Inside 90 days of attacks on AI infrastructure
Wiz honeypots uncover active campaigns targeting LiteLLM, MCP servers, and AI frameworks through RCE, blind prompt injection, and memory credential theft.
Wiz honeypots uncover active campaigns targeting LiteLLM, MCP servers, and AI frameworks through RCE, blind prompt injection, and memory credential theft.
A practitioner’s guide to log visibility, incident readiness, and threat hunting across the major version control services.
Wiz Research telemetry reveals why the majority of high-severity findings lack a path to compromise
Malicious versions of the arrayref Rust crate (and others) executed a backdoor at compile time. The campaign's infrastructure overlaps with recent DPRK supply chain attacks, including Mastra and axios.
Instead of leaving behind recognizable fingerprints from public tooling, adversaries can now generate realistic device names that blend naturally into enterprise environments. This blog explores how that changes Entra ID detection and what are the behavioral signals that still expose these attacks.
Wiz Red Agent independently discovered and exploited a GitHub Actions injection missed by GitHub’s Advanced Security, validated access to sensitive data in Snowflake’s internal Jira, and assessed the blast radius—all without human intervention, five days after the flaw became live.
A practical playbook for investigating GitHub token compromise, drawn from Wiz CIRT's response to a coordinated multi-organization campaign.
Reverse engineering Metabase CVE-2026-72898 with AI to accelerate defense.
Cloud and AI threat activity tracked by Wiz Research and CIRT, January through June 2026
Wiz Research is actively investigating an ongoing software supply chain attack affecting multiple keyv/cacheable npm packages.
S3 compatible services carry many of the same concerns as the original S3 service. This article highlights which assumptions break and what risks remain.
A critical vulnerability chain in Azure Cosmos DB enabled full read and write access to every Cosmos DB database.