π€ 65% of Forbes AI 50 companies leaked secrets on GitHub. Shay from our research team revealed how AI speed without security = leaks waiting to happen.
Full Wiz Research report π www.wiz.io/blog/forbes-...
@wizsecurity.bsky.social
Secure everything you build and run in the cloud
π€ 65% of Forbes AI 50 companies leaked secrets on GitHub. Shay from our research team revealed how AI speed without security = leaks waiting to happen.
Full Wiz Research report π www.wiz.io/blog/forbes-...
New CTF challenge ($20,000 IN PRIZES) π₯
We're running "Operation Cloudfall" - a live CTF during BlackHat & zeroday.cloud on December 10-11.
Get your free pass to the event today: zeroday.cloud/operation-cloudfall
See you in London π¬π§
πΉοΈ Meet Path-Man: Your new favorite game. πΎπΎπΎ
Our 1-minute Wiz ASM game has arrived!
π€ Here's the challenge: Navigate the attack surface to reach exploitable risk before the attackers get you.
Think you've got the skills? wiz.io/path-man
π Something spooky's brewing in the cloud...
Introducing a new CTF challenge - "Game of Pods" πΈοΈ
π Written by top Azure researcher & worth 30 points, it's our BIGGEST challenge yet!
Get your skills ready for zeroday.cloud: cloudsecuritychampionship.com
Need a partner to finish that exploit chain for ZERODAY.CLOUD?
We just launched our Research Collaboration Center at zeroday.cloud/collab to connect researchers, combine skills, and meet the deadline. π€
The clock is ticking... β±οΈ
Our biggest reminder yet. ZERODAY.CLOUD.
A first-of-its-kind, open-source cloud hacking competition.
Find vulnerabilities in the critical open-source software that powers the cloud, and compete for your share of a $4.5M prize pool.
β‘οΈ www.zeroday.cloud
π We're giving away 2,000 SHIFT LEFT keyboards β
Want one on your desk?
Fill out the form >> redeem.reachdesk.com/lp/wiz/shift...
That's it! The keyboard is on its way π¦
Why are we doing this? π
A secret game is coming⦠and the whole world is invited.
π¨ Wiz Research uncovered 100+ leaked VSCode publisher tokens that could let attackers push malicious updates to 185K+ installs. We partnered with Microsoft to secure tokens and protect the ecosystem.
15.10.2025 14:34 β π 2 π 2 π¬ 0 π 0@scottpiper.bsky.social highlights an emerging trend of attackers incorporating AI into their payloads, providing recent examples, and discussing the implications of this trend.
Full analysis: www.wiz.io/blog/the-eme...
π€ We're witnessing something unprecedented with AI agents:
Malware that literally prompts ChatGPT, Claude, and other LLMs to write its own attack code. Live. On victim machines.
Introducing ZERODAY.CLOUDπ΅οΈββοΈ
Be the first to participate in the first-of-its-kind cloud hacking competition. π€
WIN HUGE PRIZES from our up to 4.5 million dollar prize pool. π°π
Join us to help make the cloud a safer place. Register your exploit now >> zeroday.cloud
@fortune.com JUST DROPPED A FEATURE ON Wiz π₯
If you've been following the Wiz story, this one's for you.
HUGE shoutout to everyone who made this story worth telling. You helped build something Fortune couldn't ignore π
fortune.com/article/wiz-...
π¨ #Shai-Hulud: Major npm supply chain attack.
100+ packages weaponized with stolen GitHub tokens, stealing secrets, hijacking repos, and auto-propagating like a worm.
Guidance + detections inside
www.wiz.io/blog/shai-hu...
Impact: code reached ~10% of cloud envs in 2hrs. Risk highest for crypto apps serving JS. Blocklist bad versions, clear caches, rebuild, scan bundles. Wiz detections live in Threat Center. Learn more: www.wiz.io/blog/widespr...
09.09.2025 12:26 β π 0 π 0 π¬ 0 π 0π¨ Major npm hijack: Attackers took over Qix's account (chalk, debug & more). Malicious versions briefly hit npm, injecting browser code to hijack crypto transactions.
DuckDB ecosystem is also affected.
Meet WizOS π₯ Public Preview! Secure, minimal container images with near-zero CVEs. Less patching, more speed, swap images right in your CI/CD & IDEs.
www.wiz.io/blog/wizos-t...
π¨ One leaked #AWS key fueled a global phishing campaign. Wiz traced the attack, stopped it with Defend alerts, and added protections so one key never opens every door.
Full story π www.wiz.io/blog/wiz-dis...
π¨ Your Cloud DFIR Desk Mat is here!
A first-ever poster mapping MITRE ATT&CK to key AWS, Azure & GCP log sources and API events.
π₯ Get your copy: threats.wiz.io/cloud-dfir-p...
π¨ New CTF: Azure APT π
Step into the shoes of an attacker targeting Azure. Use a malicious OAuth app, bypass restrictions, and capture the flag.
Can you solve all 12 CTF's and WIN our belt?
Test your skills with this month's CTF by Lior Sonntag π www.cloudsecuritychampionship.com/challenge/3
π Thousands of secrets leaked into attacker-created public GitHub repos.
π The repos are gone, but the damage has been done
- Rotate credentials + upgrade immediately.
Full breakdown here: www.wiz.io/blog/s1ngula...
π¨ hashtag#s1ngularity: a supply chain attack hiding in the Nx npm package
Malicious versions stole hashtag#GitHub tokens, SSH keys, wallets, and secrets, even hijacking AI CLI tools to help exfiltrate data.
Full breakdown by @scottpiper.bsky.social : www.wiz.io/blog/a-new-t...
21.08.2025 12:52 β π 1 π 0 π¬ 0 π 0- Long-term keys are tied to IAM Users (and yes, we've already seen them exposed on GitHub)
- Short-term keys work differently, but both act as bearer tokens, a surprising shift from AWS's usual sigv4 approach
The good news? AWS is now scanning GitHub for exposed Bedrock keys.
π¨ New keys just droppedβ¦ and they're already leaking.
#AWS introduced Bedrock API keys, both long-term and short-term. On the surface, they look like just another way to authenticate.
But here's the twist β¬οΈ
π€ AI agents are everywhere now.
So we put together a practical security guide that actually maps out what's happening in the wild. π
No fluff. Just the stuff security teams need to know.
Save this cheat sheet πΎ
π€ AI agents are everywhere now.
So we put together a practical security guide that actually maps out what's happening in the wild. π
No fluff. Just the stuff security teams need to know.
Save this cheat sheet πΎ
Introducing Wizmojis.com >> Our cloud security emojis for your Slack & WhatsApp that finally get YOU.
π¬ Some favorites:
* blame-the-intern
* cve-part
* phishing-season
β¬οΈ Comment below β What emoji do you need on Slack?
The best ideas might just make it into the next pack of Wizmojis.
You're officially invited to the BIGGEST WIZ EVENT of the year... WIZDOM!
We're going all in: Wizdom is your exclusive, in-person pass to the people & ideas shaping the future of cloud security β¬οΈ
π New York City, Nov 3-5
π London, Nov 17-19
Your calendar won't block itself.
www.wiz.io/wizdom
Introducing... π₯ Say hello to Wiz for Exposure Management! π₯³
Wiz for Exposure Management is a NEW way to unify, prioritize, and fix exposures everywhere it lives: in your cloud, code, and on-prem infrastructure.
Learn more: www.wiz.io/blog/wiz-for...
The breakdown:
- An internal memory name leaks in an error
- The public API gets turned against the backend
- And just like that, an attacker can take over the server
This puts #AI models, sensitive data, and entire environments at serious risk.
Full research β www.wiz.io/blog/nvidia-...