Introducing Wiz for Exposure Management | Wiz Blog
Wiz now supports exposure management across cloud, code, and on-prem β combining scanner data into one view to help teams prioritize and fix real risk.
Introducing... π₯ Say hello to Wiz for Exposure Management! π₯³
Wiz for Exposure Management is a NEW way to unify, prioritize, and fix exposures everywhere it lives: in your cloud, code, and on-prem infrastructure.
Learn more: www.wiz.io/blog/wiz-for...
06.08.2025 12:41 β π 4 π 1 π¬ 0 π 0
Breaking NVIDIA Triton: CVE-2025-23319 - A Vulnerability Chain Leading to AI Server Takeover | Wiz Blog
Wiz Research discovers a critical vulnerability chain allowing unauthenticated attackers to take over NVIDIA's Triton Inference Server.
The breakdown:
- An internal memory name leaks in an error
- The public API gets turned against the backend
- And just like that, an attacker can take over the server
This puts #AI models, sensitive data, and entire environments at serious risk.
Full research β www.wiz.io/blog/nvidia-...
04.08.2025 12:57 β π 0 π 1 π¬ 0 π 0
π¨ Wiz Research found a vulnerability chain in NVIDIA's open-source Triton Inference Server
What started as a small error message turned into something big:
A path to full remote code execution, no creds, no user interaction.
04.08.2025 12:57 β π 3 π 0 π¬ 1 π 0
π Can you escape a container & become THE ULTIMATE CLOUD SECURITY CHAMPION?
This month's scenario was crafted by Sagi Tzadik to explore container escape techniques, the same kinds of risks we'll be diving into at #BlackHat next week!
Challenge #2 π
cloudsecuritychampionship.com/challenge/2
31.07.2025 12:56 β π 2 π 0 π¬ 0 π 1
Critical Vulnerability in AI βVibe Codingβ platform Base44 | Wiz Blog
New discovery underscores security implications of AI-powered development and the rise of βVibe Codingβ Platforms.
The bigger story>>
As AI dev explodes, it's now core infrastructure, shared risks mean shared responsibility (and impact) if security's skipped.
π§ Full breakdown β www.wiz.io/blog/critica...
29.07.2025 14:05 β π 2 π 0 π¬ 0 π 0
Enterprises could have had their internal tools, AI chatbots, and private propriety information exposed with a simple to exploit logic flaw. Our team responsibly disclosed the issue, and it was fixed by Base44 & Wix in under 24 hours.
29.07.2025 14:05 β π 0 π 0 π¬ 1 π 0
Wiz Research just found a critical vulnerability in the popular vibe coding platform Base44, recently acquired by Wix, that could have allowed anyone to access private applications.
29.07.2025 14:05 β π 0 π 0 π¬ 1 π 0
π¨ We found a critical vulnerability in the popular Vibe Coding Platform Base44: No password. No invite. Full access.
29.07.2025 14:05 β π 0 π 0 π¬ 1 π 0
TraderTraitor: Deep Dive | Wiz Blog
Inside the Lazarus subgroup thatβs hijacking cloud platforms, poisoning supply chains, and stealing billions in digital assets
πͺ Lures: Fake recruiters, coding challenges, even job platforms
π° Hits: $308M from DMM Bitcoin, $1.5B from Bybit π Angle: Cloud-native compromiseβfrom npm to S3
Wiz Research breaks it down + shares IOCs: www.wiz.io/blog/north-k...
28.07.2025 14:14 β π 0 π 0 π¬ 0 π 0
π¨ TraderTraitor: North Korea's cyber "traitor" inside the crypto world.
This hacking crew hijacks dev workflows, poisons open-source, and compromises cloud environments β all to steal billions in crypto.
Here's how they do it π§΅
www.wiz.io/blog/north-k...
28.07.2025 14:14 β π 0 π 0 π¬ 1 π 0
π¨ New research: A cryptomining campaign is hijacking exposed PostgreSQL, hiding payloads in fake 404 pages, and abusing legit infra. Multiplatform, stealthy, and still active π
www.wiz.io/blog/soco404...
23.07.2025 13:48 β π 0 π 0 π¬ 0 π 0
YouTube video by Wiz
CISOs Making Cocktails - Special Guest: Andrew Cal (WestCap)
What do CISOs talk about over a cocktail? EVERYTHING.πΈ
Ryan sits down for a real talk with Andrew from WestCap. And trust us, the conversation is just as strong as the tequila.
You've never seen CISOs like this...
Watch nowπΉ >> www.youtube.com/watch?v=QRrt...
23.07.2025 13:15 β π 0 π 0 π¬ 0 π 0
NVIDIAScape - NVIDIA AI Vulnerability (CVE-2025-23266) | Wiz Blog
New critical vulnerability with 9.0 CVSS presents systemic risk to the AI ecosystem, carries widespread implications for AI infrastructure.
π¨ #NVIDIAscape: Your AI workloads might not be as safe as you think...
Wiz Research uncovered a 3-line container escape vulnerability in the NVIDIA Container Toolkit
That means root access to your models, data, and infra.
Full blog π www.wiz.io/blog/nvidia-...
20.07.2025 10:24 β π 0 π 0 π¬ 0 π 0
π§± With just three lines of code, attackers can escape containers and gain full root access to the host. That's your models, data, and GPU workloads β exposed.
NVIDIA rated it 9.0. We think it's a sign: AI infra needs stronger walls.
π οΈ Full technical breakdown
π www.wiz.io/blog/nvidia-...
17.07.2025 14:52 β π 0 π 0 π¬ 0 π 0
π¨ NEW RESEARCH: #NVIDIAscape AI vulnerability uncovered!
Wiz Research discovered a critical vulnerability (CVE-2025-23266) in the NVIDIA Container Toolkit, the glue connecting containers to GPUs across major cloud providers.
17.07.2025 14:52 β π 1 π 0 π¬ 1 π 1
Live Talk: Security Minds from Riot Games, Microsoft & Wiz
Crying Out Cloud Β· Episode
π‘ Eden hosts Nichole Dove, @sherrod.bsky.social & @alonsch.bsky.social.
Cloud chaos, career confessions & the future of cybersecurity. This one hits different.
Listen now:
π open.spotify.com/episode/6vGW...
π§ podcasts.apple.com/us/podcast/l...
πΊ www.youtube.com/watch?v=7Kwi...
15.07.2025 13:27 β π 1 π 1 π¬ 0 π 0
WOOHOO! We are #1 in over 130 reports on #G2 this summer!βοΈπ
Huge G2 moment, and it's all thanks to you π
THANK YOU to our amazing Wizards and customers for your continued trust, feedback, and partnership. πͺ
www.wiz.io/lp/g2-grid-r...
08.07.2025 13:20 β π 0 π 0 π¬ 0 π 0
MCP and LLM Security Research Briefing | Wiz Blog
Explore the evolving Model Context Protocol (MCP), its security risks, and how to prepare for safe adoption as LLMs connect to external systems.
Synthesized 20+ sources and internal @wizsecurity.bsky.social expertise to come out with a comprehensive guide to MCP security
Today's options, and tomorrow's possibilities
www.wiz.io/blog/mcp-sec...
17.04.2025 14:50 β π 5 π 1 π¬ 0 π 0
Hardening GitHub Actions: Lessons from Recent Attacks | Wiz Blog
Build resilient GitHub Actions workflows with insights from real attacks, missteps to avoid, and security tips GitHubβs docs donβt fully cover.
In light of recent GitHub Actions incidents (Ultralytics, tj-actions...), I wrote up a practical guide to hardening for @wizsecurity.bsky.social
Covers permissions, secrets, 3rd-party Actions, ++
Use it to avoid learning these lessons the hard way:
www.wiz.io/blog/github-...
05.05.2025 15:45 β π 7 π 4 π¬ 0 π 0
I had a lot of fun making this challenge. I wanted to do a cloud security challenge where the cloud infrastructure is secure (IMDSv2, data perimeters), but something still allows it to be hackable and you need to know some advanced AWS security tricks to abuse it. π€« Try it out!
27.06.2025 13:50 β π 8 π 3 π¬ 0 π 1
π¨ Wiz spotted a JDWP RCE attack deploying a stealthy cryptominer within hours. Custom XMRig, no CLI flags, deep persistence.
Debug mode β safe mode.
Read the full breakdown π www.wiz.io/blog/exposed...
02.07.2025 15:27 β π 0 π 0 π¬ 0 π 0
The Ultimate Cloud Security Championship | 12 Months Γ 12 Challenges
Join our monthly cloud security CTF challenge, built by top Wiz researchers. Solve real-world scenarios and rise to the top of the leaderboard.
10k+ players have already joined the Ultimate Cloud Security Championship, and we're just getting started. π₯
π Participants from 20+ countries
π 200+ have solved Challenge #1 by @scottpiper.bsky.social
π Only the top make it to the leaderboard
Claim your spot β www.cloudsecuritychampionship.com
01.07.2025 14:43 β π 0 π 0 π¬ 0 π 0
The Ultimate Cloud Security Championship | 12 Months Γ 12 Challenges
Join our monthly cloud security CTF challenge, built by top Wiz researchers. Solve real-world scenarios and rise to the top of the leaderboard.
π¨THE ULTIMATE CLOUD SECURITY CHAMPIONSHIP begins today! π₯
12 monthly challenges.
12 top researchers.
One leaderboard.
Challenge #1 is LIVE now, created by @scottpiper.bsky.social.
Solve challenges & climb the leaderboard π
Think you've got what it takes? β cloudsecuritychampionship.com
26.06.2025 13:01 β π 4 π 1 π¬ 0 π 1
Wiz Service Catalog: Align Cloud Sec with Services | Wiz Blog
Get a shared, service-centric view of cloud risk. Empower devs, reduce friction, and speed remediation with Wizβs Service Catalog.
π£ Just dropped: Wiz Service Catalog! π οΈ
A new way to organize cloud risk by the services your teams own. Reduce noise, align development and security, and remediate faster.
Now in public preview π www.wiz.io/blog/wiz-ser...
25.06.2025 12:01 β π 0 π 0 π¬ 0 π 0
π¨ We scanned GitHub and found *hundreds* of valid secrets, 4 of the top 5 were AI-related:
HuggingFace, Azure OpenAI, Weights & Biases, and Groq.
Read more:
www.wiz.io/blog/leaking...
18.06.2025 13:09 β π 3 π 1 π¬ 0 π 0
Zero Critical Issues, Infinite Security Potential | Wiz Blog
Over 50% of Wiz customers have reduced their cloud risk by reaching Zero Critical Issues
π BIG MILESTONE π
50% of Wiz customers have joined the Zero Critical Club, reaching 0 critical issues in the cloud.
We're celebrating every customer that made this happen - and setting the bar for what's next in cloud security.
www.wiz.io/blog/celebra...
03.06.2025 14:43 β π 0 π 0 π¬ 0 π 0
The CVE Database: Curated Vulnerability Intelligence by Wiz | Wiz
Wiz's CVE Database curates CVE data to create easy-to-navigate profiles that cover the entire vulnerability timeline, exploit scenarios, and mitigation steps.
π¨ REMINDER: The Wiz Vulnerability Database is live, and already used by 30,000+ cloud security pros.
Here's what's new >>
- 138,000+ CVEs in the database
- 1,500+ new CVEs added monthly
- New expert analysis from the Wiz Research team
Start exploring β wiz.io/vulnerability-database
28.05.2025 17:18 β π 0 π 0 π¬ 0 π 0
Ivanti EPMM RCE Vulnerability Chain Exploited in the Wild | Wiz Blog
Wiz Threat Research has observed exploitation in-the-wild of CVE-2025-4427 and CVE-2025-4428, the latest vulnerabilities affecting Ivanti Endpoint Manager Mobile (EPMM).
π¨ New Wiz research: Active exploitation of Ivanti EPMM flaws (CVE-2025-4427 & 4428) enables RCE in the wild.
Cloud systems are at risk; patch now.
Wiz customers can find pre-built detection queries in the Threat Intelligence Center.
Full details π www.wiz.io/blog/ivanti-...
22.05.2025 11:19 β π 1 π 1 π¬ 0 π 0
Crying out Cloud: Our Favorite Stories of 2024 | Wiz Blog
Vulnerabilities, security incidents, and more. The Crying out Cloud team discusses our most interesting podcast episodes and newsletter editions of 2024.
From supply chain attacks to exposed AI infra, our podcast & newsletter were on π₯ this year!
π§ Thanks to everyone who joined us on Crying Out Cloud this year.
Dive into our top stories β www.wiz.io/blog/favorit...
16.05.2025 06:54 β π 0 π 0 π¬ 0 π 0
Cloud security historian.
Developed http://flaws.cloud, CloudMapper, and Parliament.
Founding team for fwdcloudsec.org
Principal Cloud Security Researcher at Wiz.
Your Friendly Cloud Antagonist
Proficient at drawing the rest of the π¦
Head of Research @ Reversec - cloud security, automation, DevOps and attack detection. Opinions are my own.
Snarkmonger. Chief Cloud Economist at The Duckbill Group.
he/him.
Get my opinionated take on AWS news: http://lastweekinaws.com/t/
Signal: 833-AWS-BILL (833-297-2455)
Washington Post reporter covering hacking, disinformation and whatβs left of privacy. Author of books on the Cult of the Dead Cow, organized criminal hacking, and Napster. Pulitzer co-finalist 2024. Signal joemenn.01
Cybersecurity reporter at Bloomberg News in DC. Signal: @howelloneill.01, email: patoneill1@bloomberg.net
hacker, poster, weird machine mechanic
https://chompie.rip
official Bluesky account (check usernameπ)
Bugs, feature requests, feedback: support@bsky.app