logo

Wiz Blog

ID: fffc6bd1-39d5-5880-bc08-09fac3aa910f

STIX ID: identity--fffc6bd1-39d5-5880-bc08-09fac3aa910f

Feed Type: rss

Earliest post: 2020-12-09

Latest post: 2026-08-14

Cloud-native security insights — risk research, real-world cloud threats, security best practices, and actionable guidance to help teams build and run safer cloud environments.

01/01/2020
08/16/2026
Title Date Published Describes IncidentAuthorVisible
How to Investigate GitHub PAT Compromise: Lessons From a Multi-Organization Campaign2026-08-13TrueEden AbergilTrue
Cloud Threat Highlights: H1 20262026-08-06TrueWiz Threat ResearchTrue
keyv and cacheable npm Package Hijacked in Supply Chain Attack2026-08-04TrueMerav BarTrue
Introducing the Wiz Sensor for Developer Workstations to Protect Endpoints in the AI Era2026-08-03TrueShashank GollaTrue
CosmosEscape: Taking Over Every Database in Azure Cosmos DB 2026-07-30TrueYuval AvrahamiTrue
Wiz’s First 6 Months as Part of Google 2026-07-29TrueAssaf RappaportTrue
The risk hiding behind exposed MCP servers2026-07-28TrueHila RamatiTrue
Atlas: Wiz's autonomous AI Agent for vulnerability research, ranked #1 on CyberGym2026-07-27TrueNir OhfeldTrue
Opening the Black Box: Agentless Threat Detection for Virtual Appliances2026-07-22TrueShahar DorfmanTrue
Agentless Threat Detection: Illuminating Cloud Blind Spots2026-07-21TrueShahar DorfmanTrue
Exploitation in the Wild of wp2shell2026-07-20TrueShahar DorfmanTrue
The Red Agent POV: The One Boolean That Broke a B2B Platform’s Credit System2026-07-15TrueRed AgentTrue
M-Red-Team: AsyncAPI Supply Chain Compromise via GitHub Actions2026-07-14TrueRami McCarthyTrue
Wiz in the Verizon DBIR: How AI Acceleration and Cloud Sprawl Impact Modern Defense2026-07-09TrueWiz Threat ResearchTrue
GhostApproval: A Trust Boundary Gap in AI Coding Assistants2026-07-08TrueMaor DokhanianTrue
The Red Agent POV: Exploiting Broken Object-Level Authorization in an Airline GraphQL API2026-06-29TrueRed AgentTrue
MCP Auto-Execution: From Git Clone to Cloud Compromise in Amazon Q VS Code Extension2026-06-26TrueMaor DokhanianTrue
The President’s Executive Actions on AI Have a Lot to Say on Cybersecurity2026-06-18TrueMitch HerckisTrue
The Red Agent POV: How it Reasoned its Way to SSRF2026-06-17TrueRed AgentTrue
Introducing the Red Agent POV Series2026-06-17TrueRed AgentTrue
Miasma: Supply Chain Attack Targeting RedHat npm Packages2026-06-01TrueMerav BarTrue
Commit to Compromise: A New Threat Actor Targeting the Cryptocurrency Industry's Software Development Infrastructure2026-05-27TrueShira AyalTrue
durabletask: TeamPCP's Latest PyPi Compromise2026-05-19TrueRami McCarthyTrue
The Worm That Keeps on Digging: TeamPCP Hits @antv in Latest Wave2026-05-19TrueRami McCarthyTrue
Fragnesia: Linux Kernel Local Privilege Escalation via ESP-in-TCP2026-05-13TrueMerav BarTrue
Mini Shai-Hulud Strikes Again: TanStack + more npm Packages Compromised2026-05-12TrueRami McCarthyTrue
A Framework for AI Threat Readiness2026-05-08TrueAlon SchindelTrue
Dirty Frag: Linux Kernel Local Privilege Escalation via ESP and RxRPC2026-05-08TrueMerav BarTrue
The Jenkins Threat Landscape 2026-05-06TrueMerav BarTrue
Critical Buffer Overflow Vulnerability in PAN-OS Exploited in-the-Wild2026-05-06TrueMerav BarTrue
Practical Package Security: The Unofficial Guide2026-05-04TrueRami McCarthyTrue
Copy Fail: Universal Linux Local Privilege Escalation Vulnerability2026-05-01TrueTrue
The (In)security Landscape of AI-Powered GitHub Actions (Part 2/2)2026-04-30TrueTrue
Supply Chain Campaign Targets SAP npm Packages with Credential-Stealing Malware2026-04-29TrueTrue
Securing GitHub: Wiz Research uncovers Remote Code Execution in GitHub.com and GitHub Enterprise Server (CVE-2026-3854)2026-04-28TrueTrue
Context.ai OAuth Token Compromise2026-04-20TrueTrue
From Code to Pipeline: Wiz Code Now Secures Your Build Environment2026-04-20TrueTrue
Primer on GitHub Actions Security - Threat Model, Attacks and Defenses (Part 1/2)2026-04-14TrueTrue
Claude Mythos: Preparing for a World Where AI Finds and Exploits Vulnerabilities Faster Than Ever2026-04-10TrueTrue
Cloud Threats Retrospective 2026: What AI Changed (and What It Didn’t)2026-04-09TrueTrue
Six Accounts, One Actor: Inside the prt-scan Supply Chain Campaign2026-04-04TrueTrue
Axios NPM Distribution Compromised in Supply Chain Attack2026-03-31TrueTrue
Tracking TeamPCP: Investigating Post-Compromise Attacks Seen in the Wild2026-03-30TrueTrue
Three’s a Crowd: TeamPCP trojanizes LiteLLM in Continuation of Campaign 2026-03-24TrueTrue
KICS GitHub Action Compromised: TeamPCP Strikes Again in Supply Chain Attack2026-03-23TrueTrue
Introducing the Wiz Red Agent- AI-Powered Attacker2026-03-23TrueTrue
AI Runtime Threat Detection: From Input to Real-World Impact2026-03-20TrueTrue
Trivy Compromised: Everything You Need to Know about the Latest Supply Chain Attack2026-03-20TrueTrue
It’s Official: Wiz Joins Google 2026-03-11TrueTrue
Would You Click ‘Accept’? Automatically detecting malicious Azure OAuth applications using LLMs2026-02-18TrueTrue

1–50 of 202