logo

Wiz Blog

ID: fffc6bd1-39d5-5880-bc08-09fac3aa910f

STIX ID: identity--fffc6bd1-39d5-5880-bc08-09fac3aa910f

Feed Type: rss

Earliest post: 2020-12-09

Latest post: 2026-05-28

Cloud-native security insights — risk research, real-world cloud threats, security best practices, and actionable guidance to help teams build and run safer cloud environments.

01/01/2020
05/29/2026
Title Date Published Describes IncidentAuthorVisible
Commit to Compromise: A New Threat Actor Targeting the Cryptocurrency Industry's Software Development Infrastructure2026-05-27TrueShira AyalTrue
durabletask: TeamPCP's Latest PyPi Compromise2026-05-19TrueRami McCarthyTrue
The Worm That Keeps on Digging: TeamPCP Hits @antv in Latest Wave2026-05-19TrueRami McCarthyTrue
Fragnesia: Linux Kernel Local Privilege Escalation via ESP-in-TCP2026-05-13TrueMerav BarTrue
Mini Shai-Hulud Strikes Again: TanStack + more npm Packages Compromised2026-05-12TrueRami McCarthyTrue
A Framework for AI Threat Readiness2026-05-08TrueAlon SchindelTrue
Dirty Frag: Linux Kernel Local Privilege Escalation via ESP and RxRPC2026-05-08TrueMerav BarTrue
The Jenkins Threat Landscape 2026-05-06TrueMerav BarTrue
Critical Buffer Overflow Vulnerability in PAN-OS Exploited in-the-Wild2026-05-06TrueMerav BarTrue
Practical Package Security: The Unofficial Guide2026-05-04TrueRami McCarthyTrue
Copy Fail: Universal Linux Local Privilege Escalation Vulnerability2026-05-01TrueTrue
The (In)security Landscape of AI-Powered GitHub Actions (Part 2/2)2026-04-30TrueTrue
Supply Chain Campaign Targets SAP npm Packages with Credential-Stealing Malware2026-04-29TrueTrue
Securing GitHub: Wiz Research uncovers Remote Code Execution in GitHub.com and GitHub Enterprise Server (CVE-2026-3854)2026-04-28TrueTrue
Context.ai OAuth Token Compromise2026-04-20TrueTrue
From Code to Pipeline: Wiz Code Now Secures Your Build Environment2026-04-20TrueTrue
Primer on GitHub Actions Security - Threat Model, Attacks and Defenses (Part 1/2)2026-04-14TrueTrue
Claude Mythos: Preparing for a World Where AI Finds and Exploits Vulnerabilities Faster Than Ever2026-04-10TrueTrue
Cloud Threats Retrospective 2026: What AI Changed (and What It Didn’t)2026-04-09TrueTrue
Six Accounts, One Actor: Inside the prt-scan Supply Chain Campaign2026-04-04TrueTrue
Axios NPM Distribution Compromised in Supply Chain Attack2026-03-31TrueTrue
Tracking TeamPCP: Investigating Post-Compromise Attacks Seen in the Wild2026-03-30TrueTrue
Three’s a Crowd: TeamPCP trojanizes LiteLLM in Continuation of Campaign 2026-03-24TrueTrue
KICS GitHub Action Compromised: TeamPCP Strikes Again in Supply Chain Attack2026-03-23TrueTrue
Introducing the Wiz Red Agent- AI-Powered Attacker2026-03-23TrueTrue
AI Runtime Threat Detection: From Input to Real-World Impact2026-03-20TrueTrue
Trivy Compromised: Everything You Need to Know about the Latest Supply Chain Attack2026-03-20TrueTrue
It’s Official: Wiz Joins Google 2026-03-11TrueTrue
Would You Click ‘Accept’? Automatically detecting malicious Azure OAuth applications using LLMs2026-02-18TrueTrue
Hacking Moltbook: The AI Social Network Any Human Can Control2026-02-02TrueTrue
The Year in Wiz Research: 2025 Most Read Blogs2026-01-30TrueTrue
AI Agents vs Humans: Who Wins at Web Hacking in 2026?2026-01-29TrueTrue
Agentic Browser Security: 2025 Year-End Review2026-01-16TrueTrue
CodeBreach: Infiltrating the AWS Console Supply Chain and Hijacking AWS GitHub Repositories via CodeBuild2026-01-15TrueTrue
Snipping the Long Tail of Shai-Hulud 2.02025-12-30TrueTrue
Protecting Against Zero-Day Vulnerabilities with SOC-Level ASM Alert2025-12-30TrueTrue
MongoBleed (CVE-2025-14847) exploited in the wild: everything you need to know2025-12-28TrueTrue
Zero-Days in the Age of AI: Behind the Scenes of ZeroDay.cloud 20252025-12-16TrueTrue
Gogs 0-Day Exploited in the Wild2025-12-10TrueTrue
Code to Cloud Attacks: From Github PAT to Cloud Control Plane2025-12-09TrueTrue
React2Shell: Technical Deep-Dive & In-the-Wild Exploitation of CVE-2025-551822025-12-08TrueTrue
Critical Vulnerabilities in React and Next.js: everything you need to know2025-12-03TrueTrue
Shai-Hulud 2.0 Aftermath: Trends, Victimology and Impact2025-12-01TrueTrue
Exposure Report: 65% of Leading AI Companies Found with Verified Secret Leaks2025-11-10TrueTrue
Dismantling a Critical Supply Chain Risk in VSCode Extension Marketplaces2025-10-15TrueTrue
RediShell: Critical Remote Code Execution Vulnerability (CVE-2025-49844) in Redis, 10 CVSS score2025-10-06TrueTrue
Defending against database ransomware attacks2025-10-06TrueTrue
The emerging use of malware invoking AI2025-09-26TrueTrue
IMDS Abused: Hunting Rare Behaviors to Uncover Exploits2025-09-22TrueTrue
Beyond CVEs: The Exploitation of Everyday Misconfigurations2025-09-19TrueTrue

1–50 of 181