The Red Agent POV: The One Boolean That Broke a B2B Platform’s Credit System
Part 3: How the Red Agent bypassed a credit and paywall system by changing a single client-side value from false to true.
Part 3: How the Red Agent bypassed a credit and paywall system by changing a single client-side value from false to true.
Detect and mitigate malicious @asyncapi npm packages linked to the latest npm supply chain attack.
Verizon's latest DBIR highlights how attackers are exploiting familiar weaknesses at increasing speed and scale. Here's what Wiz research reveals about vulnerabilities, trust relationships, and AI in modern cloud environments.
Uncovering a category-level blind spot in modern AI coding assistants, and why the Human-in-the-Loop safety model fails against this classic threat
Part 2: How the Red Agent bypassed backend resolvers to expose an entire airline booking database in fifteen minutes
By automatically loading MCP servers from workspace files, Amazon Q enabled attackers to execute code and access sensitive cloud environments.
An inside look at how the Red Agent, our AI-Powered Attacker, uncovers complex, exploitable risks in the wild
Detect and mitigate malicious npm packages linked to the latest npm supply chain attack, based on the open sourced Mini Shai-Hulud malware.
Discussion of PQC relevant statistics that we see across our customers and other data sources.
Wiz CIRT and Wiz Research detail JINX-0164, a threat actor using LinkedIn social engineering, custom macOS malware, and CI/CD hijacking to target cryptocurrency organizations.
Insights from real-world environments into how code, developer tooling, automation, and AI are reshaping application security.
Discover the latest on malicious versions of the pypi package durabletask, matching TeamPCP tactics.