The risk hiding behind exposed MCP servers
How unauthenticated Model Context Protocol (MCP) servers are opening doors to sensitive cloud data, IAM, and command execution.
How unauthenticated Model Context Protocol (MCP) servers are opening doors to sensitive cloud data, IAM, and command execution.
Wiz enables organizations to continuously assess environments against the CISA KEV catalog, automating risk prioritization, rapid remediation, and forensic triage workflows.
See how Wiz built Atlas, an autonomous AI system for vulnerability research that validates every finding with a real, working exploit.
Mapping appliances event logs to real-world campaigns: A step-by-step researcher’s guide to continuous agentless monitoring.
How Agentless Workload Detection exposes hidden threats in virtual appliances and modern cloud networks.
As AI accelerates how organizations build and how attackers operate, a deeply connected security ecosystem is how defenders keep up.
Wiz Research has identified exploitation of "wp2shell", a critical pre-auth RCE vulnerability chain impacting WordPress Core (CVE-2026-63030 & CVE-2026-60137). Attackers are deploying persistent webshells on vulnerable servers. Organizations should prioritize patching or applying WAF mitigations.
Part 3: How the Red Agent bypassed a credit and paywall system by changing a single client-side value from false to true.
Detect and mitigate malicious @asyncapi npm packages linked to the latest npm supply chain attack.
Rethinking IaC coverage as a funnel that shows how much of your infrastructure is governed, traceable, and ready for remediation at speed
Automation, resilience, and security for the modern age
Verizon's latest DBIR highlights how attackers are exploiting familiar weaknesses at increasing speed and scale. Here's what Wiz research reveals about vulnerabilities, trust relationships, and AI in modern cloud environments.
Uncovering a category-level blind spot in modern AI coding assistants, and why the Human-in-the-Loop safety model fails against this classic threat
Protect the modern attack surface with new auto-reconnaissance capabilities, deep internal context, and the Red Agent to find any risk, anywhere.
It's a common question we hear from prospects: "Does Wiz actually do runtime, or is it just risk prevention?" The short answer is yes, Wiz does runtime.
Power AI-driven security with trusted security context, Wiz AI Agents, and Wiz AI Skills.
The U.S. Federal Migration to PQC Just Got Real
As the time from vulnerability discovery to exploitation shrinks, building with minimal, secured components is more important than ever. Here is how WizOS helps.
Move beyond chasing vulnerabilities to a unified hybrid risk strategy. The Sensor Workload Scanner is now GA and extends our risk prioritization engine to on-premise environments to identify the critical attack paths across your hybrid cloud.
Aligning Modern CNAPP Telemetry with realistic risk assessments to drive agency efficiency through cross-team collaboration
Part 2: How the Red Agent bypassed backend resolvers to expose an entire airline booking database in fifteen minutes
By automatically loading MCP servers from workspace files, Amazon Q enabled attackers to execute code and access sensitive cloud environments.
Wiz now layers runtime signals into the Security Graph, exposing hidden attack paths to give security teams a complete picture of risk.
The threat landscape has changed. Adversaries operate at machine speed, shrinking attacks from days to minutes. Defenders can no longer investigate and respond before damage occurs. In this new era, Security Operations must prioritize speed, automation, and continuous decision-making.
Your guide to operationalizing AI-powered threat detection and response with Wiz to stay ahead of AI-driven attackers.