, and Cursor. 

Wiz AI-BOM give security teams a living, breathing map of how AI frameworks interact with their proprietary data

By mapping these resources onto the Wiz Security Graph, we aren’t just eliminating Shadow AI; we’re giving security teams a living, breathing map of how AI frameworks interact with their proprietary data. No more shadow AI, and instead a continuously monitored picture of your AI tool landscape.

Secure Guardrails: Prevention Integrated into the Agentic Coding Flow
AI models are optimized to make things work, not necessarily to make them secure. They often default to "allow all" permissions or client-side logic to get a prototype running, or may rely on open source repos and examples with pre-existing errors to generate solutions.

To help catch issues earlier in the dev lifecycle, Wiz will scan AI-generated code in tools like Lovable (available in May), identifying risk before it hits the pipeline. Using post-code generation inline hooks, Wiz injects organizational security guardrails and start-secure best practices before the AI writes the code, and scans the output.

Post-code generation hooks scan code for security issues before it can be pushed to source control, even blocking the action from proceeding.

These guardrails can work alongside existing rules within an AI IDE, layering in best practices and context from Wiz to strengthen the overall security posture of code from the start. Security teams can trust that the tools their partner dev teams use every day have the right security controls baked in from the start, and devs don’t have to worry about keeping up with every new best practice, and instead focus on shipping.

Agentic Remediation: Self-healing Code Bases
Finally, the app landscape is evolving quickly and new vulnerabilities and findings may be added or discovered after code has been deployed. Keeping up with vulns has always been a significant lift on development teams, but it’s now next to impossible at AI scale without leveraging AI for remediation.

We’re now releasing new pre-built skills that can be used within AI IDEs like Claude Code, Cursor, and more to feed AI agents with full code-to-cloud context and validated attack surface findings from the Wiz Security Graph. Our first Remediation Skill can be run natively in the AI IDE as a simple command, building from a predefined set of actions and best practices built from the Wiz Green Agent in order to analyze the code, identify Issues, and deploy fixes all right within the dev console.

Wiz security skills direct coding agents to pull existing issues into the IDE or terminal, provide details, summarize Green Agent remediation findings, and make the suggested fixes.

These new self-healing capabilities enable developers to rapidly burn down real, exploitable risks right within their existing workflows.

Extending to the Cloud Edge

Finally, we’re expanding our ability to ingest context across infrastructure layers; visibility cannot stop at the borders of your VPC. Our latest integrations with Cloudflare, Akamai, Vercel and Google Cloud Apigee bring the cloud “edge” into the Wiz Security Graph, breaking down the silos between your core cloud environment and the external services that handle your traffic and APIs:

  • Securing the AI Frontier with Cloudflare: The Wiz Cloudflare integration provides visibility from cloud to edge. It surfaces how AI applications are exposed through DNS and infrastructure, identifying unprotected endpoints, and enforcing guardrails against threats like prompt injection and PII exposure. 

  • Hardening the Network Edge with Akamai: Your internet edge is often the first line of defense. By pulling in Akamai Edge DNS and Property Manager configurations, Wiz analyzes your edge posture alongside your cloud workloads. This allows security teams to see how an edge misconfiguration might create a direct path to an exploitable vulnerability deep within their infrastructure.

  • Unifying Frontend and Backend with Vercel: Frontend deployments should never be a security black box. We now ingest Vercel projects, domains, and firewall settings directly into the Wiz Security Graph. This ensures that a misconfigured frontend deployment is surfaced immediately, showing exactly how it impacts the rest of your system's security.

  • Mapping the API Ecosystem with Google Cloud Apigee: APIs are the glue of modern applications, but they are often difficult to track. With Google Cloud Apigee, customers can now see their entire API architecture, including gateways and environments, mapped within the Security Graph, providing a single source of truth for API risk management.

By breaking down these silos, Wiz ensures that whether a risk lives in a serverless function, an AI endpoint, or a global CDN configuration, you have the unified context needed to remediate it before it can be exploited.

Secure innovation with Wiz AI-APP

Securing the AI frontier requires more than just new tools; it requires a fundamental shift in how security and development teams collaborate. These latest expansions to the Wiz platform provide the unified context teams need to prioritize what matters and remediate at scale.

With Wiz, you aren't just defending your infrastructure; you are building a resilient foundation for the next generation of AI-driven innovation.