Wiz io's Avatar

Wiz io

@wizsecurity.bsky.social

Secure everything you build and run in the cloud

106 Followers  |  9 Following  |  100 Posts  |  Joined: 19.11.2024  |  1.9076

Latest posts by wizsecurity.bsky.social on Bluesky

Preview
65% of Startups from Forbes AI 50 Leaked Secrets on GitHub | Wiz Blog A Wiz investigation into the Forbes AI 50 reveals 65% of leading AI startups had leaked secrets. See real examples, leak types, and how to prevent this.

πŸ€– 65% of Forbes AI 50 companies leaked secrets on GitHub. Shay from our research team revealed how AI speed without security = leaks waiting to happen.
Full Wiz Research report πŸ‘‰ www.wiz.io/blog/forbes-...

10.11.2025 14:57 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

New CTF challenge ($20,000 IN PRIZES) πŸ’₯

We're running "Operation Cloudfall" - a live CTF during BlackHat & zeroday.cloud on December 10-11.

Get your free pass to the event today: zeroday.cloud/operation-cloudfall
See you in London πŸ‡¬πŸ‡§

06.11.2025 17:55 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
Path-Man | Wiz Find exploitable exposures before hackers do

πŸ•ΉοΈ Meet Path-Man: Your new favorite game. πŸ‘ΎπŸ‘ΎπŸ‘Ύ

Our 1-minute Wiz ASM game has arrived!

πŸ€” Here's the challenge: Navigate the attack surface to reach exploitable risk before the attackers get you.

Think you've got the skills? wiz.io/path-man

05.11.2025 13:15 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

πŸŽƒ Something spooky's brewing in the cloud...

Introducing a new CTF challenge - "Game of Pods" πŸ•ΈοΈ

πŸ’€ Written by top Azure researcher & worth 30 points, it's our BIGGEST challenge yet!

Get your skills ready for zeroday.cloud: cloudsecuritychampionship.com

27.10.2025 13:40 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

Need a partner to finish that exploit chain for ZERODAY.CLOUD?

We just launched our Research Collaboration Center at zeroday.cloud/collab to connect researchers, combine skills, and meet the deadline. 🀝

The clock is ticking... ⏱️

23.10.2025 16:00 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

Our biggest reminder yet. ZERODAY.CLOUD.

A first-of-its-kind, open-source cloud hacking competition.

Find vulnerabilities in the critical open-source software that powers the cloud, and compete for your share of a $4.5M prize pool.

➑️ www.zeroday.cloud

16.10.2025 17:24 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

🎁 We're giving away 2,000 SHIFT LEFT keyboards ↓

Want one on your desk?
Fill out the form >> redeem.reachdesk.com/lp/wiz/shift...

That's it! The keyboard is on its way πŸ“¦

Why are we doing this? πŸ‘€
A secret game is coming… and the whole world is invited.

16.10.2025 16:49 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
Supply Chain Risk in VSCode Extension Marketplaces | Wiz Blog Wiz Research uncovered 500+ leaked secrets in VSCode and Open VSX extensions, exposing 150K installs to risk. Learn what happened and how it was fixed.

🚨 Wiz Research uncovered 100+ leaked VSCode publisher tokens that could let attackers push malicious updates to 185K+ installs. We partnered with Microsoft to secure tokens and protect the ecosystem.

15.10.2025 14:34 β€” πŸ‘ 2    πŸ” 2    πŸ’¬ 0    πŸ“Œ 0
Preview
Emerging Threat: AI-Powered Malware Attacks | Wiz Blog From LameHug to s1ngularity, attackers are invoking AI directly in malware payloads.

@scottpiper.bsky.social highlights an emerging trend of attackers incorporating AI into their payloads, providing recent examples, and discussing the implications of this trend.

Full analysis: www.wiz.io/blog/the-eme...

09.10.2025 14:31 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
Emerging Threat: AI-Powered Malware Attacks | Wiz Blog From LameHug to s1ngularity, attackers are invoking AI directly in malware payloads.

πŸ€– We're witnessing something unprecedented with AI agents:
Malware that literally prompts ChatGPT, Claude, and other LLMs to write its own attack code. Live. On victim machines.

09.10.2025 14:31 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
Video thumbnail

Introducing ZERODAY.CLOUDπŸ•΅οΈβ€β™€οΈ
Be the first to participate in the first-of-its-kind cloud hacking competition. 🀝

WIN HUGE PRIZES from our up to 4.5 million dollar prize pool. πŸ’°πŸ†

Join us to help make the cloud a safer place. Register your exploit now >> zeroday.cloud

30.09.2025 17:39 β€” πŸ‘ 1    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0
Post image

@fortune.com JUST DROPPED A FEATURE ON Wiz πŸ”₯

If you've been following the Wiz story, this one's for you.

HUGE shoutout to everyone who made this story worth telling. You helped build something Fortune couldn't ignore πŸ’™

fortune.com/article/wiz-...

30.09.2025 14:58 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

🚨 #Shai-Hulud: Major npm supply chain attack.

100+ packages weaponized with stolen GitHub tokens, stealing secrets, hijacking repos, and auto-propagating like a worm.

Guidance + detections inside

www.wiz.io/blog/shai-hu...

16.09.2025 14:20 β€” πŸ‘ 3    πŸ” 2    πŸ’¬ 0    πŸ“Œ 1
Preview
Widespread npm Supply Chain Attack: Breaking Down Impact & Scope Across Debug, Chalk, and Beyond | Wiz Blog A deeper look at the npm debug/chalk supply-chain incident: deobfuscating the wallet-hijacking browser interceptor, quantifying the ~2-hour exposure with Wiz telemetry (~99% package prevalence, ~10% m...

Impact: code reached ~10% of cloud envs in 2hrs. Risk highest for crypto apps serving JS. Blocklist bad versions, clear caches, rebuild, scan bundles. Wiz detections live in Threat Center. Learn more: www.wiz.io/blog/widespr...

09.09.2025 12:26 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

🚨 Major npm hijack: Attackers took over Qix's account (chalk, debug & more). Malicious versions briefly hit npm, injecting browser code to hijack crypto transactions.
DuckDB ecosystem is also affected.

09.09.2025 12:26 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
Preview
WizOS Is Here: Container Security from the Image Up | Wiz Blog WizOS is now in public preview: minimal, secured container images built by Wiz with near-zero CVEs. Join now to access the Secured Image Catalog.

Meet WizOS πŸ’₯ Public Preview! Secure, minimal container images with near-zero CVEs. Less patching, more speed, swap images right in your CI/CD & IDEs.
www.wiz.io/blog/wizos-t...

09.09.2025 11:07 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
Wiz Uncovers SES Abuse Campaign Using Stolen AWS Access Keys | Wiz Blog From leaked AWS access keys to large-scale spam: Wiz Research uncovered a live Amazon SES abuse campaign, turning insights into early-warning detections.

🚨 One leaked #AWS key fueled a global phishing campaign. Wiz traced the attack, stopped it with Defend alerts, and added protections so one key never opens every door.

Full story πŸ‘‰ www.wiz.io/blog/wiz-dis...

08.09.2025 12:13 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image Post image Post image Post image

🚨 Your Cloud DFIR Desk Mat is here!
A first-ever poster mapping MITRE ATT&CK to key AWS, Azure & GCP log sources and API events.

πŸ“₯ Get your copy: threats.wiz.io/cloud-dfir-p...

02.09.2025 13:44 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

🚨 New CTF: Azure APT πŸ†

Step into the shoes of an attacker targeting Azure. Use a malicious OAuth app, bypass restrictions, and capture the flag.

Can you solve all 12 CTF's and WIN our belt?

Test your skills with this month's CTF by Lior Sonntag πŸ‘‰ www.cloudsecuritychampionship.com/challenge/3

28.08.2025 13:03 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
s1ngularity: supply chain attack leaks secrets on GitHub: everything you need to know | Wiz Blog Detect and mitigate a critical supply chain compromise affecting the Nx NPM Package. Organizations should act urgently.

πŸ“‚ Thousands of secrets leaked into attacker-created public GitHub repos.

πŸ‘‰ The repos are gone, but the damage has been done
- Rotate credentials + upgrade immediately.

Full breakdown here: www.wiz.io/blog/s1ngula...

27.08.2025 12:10 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
s1ngularity: supply chain attack leaks secrets on GitHub: everything you need to know | Wiz Blog Detect and mitigate a critical supply chain compromise affecting the Nx NPM Package. Organizations should act urgently.

🚨 hashtag#s1ngularity: a supply chain attack hiding in the Nx npm package

Malicious versions stole hashtag#GitHub tokens, SSH keys, wallets, and secrets, even hijacking AI CLI tools to help exfiltrate data.

27.08.2025 12:10 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
Preview
A new type of long-lived key on AWS: Bedrock API keys | Wiz Blog New AWS Bedrock keys simplify authentication while raising security considerations.

Full breakdown by @scottpiper.bsky.social : www.wiz.io/blog/a-new-t...

21.08.2025 12:52 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

- Long-term keys are tied to IAM Users (and yes, we've already seen them exposed on GitHub)
- Short-term keys work differently, but both act as bearer tokens, a surprising shift from AWS's usual sigv4 approach

The good news? AWS is now scanning GitHub for exposed Bedrock keys.

21.08.2025 12:52 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
Post image

🚨 New keys just dropped… and they're already leaking.

#AWS introduced Bedrock API keys, both long-term and short-term. On the surface, they look like just another way to authenticate.
But here's the twist ⬇️

21.08.2025 12:52 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
Post image

πŸ€– AI agents are everywhere now.

So we put together a practical security guide that actually maps out what's happening in the wild. πŸ‘‡

No fluff. Just the stuff security teams need to know.

Save this cheat sheet πŸ’Ύ

19.08.2025 12:08 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

πŸ€– AI agents are everywhere now.

So we put together a practical security guide that actually maps out what's happening in the wild. πŸ‘‡

No fluff. Just the stuff security teams need to know.

Save this cheat sheet πŸ’Ύ

19.08.2025 12:03 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image Post image Post image Post image

Introducing Wizmojis.com >> Our cloud security emojis for your Slack & WhatsApp that finally get YOU.

πŸ’¬ Some favorites:
* blame-the-intern
* cve-part
* phishing-season

⬇️ Comment below β€” What emoji do you need on Slack?
The best ideas might just make it into the next pack of Wizmojis.

14.08.2025 12:45 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
Wizdom: Our first-ever user conference | Wiz An exclusive gathering of cloud security leaders, innovators, and practitioners.

You're officially invited to the BIGGEST WIZ EVENT of the year... WIZDOM!

We're going all in: Wizdom is your exclusive, in-person pass to the people & ideas shaping the future of cloud security β¬‡οΈŽ

πŸ“ New York City, Nov 3-5
πŸ“ London, Nov 17-19

Your calendar won't block itself.
www.wiz.io/wizdom

13.08.2025 12:52 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
Introducing Wiz for Exposure Management | Wiz Blog Wiz now supports exposure management across cloud, code, and on-prem – combining scanner data into one view to help teams prioritize and fix real risk.

Introducing... πŸ₯ Say hello to Wiz for Exposure Management! πŸ₯³
Wiz for Exposure Management is a NEW way to unify, prioritize, and fix exposures everywhere it lives: in your cloud, code, and on-prem infrastructure.

Learn more: www.wiz.io/blog/wiz-for...

06.08.2025 12:41 β€” πŸ‘ 3    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0
Preview
Breaking NVIDIA Triton: CVE-2025-23319 - A Vulnerability Chain Leading to AI Server Takeover | Wiz Blog Wiz Research discovers a critical vulnerability chain allowing unauthenticated attackers to take over NVIDIA's Triton Inference Server.

The breakdown:

- An internal memory name leaks in an error
- The public API gets turned against the backend
- And just like that, an attacker can take over the server

This puts #AI models, sensitive data, and entire environments at serious risk.

Full research β†’ www.wiz.io/blog/nvidia-...

04.08.2025 12:57 β€” πŸ‘ 0    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0

@wizsecurity is following 9 prominent accounts