Wiz io's Avatar

Wiz io

@wizsecurity.bsky.social

Secure everything you build and run in the cloud

118 Followers  |  9 Following  |  114 Posts  |  Joined: 19.11.2024  |  1.6316

Latest posts by wizsecurity.bsky.social on Bluesky

Post image

How good is AI at hacking? We built a benchmark to find out. πŸ§ͺ
Introducing the Offensive AI Benchmark, the framework that tests AI agents on 250+ real-world offensive security challenges.

Check it out β†’
www.wiz.io/cyber-model-...

12.02.2026 16:16 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
CodeBreach: Supply Chain Vuln & AWS CodeBuild Misconfig | Wiz Blog Wiz Research discovered CodeBreach, a critical vulnerability that risked the AWS Console supply chain. Learn how to secure your AWS CodeBuild pipelines.

Patched fast by @awscloud.bsky.social. A tiny regex, huge impact.
www.wiz.io/blog/wiz-res...

15.01.2026 15:05 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

🚨 CodeBreach: Wiz Research identified a critical repository-hijacking vulnerability that abused a CodeBuild Regex flaw to compromise core AWS GitHub repos, including a core lib running at the heart of the cloud's most critical interface - the #AWS Console.

15.01.2026 15:05 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
Post image

🧠 Just in time for a new year, a NEW CTF drop!

Think you know Terraform inside out? State of Affairs (challenge 7) might change your mind...

This challenge uncovers an overlooked #Terraform risk and proves IaC tools are part of your supply chain.

www.cloudsecuritychampionship.com/challenge/7

29.12.2025 14:22 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
MongoBleed (CVE-2025-14847) exploited in the wild | Wiz Blog Detect and mitigate CVE-2025-14847, an unauthenticated information leak vulnerability in MongoDB. Exploitation has been observed in the wild.

🚨 CRITICAL: MongoBleed (CVE-2025-14847). MongoDB bug leaks in-memory data pre-auth and is exploited in the wild. 42% of clouds vulnerable, ~87K exposed. Atlas patched. Self-hosted: patch now or disable zlib.

www.wiz.io/blog/mongobl...

28.12.2025 12:29 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

Day 2 at zeroday.cloud, let’s roll. πŸ‘Ύ

πŸ‘€ Didn’t register? No panic.

Walk-ins are welcome for the onsite CTF and all the action happening on the floor.

Flags are hidden. Only the sharp survive.

11.12.2025 12:19 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image Post image Post image

Day 1 of zeroday.cloud = PURE EXPLOIT ENERGY πŸ‘Ύ

From crowd shots πŸ‘€ to researchers buried deep in terminals πŸ’»
From first checks being claimed
To live container escapes blowing minds in real time.

See you tomorrow!

11.12.2025 10:01 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

Day 1 at zeroday.cloud didn’t come to play 😈

New vulns dropped in Grafana, Linux Kernel, 3 Redis, and 2 PostgreSQL - and every. single. one. worked 🀯

100% success rate for day one.

Let’s see what we find tomorrow πŸ‘€

11.12.2025 09:37 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image Post image

Zeroday.cloud 2025 kicks off TOMORROW! πŸ’»

London, brace yourself -
IDEs open. Exploits cooking.

13 zero-days are on the line πŸ’£
Don't miss it. Here's the schedule ahead ⬎

09.12.2025 14:56 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image Post image Post image Post image

🎧 Your age after React2Shell... 𝟴𝟴.
Cloud Security Wrapped 2025 is HERE ↓

Check out our exclusive insights from our Wiz Research team!
Spotify, are we doing it right? 🎡

09.12.2025 13:30 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

🚨 React2Shell (CVE‑2025‑55182) in‑the‑wild exploitation & deep‑dive analysis. Critical RCE across React 19, Next.js & all RSC frameworks. Patch now.
www.wiz.io/blog/nextjs-...

08.12.2025 17:24 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Video thumbnail

πŸŽ‰ This is not a dream πŸ’€ OUR WizZZZ BOOTH IS NOW OPEN.

Behold the ULTIMATE cloud security booth!

Games, demos, swag, naps… and the coziest cloud security playground in history πŸ›οΈ

Come see why CISOs are finally sleeping through the night 😴

02.12.2025 02:00 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
The Ultimate Cloud Security Championship | 12 Months Γ— 12 Challenges Join our monthly cloud security CTF challenge, built by top Wiz researchers. Solve real-world scenarios and rise to the top of the leaderboard.

It’s time to bust some malware! 🦠

Challenge #6 β€œMalware Busters” is LIVE.
Built by Gili Tikochinski for the reverse‑engineering pros - dive into assembly and uncover what’s hidden inside.
Think you can crack it?

cloudsecuritychampionship.com/challenge/6

27.11.2025 13:49 β€” πŸ‘ 2    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0
Preview
Shai-Hulud 2.0: Ongoing Supply Chain Attack | Wiz Blog Detect and mitigate malicious npm packages linked to the recent Shai-Hulud-style campaign. Over 25,000 affected repositories across ~350 unique users.

🚨 New Shai-Hulud-style npm attack hitting 25k+ repos and growing fast.
Devs & CI/CD exposed via malicious preinstall. Wiz Research has detection + mitigation.
Details: www.wiz.io/blog/shai-hu...

24.11.2025 12:12 β€” πŸ‘ 5    πŸ” 3    πŸ’¬ 0    πŸ“Œ 1
Preview
65% of Startups from Forbes AI 50 Leaked Secrets on GitHub | Wiz Blog A Wiz investigation into the Forbes AI 50 reveals 65% of leading AI startups had leaked secrets. See real examples, leak types, and how to prevent this.

πŸ€– 65% of Forbes AI 50 companies leaked secrets on GitHub. Shay from our research team revealed how AI speed without security = leaks waiting to happen.
Full Wiz Research report πŸ‘‰ www.wiz.io/blog/forbes-...

10.11.2025 14:57 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

New CTF challenge ($20,000 IN PRIZES) πŸ’₯

We're running "Operation Cloudfall" - a live CTF during BlackHat & zeroday.cloud on December 10-11.

Get your free pass to the event today: zeroday.cloud/operation-cloudfall
See you in London πŸ‡¬πŸ‡§

06.11.2025 17:55 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
Path-Man | Wiz Find exploitable exposures before hackers do

πŸ•ΉοΈ Meet Path-Man: Your new favorite game. πŸ‘ΎπŸ‘ΎπŸ‘Ύ

Our 1-minute Wiz ASM game has arrived!

πŸ€” Here's the challenge: Navigate the attack surface to reach exploitable risk before the attackers get you.

Think you've got the skills? wiz.io/path-man

05.11.2025 13:15 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

πŸŽƒ Something spooky's brewing in the cloud...

Introducing a new CTF challenge - "Game of Pods" πŸ•ΈοΈ

πŸ’€ Written by top Azure researcher & worth 30 points, it's our BIGGEST challenge yet!

Get your skills ready for zeroday.cloud: cloudsecuritychampionship.com

27.10.2025 13:40 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

Need a partner to finish that exploit chain for ZERODAY.CLOUD?

We just launched our Research Collaboration Center at zeroday.cloud/collab to connect researchers, combine skills, and meet the deadline. 🀝

The clock is ticking... ⏱️

23.10.2025 16:00 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

Our biggest reminder yet. ZERODAY.CLOUD.

A first-of-its-kind, open-source cloud hacking competition.

Find vulnerabilities in the critical open-source software that powers the cloud, and compete for your share of a $4.5M prize pool.

➑️ www.zeroday.cloud

16.10.2025 17:24 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

🎁 We're giving away 2,000 SHIFT LEFT keyboards ↓

Want one on your desk?
Fill out the form >> redeem.reachdesk.com/lp/wiz/shift...

That's it! The keyboard is on its way πŸ“¦

Why are we doing this? πŸ‘€
A secret game is coming… and the whole world is invited.

16.10.2025 16:49 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
Supply Chain Risk in VSCode Extension Marketplaces | Wiz Blog Wiz Research uncovered 500+ leaked secrets in VSCode and Open VSX extensions, exposing 150K installs to risk. Learn what happened and how it was fixed.

🚨 Wiz Research uncovered 100+ leaked VSCode publisher tokens that could let attackers push malicious updates to 185K+ installs. We partnered with Microsoft to secure tokens and protect the ecosystem.

15.10.2025 14:34 β€” πŸ‘ 2    πŸ” 2    πŸ’¬ 0    πŸ“Œ 0
Preview
Emerging Threat: AI-Powered Malware Attacks | Wiz Blog From LameHug to s1ngularity, attackers are invoking AI directly in malware payloads.

@scottpiper.bsky.social highlights an emerging trend of attackers incorporating AI into their payloads, providing recent examples, and discussing the implications of this trend.

Full analysis: www.wiz.io/blog/the-eme...

09.10.2025 14:31 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
Emerging Threat: AI-Powered Malware Attacks | Wiz Blog From LameHug to s1ngularity, attackers are invoking AI directly in malware payloads.

πŸ€– We're witnessing something unprecedented with AI agents:
Malware that literally prompts ChatGPT, Claude, and other LLMs to write its own attack code. Live. On victim machines.

09.10.2025 14:31 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
Video thumbnail

Introducing ZERODAY.CLOUDπŸ•΅οΈβ€β™€οΈ
Be the first to participate in the first-of-its-kind cloud hacking competition. 🀝

WIN HUGE PRIZES from our up to 4.5 million dollar prize pool. πŸ’°πŸ†

Join us to help make the cloud a safer place. Register your exploit now >> zeroday.cloud

30.09.2025 17:39 β€” πŸ‘ 1    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0
Post image

@fortune.com JUST DROPPED A FEATURE ON Wiz πŸ”₯

If you've been following the Wiz story, this one's for you.

HUGE shoutout to everyone who made this story worth telling. You helped build something Fortune couldn't ignore πŸ’™

fortune.com/article/wiz-...

30.09.2025 14:58 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

🚨 #Shai-Hulud: Major npm supply chain attack.

100+ packages weaponized with stolen GitHub tokens, stealing secrets, hijacking repos, and auto-propagating like a worm.

Guidance + detections inside

www.wiz.io/blog/shai-hu...

16.09.2025 14:20 β€” πŸ‘ 3    πŸ” 2    πŸ’¬ 0    πŸ“Œ 1
Preview
Widespread npm Supply Chain Attack: Breaking Down Impact & Scope Across Debug, Chalk, and Beyond | Wiz Blog A deeper look at the npm debug/chalk supply-chain incident: deobfuscating the wallet-hijacking browser interceptor, quantifying the ~2-hour exposure with Wiz telemetry (~99% package prevalence, ~10% m...

Impact: code reached ~10% of cloud envs in 2hrs. Risk highest for crypto apps serving JS. Blocklist bad versions, clear caches, rebuild, scan bundles. Wiz detections live in Threat Center. Learn more: www.wiz.io/blog/widespr...

09.09.2025 12:26 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

🚨 Major npm hijack: Attackers took over Qix's account (chalk, debug & more). Malicious versions briefly hit npm, injecting browser code to hijack crypto transactions.
DuckDB ecosystem is also affected.

09.09.2025 12:26 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
Preview
WizOS Is Here: Container Security from the Image Up | Wiz Blog WizOS is now in public preview: minimal, secured container images built by Wiz with near-zero CVEs. Join now to access the Secured Image Catalog.

Meet WizOS πŸ’₯ Public Preview! Secure, minimal container images with near-zero CVEs. Less patching, more speed, swap images right in your CI/CD & IDEs.
www.wiz.io/blog/wizos-t...

09.09.2025 11:07 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

@wizsecurity is following 9 prominent accounts