Wiz io
banner
wiz.io
Wiz io
@wiz.io
Secure everything you build and run in the cloud
We built a Cyber Arena to find out how good AI really is at hacking. 🧪
We tested AI like an attacker would (For science) with over 300 real-world offensive AI challenges! 🤖

This gives defenders real data & a clearer view of what AI can do today. www.wiz.io/cyber-model-...
Cyber Model Arena | Wiz
Evaluating AI agents across real-world security challenges
www.wiz.io
September 10, 2026 at 2:42 PM
🐶 WE ACTUALLY DID IT. We built a Magical Dog Bus. 🚌

Meet the real security pack behind the magic at Wiz.

Every morning, they hop on the bus, roll into work, and protect everything you run, build & fetch. 🐾

Happy Dog Day from Wiz and our very best threat sniffers. 💙
August 25, 2026 at 12:20 PM
🚨 BREAKING: Our AI Red Agent autonomously accessed Snowflake's Jira via a flaw written by GitHub's AI bot. Red Agent learned, exploited & extracted creds with 0 human help.

Kudos to Snowflake for swiftly addressing the issue 👏

Technical breakdown → wiz.io/blog/red-agent-snowflake-copilot-cicd-bug
August 17, 2026 at 2:03 PM
🔍 What do threat researchers really talk about when they're not hunting zero-days?

We put merav and Dan on the hot seat for Wiz Autocomplete Confessions --> and let's just say… they had a LOT to say. 👀

🎥 Watch the full video ↓
youtube.com/watch?v=VaPDXL7jt1k&feature=youtu.be&themeRefresh=1
Wiz Autocomplete Confessions | Threat Researchers Answer the Web's Most Asked Cyber and AI Questions
YouTube video by Wiz
youtube.com
August 12, 2026 at 11:41 AM
🚨 CosmosEscape: We found a single key that unlocked every database in Azure CosmosDB

One key >> Platform-wide impact.

Microsoft fully remediated the issue. ✅

Read the full research and see how Wiz uncovered CosmosEscape: www.wiz.io/blog/cosmose...
July 30, 2026 at 12:01 PM
🚨 Wiz Red Agent is GA!

AI-powered continuous pentesting that finds what traditional scanners miss: logic flaws, hidden APIs, auth bypasses & exploitable risks.

10K+ critical risks found in preview 🔥
wiz.io/blog/wiz-red...
July 29, 2026 at 12:54 PM
🧠 Meet Atlas: our AI vulnerability researcher. It found 200+ previously unknown vulnerabilities, ranked #1 on CyberGym (90.9%), and is helping power Wiz Code with continuous AI-powered security. 🏆
www.wiz.io/blog/atlas-a...
July 27, 2026 at 3:38 PM
🎊 300 WIN INTEGRATIONS. WHAT. A. MILESTONE. 🎊
Times Square is glowing Wiz today! 🗽

To the 300+ partners who built, tested, and scaled alongside us in the past 3 years: This milestone is yours.

www.wiz.io/blog/wiz-int...
Wiz Integration Network Hits 300 Partner Integrations | Wiz Blog
The Wiz Integration Network hits 300 partner integrations, connecting developer tools, CI/CD, and threat intel so security moves at AI speed.
www.wiz.io
July 21, 2026 at 12:49 PM
🚨 SDLC Security '26 report is here!

Wiz Research analyzed real dev envs, repos & prod telemetry on SDLC risk shifting upstream.

50% GH Actions
reuse risk clusters
86% macOS
AI amplifies risk

Full report ↓
www.wiz.io/reports/sdlc...
May 26, 2026 at 12:09 PM
The secret's out.🤫

Introducing THE ZERODAY.CLOUD COMMUNITY 👾

Inside:
• 0-day vulnerability deep dives from Xint, Moritz Sanft, Paul Gerste & more...
• Access to events & a network of world-class hackers
• CTFs with prizes

Join now :)
May 4, 2026 at 11:44 AM
🚨 BREAKING: Wiz Research discovered Remote Code Execution on GitHub.com with a single git push.

The flaw in @github.com allowed unauthorized access to millions of repositories belonging to other users and organizations 🤯
April 28, 2026 at 3:39 PM
🚨 500+ malicious PRs. One campaign.

Wiz Research traced 6 waves of prt-scan starting 3 weeks earlier.
AI-powered, automated attacks exploiting pull_request_target.

Low success rate—but real npm + cloud creds hit.

Full story: www.wiz.io/blog/six-acc...
prt-scan: AI-Powered GitHub Actions Supply Chain Attack | Wiz Blog
Wiz Research traces six waves of pull_request_target exploitation to one actor, starting three weeks before public disclosure. 500+ malicious PRs, 10% success.
www.wiz.io
April 6, 2026 at 10:02 AM
NEW CTF: AWS turned 20 🎉

So we built our monthly CTF challenge to celebrate: packed with challenges inspired by the last two decades of cloud ☁️

Oh, and… we made sure AI can't solve it 😅
So no prompts this time.

Ready to play?
www.cloudsecuritychampionship.com
March 30, 2026 at 3:34 PM
🎉 IT'S OFFICIAL: wiz joins Google to secure the AI era.

This is a massive moment for our customers and our team.

Thank you to every customer, partner, and Wizard who made this moment possible 💙

We can't wait to share what's next.
wiz.io/blog/google-...
March 11, 2026 at 12:54 PM
🚨New CTF Alert: Got trust issues?

Ever wondered what it's like to investigate a real data leak? Now's your chance.

🕵️ Your mission:
1) Investigate the compromised machine
2) Figure out how the attacker exfiltrated the data
3) Find the flag

🔗 Start here: cloudsecuritychampionship.com
The Ultimate Cloud Security Championship | 12 Months × 12 Challenges
Join our monthly cloud security CTF challenge, built by top Wiz researchers. Solve real-world scenarios and rise to the top of the leaderboard.
cloudsecuritychampionship.com
February 25, 2026 at 2:20 PM
How good is AI at hacking? We built a benchmark to find out. 🧪
Introducing the Offensive AI Benchmark, the framework that tests AI agents on 250+ real-world offensive security challenges.

Check it out →
www.wiz.io/cyber-model-...
February 12, 2026 at 4:16 PM
🚨 CodeBreach: Wiz Research identified a critical repository-hijacking vulnerability that abused a CodeBuild Regex flaw to compromise core AWS GitHub repos, including a core lib running at the heart of the cloud's most critical interface - the #AWS Console.
January 15, 2026 at 3:05 PM
🧠 Just in time for a new year, a NEW CTF drop!

Think you know Terraform inside out? State of Affairs (challenge 7) might change your mind...

This challenge uncovers an overlooked #Terraform risk and proves IaC tools are part of your supply chain.

www.cloudsecuritychampionship.com/challenge/7
December 29, 2025 at 2:23 PM
🚨 CRITICAL: MongoBleed (CVE-2025-14847). MongoDB bug leaks in-memory data pre-auth and is exploited in the wild. 42% of clouds vulnerable, ~87K exposed. Atlas patched. Self-hosted: patch now or disable zlib.

www.wiz.io/blog/mongobl...
MongoBleed (CVE-2025-14847) exploited in the wild | Wiz Blog
Detect and mitigate CVE-2025-14847, an unauthenticated information leak vulnerability in MongoDB. Exploitation has been observed in the wild.
www.wiz.io
December 28, 2025 at 12:29 PM
Day 2 at zeroday.cloud, let’s roll. 👾

👀 Didn’t register? No panic.

Walk-ins are welcome for the onsite CTF and all the action happening on the floor.

Flags are hidden. Only the sharp survive.
December 11, 2025 at 12:19 PM
Day 1 of zeroday.cloud = PURE EXPLOIT ENERGY 👾

From crowd shots 👀 to researchers buried deep in terminals 💻
From first checks being claimed
To live container escapes blowing minds in real time.

See you tomorrow!
December 11, 2025 at 10:01 AM
Day 1 at zeroday.cloud didn’t come to play 😈

New vulns dropped in Grafana, Linux Kernel, 3 Redis, and 2 PostgreSQL - and every. single. one. worked 🤯

100% success rate for day one.

Let’s see what we find tomorrow 👀
December 11, 2025 at 9:37 AM
Zeroday.cloud 2025 kicks off TOMORROW! 💻

London, brace yourself -
IDEs open. Exploits cooking.

13 zero-days are on the line 💣
Don't miss it. Here's the schedule ahead ⬎
December 9, 2025 at 2:57 PM
🎧 Your age after React2Shell... 𝟴𝟴.
Cloud Security Wrapped 2025 is HERE ↓

Check out our exclusive insights from our Wiz Research team!
Spotify, are we doing it right? 🎵
December 9, 2025 at 1:30 PM
🚨 React2Shell (CVE‑2025‑55182) in‑the‑wild exploitation & deep‑dive analysis. Critical RCE across React 19, Next.js & all RSC frameworks. Patch now.
www.wiz.io/blog/nextjs-...
December 8, 2025 at 5:25 PM