Wiz io

@wiz.io

Secure everything you build and run in the cloud

🚨 CosmosEscape: We found a single key that unlocked every database in Azure CosmosDB One key >> Platform-wide impact. Microsoft fully remediated the issue. ✅ Read the full research and see how Wiz uncovered CosmosEscape: www.wiz.io/blog/cosmose...

Bild

🚨 Wiz Red Agent is GA! AI-powered continuous pentesting that finds what traditional scanners miss: logic flaws, hidden APIs, auth bypasses & exploitable risks. 10K+ critical risks found in preview 🔥 wiz.io/blog/wiz-red...

🧠 Meet Atlas: our AI vulnerability researcher. It found 200+ previously unknown vulnerabilities, ranked #1 on CyberGym (90.9%), and is helping power Wiz Code with continuous AI-powered security. 🏆 www.wiz.io/blog/atlas-a...

Bild

🚨 SDLC Security '26 report is here! Wiz Research analyzed real dev envs, repos & prod telemetry on SDLC risk shifting upstream. 50% GH Actions reuse risk clusters 86% macOS AI amplifies risk Full report ↓ www.wiz.io/reports/sdlc...

Bild

The secret's out.🤫 Introducing THE ZERODAY.CLOUD COMMUNITY 👾 Inside: • 0-day vulnerability deep dives from Xint, Moritz Sanft, Paul Gerste & more... • Access to events & a network of world-class hackers • CTFs with prizes Join now :)

Bild

🚨 BREAKING: Wiz Research discovered Remote Code Execution on GitHub.com with a single git push. The flaw in @github.com allowed unauthorized access to millions of repositories belonging to other users and organizations 🤯

Bild

🚨 500+ malicious PRs. One campaign. Wiz Research traced 6 waves of prt-scan starting 3 weeks earlier. AI-powered, automated attacks exploiting pull_request_target. Low success rate—but real npm + cloud creds hit. Full story: www.wiz.io/blog/six-acc...

prt-scan: AI-Powered GitHub Actions Supply Chain Attack | Wiz Blog

Wiz Research traces six waves of pull_request_target exploitation to one actor, starting three weeks before public disclosure. 500+ malicious PRs, 10% success.

wiz.io

NEW CTF: AWS turned 20 🎉 So we built our monthly CTF challenge to celebrate: packed with challenges inspired by the last two decades of cloud ☁️ Oh, and… we made sure AI can't solve it 😅 So no prompts this time. Ready to play? www.cloudsecuritychampionship.com

Bild

🎉 IT'S OFFICIAL: wiz joins Google to secure the AI era. This is a massive moment for our customers and our team. Thank you to every customer, partner, and Wizard who made this moment possible 💙 We can't wait to share what's next. wiz.io/blog/google-...

Bild

🚨New CTF Alert: Got trust issues? Ever wondered what it's like to investigate a real data leak? Now's your chance. 🕵️ Your mission: 1) Investigate the compromised machine 2) Figure out how the attacker exfiltrated the data 3) Find the flag 🔗 Start here: cloudsecuritychampionship.com

The Ultimate Cloud Security Championship | 12 Months × 12 Challenges

Join our monthly cloud security CTF challenge, built by top Wiz researchers. Solve real-world scenarios and rise to the top of the leaderboard.

cloudsecuritychampionship.com

How good is AI at hacking? We built a benchmark to find out. 🧪 Introducing the Offensive AI Benchmark, the framework that tests AI agents on 250+ real-world offensive security challenges. Check it out → www.wiz.io/cyber-model-...

Bild

🚨 CodeBreach: Wiz Research identified a critical repository-hijacking vulnerability that abused a CodeBuild Regex flaw to compromise core AWS GitHub repos, including a core lib running at the heart of the cloud's most critical interface - the #AWS Console.

Bild

Day 2 at zeroday.cloud, let’s roll. 👾 👀 Didn’t register? No panic. Walk-ins are welcome for the onsite CTF and all the action happening on the floor. Flags are hidden. Only the sharp survive.

Bild

Day 1 of zeroday.cloud = PURE EXPLOIT ENERGY 👾 From crowd shots 👀 to researchers buried deep in terminals 💻 From first checks being claimed To live container escapes blowing minds in real time. See you tomorrow!

BildBildBild

Day 1 at zeroday.cloud didn’t come to play 😈 New vulns dropped in Grafana, Linux Kernel, 3 Redis, and 2 PostgreSQL - and every. single. one. worked 🤯 100% success rate for day one. Let’s see what we find tomorrow 👀

Bild

Zeroday.cloud 2025 kicks off TOMORROW! 💻 London, brace yourself - IDEs open. Exploits cooking. 13 zero-days are on the line 💣 Don't miss it. Here's the schedule ahead ⬎

BildBild

🎧 Your age after React2Shell... 𝟴𝟴. Cloud Security Wrapped 2025 is HERE ↓ Check out our exclusive insights from our Wiz Research team! Spotify, are we doing it right? 🎵

BildBildBildBild

🎉 This is not a dream 💤 OUR WizZZZ BOOTH IS NOW OPEN. Behold the ULTIMATE cloud security booth! Games, demos, swag, naps… and the coziest cloud security playground in history 🛏️ Come see why CISOs are finally sleeping through the night 😴

It’s time to bust some malware! 🦠 Challenge #6 “Malware Busters” is LIVE. Built by Gili Tikochinski for the reverse‑engineering pros - dive into assembly and uncover what’s hidden inside. Think you can crack it? cloudsecuritychampionship.com/challenge/6

The Ultimate Cloud Security Championship | 12 Months × 12 Challenges

Join our monthly cloud security CTF challenge, built by top Wiz researchers. Solve real-world scenarios and rise to the top of the leaderboard.

cloudsecuritychampionship.com

Need a partner to finish that exploit chain for ZERODAY.CLOUD? We just launched our Research Collaboration Center at zeroday.cloud/collab to connect researchers, combine skills, and meet the deadline. 🤝 The clock is ticking... ⏱️

Bild

Our biggest reminder yet. ZERODAY.CLOUD. A first-of-its-kind, open-source cloud hacking competition. Find vulnerabilities in the critical open-source software that powers the cloud, and compete for your share of a $4.5M prize pool. ➡️ www.zeroday.cloud

Bild