<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom">
    <channel>
        <title>Wiz Blog: Research | RSS feed</title>
        <link>https://www.wiz.io</link>
        <description>Guides, announcements, and articles about Cloud Security and the Wiz platform.</description>
        <lastBuildDate>Wed, 09 Sep 2026 14:58:50 GMT</lastBuildDate>
        <docs>https://validator.w3.org/feed/docs/rss2.html</docs>
        <generator>https://github.com/jpmonette/feed</generator>
        <language>de-DE</language>
        <image>
            <title>Wiz Blog: Research | RSS feed</title>
            <url>https://www.wiz.io/rss_feed_logo.jpg</url>
            <link>https://www.wiz.io</link>
        </image>
        <copyright>All rights reserved 2026, Wiz Inc.</copyright>
        <atom:link href="https://www.wiz.io/feed/tag/research/rss.xml" rel="self" type="application/rss+xml"/>
        <item>
            <title><![CDATA[ Inside 90 days of attacks on AI infrastructure]]></title>
            <link>https://www.wiz.io/blog/ai-infrastructure-honeypot</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/ai-infrastructure-honeypot</guid>
            <pubDate>Thu, 27 Aug 2026 16:33:16 GMT</pubDate>
            <description><![CDATA[Wiz honeypots uncover active campaigns targeting LiteLLM, MCP servers, and AI frameworks through RCE, blind prompt injection, and memory credential theft.]]></description>
            <content:encoded><![CDATA[Wiz honeypots uncover active campaigns targeting LiteLLM, MCP servers, and AI frameworks through RCE, blind prompt injection, and memory credential theft.]]></content:encoded>
            <author>Yaara Shriki</author>
            <enclosure url="https://www.datocms-assets.com/75231/1787593149-honeypots-2x.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[Version Control DFIR: a Cheatsheet to GitHub, GitLab, Bitbucket, and Azure DevOps]]></title>
            <link>https://www.wiz.io/blog/vcs-dfir-threat-hunting-github-gitlab-azure-devops</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/vcs-dfir-threat-hunting-github-gitlab-azure-devops</guid>
            <pubDate>Thu, 27 Aug 2026 12:00:00 GMT</pubDate>
            <description><![CDATA[A practitioner’s guide to log visibility, incident readiness, and threat hunting across the major version control services.]]></description>
            <content:encoded><![CDATA[A practitioner’s guide to log visibility, incident readiness, and threat hunting across the major version control services.]]></content:encoded>
            <author>Shira Ayal</author>
            <author>Sean Johnstone</author>
            <enclosure url="https://www.datocms-assets.com/75231/1787767961-vcs-2x-1.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[ The State of Cloud Risk 2026: Most Security Findings Aren’t Real Attacker Opportunities]]></title>
            <link>https://www.wiz.io/blog/cloud-risk-report-2026</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/cloud-risk-report-2026</guid>
            <pubDate>Wed, 26 Aug 2026 15:01:58 GMT</pubDate>
            <description><![CDATA[Wiz Research telemetry reveals why the majority of high-severity findings lack a path to compromise]]></description>
            <content:encoded><![CDATA[Wiz Research telemetry reveals why the majority of high-severity findings lack a path to compromise]]></content:encoded>
            <author>Wiz Threat Research</author>
            <enclosure url="https://www.datocms-assets.com/75231/1787243044-1200x600-1.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[Rust Supply Chain Attack on arrayref: Significant Overlap with DPRK Campaigns]]></title>
            <link>https://www.wiz.io/blog/rust-supply-chain-attack-on-arrayref-significant-overlap-with-dprk-campaigns</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/rust-supply-chain-attack-on-arrayref-significant-overlap-with-dprk-campaigns</guid>
            <pubDate>Thu, 20 Aug 2026 15:56:39 GMT</pubDate>
            <description><![CDATA[Malicious versions of the arrayref Rust crate (and others) executed a backdoor at compile time. The campaign's infrastructure overlaps with recent DPRK supply chain attacks, including Mastra and axios.]]></description>
            <content:encoded><![CDATA[Malicious versions of the arrayref Rust crate (and others) executed a backdoor at compile time. The campaign's infrastructure overlaps with recent DPRK supply chain attacks, including Mastra and axios.]]></content:encoded>
            <author>Rami McCarthy</author>
            <author>Benjamin Read</author>
            <enclosure url="https://www.datocms-assets.com/75231/1787237870-threat-update-blue-wireframe_custom-1.jpeg" length="0" type="image/jpeg"/>
        </item>
        <item>
            <title><![CDATA[ How to Spot and Stop Rogue Device Joins]]></title>
            <link>https://www.wiz.io/blog/detecting-entra-device-registration-abuse</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/detecting-entra-device-registration-abuse</guid>
            <pubDate>Tue, 18 Aug 2026 16:24:13 GMT</pubDate>
            <description><![CDATA[Instead of leaving behind recognizable fingerprints from public tooling, adversaries can now generate realistic device names that blend naturally into enterprise environments. This blog explores how that changes Entra ID detection and what are the behavioral signals that still expose these attacks.]]></description>
            <content:encoded><![CDATA[Instead of leaving behind recognizable fingerprints from public tooling, adversaries can now generate realistic device names that blend naturally into enterprise environments. This blog explores how that changes Entra ID detection and what are the behavioral signals that still expose these attacks.]]></content:encoded>
            <author>Shahar Dorfman</author>
            <author>Sapir Federovsky</author>
            <enclosure url="https://www.datocms-assets.com/75231/1787048534-design-for-device-registration.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[ Wiz Red Agent Finds Its Way Into Snowflake’s Internal Jira Through a Flaw in a GitHub Copilot–Assisted PR]]></title>
            <link>https://www.wiz.io/blog/red-agent-snowflake-copilot-cicd-bug</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/red-agent-snowflake-copilot-cicd-bug</guid>
            <pubDate>Mon, 17 Aug 2026 14:00:00 GMT</pubDate>
            <description><![CDATA[Wiz Red Agent independently discovered and exploited a GitHub Actions injection missed by GitHub’s Advanced Security, validated access to sensitive data in Snowflake’s internal Jira, and assessed the blast radius—all without human intervention, five days after the flaw became live.]]></description>
            <content:encoded><![CDATA[Wiz Red Agent independently discovered and exploited a GitHub Actions injection missed by GitHub’s Advanced Security, validated access to sensitive data in Snowflake’s internal Jira, and assessed the blast radius—all without human intervention, five days after the flaw became live.]]></content:encoded>
            <author>Gal Nagli</author>
            <enclosure url="https://www.datocms-assets.com/75231/1786964856-image.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[How to Investigate GitHub PAT Compromise: Lessons From a Multi-Organization Campaign]]></title>
            <link>https://www.wiz.io/blog/investigating-github-pat-compromise</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/investigating-github-pat-compromise</guid>
            <pubDate>Thu, 13 Aug 2026 15:04:28 GMT</pubDate>
            <description><![CDATA[A practical playbook for investigating GitHub token compromise, drawn from Wiz CIRT's response to a coordinated multi-organization campaign.]]></description>
            <content:encoded><![CDATA[A practical playbook for investigating GitHub token compromise, drawn from Wiz CIRT's response to a coordinated multi-organization campaign.]]></content:encoded>
            <author>Eden Abergil</author>
            <enclosure url="https://www.datocms-assets.com/75231/1786570602-github-pat-compromise-2.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[Inside the Metabase SQLi: Exploited in the Wild]]></title>
            <link>https://www.wiz.io/blog/inside-the-metabase-sqli-exploited-in-the-wild</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/inside-the-metabase-sqli-exploited-in-the-wild</guid>
            <pubDate>Mon, 10 Aug 2026 12:30:17 GMT</pubDate>
            <description><![CDATA[Reverse engineering Metabase CVE-2026-72898 with AI to accelerate defense. ]]></description>
            <content:encoded><![CDATA[Reverse engineering Metabase CVE-2026-72898 with AI to accelerate defense. ]]></content:encoded>
            <author>Rami McCarthy</author>
            <enclosure url="https://www.datocms-assets.com/75231/1786360608-wiz-research-live-24_custom.jpeg" length="0" type="image/jpeg"/>
        </item>
        <item>
            <title><![CDATA[Cloud Threat Highlights: H1 2026]]></title>
            <link>https://www.wiz.io/blog/cloud-threat-highlights-h1-2026</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/cloud-threat-highlights-h1-2026</guid>
            <pubDate>Thu, 06 Aug 2026 14:03:03 GMT</pubDate>
            <description><![CDATA[Cloud and AI threat activity tracked by Wiz Research and CIRT, January through June 2026]]></description>
            <content:encoded><![CDATA[Cloud and AI threat activity tracked by Wiz Research and CIRT, January through June 2026]]></content:encoded>
            <author>Wiz Threat Research</author>
            <enclosure url="https://www.datocms-assets.com/75231/1786019706-cloud_threat_highlights_blog-1.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[keyv and cacheable npm Package Hijacked in Supply Chain Attack]]></title>
            <link>https://www.wiz.io/blog/keyv-and-cacheable-npm-supply-chain-attack</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/keyv-and-cacheable-npm-supply-chain-attack</guid>
            <pubDate>Tue, 04 Aug 2026 11:25:22 GMT</pubDate>
            <description><![CDATA[Wiz Research is actively investigating an ongoing software supply chain attack affecting multiple keyv/cacheable npm packages. ]]></description>
            <content:encoded><![CDATA[Wiz Research is actively investigating an ongoing software supply chain attack affecting multiple keyv/cacheable npm packages. ]]></content:encoded>
            <author>Merav Bar</author>
            <author>Rami McCarthy</author>
            <enclosure url="https://www.datocms-assets.com/75231/1785842280-screenshot-2026-08-04-at-14-17-24.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[S3 Clones in the Neoclouds]]></title>
            <link>https://www.wiz.io/blog/s3-clones-in-the-neoclouds</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/s3-clones-in-the-neoclouds</guid>
            <pubDate>Fri, 31 Jul 2026 13:48:07 GMT</pubDate>
            <description><![CDATA[S3 compatible services carry many of the same concerns as the original S3 service.  This article highlights which assumptions break and what risks remain.]]></description>
            <content:encoded><![CDATA[S3 compatible services carry many of the same concerns as the original S3 service.  This article highlights which assumptions break and what risks remain.]]></content:encoded>
            <author>Scott Piper</author>
            <enclosure url="https://www.datocms-assets.com/75231/1785428555-s3-2x.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[CosmosEscape: Taking Over Every Database in Azure Cosmos DB ]]></title>
            <link>https://www.wiz.io/blog/cosmosescape-taking-over-every-database-in-azure-cosmos-db</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/cosmosescape-taking-over-every-database-in-azure-cosmos-db</guid>
            <pubDate>Thu, 30 Jul 2026 12:00:01 GMT</pubDate>
            <description><![CDATA[A critical vulnerability chain in Azure Cosmos DB enabled full read and write access to every Cosmos DB database. ]]></description>
            <content:encoded><![CDATA[A critical vulnerability chain in Azure Cosmos DB enabled full read and write access to every Cosmos DB database. ]]></content:encoded>
            <author>Yuval Avrahami</author>
            <author>Lior Maman</author>
            <enclosure url="https://www.datocms-assets.com/75231/1785342613-cosmos-2x-1.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[ The risk hiding behind exposed MCP servers]]></title>
            <link>https://www.wiz.io/blog/the-risk-hiding-behind-exposed-mcp-servers</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/the-risk-hiding-behind-exposed-mcp-servers</guid>
            <pubDate>Tue, 28 Jul 2026 15:58:22 GMT</pubDate>
            <description><![CDATA[How unauthenticated Model Context Protocol (MCP) servers are opening doors to sensitive cloud data, IAM, and command execution.]]></description>
            <content:encoded><![CDATA[How unauthenticated Model Context Protocol (MCP) servers are opening doors to sensitive cloud data, IAM, and command execution.]]></content:encoded>
            <author>Hila Ramati</author>
            <enclosure url="https://www.datocms-assets.com/75231/1785241301-mcp22-2x.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[Opening the Black Box: Agentless Threat Detection for Virtual Appliances]]></title>
            <link>https://www.wiz.io/blog/agentless-threat-hunting-fortigate</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/agentless-threat-hunting-fortigate</guid>
            <pubDate>Wed, 22 Jul 2026 14:24:50 GMT</pubDate>
            <description><![CDATA[Mapping appliances event logs to real-world campaigns: A step-by-step researcher’s guide to continuous agentless monitoring.

]]></description>
            <content:encoded><![CDATA[Mapping appliances event logs to real-world campaigns: A step-by-step researcher’s guide to continuous agentless monitoring.

]]></content:encoded>
            <author>Shahar Dorfman</author>
            <enclosure url="https://www.datocms-assets.com/75231/1784710933-forigate2x.webp" length="0" type="image/webp"/>
        </item>
        <item>
            <title><![CDATA[Agentless Threat Detection: Illuminating Cloud Blind Spots]]></title>
            <link>https://www.wiz.io/blog/agentless-visibility-uncovering-cloud-blind-spots</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/agentless-visibility-uncovering-cloud-blind-spots</guid>
            <pubDate>Tue, 21 Jul 2026 13:26:13 GMT</pubDate>
            <description><![CDATA[How Agentless Workload Detection exposes hidden threats in virtual appliances and modern cloud networks.]]></description>
            <content:encoded><![CDATA[How Agentless Workload Detection exposes hidden threats in virtual appliances and modern cloud networks.]]></content:encoded>
            <author>Shahar Dorfman</author>
            <enclosure url="https://www.datocms-assets.com/75231/1784567027-av-2x.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[Exploitation in the Wild of wp2shell]]></title>
            <link>https://www.wiz.io/blog/wp2shell-cve-2026-63030-cve-2026-60137</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/wp2shell-cve-2026-63030-cve-2026-60137</guid>
            <pubDate>Mon, 20 Jul 2026 18:00:08 GMT</pubDate>
            <description><![CDATA[Wiz Research has identified exploitation of "wp2shell", a critical pre-auth RCE vulnerability chain impacting WordPress Core (CVE-2026-63030 & CVE-2026-60137). Attackers are deploying persistent webshells on vulnerable servers. Organizations should prioritize patching or applying WAF mitigations.]]></description>
            <content:encoded><![CDATA[Wiz Research has identified exploitation of "wp2shell", a critical pre-auth RCE vulnerability chain impacting WordPress Core (CVE-2026-63030 & CVE-2026-60137). Attackers are deploying persistent webshells on vulnerable servers. Organizations should prioritize patching or applying WAF mitigations.]]></content:encoded>
            <author>Shahar Dorfman</author>
            <author>Gili Tikochinski</author>
            <enclosure url="https://www.datocms-assets.com/75231/1784570339-wp2shell.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[The Red Agent POV: The One Boolean That Broke a B2B Platform’s Credit System]]></title>
            <link>https://www.wiz.io/blog/red-agent-pov-business-logic</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/red-agent-pov-business-logic</guid>
            <pubDate>Wed, 15 Jul 2026 13:33:42 GMT</pubDate>
            <description><![CDATA[Part 3: How the Red Agent bypassed a credit and paywall system by changing a single client-side value from false to true.]]></description>
            <content:encoded><![CDATA[Part 3: How the Red Agent bypassed a credit and paywall system by changing a single client-side value from false to true.]]></content:encoded>
            <author>Red Agent</author>
            <author>Gal Nagli</author>
            <enclosure url="https://www.datocms-assets.com/75231/1784050948-red-agent-02-2-copy-2x.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[M-Red-Team: AsyncAPI Supply Chain Compromise via GitHub Actions]]></title>
            <link>https://www.wiz.io/blog/m-red-team-asyncapi-supply-chain-compromise-via-github-actions</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/m-red-team-asyncapi-supply-chain-compromise-via-github-actions</guid>
            <pubDate>Tue, 14 Jul 2026 10:33:36 GMT</pubDate>
            <description><![CDATA[Detect and mitigate malicious @asyncapi npm packages linked to the latest npm supply chain attack. ]]></description>
            <content:encoded><![CDATA[Detect and mitigate malicious @asyncapi npm packages linked to the latest npm supply chain attack. ]]></content:encoded>
            <author>Rami McCarthy</author>
            <author>Merav Bar</author>
            <enclosure url="https://www.datocms-assets.com/75231/1784022504-threat-update-blue-wireframe_custom.jpeg" length="0" type="image/jpeg"/>
        </item>
        <item>
            <title><![CDATA[Wiz in the Verizon DBIR: How AI Acceleration and Cloud Sprawl Impact Modern Defense]]></title>
            <link>https://www.wiz.io/blog/verizon-dbir-2026-ai-cloud-security</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/verizon-dbir-2026-ai-cloud-security</guid>
            <pubDate>Thu, 09 Jul 2026 16:18:49 GMT</pubDate>
            <description><![CDATA[Verizon's latest DBIR highlights how attackers are exploiting familiar weaknesses at increasing speed and scale. Here's what Wiz research reveals about vulnerabilities, trust relationships, and AI in modern cloud environments.]]></description>
            <content:encoded><![CDATA[Verizon's latest DBIR highlights how attackers are exploiting familiar weaknesses at increasing speed and scale. Here's what Wiz research reveals about vulnerabilities, trust relationships, and AI in modern cloud environments.]]></content:encoded>
            <author>Wiz Threat Research</author>
            <enclosure url="https://www.datocms-assets.com/75231/1783455410-dbir-2x.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[GhostApproval: A Trust Boundary Gap in AI Coding Assistants]]></title>
            <link>https://www.wiz.io/blog/ghostapproval-a-trust-boundary-gap-in-ai-coding-assistants</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/ghostapproval-a-trust-boundary-gap-in-ai-coding-assistants</guid>
            <pubDate>Wed, 08 Jul 2026 14:00:00 GMT</pubDate>
            <description><![CDATA[Uncovering a category-level blind spot in modern AI coding assistants, and why the Human-in-the-Loop safety model fails against this classic threat]]></description>
            <content:encoded><![CDATA[Uncovering a category-level blind spot in modern AI coding assistants, and why the Human-in-the-Loop safety model fails against this classic threat]]></content:encoded>
            <author>Maor Dokhanian</author>
            <enclosure url="https://www.datocms-assets.com/75231/1783443500-ghostcover.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[The Red Agent POV: Exploiting Broken Object-Level Authorization in an Airline GraphQL API]]></title>
            <link>https://www.wiz.io/blog/red-agent-pov-bola</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/red-agent-pov-bola</guid>
            <pubDate>Mon, 29 Jun 2026 09:31:40 GMT</pubDate>
            <description><![CDATA[Part 2: How the Red Agent bypassed backend resolvers to expose an entire airline booking database in fifteen minutes]]></description>
            <content:encoded><![CDATA[Part 2: How the Red Agent bypassed backend resolvers to expose an entire airline booking database in fifteen minutes]]></content:encoded>
            <author>Red Agent</author>
            <author>Gal Nagli</author>
            <enclosure url="https://www.datocms-assets.com/75231/1782993716-red-agent-02-2-2x.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[MCP Auto-Execution: From Git Clone to Cloud Compromise in Amazon Q VS Code Extension]]></title>
            <link>https://www.wiz.io/blog/amazon-q-vulnerability</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/amazon-q-vulnerability</guid>
            <pubDate>Fri, 26 Jun 2026 12:00:01 GMT</pubDate>
            <description><![CDATA[By automatically loading MCP servers from workspace files, Amazon Q enabled attackers to execute code and access sensitive cloud environments.]]></description>
            <content:encoded><![CDATA[By automatically loading MCP servers from workspace files, Amazon Q enabled attackers to execute code and access sensitive cloud environments.]]></content:encoded>
            <author>Maor Dokhanian</author>
            <enclosure url="https://www.datocms-assets.com/75231/1782400207-amazon-q-2x-100.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Introducing the Red Agent POV Series]]></title>
            <link>https://www.wiz.io/blog/red-agent-pov-series</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/red-agent-pov-series</guid>
            <pubDate>Wed, 17 Jun 2026 14:33:41 GMT</pubDate>
            <description><![CDATA[An inside look at how the Red Agent, our AI-Powered Attacker, uncovers complex, exploitable risks in the wild]]></description>
            <content:encoded><![CDATA[An inside look at how the Red Agent, our AI-Powered Attacker, uncovers complex, exploitable risks in the wild]]></content:encoded>
            <author>Red Agent</author>
            <author>Gal Nagli</author>
            <author>Danielle Aminov</author>
            <author>Mika Maymon</author>
            <author>Shaked Rotlevi</author>
            <enclosure url="https://www.datocms-assets.com/75231/1781685807-pov-2x-2.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[Miasma: Supply Chain Attack Targeting RedHat npm Packages]]></title>
            <link>https://www.wiz.io/blog/miasma-supply-chain-attack-targeting-redhat-npm-packages</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/miasma-supply-chain-attack-targeting-redhat-npm-packages</guid>
            <pubDate>Mon, 01 Jun 2026 12:45:51 GMT</pubDate>
            <description><![CDATA[Detect and mitigate malicious npm packages linked to the latest npm supply chain attack, based on the open sourced Mini Shai-Hulud malware. ]]></description>
            <content:encoded><![CDATA[Detect and mitigate malicious npm packages linked to the latest npm supply chain attack, based on the open sourced Mini Shai-Hulud malware. ]]></content:encoded>
            <author>Merav Bar</author>
            <author>Rami McCarthy</author>
            <enclosure url="https://www.datocms-assets.com/75231/1780321098-1.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[State of Post Quantum Cryptography]]></title>
            <link>https://www.wiz.io/blog/state-of-post-quantum-cryptography</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/state-of-post-quantum-cryptography</guid>
            <pubDate>Thu, 28 May 2026 13:34:55 GMT</pubDate>
            <description><![CDATA[Discussion of PQC relevant statistics that we see across our customers and other data sources.]]></description>
            <content:encoded><![CDATA[Discussion of PQC relevant statistics that we see across our customers and other data sources.]]></content:encoded>
            <author>Scott Piper</author>
            <enclosure url="https://www.datocms-assets.com/75231/1779818053-state-of-pqc-2x.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[Commit to Compromise: A New Threat Actor Targeting the Cryptocurrency Industry's Software Development Infrastructure]]></title>
            <link>https://www.wiz.io/blog/threat-actors-target-crypto-orgs</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/threat-actors-target-crypto-orgs</guid>
            <pubDate>Wed, 27 May 2026 13:52:45 GMT</pubDate>
            <description><![CDATA[Wiz CIRT and Wiz Research detail JINX-0164, a threat actor using LinkedIn social engineering, custom macOS malware, and CI/CD hijacking to target cryptocurrency organizations.]]></description>
            <content:encoded><![CDATA[Wiz CIRT and Wiz Research detail JINX-0164, a threat actor using LinkedIn social engineering, custom macOS malware, and CI/CD hijacking to target cryptocurrency organizations.]]></content:encoded>
            <author>Shira Ayal</author>
            <author>Eden Abergil</author>
            <author>Andre Maccarone</author>
            <author>Yuval Dan</author>
            <author>Benjamin Read</author>
            <enclosure url="https://www.datocms-assets.com/75231/1779831567-dprk-2x.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[State of SDLC Security 2026: How Risk Scales in Modern Development]]></title>
            <link>https://www.wiz.io/blog/sdlc-security-report-2026-key-takeaways</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/sdlc-security-report-2026-key-takeaways</guid>
            <pubDate>Tue, 26 May 2026 12:45:02 GMT</pubDate>
            <description><![CDATA[Insights from real-world environments into how code, developer tooling, automation, and AI are reshaping application security.]]></description>
            <content:encoded><![CDATA[Insights from real-world environments into how code, developer tooling, automation, and AI are reshaping application security.]]></content:encoded>
            <author>Wiz Threat Research</author>
            <enclosure url="https://www.datocms-assets.com/75231/1778605260-sdlc-blog-cover.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[durabletask: TeamPCP's Latest PyPi Compromise]]></title>
            <link>https://www.wiz.io/blog/durabletask-teampcp-supply-chain-attack</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/durabletask-teampcp-supply-chain-attack</guid>
            <pubDate>Tue, 19 May 2026 17:30:20 GMT</pubDate>
            <description><![CDATA[Discover the latest on malicious versions of the pypi package durabletask, matching TeamPCP tactics.]]></description>
            <content:encoded><![CDATA[Discover the latest on malicious versions of the pypi package durabletask, matching TeamPCP tactics.]]></content:encoded>
            <author>Rami McCarthy</author>
            <enclosure url="https://www.datocms-assets.com/75231/1779210111-threat-update-large-title_custom.jpeg" length="0" type="image/jpeg"/>
        </item>
        <item>
            <title><![CDATA[The Worm That Keeps on Digging: TeamPCP Hits @antv in Latest Wave]]></title>
            <link>https://www.wiz.io/blog/mini-shai-hulud-teampcp-hits-antv-supply-chain</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/mini-shai-hulud-teampcp-hits-antv-supply-chain</guid>
            <pubDate>Tue, 19 May 2026 08:29:30 GMT</pubDate>
            <description><![CDATA[Multi-ecosystem supply chain compromise by TeamPCP targets GitHub, NPM, and VSCode to steal credentials and establish persistence. ]]></description>
            <content:encoded><![CDATA[Multi-ecosystem supply chain compromise by TeamPCP targets GitHub, NPM, and VSCode to steal credentials and establish persistence. ]]></content:encoded>
            <author>Rami McCarthy</author>
            <author>Benjamin Read</author>
            <author>Merav Bar</author>
            <enclosure url="https://www.datocms-assets.com/75231/1779178134-threat-update-mini-worm_custom.jpeg" length="0" type="image/jpeg"/>
        </item>
        <item>
            <title><![CDATA[Fragnesia: Linux Kernel Local Privilege Escalation via ESP-in-TCP]]></title>
            <link>https://www.wiz.io/blog/fragnesia-linux-kernel-local-privilege-escalation-via-esp-in-tcp</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/fragnesia-linux-kernel-local-privilege-escalation-via-esp-in-tcp</guid>
            <pubDate>Wed, 13 May 2026 12:13:44 GMT</pubDate>
            <description><![CDATA[A new page-cache corruption vulnerability in the Dirty Frag family enables unprivileged local attackers to achieve root]]></description>
            <content:encoded><![CDATA[A new page-cache corruption vulnerability in the Dirty Frag family enables unprivileged local attackers to achieve root]]></content:encoded>
            <author>Merav Bar</author>
            <author>Rami McCarthy</author>
            <enclosure url="https://www.datocms-assets.com/75231/1778670009-fragnesia.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[Mini Shai-Hulud Strikes Again: TanStack + more npm Packages Compromised]]></title>
            <link>https://www.wiz.io/blog/mini-shai-hulud-strikes-again-tanstack-more-npm-packages-compromised</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/mini-shai-hulud-strikes-again-tanstack-more-npm-packages-compromised</guid>
            <pubDate>Tue, 12 May 2026 01:38:56 GMT</pubDate>
            <description><![CDATA[Detect and mitigate malicious npm packages linked to the latest Mini Shai-Hulud supply chain campaign targeting high-value developer tooling.]]></description>
            <content:encoded><![CDATA[Detect and mitigate malicious npm packages linked to the latest Mini Shai-Hulud supply chain campaign targeting high-value developer tooling.]]></content:encoded>
            <author>Rami McCarthy</author>
            <author>Amitai Cohen</author>
            <author>Benjamin Read</author>
            <enclosure url="https://www.datocms-assets.com/75231/1778542566-tanstack.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[Dirty Frag: Linux Kernel Local Privilege Escalation via ESP and RxRPC]]></title>
            <link>https://www.wiz.io/blog/dirty-frag-linux-kernel-local-privilege-escalation-via-esp-and-rxrpc</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/dirty-frag-linux-kernel-local-privilege-escalation-via-esp-and-rxrpc</guid>
            <pubDate>Fri, 08 May 2026 08:57:17 GMT</pubDate>
            <description><![CDATA[Unpatched kernel flaw chain (CVE-2026-43284, CVE-2026-43500) enables root escalation on major Linux distributions.]]></description>
            <content:encoded><![CDATA[Unpatched kernel flaw chain (CVE-2026-43284, CVE-2026-43500) enables root escalation on major Linux distributions.]]></content:encoded>
            <author>Merav Bar</author>
            <author>Rami McCarthy</author>
            <enclosure url="https://www.datocms-assets.com/75231/1778236280-image-19.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[The Jenkins Threat Landscape ]]></title>
            <link>https://www.wiz.io/blog/jenkins-threat-risk-insights</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/jenkins-threat-risk-insights</guid>
            <pubDate>Wed, 06 May 2026 15:10:07 GMT</pubDate>
            <description><![CDATA[What usage patterns, plugin adoption, and configuration choices reveal about the Jenkins attack surface.]]></description>
            <content:encoded><![CDATA[What usage patterns, plugin adoption, and configuration choices reveal about the Jenkins attack surface.]]></content:encoded>
            <author>Merav Bar</author>
            <enclosure url="https://www.datocms-assets.com/75231/1778078563-jenkins-2.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[Critical Buffer Overflow Vulnerability in PAN-OS Exploited in-the-Wild]]></title>
            <link>https://www.wiz.io/blog/critical-vulnerability-in-pan-os-exploited-in-the-wild-cve-2026-0300</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/critical-vulnerability-in-pan-os-exploited-in-the-wild-cve-2026-0300</guid>
            <pubDate>Wed, 06 May 2026 12:33:26 GMT</pubDate>
            <description><![CDATA[Detect and mitigate CVE-2026-0300, a critical vulnerability in Palo Alto Networks PAN-OS User-ID Authentication Portal that allows unauthenticated attackers to achieve remote code execution (RCE) with root privileges.]]></description>
            <content:encoded><![CDATA[Detect and mitigate CVE-2026-0300, a critical vulnerability in Palo Alto Networks PAN-OS User-ID Authentication Portal that allows unauthenticated attackers to achieve remote code execution (RCE) with root privileges.]]></content:encoded>
            <author>Merav Bar</author>
            <enclosure url="https://www.datocms-assets.com/75231/1778064378-threat-update-pink-subtitle_custom.jpeg" length="0" type="image/jpeg"/>
        </item>
        <item>
            <title><![CDATA[Copy Fail: Universal Linux Local Privilege Escalation Vulnerability]]></title>
            <link>https://www.wiz.io/blog/copyfail-cve-2026-31431-linux-privilege-escalation-vulnerability</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/copyfail-cve-2026-31431-linux-privilege-escalation-vulnerability</guid>
            <pubDate>Fri, 01 May 2026 12:38:09 GMT</pubDate>
            <description><![CDATA[Detect and mitigate Copy Fail (CVE-2026-31431), an easily exploitable vulnerability in the Linux kernel that allows escalation from an unprivileged local user account to root access.]]></description>
            <content:encoded><![CDATA[Detect and mitigate Copy Fail (CVE-2026-31431), an easily exploitable vulnerability in the Linux kernel that allows escalation from an unprivileged local user account to root access.]]></content:encoded>
            <author>Amitai Cohen</author>
            <author>Merav Bar</author>
            <author>Shahar Dorfman</author>
            <enclosure url="https://www.datocms-assets.com/75231/1777638475-copyfail.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[The (In)security Landscape of AI-Powered GitHub Actions (Part 2/2)]]></title>
            <link>https://www.wiz.io/blog/github-actions-security-ai-powered-actions-vulnerabilities</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/github-actions-security-ai-powered-actions-vulnerabilities</guid>
            <pubDate>Thu, 30 Apr 2026 13:21:18 GMT</pubDate>
            <description><![CDATA[When AI meets CI/CD: permission bypasses, prompt injection, and what to do about it.]]></description>
            <content:encoded><![CDATA[When AI meets CI/CD: permission bypasses, prompt injection, and what to do about it.]]></content:encoded>
            <author>Shay Berkovich</author>
            <enclosure url="https://www.datocms-assets.com/75231/1777557067-github-part02-2x.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[Key Takeaways from the 2026 State of AI in the Cloud Report]]></title>
            <link>https://www.wiz.io/blog/state-of-ai-in-cloud-2026-recap</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/state-of-ai-in-cloud-2026-recap</guid>
            <pubDate>Wed, 29 Apr 2026 21:00:00 GMT</pubDate>
            <description><![CDATA[How AI Adoption, Autonomy, and Attacker Innovation Are Reshaping Cloud Security]]></description>
            <content:encoded><![CDATA[How AI Adoption, Autonomy, and Attacker Innovation Are Reshaping Cloud Security]]></content:encoded>
            <author>Wiz Threat Research</author>
            <enclosure url="https://www.datocms-assets.com/75231/1777304729-report01-ai-cover-2x-100-3.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Supply Chain Campaign Targets SAP npm Packages with Credential-Stealing Malware]]></title>
            <link>https://www.wiz.io/blog/mini-shai-hulud-supply-chain-sap-npm</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/mini-shai-hulud-supply-chain-sap-npm</guid>
            <pubDate>Wed, 29 Apr 2026 15:14:27 GMT</pubDate>
            <description><![CDATA[Detect and mitigate malicious npm packages linked to the recent Shai-Hulud-style campaign - Mini Shai Hulud.]]></description>
            <content:encoded><![CDATA[Detect and mitigate malicious npm packages linked to the recent Shai-Hulud-style campaign - Mini Shai Hulud.]]></content:encoded>
            <author>Benjamin Read</author>
            <author>Merav Bar</author>
            <author>Shay Berkovich</author>
            <author>Gili Tikochinski</author>
            <enclosure url="https://www.datocms-assets.com/75231/1777475003-5-1.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[Securing GitHub: Wiz Research uncovers Remote Code Execution in GitHub.com and GitHub Enterprise Server (CVE-2026-3854)]]></title>
            <link>https://www.wiz.io/blog/github-rce-vulnerability-cve-2026-3854</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/github-rce-vulnerability-cve-2026-3854</guid>
            <pubDate>Tue, 28 Apr 2026 15:30:00 GMT</pubDate>
            <description><![CDATA[Details on CVE-2026-3854: A critical flaw in GitHub’s internal git infrastructure enabling RCE on GitHub.com and GitHub Enterprise Server.]]></description>
            <content:encoded><![CDATA[Details on CVE-2026-3854: A critical flaw in GitHub’s internal git infrastructure enabling RCE on GitHub.com and GitHub Enterprise Server.]]></content:encoded>
            <author>Sagi Tzadik</author>
            <enclosure url="https://www.datocms-assets.com/75231/1777300906-github-2x-100-1.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Context.ai OAuth Token Compromise]]></title>
            <link>https://www.wiz.io/blog/contextai-oauth-token-compromise</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/contextai-oauth-token-compromise</guid>
            <pubDate>Mon, 20 Apr 2026 18:20:06 GMT</pubDate>
            <description><![CDATA[Compromised Context.ai OAuth tokens enabled attackers to perform a supply chain attack via trusted SaaS integrations.
Learn how to assess the risk in your environment and how to prevent the next attack.]]></description>
            <content:encoded><![CDATA[Compromised Context.ai OAuth tokens enabled attackers to perform a supply chain attack via trusted SaaS integrations.
Learn how to assess the risk in your environment and how to prevent the next attack.]]></content:encoded>
            <author>Merav Bar</author>
            <author>Hila Ramati</author>
            <author>Maayan Bentor</author>
            <enclosure url="https://www.datocms-assets.com/75231/1776693881-8.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[How to Harden GitHub Actions: An Updated Guide]]></title>
            <link>https://www.wiz.io/blog/github-actions-security-guide</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/github-actions-security-guide</guid>
            <pubDate>Wed, 15 Apr 2026 13:19:21 GMT</pubDate>
            <description><![CDATA[Build resilient GitHub Actions workflows with lessons from recent attacks like TeamPCP and Axios. ]]></description>
            <content:encoded><![CDATA[Build resilient GitHub Actions workflows with lessons from recent attacks like TeamPCP and Axios. ]]></content:encoded>
            <author>Rami McCarthy</author>
            <author>Shay Berkovich</author>
            <enclosure url="https://www.datocms-assets.com/75231/1746194378-github-actions-security.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[Primer on GitHub Actions Security - Threat Model, Attacks and Defenses (Part 1/2)]]></title>
            <link>https://www.wiz.io/blog/github-actions-security-threat-model-and-defenses</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/github-actions-security-threat-model-and-defenses</guid>
            <pubDate>Tue, 14 Apr 2026 11:33:05 GMT</pubDate>
            <description><![CDATA[Understanding and defending your GitHub Actions - from threat model to security controls.]]></description>
            <content:encoded><![CDATA[Understanding and defending your GitHub Actions - from threat model to security controls.]]></content:encoded>
            <author>Shay Berkovich</author>
            <enclosure url="https://www.datocms-assets.com/75231/1776096234-github-2x.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[Claude Mythos: Preparing for a World Where AI Finds and Exploits Vulnerabilities Faster Than Ever]]></title>
            <link>https://www.wiz.io/blog/claude-mythos</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/claude-mythos</guid>
            <pubDate>Fri, 10 Apr 2026 15:25:54 GMT</pubDate>
            <description><![CDATA[Anthropic's new model can autonomously discover zero-days and develop working exploits. While access is currently limited to responsible actors, now is the time to strengthen response playbooks, reduce exposure, and incorporate AI into security programs.]]></description>
            <content:encoded><![CDATA[Anthropic's new model can autonomously discover zero-days and develop working exploits. While access is currently limited to responsible actors, now is the time to strengthen response playbooks, reduce exposure, and incorporate AI into security programs.]]></content:encoded>
            <author>Ami Luttwak</author>
            <enclosure url="https://www.datocms-assets.com/75231/1775834079-ai-y2k-copy-3-2x.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[Cloud Threats Retrospective 2026: What AI Changed (and What It Didn’t)]]></title>
            <link>https://www.wiz.io/blog/cloud-threat-retrospective-2026</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/cloud-threat-retrospective-2026</guid>
            <pubDate>Thu, 09 Apr 2026 13:00:02 GMT</pubDate>
            <description><![CDATA[Insights from public incidents, cloud telemetry, and investigations into how cloud risk evolved in 2025]]></description>
            <content:encoded><![CDATA[Insights from public incidents, cloud telemetry, and investigations into how cloud risk evolved in 2025]]></content:encoded>
            <author>Wiz Threat Research</author>
            <enclosure url="https://www.datocms-assets.com/75231/1775576616-blog_cover_open_graph.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[Six Accounts, One Actor: Inside the prt-scan Supply Chain Campaign]]></title>
            <link>https://www.wiz.io/blog/six-accounts-one-actor-inside-the-prt-scan-supply-chain-campaign</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/six-accounts-one-actor-inside-the-prt-scan-supply-chain-campaign</guid>
            <pubDate>Sat, 04 Apr 2026 09:36:51 GMT</pubDate>
            <description><![CDATA[After hackerbot-claw, another AI-powered campaign exploiting pull_request_target confirms the threat is here to stay. We trace the attacker back to three weeks before anyone noticed.]]></description>
            <content:encoded><![CDATA[After hackerbot-claw, another AI-powered campaign exploiting pull_request_target confirms the threat is here to stay. We trace the attacker back to three weeks before anyone noticed.]]></content:encoded>
            <author>Rami McCarthy</author>
            <author>Hila Ramati</author>
            <author>Scott Piper</author>
            <author>Benjamin Read</author>
            <enclosure url="https://www.datocms-assets.com/75231/1775309029-7.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[Axios NPM Distribution Compromised in Supply Chain Attack]]></title>
            <link>https://www.wiz.io/blog/axios-npm-compromised-in-supply-chain-attack</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/axios-npm-compromised-in-supply-chain-attack</guid>
            <pubDate>Tue, 31 Mar 2026 08:26:35 GMT</pubDate>
            <description><![CDATA[A compromised axios maintainer account led to malicious npm releases that propagated across environments. Learn how to assess impact, detect compromise, and secure your development workflows.]]></description>
            <content:encoded><![CDATA[A compromised axios maintainer account led to malicious npm releases that propagated across environments. Learn how to assess impact, detect compromise, and secure your development workflows.]]></content:encoded>
            <author>Benjamin Read</author>
            <author>Amitai Cohen</author>
            <author>Hila Ramati</author>
            <author>Merav Bar</author>
            <enclosure url="https://www.datocms-assets.com/75231/1774944977-screenshot-2026-03-31-at-11-15-14.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[Tracking TeamPCP: Investigating Post-Compromise Attacks Seen in the Wild]]></title>
            <link>https://www.wiz.io/blog/tracking-teampcp-investigating-post-compromise-attacks-seen-in-the-wild</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/tracking-teampcp-investigating-post-compromise-attacks-seen-in-the-wild</guid>
            <pubDate>Mon, 30 Mar 2026 23:54:14 GMT</pubDate>
            <description><![CDATA[How TeamPCP are leveraging stolen secrets from the recent supply chain attacks to compromise cloud environments]]></description>
            <content:encoded><![CDATA[How TeamPCP are leveraging stolen secrets from the recent supply chain attacks to compromise cloud environments]]></content:encoded>
            <author>Eden Abergil</author>
            <author>Sean Johnstone</author>
            <author>Zoe Rabi</author>
            <author>Hila Ramati</author>
            <enclosure url="https://www.datocms-assets.com/75231/1774960503-tracking-teampcp.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[Three’s a Crowd: TeamPCP trojanizes LiteLLM in Continuation of Campaign ]]></title>
            <link>https://www.wiz.io/blog/threes-a-crowd-teampcp-trojanizes-litellm-in-continuation-of-campaign</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/threes-a-crowd-teampcp-trojanizes-litellm-in-continuation-of-campaign</guid>
            <pubDate>Tue, 24 Mar 2026 18:40:52 GMT</pubDate>
            <description><![CDATA[LiteLLM is the latest victim of TeamPCP’s open-source attack spree. Malicious versions 1.82.7 and 1.82.8 abuse Python’s .pth mechanism for stealthy persistence. The malware exfiltrates cloud credentials, CI/CD secrets, and keys to attacker-controlled domains.]]></description>
            <content:encoded><![CDATA[LiteLLM is the latest victim of TeamPCP’s open-source attack spree. Malicious versions 1.82.7 and 1.82.8 abuse Python’s .pth mechanism for stealthy persistence. The malware exfiltrates cloud credentials, CI/CD secrets, and keys to attacker-controlled domains.]]></content:encoded>
            <author>Benjamin Read</author>
            <author>Merav Bar</author>
            <author>Rami McCarthy</author>
            <author>James Haughom</author>
            <enclosure url="https://www.datocms-assets.com/75231/1774966246-2.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[KICS GitHub Action Compromised: TeamPCP Strikes Again in Supply Chain Attack]]></title>
            <link>https://www.wiz.io/blog/teampcp-attack-kics-github-action</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/teampcp-attack-kics-github-action</guid>
            <pubDate>Mon, 23 Mar 2026 17:38:41 GMT</pubDate>
            <description><![CDATA[Checkmarx KICS scanner is the latest victim of a credential-stealing supply chain attack by TeamPCP. Between 12:58–16:50 UTC on March 23, 35 tags were hijacked. Learn how to audit your workflows, identify malicious activity, and secure your GitHub Actions.]]></description>
            <content:encoded><![CDATA[Checkmarx KICS scanner is the latest victim of a credential-stealing supply chain attack by TeamPCP. Between 12:58–16:50 UTC on March 23, 35 tags were hijacked. Learn how to audit your workflows, identify malicious activity, and secure your GitHub Actions.]]></content:encoded>
            <author>Rami McCarthy</author>
            <author>James Haughom</author>
            <author>Benjamin Read</author>
            <enclosure url="https://www.datocms-assets.com/75231/1774966146-3.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[Trivy Compromised: Everything You Need to Know about the Latest Supply Chain Attack]]></title>
            <link>https://www.wiz.io/blog/trivy-compromised-teampcp-supply-chain-attack</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/trivy-compromised-teampcp-supply-chain-attack</guid>
            <pubDate>Fri, 20 Mar 2026 15:18:51 GMT</pubDate>
            <description><![CDATA[On March 19, 2026, threat actors injected credential-stealing malware into Aqua Security’s Trivy scanner and related GitHub Actions. Learn how "TeamPCP" executed this breach and how to audit your environment.]]></description>
            <content:encoded><![CDATA[On March 19, 2026, threat actors injected credential-stealing malware into Aqua Security’s Trivy scanner and related GitHub Actions. Learn how "TeamPCP" executed this breach and how to audit your environment.]]></content:encoded>
            <author>Rami McCarthy</author>
            <enclosure url="https://www.datocms-assets.com/75231/1774012170-threat-templat_02-1.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[Twenty Years of Cloud Security Research]]></title>
            <link>https://www.wiz.io/blog/twenty-years-of-cloud-security-research</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/twenty-years-of-cloud-security-research</guid>
            <pubDate>Fri, 13 Mar 2026 13:00:00 GMT</pubDate>
            <description><![CDATA[This post will look at the past 20 years of cloud security research, separating the two decades into eras with important milestones defined that resulted in the change of one era to the next.]]></description>
            <content:encoded><![CDATA[This post will look at the past 20 years of cloud security research, separating the two decades into eras with important milestones defined that resulted in the change of one era to the next.]]></content:encoded>
            <author>Scott Piper</author>
            <enclosure url="https://www.datocms-assets.com/75231/1773328726-20-birthday-2x-100.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Would You Click ‘Accept’? Automatically detecting malicious Azure OAuth applications using LLMs]]></title>
            <link>https://www.wiz.io/blog/detecting-malicious-oauth-applications</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/detecting-malicious-oauth-applications</guid>
            <pubDate>Wed, 18 Feb 2026 19:09:54 GMT</pubDate>
            <description><![CDATA[How Wiz Research automates detection of emerging malicious Azure app and consent phishing campaigns.]]></description>
            <content:encoded><![CDATA[How Wiz Research automates detection of emerging malicious Azure app and consent phishing campaigns.]]></content:encoded>
            <author>Shahar Dorfman</author>
            <author>Sapir Federovsky</author>
            <enclosure url="https://www.datocms-assets.com/75231/1770310855-oauth-2x-100.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Introducing AI Cyber Model Arena: A Real-World Benchmark for AI Agents in Cybersecurity]]></title>
            <link>https://www.wiz.io/blog/introducing-ai-cyber-model-arena-a-real-world-benchmark-for-ai-agents-in-cybersec</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/introducing-ai-cyber-model-arena-a-real-world-benchmark-for-ai-agents-in-cybersec</guid>
            <pubDate>Thu, 12 Feb 2026 18:05:58 GMT</pubDate>
            <description><![CDATA[Wiz Research’s AI Cyber Model Arena benchmarks offensive AI security on 257 real-world challenges (zero-days, CVEs, API/web, and cloud across AWS/Azure/GCP/K8s) demonstrating what AI models and agents can really do
]]></description>
            <content:encoded><![CDATA[Wiz Research’s AI Cyber Model Arena benchmarks offensive AI security on 257 real-world challenges (zero-days, CVEs, API/web, and cloud across AWS/Azure/GCP/K8s) demonstrating what AI models and agents can really do
]]></content:encoded>
            <author>Nir Ohfeld</author>
            <author>Alon Schindel</author>
            <enclosure url="https://www.datocms-assets.com/75231/1770917239-thumbnail-5.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[Hacking Moltbook: The AI Social Network Any Human Can Control]]></title>
            <link>https://www.wiz.io/blog/exposed-moltbook-database-reveals-millions-of-api-keys</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/exposed-moltbook-database-reveals-millions-of-api-keys</guid>
            <pubDate>Mon, 02 Feb 2026 15:00:03 GMT</pubDate>
            <description><![CDATA[1 exposed database. 35,000 emails. 1.5M API keys. And 17,000 humans behind the not-so-autonomous AI network.]]></description>
            <content:encoded><![CDATA[1 exposed database. 35,000 emails. 1.5M API keys. And 17,000 humans behind the not-so-autonomous AI network.]]></content:encoded>
            <author>Gal Nagli</author>
            <enclosure url="https://www.datocms-assets.com/75231/1769995179-image5.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[AI Agents vs Humans: Who Wins at Web Hacking in 2026?]]></title>
            <link>https://www.wiz.io/blog/ai-agents-vs-humans-who-wins-at-web-hacking-in-2026</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/ai-agents-vs-humans-who-wins-at-web-hacking-in-2026</guid>
            <pubDate>Thu, 29 Jan 2026 18:00:02 GMT</pubDate>
            <description><![CDATA[Wiz Research teamed up with Irregular, a frontier AI security lab, to settle this once and for all.]]></description>
            <content:encoded><![CDATA[Wiz Research teamed up with Irregular, a frontier AI security lab, to settle this once and for all.]]></content:encoded>
            <author>Gal Nagli</author>
            <author>Irregular</author>
            <enclosure url="https://www.datocms-assets.com/75231/1769636578-unnamed-27.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[Introducing SITF: The First Threat Framework Dedicated to SDLC Infrastructure]]></title>
            <link>https://www.wiz.io/blog/sitf-sdlc-threat-framework</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/sitf-sdlc-threat-framework</guid>
            <pubDate>Mon, 26 Jan 2026 17:25:25 GMT</pubDate>
            <description><![CDATA[Moving beyond simple checklists to visualize, map, and block attacks on production SDLC infrastructure.]]></description>
            <content:encoded><![CDATA[Moving beyond simple checklists to visualize, map, and block attacks on production SDLC infrastructure.]]></content:encoded>
            <author>Shay Berkovich</author>
            <enclosure url="https://www.datocms-assets.com/75231/1769446349-sitf-blog-cover.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[Agentic Browser Security: 2025 Year-End Review]]></title>
            <link>https://www.wiz.io/blog/agentic-browser-security-2025-year-end-review</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/agentic-browser-security-2025-year-end-review</guid>
            <pubDate>Fri, 16 Jan 2026 17:23:17 GMT</pubDate>
            <description><![CDATA[Are agentic browsers the new Flash? A 2025 review of new attacks, vendor security layers, and a roadmap for navigating AI browser risks.]]></description>
            <content:encoded><![CDATA[Are agentic browsers the new Flash? A 2025 review of new attacks, vendor security layers, and a roadmap for navigating AI browser risks.]]></content:encoded>
            <author>Rami McCarthy</author>
            <enclosure url="https://www.datocms-assets.com/75231/1768421320-reaserch_1-2x-1.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[CodeBreach: Infiltrating the AWS Console Supply Chain and Hijacking AWS GitHub Repositories via CodeBuild]]></title>
            <link>https://www.wiz.io/blog/wiz-research-codebreach-vulnerability-aws-codebuild</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/wiz-research-codebreach-vulnerability-aws-codebuild</guid>
            <pubDate>Thu, 15 Jan 2026 15:00:00 GMT</pubDate>
            <description><![CDATA[Wiz Research discovered a critical supply chain vulnerability that abused a CodeBuild misconfiguration to take over key AWS GitHub repositories - including the JavaScript SDK powering the AWS Console.]]></description>
            <content:encoded><![CDATA[Wiz Research discovered a critical supply chain vulnerability that abused a CodeBuild misconfiguration to take over key AWS GitHub repositories - including the JavaScript SDK powering the AWS Console.]]></content:encoded>
            <author>Yuval Avrahami</author>
            <author>Nir Ohfeld</author>
            <enclosure url="https://www.datocms-assets.com/75231/1768487317-aws-supply-chain-copy-2-2x-100.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Preparing for Post-Quantum Cryptography]]></title>
            <link>https://www.wiz.io/blog/preparing-for-post-quantum-cryptography</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/preparing-for-post-quantum-cryptography</guid>
            <pubDate>Thu, 08 Jan 2026 14:51:34 GMT</pubDate>
            <description><![CDATA[Learn what you can do today to prepare for Q-Day]]></description>
            <content:encoded><![CDATA[Learn what you can do today to prepare for Q-Day]]></content:encoded>
            <author>Scott Piper</author>
            <author>Yali Gottlib</author>
            <author>Addi Grinbaum</author>
            <enclosure url="https://www.datocms-assets.com/75231/1767636769-image-20.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[Snipping the Long Tail of Shai-Hulud 2.0]]></title>
            <link>https://www.wiz.io/blog/snipping-the-long-tail-of-shai-hulud-2-0</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/snipping-the-long-tail-of-shai-hulud-2-0</guid>
            <pubDate>Tue, 30 Dec 2025 15:21:30 GMT</pubDate>
            <description><![CDATA[Wiz Research reveals the data behind Shai-Hulud's  2.0 long tail, the massive gap in cloud credential rotation, a potential link to the Trust Wallet incident, and how we finally "snipped the tail" on a month of ongoing infections.]]></description>
            <content:encoded><![CDATA[Wiz Research reveals the data behind Shai-Hulud's  2.0 long tail, the massive gap in cloud credential rotation, a potential link to the Trust Wallet incident, and how we finally "snipped the tail" on a month of ongoing infections.]]></content:encoded>
            <author>Rami McCarthy</author>
            <enclosure url="https://www.datocms-assets.com/75231/1767094793-shai-hulud-long-tail.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[MongoBleed (CVE-2025-14847) exploited in the wild: everything you need to know]]></title>
            <link>https://www.wiz.io/blog/mongobleed-cve-2025-14847-exploited-in-the-wild-mongodb</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/mongobleed-cve-2025-14847-exploited-in-the-wild-mongodb</guid>
            <pubDate>Sun, 28 Dec 2025 09:24:54 GMT</pubDate>
            <description><![CDATA[Detect and mitigate CVE-2025-14847, an unauthenticated information leak vulnerability in MongoDB. Exploitation has been observed in the wild. Organizations should patch urgently.]]></description>
            <content:encoded><![CDATA[Detect and mitigate CVE-2025-14847, an unauthenticated information leak vulnerability in MongoDB. Exploitation has been observed in the wild. Organizations should patch urgently.]]></content:encoded>
            <author>Merav Bar</author>
            <author>Amitai Cohen</author>
            <author>Yaara Shriki</author>
            <author>Gili Tikochinski</author>
            <enclosure url="https://www.datocms-assets.com/75231/1766913880-screenshot-2025-12-28-at-11-24-27.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[Zero‑Days in the Age of AI: Behind the Scenes of ZeroDay.cloud 2025, with a Record High of CVEs in Critical Cloud Infra]]></title>
            <link>https://www.wiz.io/blog/wiz-zeroday-cloud-hacking-competition-behind-the-scenes</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/wiz-zeroday-cloud-hacking-competition-behind-the-scenes</guid>
            <pubDate>Tue, 16 Dec 2025 15:30:00 GMT</pubDate>
            <description><![CDATA[ZDC awarded hackers $320,000 and uncovered a record‑breaking tally of critical CVEs for core cloud infrastructure, underscoring the scale and urgency of securing the open‑source software that underpins the modern cloud.]]></description>
            <content:encoded><![CDATA[ZDC awarded hackers $320,000 and uncovered a record‑breaking tally of critical CVEs for core cloud infrastructure, underscoring the scale and urgency of securing the open‑source software that underpins the modern cloud.]]></content:encoded>
            <author>Nir Ohfeld</author>
            <enclosure url="https://www.datocms-assets.com/75231/1764078868-zeroday-cloud-hh.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[Gogs 0-Day Exploited in the Wild]]></title>
            <link>https://www.wiz.io/blog/wiz-research-gogs-cve-2025-8110-rce-exploit</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/wiz-research-gogs-cve-2025-8110-rce-exploit</guid>
            <pubDate>Wed, 10 Dec 2025 15:00:01 GMT</pubDate>
            <description><![CDATA[Wiz Threat Research has observed exploitation in-the-wild of CVE-2025-8110]]></description>
            <content:encoded><![CDATA[Wiz Threat Research has observed exploitation in-the-wild of CVE-2025-8110]]></content:encoded>
            <author>Gili Tikochinski</author>
            <author>Yaara Shriki</author>
            <enclosure url="https://www.datocms-assets.com/75231/1765311013-gogs-2x.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[Code to Cloud Attacks: From Github PAT to Cloud Control Plane]]></title>
            <link>https://www.wiz.io/blog/github-attacks-pat-control-plane</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/github-attacks-pat-control-plane</guid>
            <pubDate>Tue, 09 Dec 2025 13:00:02 GMT</pubDate>
            <description><![CDATA[How attackers are leveraging compromised employee GitHub Personal Access Tokens to compromise cloud environments.]]></description>
            <content:encoded><![CDATA[How attackers are leveraging compromised employee GitHub Personal Access Tokens to compromise cloud environments.]]></content:encoded>
            <author>Shira Ayal</author>
            <enclosure url="https://www.datocms-assets.com/75231/1765223281-github-pats-2x.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[Top AWS re:Invent Announcements for Security Teams in 2025]]></title>
            <link>https://www.wiz.io/blog/top-aws-re-invent-announcements-for-security-teams-in-2025</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/top-aws-re-invent-announcements-for-security-teams-in-2025</guid>
            <pubDate>Mon, 08 Dec 2025 21:54:29 GMT</pubDate>
            <description><![CDATA[The re:Invent announcements that are most impactful to security teams.]]></description>
            <content:encoded><![CDATA[The re:Invent announcements that are most impactful to security teams.]]></content:encoded>
            <author>Scott Piper</author>
            <enclosure url="https://www.datocms-assets.com/75231/1765215423-reinvent-2x-2.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[React2Shell: Technical Deep-Dive & In-the-Wild Exploitation of CVE-2025-55182]]></title>
            <link>https://www.wiz.io/blog/nextjs-cve-2025-55182-react2shell-deep-dive</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/nextjs-cve-2025-55182-react2shell-deep-dive</guid>
            <pubDate>Mon, 08 Dec 2025 17:18:38 GMT</pubDate>
            <description><![CDATA[We break down the exploit mechanics and detail active in-the-wild attacks observed by our team, from credential harvesting to sophisticated cloud backdoors.]]></description>
            <content:encoded><![CDATA[We break down the exploit mechanics and detail active in-the-wild attacks observed by our team, from credential harvesting to sophisticated cloud backdoors.]]></content:encoded>
            <author>Shir Tamari</author>
            <author>Gili Tikochinski</author>
            <author>Hila Ramati</author>
            <author>Benjamin Read</author>
            <enclosure url="https://www.datocms-assets.com/75231/1765185699-screenshot-2025-12-08-112107.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[React2Shell (CVE-2025-55182): Everything You Need to Know About the Critical React Vulnerability]]></title>
            <link>https://www.wiz.io/blog/critical-vulnerability-in-react-cve-2025-55182</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/critical-vulnerability-in-react-cve-2025-55182</guid>
            <pubDate>Wed, 03 Dec 2025 15:57:17 GMT</pubDate>
            <description><![CDATA[Detect and mitigate React2Shell (CVE-2025-55182), critical RCE vulnerability in React and Next.js exploited in the wild. Organizations should patch urgently.]]></description>
            <content:encoded><![CDATA[Detect and mitigate React2Shell (CVE-2025-55182), critical RCE vulnerability in React and Next.js exploited in the wild. Organizations should patch urgently.]]></content:encoded>
            <author>Gili Tikochinski</author>
            <author>Merav Bar</author>
            <author>Danielle Aminov</author>
            <enclosure url="https://www.datocms-assets.com/75231/1764778120-react-next.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[Shai-Hulud 2.0 Aftermath: Trends, Victimology and Impact]]></title>
            <link>https://www.wiz.io/blog/shai-hulud-2-0-aftermath-ongoing-supply-chain-attack</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/shai-hulud-2-0-aftermath-ongoing-supply-chain-attack</guid>
            <pubDate>Mon, 01 Dec 2025 17:52:01 GMT</pubDate>
            <description><![CDATA[A deeper look at the Shai-Hulud 2.0 supply chain attack: reviewing the infection spread, victimology, leaked secrets distribution, and community response so far.]]></description>
            <content:encoded><![CDATA[A deeper look at the Shai-Hulud 2.0 supply chain attack: reviewing the infection spread, victimology, leaked secrets distribution, and community response so far.]]></content:encoded>
            <author>Shay Berkovich</author>
            <author>Rami McCarthy</author>
            <enclosure url="https://www.datocms-assets.com/75231/1764587454-cover.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[3 OAuth TTPs Seen This Month — and How to Detect Them with Entra ID Logs]]></title>
            <link>https://www.wiz.io/blog/recent-oauth-attacks-detection-strategies</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/recent-oauth-attacks-detection-strategies</guid>
            <pubDate>Thu, 27 Nov 2025 16:27:41 GMT</pubDate>
            <description><![CDATA[How OAuth tokens, JWT fields and Entra sign-in logs reveal attacker behavior, and how to turn those signals into reliable detections.]]></description>
            <content:encoded><![CDATA[How OAuth tokens, JWT fields and Entra sign-in logs reveal attacker behavior, and how to turn those signals into reliable detections.]]></content:encoded>
            <author>Sapir Federovsky</author>
            <enclosure url="https://www.datocms-assets.com/75231/1763499865-signin-logs-detection-engineering-2x.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[Shai-Hulud 2.0 Supply Chain Attack: 25K+ Repos Exposing Secrets]]></title>
            <link>https://www.wiz.io/blog/shai-hulud-2-0-ongoing-supply-chain-attack</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/shai-hulud-2-0-ongoing-supply-chain-attack</guid>
            <pubDate>Mon, 24 Nov 2025 10:27:46 GMT</pubDate>
            <description><![CDATA[Detect and mitigate malicious npm packages linked to the recent Shai-Hulud-style campaign. Over 25,000 affected repositories across ~350 unique users. ]]></description>
            <content:encoded><![CDATA[Detect and mitigate malicious npm packages linked to the recent Shai-Hulud-style campaign. Over 25,000 affected repositories across ~350 unique users. ]]></content:encoded>
            <author>Hila Ramati</author>
            <author>Merav Bar</author>
            <author>Gal Benmocha</author>
            <author>Gili Tikochinski</author>
            <enclosure url="https://www.datocms-assets.com/75231/1763978937-shai-hulud2.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Exposure Report: 65% of Leading AI Companies Found with Verified Secret Leaks]]></title>
            <link>https://www.wiz.io/blog/forbes-ai-50-leaking-secrets</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/forbes-ai-50-leaking-secrets</guid>
            <pubDate>Mon, 10 Nov 2025 13:34:02 GMT</pubDate>
            <description><![CDATA[How secure are top private AI companies? Find out from our scans and disclosures.]]></description>
            <content:encoded><![CDATA[How secure are top private AI companies? Find out from our scans and disclosures.]]></content:encoded>
            <author>Shay Berkovich</author>
            <author>Rami McCarthy</author>
            <enclosure url="https://www.datocms-assets.com/75231/1762356190-secrets-2x.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[Dismantling a Critical Supply Chain Risk in VSCode Extension Marketplaces]]></title>
            <link>https://www.wiz.io/blog/supply-chain-risk-in-vscode-extension-marketplaces</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/supply-chain-risk-in-vscode-extension-marketplaces</guid>
            <pubDate>Wed, 15 Oct 2025 12:00:01 GMT</pubDate>
            <description><![CDATA[Wiz Research has uncovered 550+ secrets hiding in plain sight. We worked with Microsoft to shut the door.]]></description>
            <content:encoded><![CDATA[Wiz Research has uncovered 550+ secrets hiding in plain sight. We worked with Microsoft to shut the door.]]></content:encoded>
            <author>Rami McCarthy</author>
            <enclosure url="https://www.datocms-assets.com/75231/1760466286-msrc-2x.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[Introducing HoneyBee: How We Automate Honeypot Deployment for Threat Research]]></title>
            <link>https://www.wiz.io/blog/honeybee-threat-research</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/honeybee-threat-research</guid>
            <pubDate>Tue, 07 Oct 2025 15:16:34 GMT</pubDate>
            <description><![CDATA[Turning attacker insights into stronger cloud security protections.]]></description>
            <content:encoded><![CDATA[Turning attacker insights into stronger cloud security protections.]]></content:encoded>
            <author>Yaara Shriki</author>
            <enclosure url="https://www.datocms-assets.com/75231/1759769818-honeybee-2x.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[RediShell: Critical Remote Code Execution Vulnerability (CVE-2025-49844) in Redis, 10 CVSS score]]></title>
            <link>https://www.wiz.io/blog/wiz-research-redis-rce-cve-2025-49844</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/wiz-research-redis-rce-cve-2025-49844</guid>
            <pubDate>Mon, 06 Oct 2025 21:00:01 GMT</pubDate>
            <description><![CDATA[Wiz Research discovers vulnerability stemming from 13-year-old bug present in all Redis versions, used in 75% of cloud environments.]]></description>
            <content:encoded><![CDATA[Wiz Research discovers vulnerability stemming from 13-year-old bug present in all Redis versions, used in 75% of cloud environments.]]></content:encoded>
            <author>Benny Isaacs</author>
            <author>Nir Brakha</author>
            <enclosure url="https://www.datocms-assets.com/75231/1759772061-redis2-2x.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[Defending against database ransomware attacks]]></title>
            <link>https://www.wiz.io/blog/database-ransomware-research</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/database-ransomware-research</guid>
            <pubDate>Mon, 06 Oct 2025 13:09:13 GMT</pubDate>
            <description><![CDATA[How attackers exploit exposed databases for extortion—and the defenses that work.]]></description>
            <content:encoded><![CDATA[How attackers exploit exposed databases for extortion—and the defenses that work.]]></content:encoded>
            <author>Danielle Aminov</author>
            <author>Shahar Dorfman</author>
            <author>Hila Ramati</author>
            <enclosure url="https://www.datocms-assets.com/75231/1759753056-db-2x.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[Introducing zeroday.cloud: First-of-its-kind cloud and AI hacking competition]]></title>
            <link>https://www.wiz.io/blog/zeroday-cloud-ai-hacking-competition</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/zeroday-cloud-ai-hacking-competition</guid>
            <pubDate>Tue, 30 Sep 2025 17:03:57 GMT</pubDate>
            <description><![CDATA[Wiz and the leading CSPs are launching one of the largest hacking competitions ever to secure the open-source software powering the cloud ecosystem]]></description>
            <content:encoded><![CDATA[Wiz and the leading CSPs are launching one of the largest hacking competitions ever to secure the open-source software powering the cloud ecosystem]]></content:encoded>
            <author>Nir Ohfeld</author>
            <enclosure url="https://www.datocms-assets.com/75231/1759250698-zeroday-assets-for-gil.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[The emerging use of malware invoking AI]]></title>
            <link>https://www.wiz.io/blog/the-emerging-use-of-malware-invoking-ai</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/the-emerging-use-of-malware-invoking-ai</guid>
            <pubDate>Fri, 26 Sep 2025 12:37:37 GMT</pubDate>
            <description><![CDATA[A closer look at LameHug, the Amazon Q Developer Extension compromise, s1ngularity, and PromptLock.]]></description>
            <content:encoded><![CDATA[A closer look at LameHug, the Amazon Q Developer Extension compromise, s1ngularity, and PromptLock.]]></content:encoded>
            <author>Scott Piper</author>
            <enclosure url="https://www.datocms-assets.com/75231/1758811216-payloads-2x.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[IMDS Abused: Hunting Rare Behaviors to Uncover Exploits]]></title>
            <link>https://www.wiz.io/blog/imds-anomaly-hunting-zero-day</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/imds-anomaly-hunting-zero-day</guid>
            <pubDate>Mon, 22 Sep 2025 14:50:13 GMT</pubDate>
            <description><![CDATA[When common processes start asking the wrong questions]]></description>
            <content:encoded><![CDATA[When common processes start asking the wrong questions]]></content:encoded>
            <author>Hila Ramati</author>
            <author>Gili Tikochinski</author>
            <enclosure url="https://www.datocms-assets.com/75231/1758492917-anomality_copy2x-1.webp" length="0" type="image/webp"/>
        </item>
        <item>
            <title><![CDATA[Beyond CVEs: The Exploitation of Everyday Misconfigurations]]></title>
            <link>https://www.wiz.io/blog/beyond-cves-the-exploitation-of-everyday-misconfigurations</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/beyond-cves-the-exploitation-of-everyday-misconfigurations</guid>
            <pubDate>Fri, 19 Sep 2025 12:00:00 GMT</pubDate>
            <description><![CDATA[Exploring how simple setup flaws become open doors for attackers—and what teams can do to shut them.]]></description>
            <content:encoded><![CDATA[Exploring how simple setup flaws become open doors for attackers—and what teams can do to shut them.]]></content:encoded>
            <author>Danielle Aminov</author>
            <author>Gili Tikochinski</author>
            <enclosure url="https://www.datocms-assets.com/75231/1758212350-misconfigurations-2x.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[Wiz Research Discovers One in Five Organizations Exposed to Systemic Risks in Vibe-Coded Applications - Here's How to Secure Them]]></title>
            <link>https://www.wiz.io/blog/common-security-risks-in-vibe-coded-apps</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/common-security-risks-in-vibe-coded-apps</guid>
            <pubDate>Thu, 18 Sep 2025 18:37:42 GMT</pubDate>
            <description><![CDATA[New research reveals four common security risks systematically affecting vibe-coded applications - with remediation strategies curated together with Lovable.]]></description>
            <content:encoded><![CDATA[New research reveals four common security risks systematically affecting vibe-coded applications - with remediation strategies curated together with Lovable.]]></content:encoded>
            <author>Gal Nagli</author>
            <author>Alon Schindel</author>
            <enclosure url="https://www.datocms-assets.com/75231/1758219318-vc-2x-1.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[Shai-Hulud: Ongoing Package Supply Chain Worm Delivering Data-Stealing Malware]]></title>
            <link>https://www.wiz.io/blog/shai-hulud-npm-supply-chain-attack</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/shai-hulud-npm-supply-chain-attack</guid>
            <pubDate>Tue, 16 Sep 2025 14:04:50 GMT</pubDate>
            <description><![CDATA[Detect and mitigate a critical supply chain compromise affecting over 100+ packages, organizations should act urgently.]]></description>
            <content:encoded><![CDATA[Detect and mitigate a critical supply chain compromise affecting over 100+ packages, organizations should act urgently.]]></content:encoded>
            <author>Merav Bar</author>
            <author>Rami McCarthy</author>
            <author>Barak Sharoni</author>
            <enclosure url="https://www.datocms-assets.com/75231/1758030724-shai-hulud.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[Widespread npm Supply Chain Attack: Breaking Down Impact & Scope Across Debug, Chalk, and Beyond]]></title>
            <link>https://www.wiz.io/blog/widespread-npm-supply-chain-attack-breaking-down-impact-scope-across-debug-chalk</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/widespread-npm-supply-chain-attack-breaking-down-impact-scope-across-debug-chalk</guid>
            <pubDate>Tue, 09 Sep 2025 12:20:17 GMT</pubDate>
            <description><![CDATA[A deeper look at the npm debug/chalk supply-chain incident: deobfuscating the wallet-hijacking browser interceptor, quantifying the ~2-hour exposure with Wiz telemetry (~99% package prevalence, ~10% malware presence), and unpacking what made it spread so fast.]]></description>
            <content:encoded><![CDATA[A deeper look at the npm debug/chalk supply-chain incident: deobfuscating the wallet-hijacking browser interceptor, quantifying the ~2-hour exposure with Wiz telemetry (~99% package prevalence, ~10% malware presence), and unpacking what made it spread so fast.]]></content:encoded>
            <author>Hila Ramati</author>
            <author>Gal Benmocha</author>
            <author>Danielle Aminov</author>
            <enclosure url="https://www.datocms-assets.com/75231/1757420284-image-22.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[From Compromised Keys to Phishing Campaigns: Inside a Cloud Email Service Takeover]]></title>
            <link>https://www.wiz.io/blog/wiz-discovers-cloud-email-abuse-campaign</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/wiz-discovers-cloud-email-abuse-campaign</guid>
            <pubDate>Thu, 04 Sep 2025 16:39:21 GMT</pubDate>
            <description><![CDATA[Exposed cloud credentials become the launchpad for mass phishing, highlighting email services as a prime target in cloud exploitation campaigns.]]></description>
            <content:encoded><![CDATA[Exposed cloud credentials become the launchpad for mass phishing, highlighting email services as a prime target in cloud exploitation campaigns.]]></content:encoded>
            <author>Itay Harel</author>
            <author>Hila Ramati</author>
            <enclosure url="https://www.datocms-assets.com/75231/1756998539-leak-copy-2x.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[s1ngularity's Aftermath: AI, TTPs, and Impact in the Nx Supply Chain Attack]]></title>
            <link>https://www.wiz.io/blog/s1ngularitys-aftermath</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/s1ngularitys-aftermath</guid>
            <pubDate>Wed, 03 Sep 2025 14:13:55 GMT</pubDate>
            <description><![CDATA[A deeper look at the Nx supply chain attack: analyzing the performance of AI-powered malware, calculating incident impact, and sharing novel TTPs for further investigation.]]></description>
            <content:encoded><![CDATA[A deeper look at the Nx supply chain attack: analyzing the performance of AI-powered malware, calculating incident impact, and sharing novel TTPs for further investigation.]]></content:encoded>
            <author>Rami McCarthy</author>
            <enclosure url="https://www.datocms-assets.com/75231/1756901276-s1ngularity-s-aftermath-ai-ttps-and-impact-in-the-nx-supply-chain-attack-4.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[s1ngularity: supply chain attack leaks secrets on GitHub: everything you need to know]]></title>
            <link>https://www.wiz.io/blog/s1ngularity-supply-chain-attack</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/s1ngularity-supply-chain-attack</guid>
            <pubDate>Wed, 27 Aug 2025 12:00:54 GMT</pubDate>
            <description><![CDATA[Detect and mitigate a critical supply chain compromise affecting the Nx NPM Package. Organizations should act urgently.]]></description>
            <content:encoded><![CDATA[Detect and mitigate a critical supply chain compromise affecting the Nx NPM Package. Organizations should act urgently.]]></content:encoded>
            <author>Merav Bar</author>
            <author>Rami McCarthy</author>
            <enclosure url="https://www.datocms-assets.com/75231/1756299083-image-21.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[A new type of long-lived key on AWS: Bedrock API keys]]></title>
            <link>https://www.wiz.io/blog/a-new-type-of-long-lived-key-on-aws-bedrock-api-keys</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/a-new-type-of-long-lived-key-on-aws-bedrock-api-keys</guid>
            <pubDate>Thu, 21 Aug 2025 12:18:13 GMT</pubDate>
            <description><![CDATA[New AWS Bedrock keys simplify authentication while raising security considerations.]]></description>
            <content:encoded><![CDATA[New AWS Bedrock keys simplify authentication while raising security considerations.]]></content:encoded>
            <author>Scott Piper</author>
            <enclosure url="https://www.datocms-assets.com/75231/1755701208-bedrock.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[Breaking NVIDIA Triton: CVE-2025-23319 - A Vulnerability Chain Leading to AI Server Takeover]]></title>
            <link>https://www.wiz.io/blog/nvidia-triton-cve-2025-23319-vuln-chain-to-ai-server</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/nvidia-triton-cve-2025-23319-vuln-chain-to-ai-server</guid>
            <pubDate>Mon, 04 Aug 2025 12:55:59 GMT</pubDate>
            <description><![CDATA[Wiz Research discovers a critical vulnerability chain allowing unauthenticated attackers to take over NVIDIA's Triton Inference Server.]]></description>
            <content:encoded><![CDATA[Wiz Research discovers a critical vulnerability chain allowing unauthenticated attackers to take over NVIDIA's Triton Inference Server.]]></content:encoded>
            <author>Ronen Shustin</author>
            <author>Nir Ohfeld</author>
            <enclosure url="https://www.datocms-assets.com/75231/1754309213-nvidia-3-2x.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[Wiz Research Uncovers Critical Vulnerability in AI Vibe Coding platform Base44 Allowing Unauthorized Access to Private Applications]]></title>
            <link>https://www.wiz.io/blog/critical-vulnerability-base44</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/critical-vulnerability-base44</guid>
            <pubDate>Tue, 29 Jul 2025 14:00:00 GMT</pubDate>
            <description><![CDATA[New discovery underscores security implications of AI-powered development and the rise of Vibe Coding Platforms]]></description>
            <content:encoded><![CDATA[New discovery underscores security implications of AI-powered development and the rise of Vibe Coding Platforms]]></content:encoded>
            <author>Gal Nagli</author>
            <enclosure url="https://www.datocms-assets.com/75231/1753388286-unnamed-2.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[TraderTraitor: Deep Dive]]></title>
            <link>https://www.wiz.io/blog/north-korean-tradertraitor-crypto-heist</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/north-korean-tradertraitor-crypto-heist</guid>
            <pubDate>Mon, 28 Jul 2025 13:17:56 GMT</pubDate>
            <description><![CDATA[Inside the Lazarus subgroup that’s hijacking cloud platforms, poisoning supply chains, and stealing billions in digital assets.]]></description>
            <content:encoded><![CDATA[Inside the Lazarus subgroup that’s hijacking cloud platforms, poisoning supply chains, and stealing billions in digital assets.]]></content:encoded>
            <author>Merav Bar</author>
            <enclosure url="https://www.datocms-assets.com/75231/1753706510-traitor-2x.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[Soco404: Multiplatform Cryptomining Campaign Uses Fake Error Pages to Hide Payload]]></title>
            <link>https://www.wiz.io/blog/soco404-multiplatform-cryptomining-campaign-uses-fake-error-pages-to-hide-payload</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/soco404-multiplatform-cryptomining-campaign-uses-fake-error-pages-to-hide-payload</guid>
            <pubDate>Wed, 23 Jul 2025 12:00:00 GMT</pubDate>
            <description><![CDATA[Wiz Research has identified a new iteration of a broader malicious cryptomining campaign, which we’ve dubbed Soco404.]]></description>
            <content:encoded><![CDATA[Wiz Research has identified a new iteration of a broader malicious cryptomining campaign, which we’ve dubbed Soco404.]]></content:encoded>
            <author>Maor Dokhanian</author>
            <author>Shahar Dorfman</author>
            <author>Avigayil Mechtinger</author>
            <enclosure url="https://www.datocms-assets.com/75231/1753204564-404-cover-2x.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[SharePoint Vulnerabilities (CVE-2025-53770 & CVE-2025-53771): Everything You Need to Know]]></title>
            <link>https://www.wiz.io/blog/sharepoint-vulnerabilities-cve-2025-53770-cve-2025-53771-everything-you-need-to-k</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/sharepoint-vulnerabilities-cve-2025-53770-cve-2025-53771-everything-you-need-to-k</guid>
            <pubDate>Mon, 21 Jul 2025 17:42:00 GMT</pubDate>
            <description><![CDATA[Detect and mitigate CVE-2025-53770 and CVE-2025-53771 - critical vulnerabilities in Microsoft SharePoint Server currently under active exploitation.]]></description>
            <content:encoded><![CDATA[Detect and mitigate CVE-2025-53770 and CVE-2025-53771 - critical vulnerabilities in Microsoft SharePoint Server currently under active exploitation.]]></content:encoded>
            <author>Hila Ramati</author>
            <enclosure url="https://www.datocms-assets.com/75231/1753118891-share-poing.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[NVIDIAScape - Critical NVIDIA AI Vulnerability: A Three-Line Container Escape in NVIDIA Container Toolkit (CVE-2025-23266)]]></title>
            <link>https://www.wiz.io/blog/nvidia-ai-vulnerability-cve-2025-23266-nvidiascape</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/nvidia-ai-vulnerability-cve-2025-23266-nvidiascape</guid>
            <pubDate>Thu, 17 Jul 2025 14:46:47 GMT</pubDate>
            <description><![CDATA[New critical vulnerability with 9.0 CVSS presents systemic risk to the AI ecosystem, carries widespread implications for AI infrastructure.]]></description>
            <content:encoded><![CDATA[New critical vulnerability with 9.0 CVSS presents systemic risk to the AI ecosystem, carries widespread implications for AI infrastructure.]]></content:encoded>
            <author>Nir Ohfeld</author>
            <author>Shir Tamari</author>
            <enclosure url="https://www.datocms-assets.com/75231/1752757980-image-26.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[Critical vulnerabilities in NetScaler ADC exploited in-the-wild: everything you need to know]]></title>
            <link>https://www.wiz.io/blog/critical-vulnerabilities-netscaler-adc-exploited-in-the-wild-cve-2025-5777</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/critical-vulnerabilities-netscaler-adc-exploited-in-the-wild-cve-2025-5777</guid>
            <pubDate>Sun, 06 Jul 2025 12:45:49 GMT</pubDate>
            <description><![CDATA[Detect and mitigate CVE-2025-5349, CVE-2025-5777, and CVE-2025-6543, Citrix Netscaler ADC and Gateway vulnerabilities being exploited in the wild. Organizations should patch urgently.]]></description>
            <content:encoded><![CDATA[Detect and mitigate CVE-2025-5349, CVE-2025-5777, and CVE-2025-6543, Citrix Netscaler ADC and Gateway vulnerabilities being exploited in the wild. Organizations should patch urgently.]]></content:encoded>
            <author>Merav Bar</author>
            <author>Amitai Cohen</author>
            <enclosure url="https://www.datocms-assets.com/75231/1751804768-image-19.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[Exposed JDWP Exploited in the Wild: What Happens When Debug Ports Are Left Open]]></title>
            <link>https://www.wiz.io/blog/exposed-jdwp-exploited-in-the-wild</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/exposed-jdwp-exploited-in-the-wild</guid>
            <pubDate>Wed, 02 Jul 2025 15:00:13 GMT</pubDate>
            <description><![CDATA[Understanding the risks and impact of deploying dev-mode in production environments]]></description>
            <content:encoded><![CDATA[Understanding the risks and impact of deploying dev-mode in production environments]]></content:encoded>
            <author>Yaara Shriki</author>
            <author>Gili Tikochinski</author>
            <enclosure url="https://www.datocms-assets.com/75231/1751400778-image-24.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[The Ultimate Cloud Security Championship | 12 Months × 12 Challenges]]></title>
            <link>https://www.wiz.io/blog/the-ultimate-cloud-security-championship-12-months-x-12-challenges</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/the-ultimate-cloud-security-championship-12-months-x-12-challenges</guid>
            <pubDate>Thu, 26 Jun 2025 13:13:08 GMT</pubDate>
            <description><![CDATA[We’re excited to announce our latest cloud security challenge series.]]></description>
            <content:encoded><![CDATA[We’re excited to announce our latest cloud security challenge series.]]></content:encoded>
            <author>Scott Piper</author>
            <enclosure url="https://www.datocms-assets.com/75231/1750691134-blog-cover.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[Cloud Attacks Retrospective: Evolving Tactics, Familiar Entry Points]]></title>
            <link>https://www.wiz.io/blog/cloud-attack-retrospective-2025</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/cloud-attack-retrospective-2025</guid>
            <pubDate>Wed, 18 Jun 2025 12:00:01 GMT</pubDate>
            <description><![CDATA[Let's break down eight attack patterns security teams should be watching in 2025. ]]></description>
            <content:encoded><![CDATA[Let's break down eight attack patterns security teams should be watching in 2025. ]]></content:encoded>
            <author>Wiz Threat Research</author>
            <enclosure url="https://www.datocms-assets.com/75231/1749146586-blog-cover-3.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[Leaking Secrets in the Age of AI]]></title>
            <link>https://www.wiz.io/blog/leaking-ai-secrets-in-public-code</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/leaking-ai-secrets-in-public-code</guid>
            <pubDate>Tue, 17 Jun 2025 17:47:54 GMT</pubDate>
            <description><![CDATA[How has AI-assisted development impacted secrets leakage? Learn the new patterns and emerging trends.]]></description>
            <content:encoded><![CDATA[How has AI-assisted development impacted secrets leakage? Learn the new patterns and emerging trends.]]></content:encoded>
            <author>Shay Berkovich</author>
            <author>Rami McCarthy</author>
            <enclosure url="https://www.datocms-assets.com/75231/1749746295-leaking-secrets-in-the-age-of-ai.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[Lean and Mean: How We Fine-Tuned a Small Language Model for Secret Detection in Code]]></title>
            <link>https://www.wiz.io/blog/small-language-model-for-secrets-detection-in-code</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/small-language-model-for-secrets-detection-in-code</guid>
            <pubDate>Tue, 10 Jun 2025 16:01:49 GMT</pubDate>
            <description><![CDATA[Building an efficient small language model for cybersecurity, from data prep to deployment  ]]></description>
            <content:encoded><![CDATA[Building an efficient small language model for cybersecurity, from data prep to deployment  ]]></content:encoded>
            <author>Erez Harush</author>
            <author>Daniel Lazarev</author>
            <enclosure url="https://www.datocms-assets.com/75231/1749489546-secret-detection-using-smls.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[Rules Files for Safer Vibe Coding]]></title>
            <link>https://www.wiz.io/blog/safer-vibe-coding-rules-files</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/safer-vibe-coding-rules-files</guid>
            <pubDate>Fri, 06 Jun 2025 10:00:00 GMT</pubDate>
            <description><![CDATA[Helping LLMs generate safer and more secure code through open-sourced rules files.]]></description>
            <content:encoded><![CDATA[Helping LLMs generate safer and more secure code through open-sourced rules files.]]></content:encoded>
            <author>Rami McCarthy</author>
            <enclosure url="https://www.datocms-assets.com/75231/1749120368-artboard-16-copy-2-2x.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[ DevOps Tools Targeted for Cryptojacking]]></title>
            <link>https://www.wiz.io/blog/jinx-0132-cryptojacking-campaign</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/jinx-0132-cryptojacking-campaign</guid>
            <pubDate>Mon, 02 Jun 2025 14:00:00 GMT</pubDate>
            <description><![CDATA[
The Wiz Threat Research team has identified a widespread cryptojacking campaign targeting commonly used DevOps applications including Nomad and Consul.]]></description>
            <content:encoded><![CDATA[
The Wiz Threat Research team has identified a widespread cryptojacking campaign targeting commonly used DevOps applications including Nomad and Consul.]]></content:encoded>
            <author>Gili Tikochinski</author>
            <author>Danielle Aminov</author>
            <author>Merav Bar</author>
            <enclosure url="https://www.datocms-assets.com/75231/1748635384-devops-tools-targeted-for-cryptojacking.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[Ivanti EPMM RCE Vulnerability Chain Exploited in the Wild]]></title>
            <link>https://www.wiz.io/blog/ivanti-epmm-rce-vulnerability-chain-cve-2025-4427-cve-2025-4428</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/ivanti-epmm-rce-vulnerability-chain-cve-2025-4427-cve-2025-4428</guid>
            <pubDate>Tue, 20 May 2025 18:13:13 GMT</pubDate>
            <description><![CDATA[Wiz Threat Research has observed exploitation in-the-wild of CVE-2025-4427 and CVE-2025-4428, the latest vulnerabilities affecting Ivanti Endpoint Manager Mobile (EPMM).]]></description>
            <content:encoded><![CDATA[Wiz Threat Research has observed exploitation in-the-wild of CVE-2025-4427 and CVE-2025-4428, the latest vulnerabilities affecting Ivanti Endpoint Manager Mobile (EPMM).]]></content:encoded>
            <author>Merav Bar</author>
            <author>Shahar Dorfman</author>
            <author>Gili Tikochinski</author>
            <enclosure url="https://www.datocms-assets.com/75231/1747763396-image-218.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[What Analyzing Hundreds of Thousands of Cloud Environments Taught Us About Data Exposure]]></title>
            <link>https://www.wiz.io/blog/cloud-data-security-report-snapshot</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/cloud-data-security-report-snapshot</guid>
            <pubDate>Wed, 07 May 2025 12:00:00 GMT</pubDate>
            <description><![CDATA[Wiz Research reveals the latest cloud data security trends across hundreds of thousands of real-world environments. ]]></description>
            <content:encoded><![CDATA[Wiz Research reveals the latest cloud data security trends across hundreds of thousands of real-world environments. ]]></content:encoded>
            <author>Wiz Threat Research</author>
            <enclosure url="https://www.datocms-assets.com/75231/1745438392-blog-cover-2.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[Research Briefing: MCP Security]]></title>
            <link>https://www.wiz.io/blog/mcp-security-research-briefing</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/mcp-security-research-briefing</guid>
            <pubDate>Thu, 17 Apr 2025 14:00:37 GMT</pubDate>
            <description><![CDATA[The present and future of security for the Model Context Protocol.]]></description>
            <content:encoded><![CDATA[The present and future of security for the Model Context Protocol.]]></content:encoded>
            <author>Rami McCarthy</author>
            <enclosure url="https://www.datocms-assets.com/75231/1744892293-mcp2-2x.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[CPU_HU: Fileless cryptominer targeting exposed PostgreSQL with over 1.5K victims ]]></title>
            <link>https://www.wiz.io/blog/postgresql-cryptomining</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/postgresql-cryptomining</guid>
            <pubDate>Mon, 31 Mar 2025 15:13:26 GMT</pubDate>
            <description><![CDATA[Cloud environments at risk: Attackers target weak PostgreSQL instances with fileless cryptominer payloads.]]></description>
            <content:encoded><![CDATA[Cloud environments at risk: Attackers target weak PostgreSQL instances with fileless cryptominer payloads.]]></content:encoded>
            <author>Avigayil Mechtinger</author>
            <author>Yaara Shriki</author>
            <author>Gili Tikochinski</author>
            <enclosure url="https://www.datocms-assets.com/75231/1743093663-sql-2x.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[IngressNightmare: CVE-2025-1974 - 9.8 Critical Unauthenticated Remote Code Execution Vulnerabilities in Ingress NGINX]]></title>
            <link>https://www.wiz.io/blog/ingress-nginx-kubernetes-vulnerabilities</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/ingress-nginx-kubernetes-vulnerabilities</guid>
            <pubDate>Mon, 24 Mar 2025 21:45:26 GMT</pubDate>
            <description><![CDATA[Over 40% of cloud environments are vulnerable to RCE, likely leading to a complete cluster takeover.]]></description>
            <content:encoded><![CDATA[Over 40% of cloud environments are vulnerable to RCE, likely leading to a complete cluster takeover.]]></content:encoded>
            <author>Nir Ohfeld</author>
            <author>Ronen Shustin</author>
            <author>Sagi Tzadik</author>
            <author>Hillai Ben-Sasson</author>
            <enclosure url="https://www.datocms-assets.com/75231/1742578873-image-174.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[How to use the new CloudTrail network activity events for AWS VPC Endpoints ]]></title>
            <link>https://www.wiz.io/blog/aws-vpc-endpoint-cloudtrail</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/aws-vpc-endpoint-cloudtrail</guid>
            <pubDate>Thu, 20 Mar 2025 12:00:00 GMT</pubDate>
            <description><![CDATA[Learn how AWS VPC Endpoint CloudTrail logs can help you troubleshoot endpoint policies and strengthen your network's security against data exfiltration. ]]></description>
            <content:encoded><![CDATA[Learn how AWS VPC Endpoint CloudTrail logs can help you troubleshoot endpoint policies and strengthen your network's security against data exfiltration. ]]></content:encoded>
            <author>Rami McCarthy</author>
            <author>Scott Piper</author>
            <enclosure url="https://www.datocms-assets.com/75231/1742404839-vpc2-2x-2.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[New GitHub Action supply chain attack: reviewdog/action-setup ]]></title>
            <link>https://www.wiz.io/blog/new-github-action-supply-chain-attack-reviewdog-action-setup</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/new-github-action-supply-chain-attack-reviewdog-action-setup</guid>
            <pubDate>Mon, 17 Mar 2025 21:28:56 GMT</pubDate>
            <description><![CDATA[A supply chain attack on tj-actions/changed-files caused many repositories to leak their secrets over the weekend. Wiz Research has discovered an additional supply chain attack on reviewdog/actions-setup@v1, that may have contributed to the compromise of tj-actions/changed-files.]]></description>
            <content:encoded><![CDATA[A supply chain attack on tj-actions/changed-files caused many repositories to leak their secrets over the weekend. Wiz Research has discovered an additional supply chain attack on reviewdog/actions-setup@v1, that may have contributed to the compromise of tj-actions/changed-files.]]></content:encoded>
            <author>Rami McCarthy</author>
            <enclosure url="https://www.datocms-assets.com/75231/1742245826-supplychainception2.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[GitHub Action tj-actions/changed-files supply chain attack: everything you need to know]]></title>
            <link>https://www.wiz.io/blog/github-action-tj-actions-changed-files-supply-chain-attack-cve-2025-30066</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/github-action-tj-actions-changed-files-supply-chain-attack-cve-2025-30066</guid>
            <pubDate>Sat, 15 Mar 2025 16:19:08 GMT</pubDate>
            <description><![CDATA[A supply chain attack on popular GitHub Action tj-actions/changed-files caused many repositories to leak their secrets. Discover how it unfolded and the steps to mitigate the risk. ]]></description>
            <content:encoded><![CDATA[A supply chain attack on popular GitHub Action tj-actions/changed-files caused many repositories to leak their secrets. Discover how it unfolded and the steps to mitigate the risk. ]]></content:encoded>
            <author>Merav Bar</author>
            <author>Shay Berkovich</author>
            <author>Gal Nagli</author>
            <enclosure url="https://www.datocms-assets.com/75231/1742054564-report-2x.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[Key Takeaways from the 2025 State of AI in the Cloud Report ]]></title>
            <link>https://www.wiz.io/blog/state-of-cloud-ai-report-takeaways</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/state-of-cloud-ai-report-takeaways</guid>
            <pubDate>Fri, 07 Mar 2025 13:00:01 GMT</pubDate>
            <description><![CDATA[From DeepSeek adoption to impact on security and governance. ]]></description>
            <content:encoded><![CDATA[From DeepSeek adoption to impact on security and governance. ]]></content:encoded>
            <author>Amitai Cohen</author>
            <author>Dan Segev</author>
            <enclosure url="https://www.datocms-assets.com/75231/1741282816-artboard-12-copy-2-2x-1.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[2025 State of Code Security: Key Trends and Risks]]></title>
            <link>https://www.wiz.io/blog/state-of-code-security-report-2025</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/state-of-code-security-report-2025</guid>
            <pubDate>Thu, 20 Feb 2025 16:38:04 GMT</pubDate>
            <description><![CDATA[Explore the key insights on code and cloud security risks shaping 2025.]]></description>
            <content:encoded><![CDATA[Explore the key insights on code and cloud security risks shaping 2025.]]></content:encoded>
            <author>Shay Berkovich</author>
            <enclosure url="https://www.datocms-assets.com/75231/1739306813-blog-cover.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[How Wiz found a Critical NVIDIA AI vulnerability:  Deep Dive into a container escape (CVE-2024-0132)]]></title>
            <link>https://www.wiz.io/blog/nvidia-ai-vulnerability-deep-dive-cve-2024-0132</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/nvidia-ai-vulnerability-deep-dive-cve-2024-0132</guid>
            <pubDate>Tue, 11 Feb 2025 18:18:39 GMT</pubDate>
            <description><![CDATA[Technical details on a critical severity vulnerability (CVE-2024-0132) in NVIDIA Container Toolkit and GPU Operator, affecting cloud service providers .]]></description>
            <content:encoded><![CDATA[Technical details on a critical severity vulnerability (CVE-2024-0132) in NVIDIA Container Toolkit and GPU Operator, affecting cloud service providers .]]></content:encoded>
            <author>Shir Tamari</author>
            <author>Ronen Shustin</author>
            <author>Andres Riancho</author>
            <enclosure url="https://www.datocms-assets.com/75231/1736790398-nvidia-vuln-cover.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[Wiz Research Uncovers Exposed DeepSeek Database Leaking Sensitive Information, Including Chat History]]></title>
            <link>https://www.wiz.io/blog/wiz-research-uncovers-exposed-deepseek-database-leak</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/wiz-research-uncovers-exposed-deepseek-database-leak</guid>
            <pubDate>Wed, 29 Jan 2025 20:47:40 GMT</pubDate>
            <description><![CDATA[A publicly accessible database belonging to DeepSeek allowed full control over database operations, including the ability to access internal data. The exposure includes over a million lines of log streams with highly sensitive information.]]></description>
            <content:encoded><![CDATA[A publicly accessible database belonging to DeepSeek allowed full control over database operations, including the ability to access internal data. The exposure includes over a million lines of log streams with highly sensitive information.]]></content:encoded>
            <author>Gal Nagli</author>
            <enclosure url="https://www.datocms-assets.com/75231/1738180897-ds-2x.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[Securing the Container Frontier: Kubernetes Trends Report 2025]]></title>
            <link>https://www.wiz.io/blog/kubernetes-report-preview-2025</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/kubernetes-report-preview-2025</guid>
            <pubDate>Thu, 23 Jan 2025 14:00:00 GMT</pubDate>
            <description><![CDATA[From rapid-fire attack attempts to evolving defense strategies, our Kubernetes Security Report paints a vivid picture of a dynamic landscape. Check out the preview here.]]></description>
            <content:encoded><![CDATA[From rapid-fire attack attempts to evolving defense strategies, our Kubernetes Security Report paints a vivid picture of a dynamic landscape. Check out the preview here.]]></content:encoded>
            <author>Shay Berkovich</author>
            <enclosure url="https://www.datocms-assets.com/75231/1737576063-k8-2x.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[Tracking cloud-fluent threat actors - Part two: Behavioral cloud IOCs]]></title>
            <link>https://www.wiz.io/blog/detecting-behavioral-cloud-indicators-of-compromise-iocs</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/detecting-behavioral-cloud-indicators-of-compromise-iocs</guid>
            <pubDate>Wed, 15 Jan 2025 09:56:28 GMT</pubDate>
            <description><![CDATA[Discover how behavioral cloud IOCs can expose malicious activity as we break down real-world examples to reveal actionable detection techniques.]]></description>
            <content:encoded><![CDATA[Discover how behavioral cloud IOCs can expose malicious activity as we break down real-world examples to reveal actionable detection techniques.]]></content:encoded>
            <author>Merav Bar</author>
            <author>Gili Tikochinski</author>
            <enclosure url="https://www.datocms-assets.com/75231/1736869413-v5-2x.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[Wiz Research Identifies Exploitation in the Wild of Aviatrix Controller RCE (CVE-2024-50603)]]></title>
            <link>https://www.wiz.io/blog/wiz-research-identifies-exploitation-in-the-wild-of-aviatrix-cve-2024-50603</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/wiz-research-identifies-exploitation-in-the-wild-of-aviatrix-cve-2024-50603</guid>
            <pubDate>Sat, 11 Jan 2025 17:23:53 GMT</pubDate>
            <description><![CDATA[The Wiz Incident Response team is currently responding to multiple incidents involving CVE-2024-50603, an Aviatrix Controller unauthenticated RCE vulnerability, that can lead to privileges escalation in the AWS control plane. Organizations should patch urgently.]]></description>
            <content:encoded><![CDATA[The Wiz Incident Response team is currently responding to multiple incidents involving CVE-2024-50603, an Aviatrix Controller unauthenticated RCE vulnerability, that can lead to privileges escalation in the AWS control plane. Organizations should patch urgently.]]></content:encoded>
            <author>Gal Nagli</author>
            <author>Merav Bar</author>
            <author>Gili Tikochinski</author>
            <author>Shaked Tanchuma Yogev</author>
            <enclosure url="https://www.datocms-assets.com/75231/1736607182-aviatrix-rce-exploited-in-the-wild.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[CVE-2025-0282 and CVE-2025-0283: Critical Ivanti 0days Exploited in the Wild]]></title>
            <link>https://www.wiz.io/blog/cve-2025-0282-and-cve-2025-0283-critical-ivanti-0days-exploited-in-the-wild</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/cve-2025-0282-and-cve-2025-0283-critical-ivanti-0days-exploited-in-the-wild</guid>
            <pubDate>Thu, 09 Jan 2025 14:23:44 GMT</pubDate>
            <description><![CDATA[Detect and mitigate CVE-2025-0282, a critical RCE vulnerability in Ivanti Connect Secure and CVE-2025-0283, exploited as 0day vulnerabilities in the wild. Organizations should patch urgently. ]]></description>
            <content:encoded><![CDATA[Detect and mitigate CVE-2025-0282, a critical RCE vulnerability in Ivanti Connect Secure and CVE-2025-0283, exploited as 0day vulnerabilities in the wild. Organizations should patch urgently. ]]></content:encoded>
            <author>Merav Bar</author>
            <enclosure url="https://www.datocms-assets.com/75231/1736431970-ivanti-vulnerabilities-exploited-in-the-wild-1.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[Breaking the Chain: Wiz Uncovers a Signature Verification Bypass in Nuclei, the Popular Vulnerability Scanner (CVE-2024-43405)]]></title>
            <link>https://www.wiz.io/blog/nuclei-signature-verification-bypass</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/nuclei-signature-verification-bypass</guid>
            <pubDate>Fri, 03 Jan 2025 15:00:01 GMT</pubDate>
            <description><![CDATA[Wiz’s engineering team discovered a high-severity signature verification bypass in Nuclei, one of the most popular open-source security tools, which could potentially lead to arbitrary code execution.]]></description>
            <content:encoded><![CDATA[Wiz’s engineering team discovered a high-severity signature verification bypass in Nuclei, one of the most popular open-source security tools, which could potentially lead to arbitrary code execution.]]></content:encoded>
            <author>Guy Goldenberg</author>
            <enclosure url="https://www.datocms-assets.com/75231/1735835604-nuclei-vulnerability.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[Avoiding mistakes with AWS OIDC integration conditions ]]></title>
            <link>https://www.wiz.io/blog/avoiding-mistakes-with-aws-oidc-integration-conditions</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/avoiding-mistakes-with-aws-oidc-integration-conditions</guid>
            <pubDate>Wed, 01 Jan 2025 14:00:00 GMT</pubDate>
            <description><![CDATA[Let’s explore some common missteps in securing your AWS OIDC.]]></description>
            <content:encoded><![CDATA[Let’s explore some common missteps in securing your AWS OIDC.]]></content:encoded>
            <author>Scott Piper</author>
            <enclosure url="https://www.datocms-assets.com/75231/1735659219-image-37.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[The many ways to obtain credentials in AWS ]]></title>
            <link>https://www.wiz.io/blog/the-many-ways-to-obtain-credentials-in-aws</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/the-many-ways-to-obtain-credentials-in-aws</guid>
            <pubDate>Fri, 20 Dec 2024 13:00:00 GMT</pubDate>
            <description><![CDATA[Dive into the complexities of AWS IAM credentials and uncover how defenders can stay ahead with in-depth knowledge of SDK behaviors and service-specific mechanisms. ]]></description>
            <content:encoded><![CDATA[Dive into the complexities of AWS IAM credentials and uncover how defenders can stay ahead with in-depth knowledge of SDK behaviors and service-specific mechanisms. ]]></content:encoded>
            <author>Scott Piper</author>
            <enclosure url="https://www.datocms-assets.com/75231/1734630410-obtain_credentials_in_aws.webp" length="0" type="image/webp"/>
        </item>
        <item>
            <title><![CDATA[Unpacking Diicot - Evolving Campaign Targeting Linux Environments ]]></title>
            <link>https://www.wiz.io/blog/diicot-threat-group-malware-campaign</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/diicot-threat-group-malware-campaign</guid>
            <pubDate>Tue, 17 Dec 2024 17:31:22 GMT</pubDate>
            <description><![CDATA[Wiz Threat Research uncovered a new malware campaign targeting Linux environments attributed to the Diicot threat group.]]></description>
            <content:encoded><![CDATA[Wiz Threat Research uncovered a new malware campaign targeting Linux environments attributed to the Diicot threat group.]]></content:encoded>
            <author>Gili Tikochinski</author>
            <author>Yaara Shriki</author>
            <enclosure url="https://www.datocms-assets.com/75231/1734451574-blog-image-diicot-campaign.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[Under the Radar: Exploring Spring Boot Actuator Misconfigurations]]></title>
            <link>https://www.wiz.io/blog/spring-boot-actuator-misconfigurations</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/spring-boot-actuator-misconfigurations</guid>
            <pubDate>Mon, 16 Dec 2024 14:00:34 GMT</pubDate>
            <description><![CDATA[Wiz Threat Research investigates misconfigurations in Spring Boot Actuator’s endpoints that can leak environment variables, passwords, and API keys, and even lead to remote code execution. ]]></description>
            <content:encoded><![CDATA[Wiz Threat Research investigates misconfigurations in Spring Boot Actuator’s endpoints that can leak environment variables, passwords, and API keys, and even lead to remote code execution. ]]></content:encoded>
            <author>Danielle Aminov</author>
            <enclosure url="https://www.datocms-assets.com/75231/1734355782-springboot-actuator-blog2.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[New Developments in LLM Hijacking Activity]]></title>
            <link>https://www.wiz.io/blog/jinx-2401-llm-hijacking-aws</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/jinx-2401-llm-hijacking-aws</guid>
            <pubDate>Sun, 15 Dec 2024 14:07:55 GMT</pubDate>
            <description><![CDATA[Discover the latest in LLM hijacking activity, including a dive into the JINX-2401 campaign targeting AWS environments with IAM privilege escalation tactics. ]]></description>
            <content:encoded><![CDATA[Discover the latest in LLM hijacking activity, including a dive into the JINX-2401 campaign targeting AWS environments with IAM privilege escalation tactics. ]]></content:encoded>
            <author>Maayan Bentor</author>
            <enclosure url="https://www.datocms-assets.com/75231/1734270864-new-developments-in-llm-hijacking.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[Top AWS re:Invent Announcements for Security Teams in 2024]]></title>
            <link>https://www.wiz.io/blog/top-aws-re-invent-announcements-for-security-teams-in-2024</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/top-aws-re-invent-announcements-for-security-teams-in-2024</guid>
            <pubDate>Wed, 11 Dec 2024 13:00:00 GMT</pubDate>
            <description><![CDATA[AWS re:Invent 2024 brought an avalanche of announcements, with over 500 updates since November. Let's spotlight the most impactful ones for security teams, from Resource Control Policies to centrally managed root access.]]></description>
            <content:encoded><![CDATA[AWS re:Invent 2024 brought an avalanche of announcements, with over 500 updates since November. Let's spotlight the most impactful ones for security teams, from Resource Control Policies to centrally managed root access.]]></content:encoded>
            <author>Scott Piper</author>
            <enclosure url="https://www.datocms-assets.com/75231/1733925576-reinvent.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[Ultralytics AI Library Hacked via GitHub for Cryptomining]]></title>
            <link>https://www.wiz.io/blog/ultralytics-ai-library-hacked-via-github-for-cryptomining</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/ultralytics-ai-library-hacked-via-github-for-cryptomining</guid>
            <pubDate>Mon, 09 Dec 2024 15:56:01 GMT</pubDate>
            <description><![CDATA[A supply chain attack on Ultralytics exploited GitHub Actions to inject malicious PyPI packages. Discover how it unfolded and the steps to mitigate the risk.]]></description>
            <content:encoded><![CDATA[A supply chain attack on Ultralytics exploited GitHub Actions to inject malicious PyPI packages. Discover how it unfolded and the steps to mitigate the risk.]]></content:encoded>
            <author>Wiz Threat Research</author>
            <enclosure url="https://www.datocms-assets.com/75231/1733757600-threat-update-new.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[How to use AWS Resource Control Policies ]]></title>
            <link>https://www.wiz.io/blog/how-to-use-aws-resource-control-policies</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/how-to-use-aws-resource-control-policies</guid>
            <pubDate>Thu, 28 Nov 2024 05:00:00 GMT</pubDate>
            <description><![CDATA[Unlock the Power of AWS Resource Control Policies: Enforce Security and Streamline Governance Across Your Organization.]]></description>
            <content:encoded><![CDATA[Unlock the Power of AWS Resource Control Policies: Enforce Security and Streamline Governance Across Your Organization.]]></content:encoded>
            <author>Scott Piper</author>
            <enclosure url="https://www.datocms-assets.com/75231/1732736270-artboard-59_1-2x-1.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[Wiz collaborates with NVIDIA to advance ML research for data classification ]]></title>
            <link>https://www.wiz.io/blog/nvidia-ml-data-classification</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/nvidia-ml-data-classification</guid>
            <pubDate>Tue, 26 Nov 2024 12:02:31 GMT</pubDate>
            <description><![CDATA[Wiz Research taps Llama 3 model NVIDIA NIM microservices for sensitive data classification]]></description>
            <content:encoded><![CDATA[Wiz Research taps Llama 3 model NVIDIA NIM microservices for sensitive data classification]]></content:encoded>
            <author>Erez Harush</author>
            <author>Nadav Tzuker</author>
            <author>Shaked Rotlevi</author>
            <enclosure url="https://www.datocms-assets.com/75231/1732613026-vidia-2x-1.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[Wiz observes exploitation in the wild of PAN-OS vulnerabilities]]></title>
            <link>https://www.wiz.io/blog/cve-2024-0012-pan-os-vulnerability-exploited-in-the-wild</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/cve-2024-0012-pan-os-vulnerability-exploited-in-the-wild</guid>
            <pubDate>Fri, 22 Nov 2024 13:50:17 GMT</pubDate>
            <description><![CDATA[Detect and mitigate CVE-2024-0012 and CVE-2024-9474, PAN-OS vulnerabilities which Wiz Threat Research has observed being exploited in-the-wild. Organizations should patch urgently. ]]></description>
            <content:encoded><![CDATA[Detect and mitigate CVE-2024-0012 and CVE-2024-9474, PAN-OS vulnerabilities which Wiz Threat Research has observed being exploited in-the-wild. Organizations should patch urgently. ]]></content:encoded>
            <author>Wiz Threat Research</author>
            <enclosure url="https://www.datocms-assets.com/75231/1732282774-threat-template_v0h3-1.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[Unmasking Phishing: Strategies for identifying 0ktapus domains and beyond ]]></title>
            <link>https://www.wiz.io/blog/unmasking-phishing-strategies-for-identifying-0ktapus-domains</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/unmasking-phishing-strategies-for-identifying-0ktapus-domains</guid>
            <pubDate>Thu, 07 Nov 2024 17:09:51 GMT</pubDate>
            <description><![CDATA[Wiz Research looks at phishing tactics, along with how to trace and investigate these campaigns. ]]></description>
            <content:encoded><![CDATA[Wiz Research looks at phishing tactics, along with how to trace and investigate these campaigns. ]]></content:encoded>
            <author>Amitai Cohen</author>
            <author>Shahar Dorfman</author>
            <enclosure url="https://www.datocms-assets.com/75231/1730995888-v8-4x.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[Supply chain attack on lottie-player: everything you need to know ]]></title>
            <link>https://www.wiz.io/blog/lottie-player-supply-chain-attack</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/lottie-player-supply-chain-attack</guid>
            <pubDate>Thu, 31 Oct 2024 12:55:28 GMT</pubDate>
            <description><![CDATA[Supply chain attack in popular lottie-player library compromises websites with malicious Web3 wallet prompts – update or revert the library to avoid the compromised versions.]]></description>
            <content:encoded><![CDATA[Supply chain attack in popular lottie-player library compromises websites with malicious Web3 wallet prompts – update or revert the library to avoid the compromised versions.]]></content:encoded>
            <author>Merav Bar</author>
            <author>Gal Nagli</author>
            <author>Danielle Aminov</author>
            <enclosure url="https://www.datocms-assets.com/75231/1730378577-lottie.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[AskAI – Text to Security Graph Query   ]]></title>
            <link>https://www.wiz.io/blog/askai-text-to-security-graph-query</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/askai-text-to-security-graph-query</guid>
            <pubDate>Wed, 23 Oct 2024 14:00:00 GMT</pubDate>
            <description><![CDATA[AskAI – Text to Security Graph Query   ]]></description>
            <content:encoded><![CDATA[AskAI – Text to Security Graph Query   ]]></content:encoded>
            <author>Daniel Lazarev</author>
            <author>Erez Harush</author>
            <enclosure url="https://www.datocms-assets.com/75231/1729016827-ask_ai_blog_cover.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[Critical vulnerabilities in Palo Alto Expedition: everything you need to know ]]></title>
            <link>https://www.wiz.io/blog/palo-alto-networks-expedition-critical-vulnerabilities-advisory</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/palo-alto-networks-expedition-critical-vulnerabilities-advisory</guid>
            <pubDate>Thu, 10 Oct 2024 17:45:48 GMT</pubDate>
            <description><![CDATA[Detect and mitigate critical vulnerabilities (CVE-2024-9463, CVE-2024-9464, CVE-2024-9465, CVE-2024-9466, CVE-2024-9467) in Palo Alto Networks’ Expedition tool. Organizations should patch urgently. ]]></description>
            <content:encoded><![CDATA[Detect and mitigate critical vulnerabilities (CVE-2024-9463, CVE-2024-9464, CVE-2024-9465, CVE-2024-9466, CVE-2024-9467) in Palo Alto Networks’ Expedition tool. Organizations should patch urgently. ]]></content:encoded>
            <author>Merav Bar</author>
            <author>Gili Tikochinski</author>
            <enclosure url="https://www.datocms-assets.com/75231/1728581242-screenshot-2024-10-10-at-20-26-49.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[CVE-2024-47076, CVE-2024-47175, CVE-2024-47176, CVE-2024-47177: Everything you need to know]]></title>
            <link>https://www.wiz.io/blog/openprinting-cups-vulnerabilities-cve-2024-47076-cve-2024-47175-cve-2024-47176-cve-2024-47177</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/openprinting-cups-vulnerabilities-cve-2024-47076-cve-2024-47175-cve-2024-47176-cve-2024-47177</guid>
            <pubDate>Sun, 29 Sep 2024 17:00:51 GMT</pubDate>
            <description><![CDATA[Detect and mitigate CVE-2024-47076, CVE-2024-47175, CVE-2024-47176, and CVE-2024-47177 vulnerabilities impacting CUPS and IPP packages.]]></description>
            <content:encoded><![CDATA[Detect and mitigate CVE-2024-47076, CVE-2024-47175, CVE-2024-47176, and CVE-2024-47177 vulnerabilities impacting CUPS and IPP packages.]]></content:encoded>
            <author>Merav Bar</author>
            <author>Scott Piper</author>
            <enclosure url="https://www.datocms-assets.com/75231/1727628965-screenshot-2024-09-29-at-19-55-36.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[Wiz Research Finds Critical NVIDIA AI Vulnerability Affecting Containers Using NVIDIA GPUs, Including Over 35% of Cloud Environments ]]></title>
            <link>https://www.wiz.io/blog/wiz-research-critical-nvidia-ai-vulnerability</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/wiz-research-critical-nvidia-ai-vulnerability</guid>
            <pubDate>Thu, 26 Sep 2024 12:33:43 GMT</pubDate>
            <description><![CDATA[Critical severity vulnerability CVE-2024-0132 affecting NVIDIA Container Toolkit and GPU Operator presents high risk to AI workloads and environments. ]]></description>
            <content:encoded><![CDATA[Critical severity vulnerability CVE-2024-0132 affecting NVIDIA Container Toolkit and GPU Operator presents high risk to AI workloads and environments. ]]></content:encoded>
            <author>Shir Tamari</author>
            <author>Ronen Shustin</author>
            <author>Andres Riancho</author>
            <enclosure url="https://www.datocms-assets.com/75231/1727352987-nvidia-vuln-cover-option-1-final.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[Tracking cloud-fluent threat actors - Part one: Atomic cloud IOCs]]></title>
            <link>https://www.wiz.io/blog/mastering-cloud-specific-indicators-of-compromise-iocs</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/mastering-cloud-specific-indicators-of-compromise-iocs</guid>
            <pubDate>Mon, 23 Sep 2024 15:45:17 GMT</pubDate>
            <description><![CDATA[Strategies for tracking and defending against malicious activity and threats in the cloud using atomic indicators of compromise (IOCs).]]></description>
            <content:encoded><![CDATA[Strategies for tracking and defending against malicious activity and threats in the cloud using atomic indicators of compromise (IOCs).]]></content:encoded>
            <author>Merav Bar</author>
            <author>Amitai Cohen</author>
            <enclosure url="https://www.datocms-assets.com/75231/1727104052-cloud-iocs.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[Avoiding security incidents due to request collapsing ]]></title>
            <link>https://www.wiz.io/blog/preventing-risk-of-request-collapsing-in-web-caching</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/preventing-risk-of-request-collapsing-in-web-caching</guid>
            <pubDate>Tue, 03 Sep 2024 13:47:27 GMT</pubDate>
            <description><![CDATA[This feature of caching services can result in unexpected behavior. Here's how to prevent sensitive data from being accidentally exposed.]]></description>
            <content:encoded><![CDATA[This feature of caching services can result in unexpected behavior. Here's how to prevent sensitive data from being accidentally exposed.]]></content:encoded>
            <author>Scott Piper</author>
            <enclosure url="https://www.datocms-assets.com/75231/1724956608-domino-2x-8.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[Strategies for performing security migrations]]></title>
            <link>https://www.wiz.io/blog/cloud-security-migrations-best-practices</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/cloud-security-migrations-best-practices</guid>
            <pubDate>Fri, 16 Aug 2024 15:01:45 GMT</pubDate>
            <description><![CDATA[Advice for tackling and completing these major projects, including metrics, alerts, and prevention strategies.]]></description>
            <content:encoded><![CDATA[Advice for tackling and completing these major projects, including metrics, alerts, and prevention strategies.]]></content:encoded>
            <author>Scott Piper</author>
            <enclosure url="https://www.datocms-assets.com/75231/1723653356-performing-security-migrations.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[Increasing transparency in cloud security: Wiz is now a CVE Numbering Authority (CNA)]]></title>
            <link>https://www.wiz.io/blog/wiz-becomes-a-cve-numbering-authority-cna</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/wiz-becomes-a-cve-numbering-authority-cna</guid>
            <pubDate>Wed, 14 Aug 2024 13:43:30 GMT</pubDate>
            <description><![CDATA[Our next steps and hope for the industry.]]></description>
            <content:encoded><![CDATA[Our next steps and hope for the industry.]]></content:encoded>
            <author>Mitch Herckis</author>
            <author>Alon Schindel</author>
            <enclosure url="https://www.datocms-assets.com/75231/1723640745-cna-blog-cover-4.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[Emerging phishing campaign targeting AWS accounts ]]></title>
            <link>https://www.wiz.io/blog/emerging-phishing-campaign-targeting-aws-accounts</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/emerging-phishing-campaign-targeting-aws-accounts</guid>
            <pubDate>Thu, 08 Aug 2024 13:28:59 GMT</pubDate>
            <description><![CDATA[Wiz Threat Research recently spotted a new phishing campaign targeting AWS accounts.  ]]></description>
            <content:encoded><![CDATA[Wiz Threat Research recently spotted a new phishing campaign targeting AWS accounts.  ]]></content:encoded>
            <author>Gili Tikochinski</author>
            <author>Scott Piper</author>
            <enclosure url="https://www.datocms-assets.com/75231/1723122109-screenshot-2024-08-08-at-16-01-36.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[SeleniumGreed: Threat actors exploit exposed Selenium Grid services for Cryptomining]]></title>
            <link>https://www.wiz.io/blog/seleniumgreed-cryptomining-exploit-attack-flow-remediation-steps</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/seleniumgreed-cryptomining-exploit-attack-flow-remediation-steps</guid>
            <pubDate>Thu, 25 Jul 2024 14:05:39 GMT</pubDate>
            <description><![CDATA[Wiz researchers discover ongoing threat to popular testing framework.]]></description>
            <content:encoded><![CDATA[Wiz researchers discover ongoing threat to popular testing framework.]]></content:encoded>
            <author>Avigayil Mechtinger</author>
            <author>Gili Tikochinski</author>
            <author>Dor Laska</author>
            <enclosure url="https://www.datocms-assets.com/75231/1721407493-stop-copy-2-2x.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[SAPwned: SAP AI vulnerabilities expose customers’ cloud environments and private AI artifacts]]></title>
            <link>https://www.wiz.io/blog/sapwned-sap-ai-vulnerabilities-ai-security</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/sapwned-sap-ai-vulnerabilities-ai-security</guid>
            <pubDate>Wed, 17 Jul 2024 17:45:17 GMT</pubDate>
            <description><![CDATA[Wiz Research uncovers vulnerabilities in SAP AI Core, allowing malicious actors to take over the service and access customer data.]]></description>
            <content:encoded><![CDATA[Wiz Research uncovers vulnerabilities in SAP AI Core, allowing malicious actors to take over the service and access customer data.]]></content:encoded>
            <author>Hillai Ben-Sasson</author>
            <enclosure url="https://www.datocms-assets.com/75231/1721220504-sap-ai-core-blog3-1.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[RCE vulnerability in OpenSSH: everything you need to know ]]></title>
            <link>https://www.wiz.io/blog/cve-2024-6387-critical-rce-openssh</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/cve-2024-6387-critical-rce-openssh</guid>
            <pubDate>Mon, 01 Jul 2024 13:49:17 GMT</pubDate>
            <description><![CDATA[Detect and mitigate CVE-2024-6387, a remote code execution vulnerability in OpenSSH. Organizations are advised to patch urgently. ]]></description>
            <content:encoded><![CDATA[Detect and mitigate CVE-2024-6387, a remote code execution vulnerability in OpenSSH. Organizations are advised to patch urgently. ]]></content:encoded>
            <author>Amitai Cohen</author>
            <author>Gili Tikochinski</author>
            <author>Merav Bar</author>
            <author>Danielle Aminov</author>
            <enclosure url="https://www.datocms-assets.com/75231/1719841024-screenshot-2024-07-01-at-16-36-42.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[Probllama: Ollama Remote Code Execution Vulnerability (CVE-2024-37032) – Overview and Mitigations]]></title>
            <link>https://www.wiz.io/blog/probllama-ollama-vulnerability-cve-2024-37032</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/probllama-ollama-vulnerability-cve-2024-37032</guid>
            <pubDate>Mon, 24 Jun 2024 13:09:04 GMT</pubDate>
            <description><![CDATA[Wiz Research discovered CVE-2024-37032, an easy-to-exploit Remote Code Execution vulnerability in the open-source AI Infrastructure project Ollama. ]]></description>
            <content:encoded><![CDATA[Wiz Research discovered CVE-2024-37032, an easy-to-exploit Remote Code Execution vulnerability in the open-source AI Infrastructure project Ollama. ]]></content:encoded>
            <author>Sagi Tzadik</author>
            <enclosure url="https://www.datocms-assets.com/75231/1719175008-threat-template_v04-1-4.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[Critical RCE vulnerability in PHP CGI: everything you need to know ]]></title>
            <link>https://www.wiz.io/blog/critical-rce-php-cgi-vulnerability</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/critical-rce-php-cgi-vulnerability</guid>
            <pubDate>Mon, 10 Jun 2024 17:08:03 GMT</pubDate>
            <description><![CDATA[Detect and mitigate CVE-2024-4577, a critical remote code execution vulnerability in PHP CGI. Organizations are advised to patch urgently. ]]></description>
            <content:encoded><![CDATA[Detect and mitigate CVE-2024-4577, a critical remote code execution vulnerability in PHP CGI. Organizations are advised to patch urgently. ]]></content:encoded>
            <author>Merav Bar</author>
            <enclosure url="https://www.datocms-assets.com/75231/1718037728-screenshot-2024-06-10-at-19-41-28.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[Pause off my cluster: DERO cryptojacking takes a new shape]]></title>
            <link>https://www.wiz.io/blog/dero-cryptojacking-campaign-adapts-to-evade-detection</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/dero-cryptojacking-campaign-adapts-to-evade-detection</guid>
            <pubDate>Fri, 07 Jun 2024 12:04:51 GMT</pubDate>
            <description><![CDATA[Learn how the threat actors behind the 2023 DERO cryptojacking campaign have adapted their techniques to evade detection, and the best practices for mitigation.]]></description>
            <content:encoded><![CDATA[Learn how the threat actors behind the 2023 DERO cryptojacking campaign have adapted their techniques to evade detection, and the best practices for mitigation.]]></content:encoded>
            <author>Avigayil Mechtinger</author>
            <author>Shay Berkovich</author>
            <author>Gili Tikochinski</author>
            <enclosure url="https://www.datocms-assets.com/75231/1717731215-stop-copy-2x.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[The risk in malicious AI models: Wiz Research discovers critical vulnerability in AI-as-a-Service provider, Replicate]]></title>
            <link>https://www.wiz.io/blog/wiz-research-discovers-critical-vulnerability-in-replicate</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/wiz-research-discovers-critical-vulnerability-in-replicate</guid>
            <pubDate>Thu, 23 May 2024 13:58:31 GMT</pubDate>
            <description><![CDATA[The Wiz Research team's investigations into AI-as-a-service providers reveals a major risk to AI systems. ]]></description>
            <content:encoded><![CDATA[The Wiz Research team's investigations into AI-as-a-service providers reveals a major risk to AI systems. ]]></content:encoded>
            <author>Shir Tamari</author>
            <author>Sagi Tzadik</author>
            <enclosure url="https://www.datocms-assets.com/75231/1716469438-replicate_blog.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[CVE-2024-4040 exploited in the wild: everything you need to know]]></title>
            <link>https://www.wiz.io/blog/crushftp-vfs-sandbox-vulnerability</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/crushftp-vfs-sandbox-vulnerability</guid>
            <pubDate>Wed, 24 Apr 2024 16:15:18 GMT</pubDate>
            <description><![CDATA[Detect and mitigate CVE-2024-4040, a critical vulnerability in CrushFTP exploited in the wild. Organizations should patch urgently. ]]></description>
            <content:encoded><![CDATA[Detect and mitigate CVE-2024-4040, a critical vulnerability in CrushFTP exploited in the wild. Organizations should patch urgently. ]]></content:encoded>
            <author>Merav Bar</author>
            <author>Gili Tikochinski</author>
            <enclosure url="https://www.datocms-assets.com/75231/1713974994-critical-0-day-vulnerability-in-crushftp.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[Wiz Research finds architecture risks that may compromise AI-as-a-Service providers and consequently risk customer data; works with Hugging Face on mitigations]]></title>
            <link>https://www.wiz.io/blog/wiz-and-hugging-face-address-risks-to-ai-infrastructure</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/wiz-and-hugging-face-address-risks-to-ai-infrastructure</guid>
            <pubDate>Thu, 04 Apr 2024 15:55:05 GMT</pubDate>
            <description><![CDATA[Wiz researchers discovered architecture risks that may compromise AI-as-a-Service providers and put customer data at risk. Wiz and Hugging Face worked together to mitigate the issue.]]></description>
            <content:encoded><![CDATA[Wiz researchers discovered architecture risks that may compromise AI-as-a-Service providers and put customer data at risk. Wiz and Hugging Face worked together to mitigate the issue.]]></content:encoded>
            <author>Shir Tamari</author>
            <author>Sagi Tzadik</author>
            <enclosure url="https://www.datocms-assets.com/75231/1712239454-hugging-face-research-blog-cover.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[Backdoor in XZ Utils allows RCE: everything you need to know]]></title>
            <link>https://www.wiz.io/blog/cve-2024-3094-critical-rce-vulnerability-found-in-xz-utils</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/cve-2024-3094-critical-rce-vulnerability-found-in-xz-utils</guid>
            <pubDate>Fri, 29 Mar 2024 22:02:58 GMT</pubDate>
            <description><![CDATA[Detect and mitigate CVE-2024-3094, a critical supply chain compromise, affecting XZ Utils Data compression library. Organizations should patch urgently. ]]></description>
            <content:encoded><![CDATA[Detect and mitigate CVE-2024-3094, a critical supply chain compromise, affecting XZ Utils Data compression library. Organizations should patch urgently. ]]></content:encoded>
            <author>Merav Bar</author>
            <author>Amitai Cohen</author>
            <author>Danielle Aminov</author>
            <enclosure url="https://www.datocms-assets.com/75231/1711749237-screenshot-2024-03-30-at-0-53-44.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[NamespaceHound: protecting multi-tenant K8s clusters  ]]></title>
            <link>https://www.wiz.io/blog/introducing-namespacehound-for-cross-tenant-violation-assessments</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/introducing-namespacehound-for-cross-tenant-violation-assessments</guid>
            <pubDate>Wed, 13 Mar 2024 17:57:49 GMT</pubDate>
            <description><![CDATA[NamespaceHound is an open-source tool for detecting the risk of potential namespace crossing violations and anonymous access opportunities in multi-tenant clusters. ]]></description>
            <content:encoded><![CDATA[NamespaceHound is an open-source tool for detecting the risk of potential namespace crossing violations and anonymous access opportunities in multi-tenant clusters. ]]></content:encoded>
            <author>Shay Berkovich</author>
            <author>Megan Moore</author>
            <enclosure url="https://www.datocms-assets.com/75231/1710347402-namespace-hound.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[Authentication bypass vulnerabilities in TeamCity: everything you need to know ]]></title>
            <link>https://www.wiz.io/blog/jetbrains-teamcity-authentication-bypass-vulnerabilities-cve-2024-27198-cve-2024-27199</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/jetbrains-teamcity-authentication-bypass-vulnerabilities-cve-2024-27198-cve-2024-27199</guid>
            <pubDate>Wed, 06 Mar 2024 16:49:16 GMT</pubDate>
            <description><![CDATA[Detect and mitigate CVE-2024-27198 (CVSS score: 9.8) and CVE-2024-27199 (CVSS score: 7.3), authentication bypass vulnerabilities in JetBrains TeamCity.  ]]></description>
            <content:encoded><![CDATA[Detect and mitigate CVE-2024-27198 (CVSS score: 9.8) and CVE-2024-27199 (CVSS score: 7.3), authentication bypass vulnerabilities in JetBrains TeamCity.  ]]></content:encoded>
            <author>Merav Bar</author>
            <author>Gili Tikochinski</author>
            <enclosure url="https://www.datocms-assets.com/75231/1709742131-teamcity-authentication-bypass-vulnerabilities.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[Proof of storage crypto miners]]></title>
            <link>https://www.wiz.io/blog/chia-and-the-dangers-of-proof-of-storage-cryptojacking-in-the-cloud</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/chia-and-the-dangers-of-proof-of-storage-cryptojacking-in-the-cloud</guid>
            <pubDate>Wed, 21 Feb 2024 16:30:02 GMT</pubDate>
            <description><![CDATA[We explore “proof-of-storage" cryptocurrencies like Chia, the potential for proof-of-storage cryptojacking attacks, and steps defenders can take to detect them. ]]></description>
            <content:encoded><![CDATA[We explore “proof-of-storage" cryptocurrencies like Chia, the potential for proof-of-storage cryptojacking attacks, and steps defenders can take to detect them. ]]></content:encoded>
            <author>Scott Piper</author>
            <enclosure url="https://www.datocms-assets.com/75231/1708527170-coins-2x.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[February Fortinet Advisory: everything you need to know ]]></title>
            <link>https://www.wiz.io/blog/critical-rce-vulnerabilities-in-fortios-cve-2024-21762-cve-2024-23113</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/critical-rce-vulnerabilities-in-fortios-cve-2024-21762-cve-2024-23113</guid>
            <pubDate>Mon, 12 Feb 2024 13:53:10 GMT</pubDate>
            <description><![CDATA[Fortinet offers guidance to detect and mitigate CVE-2024-21762 and CVE-2024-23113, critical RCE vulnerabilities in FortiOS and FortiProxy, including guidance that organizations should patch urgently. ]]></description>
            <content:encoded><![CDATA[Fortinet offers guidance to detect and mitigate CVE-2024-21762 and CVE-2024-23113, critical RCE vulnerabilities in FortiOS and FortiProxy, including guidance that organizations should patch urgently. ]]></content:encoded>
            <author>Amitai Cohen</author>
            <author>Merav Bar</author>
            <enclosure url="https://www.datocms-assets.com/75231/1707741796-fortios-vulnerabilities-exploited-in-the-wild.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[New attack vectors in EKS]]></title>
            <link>https://www.wiz.io/blog/new-attack-vectors-emerge-via-recent-eks-access-entries-and-pod-identity-features</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/new-attack-vectors-emerge-via-recent-eks-access-entries-and-pod-identity-features</guid>
            <pubDate>Fri, 09 Feb 2024 19:10:22 GMT</pubDate>
            <description><![CDATA[We explore how advancements in EKS Access Entries and Pod Identity have opened new attack vectors and offer examples of how adversaries could exploit them. ]]></description>
            <content:encoded><![CDATA[We explore how advancements in EKS Access Entries and Pod Identity have opened new attack vectors and offer examples of how adversaries could exploit them. ]]></content:encoded>
            <author>Shay Berkovich</author>
            <author>Lior Sonntag</author>
            <enclosure url="https://www.datocms-assets.com/75231/1707486451-new_attack_vectors_eks1.jpeg" length="0" type="image/jpeg"/>
        </item>
        <item>
            <title><![CDATA[Midnight Blizzard attack on Microsoft corporate environment: a detailed analysis, detections and recommendations  ]]></title>
            <link>https://www.wiz.io/blog/midnight-blizzard-microsoft-breach-analysis-and-best-practices</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/midnight-blizzard-microsoft-breach-analysis-and-best-practices</guid>
            <pubDate>Thu, 08 Feb 2024 18:00:03 GMT</pubDate>
            <description><![CDATA[Get a detailed analysis of the entire attack chain of Microsoft's breach by Midnight Blizzard (APT29), as well as detection and mitigation recommendations. ]]></description>
            <content:encoded><![CDATA[Get a detailed analysis of the entire attack chain of Microsoft's breach by Midnight Blizzard (APT29), as well as detection and mitigation recommendations. ]]></content:encoded>
            <author>Lior Sonntag</author>
            <enclosure url="https://www.datocms-assets.com/75231/1707410425-ai-copy-5-2x-3.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[New EKS Access Management and Pod Identity features: a security analysis ]]></title>
            <link>https://www.wiz.io/blog/eks-cluster-access-management-and-pod-identity-security-recommendations</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/eks-cluster-access-management-and-pod-identity-security-recommendations</guid>
            <pubDate>Tue, 06 Feb 2024 17:19:13 GMT</pubDate>
            <description><![CDATA[The Wiz research team unpacks the security implications of the new EKS access and identity management features and recommends best practices when using them.]]></description>
            <content:encoded><![CDATA[The Wiz research team unpacks the security implications of the new EKS access and identity management features and recommends best practices when using them.]]></content:encoded>
            <author>Shay Berkovich</author>
            <enclosure url="https://www.datocms-assets.com/75231/1707228055-new_eks_blogcover.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[Critical Vulnerabilities in Ivanti Exploited in-the-Wild: everything you need to know]]></title>
            <link>https://www.wiz.io/blog/ivanti-vulnerabilities-cve-2023-46805-cve-2024-21887-cve-2024-21888-and-cve-2024-21893</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/ivanti-vulnerabilities-cve-2023-46805-cve-2024-21887-cve-2024-21888-and-cve-2024-21893</guid>
            <pubDate>Tue, 06 Feb 2024 16:06:48 GMT</pubDate>
            <description><![CDATA[Detect and mitigate CVE-2023-46805, CVE-2024-21887, CVE-2024-21888 and CVE-2024-21893, critical vulnerabilities in Ivanti VPN products. Organizations should patch urgently, and government agencies are instructed to isolate Ivanti VPN instances.]]></description>
            <content:encoded><![CDATA[Detect and mitigate CVE-2023-46805, CVE-2024-21887, CVE-2024-21888 and CVE-2024-21893, critical vulnerabilities in Ivanti VPN products. Organizations should patch urgently, and government agencies are instructed to isolate Ivanti VPN instances.]]></content:encoded>
            <author>Merav Bar</author>
            <author>Amitai Cohen</author>
            <enclosure url="https://www.datocms-assets.com/75231/1707233304-ivanti-vulnerabilities-exploited-in-the-wild.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[Leaky Vessels: runC and BuildKit container escape vulnerabilities - everything you need to know ]]></title>
            <link>https://www.wiz.io/blog/leaky-vessels-container-escape-vulnerabilities</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/leaky-vessels-container-escape-vulnerabilities</guid>
            <pubDate>Mon, 05 Feb 2024 17:28:28 GMT</pubDate>
            <description><![CDATA[Detect and mitigate “Leaky Vessels”, container escape vulnerabilities affecting runC and BuildKit. Learn how to prioritize patching and detect exploitation attempts in runtime.]]></description>
            <content:encoded><![CDATA[Detect and mitigate “Leaky Vessels”, container escape vulnerabilities affecting runC and BuildKit. Learn how to prioritize patching and detect exploitation attempts in runtime.]]></content:encoded>
            <author>Merav Bar</author>
            <author>Amitai Cohen</author>
            <author>Itamar Gilad</author>
            <enclosure url="https://www.datocms-assets.com/75231/1707151043-image-7.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[5 Surprising facts from the Cloud Security Salary Guide]]></title>
            <link>https://www.wiz.io/blog/5-facts-from-the-cybersecurity-compensation-report</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/5-facts-from-the-cybersecurity-compensation-report</guid>
            <pubDate>Mon, 29 Jan 2024 16:15:30 GMT</pubDate>
            <description><![CDATA[Wiz is releasing a new report providing insight into various jobs in the field of cloud security and compensation packages they offer; here are 5 key facts from our data.]]></description>
            <content:encoded><![CDATA[Wiz is releasing a new report providing insight into various jobs in the field of cloud security and compensation packages they offer; here are 5 key facts from our data.]]></content:encoded>
            <author>Wiz Team</author>
            <enclosure url="https://www.datocms-assets.com/75231/1706543790-salary_guide_cover.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[Announcing the Release of "Kubernetes Security for Dummies" ]]></title>
            <link>https://www.wiz.io/blog/kubernetes-security-for-dummies</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/kubernetes-security-for-dummies</guid>
            <pubDate>Thu, 25 Jan 2024 14:14:24 GMT</pubDate>
            <description><![CDATA[We're excited to announce the release of a comprehensive guide to mastering Kubernetes security: "Kubernetes Security for Dummies." Wiz collaborated with Wiley publications to create this essential resource, which covers various aspects of securing Kubernetes environments.  ]]></description>
            <content:encoded><![CDATA[We're excited to announce the release of a comprehensive guide to mastering Kubernetes security: "Kubernetes Security for Dummies." Wiz collaborated with Wiley publications to create this essential resource, which covers various aspects of securing Kubernetes environments.  ]]></content:encoded>
            <author>Wiz Team</author>
            <enclosure url="https://www.datocms-assets.com/75231/1706191630-k8s_for_dummies_banner.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[Introducing the Cloud Threat Landscape, a new TI resource for cloud defenders]]></title>
            <link>https://www.wiz.io/blog/introducing-the-cloud-threat-landscape</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/introducing-the-cloud-threat-landscape</guid>
            <pubDate>Wed, 24 Jan 2024 15:28:30 GMT</pubDate>
            <description><![CDATA[The Cloud Threat Landscape is a threat intelligence database that summarizes cloud incidents and offers insights into targeting patterns and initial access methods. ]]></description>
            <content:encoded><![CDATA[The Cloud Threat Landscape is a threat intelligence database that summarizes cloud incidents and offers insights into targeting patterns and initial access methods. ]]></content:encoded>
            <author>Amitai Cohen</author>
            <author>Alon Schindel</author>
            <enclosure url="https://www.datocms-assets.com/75231/1706108817-incidents-cloud-cover-02.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[Wiz Research presents its latest report: “State of AI in the Cloud 2024” ]]></title>
            <link>https://www.wiz.io/blog/key-findings-from-the-state-of-ai-in-the-cloud-report-2024</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/key-findings-from-the-state-of-ai-in-the-cloud-report-2024</guid>
            <pubDate>Wed, 17 Jan 2024 16:00:28 GMT</pubDate>
            <description><![CDATA[Get a sneak peek at the Wiz research team’s new report examining key observations about AI use in the cloud. ]]></description>
            <content:encoded><![CDATA[Get a sneak peek at the Wiz research team’s new report examining key observations about AI use in the cloud. ]]></content:encoded>
            <author>Amitai Cohen</author>
            <author>Megan Moore</author>
            <enclosure url="https://www.datocms-assets.com/75231/1705503365-state-of-ai-blog-cover.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[Crying out Cloud – Our Favorite Stories of 2023 ]]></title>
            <link>https://www.wiz.io/blog/crying-out-cloud-favorite-stories-of-2023</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/crying-out-cloud-favorite-stories-of-2023</guid>
            <pubDate>Tue, 16 Jan 2024 17:21:03 GMT</pubDate>
            <description><![CDATA[Each member of the Crying out Cloud team at Wiz shares their top stories from the past year ]]></description>
            <content:encoded><![CDATA[Each member of the Crying out Cloud team at Wiz shares their top stories from the past year ]]></content:encoded>
            <author>Amitai Cohen</author>
            <author>Merav Bar</author>
            <author>Eden Naftali</author>
            <enclosure url="https://www.datocms-assets.com/75231/1705421253-croc2023.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[Key takeaways from the Wiz 2023 Kubernetes Security Report]]></title>
            <link>https://www.wiz.io/blog/key-takeaways-from-the-wiz-2023-kubernetes-security-report</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/key-takeaways-from-the-wiz-2023-kubernetes-security-report</guid>
            <pubDate>Wed, 08 Nov 2023 16:37:49 GMT</pubDate>
            <description><![CDATA[Today, Wiz published its 2023 Kubernetes Security Report. Here are some key takeaways.]]></description>
            <content:encoded><![CDATA[Today, Wiz published its 2023 Kubernetes Security Report. Here are some key takeaways.]]></content:encoded>
            <author>Shay Berkovich</author>
            <author>Rotem Zarin</author>
            <enclosure url="https://www.datocms-assets.com/75231/1699451961-k8s-report-blog-cover.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[Eight questions to measure vulnerability remediation "pain" ]]></title>
            <link>https://www.wiz.io/blog/eight-questions-to-measure-vulnerability-remediation-pain</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/eight-questions-to-measure-vulnerability-remediation-pain</guid>
            <pubDate>Fri, 03 Nov 2023 13:07:46 GMT</pubDate>
            <description><![CDATA[What is it about certain vulnerabilities that makes them especially hard to deal with, and how can vendors make things easier for security teams? ]]></description>
            <content:encoded><![CDATA[What is it about certain vulnerabilities that makes them especially hard to deal with, and how can vendors make things easier for security teams? ]]></content:encoded>
            <author>Amitai Cohen</author>
            <enclosure url="https://www.datocms-assets.com/75231/1699016361-remediation-pain-header.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[Announcing the EKS Cluster Games]]></title>
            <link>https://www.wiz.io/blog/announcing-the-eks-cluster-games</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/announcing-the-eks-cluster-games</guid>
            <pubDate>Wed, 01 Nov 2023 15:29:42 GMT</pubDate>
            <description><![CDATA[Test your investigation skills and K8s knowledge in a new Wiz-sponsored CTF event: the EKS Cluster Games!]]></description>
            <content:encoded><![CDATA[Test your investigation skills and K8s knowledge in a new Wiz-sponsored CTF event: the EKS Cluster Games!]]></content:encoded>
            <author>Nir Ohfeld</author>
            <author>Ronen Shustin</author>
            <enclosure url="https://www.datocms-assets.com/75231/1698666309-eks-challenge-logos_2-01.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[CVE-2023-38545 high severity vulnerability in cURL: everything you need to know ]]></title>
            <link>https://www.wiz.io/blog/cve-2023-38545-curl-vulnerability</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/cve-2023-38545-curl-vulnerability</guid>
            <pubDate>Wed, 11 Oct 2023 16:56:35 GMT</pubDate>
            <description><![CDATA[Detect and mitigate CVE-2023-38545, a high severity buffer overflow vulnerability in cURL. Organizations should upgrade to the patched version. ]]></description>
            <content:encoded><![CDATA[Detect and mitigate CVE-2023-38545, a high severity buffer overflow vulnerability in cURL. Organizations should upgrade to the patched version. ]]></content:encoded>
            <author>Merav Bar</author>
            <author>Sagi Tzadik</author>
            <enclosure url="https://www.datocms-assets.com/75231/1697043062-curl-vulnerability.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[The good, the bad, and the vulnerable]]></title>
            <link>https://www.wiz.io/blog/the-good-the-bad-and-the-vulnerable-summary</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/the-good-the-bad-and-the-vulnerable-summary</guid>
            <pubDate>Tue, 10 Oct 2023 13:37:20 GMT</pubDate>
            <description><![CDATA[Get the tl;dr on Wiz's methodology for cloud vulnerability triage in our new report, "The good, the bad, and the vulnerable." ]]></description>
            <content:encoded><![CDATA[Get the tl;dr on Wiz's methodology for cloud vulnerability triage in our new report, "The good, the bad, and the vulnerable." ]]></content:encoded>
            <author>Merav Bar</author>
            <author>Amitai Cohen</author>
            <enclosure url="https://www.datocms-assets.com/75231/1696894917-flag-copy-2x.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[Critical and high severity Exim vulnerabilities: everything you need to know]]></title>
            <link>https://www.wiz.io/blog/exim-zero-day-vulnerabilities</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/exim-zero-day-vulnerabilities</guid>
            <pubDate>Mon, 02 Oct 2023 13:53:02 GMT</pubDate>
            <description><![CDATA[Detect and mitigate CVE-2023-42115, and 5 more vulnerabilities in Exim. Organizations using affected configurations should mitigate and patch the vulnerabilities urgently. ]]></description>
            <content:encoded><![CDATA[Detect and mitigate CVE-2023-42115, and 5 more vulnerabilities in Exim. Organizations using affected configurations should mitigate and patch the vulnerabilities urgently. ]]></content:encoded>
            <author>Merav Bar</author>
            <enclosure url="https://www.datocms-assets.com/75231/1696253915-critical-exim-vulnerabilities2.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[Critical vulnerabilities in media libraries exploited in the wild: everything you need to know]]></title>
            <link>https://www.wiz.io/blog/cve-2023-4863-and-cve-2023-5217-exploited-in-the-wild</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/cve-2023-4863-and-cve-2023-5217-exploited-in-the-wild</guid>
            <pubDate>Sun, 01 Oct 2023 13:31:06 GMT</pubDate>
            <description><![CDATA[Delving into CVE-2023-4863 and CVE-2023-5217 - critical vulnerabilities in libwebp and libvpx exploited in the wild. ]]></description>
            <content:encoded><![CDATA[Delving into CVE-2023-4863 and CVE-2023-5217 - critical vulnerabilities in libwebp and libvpx exploited in the wild. ]]></content:encoded>
            <author>Merav Bar</author>
            <author>Amitai Cohen</author>
            <enclosure url="https://www.datocms-assets.com/75231/1696165198-critical-webp-vulnerability.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[38TB of data accidentally exposed by Microsoft AI researchers ]]></title>
            <link>https://www.wiz.io/blog/38-terabytes-of-private-data-accidentally-exposed-by-microsoft-ai-researchers</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/38-terabytes-of-private-data-accidentally-exposed-by-microsoft-ai-researchers</guid>
            <pubDate>Mon, 18 Sep 2023 13:01:29 GMT</pubDate>
            <description><![CDATA[Wiz Research found a data exposure incident on Microsoft’s AI GitHub repository, including over 30,000 internal Microsoft Teams messages – all caused by one misconfigured SAS token ]]></description>
            <content:encoded><![CDATA[Wiz Research found a data exposure incident on Microsoft’s AI GitHub repository, including over 30,000 internal Microsoft Teams messages – all caused by one misconfigured SAS token ]]></content:encoded>
            <author>Hillai Ben-Sasson</author>
            <author> Ronny Greenberg</author>
            <enclosure url="https://www.datocms-assets.com/75231/1695038585-azure_sas.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[Storm-0558 Update: Takeaways from Microsoft's recent report]]></title>
            <link>https://www.wiz.io/blog/key-takeaways-from-microsofts-latest-storm-0558-report</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/key-takeaways-from-microsofts-latest-storm-0558-report</guid>
            <pubDate>Thu, 07 Sep 2023 19:42:14 GMT</pubDate>
            <description><![CDATA[The Wiz research team examines Microsoft's latest Storm-0558 findings and summarizes the key learnings cloud customers should take away from the incident.]]></description>
            <content:encoded><![CDATA[The Wiz research team examines Microsoft's latest Storm-0558 findings and summarizes the key learnings cloud customers should take away from the incident.]]></content:encoded>
            <author>Amitai Cohen</author>
            <enclosure url="https://www.datocms-assets.com/75231/1694113503-wiz_research_compromised_key.webp" length="0" type="image/webp"/>
        </item>
        <item>
            <title><![CDATA[I know what you mined last summer: summarizing Summer '23 cryptomining activity]]></title>
            <link>https://www.wiz.io/blog/cryptojacking-attacks-summer-2023</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/cryptojacking-attacks-summer-2023</guid>
            <pubDate>Wed, 06 Sep 2023 13:49:59 GMT</pubDate>
            <description><![CDATA[During the summer of 2023, using the Wiz Sensor, Wiz Research detected several different cryptomining campaigns targeting cloud workloads. Learn about these campaigns and their associated IoCs, and how to detect and prevent similar threats.]]></description>
            <content:encoded><![CDATA[During the summer of 2023, using the Wiz Sensor, Wiz Research detected several different cryptomining campaigns targeting cloud workloads. Learn about these campaigns and their associated IoCs, and how to detect and prevent similar threats.]]></content:encoded>
            <author>Avigayil Mechtinger</author>
            <enclosure url="https://www.datocms-assets.com/75231/1694002349-image.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[GameOver(lay): Easy-to-exploit local privilege escalation vulnerabilities in Ubuntu Linux affect 40% of Ubuntu cloud workloads]]></title>
            <link>https://www.wiz.io/blog/ubuntu-overlayfs-vulnerability</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/ubuntu-overlayfs-vulnerability</guid>
            <pubDate>Thu, 27 Jul 2023 19:33:45 GMT</pubDate>
            <description><![CDATA[Wiz Research discovered CVE-2023-2640 and CVE-2023-32629, two easy-to-exploit privilege escalation vulnerabilities in the OverlayFS module in Ubuntu affecting 40% of Ubuntu cloud workloads.]]></description>
            <content:encoded><![CDATA[Wiz Research discovered CVE-2023-2640 and CVE-2023-32629, two easy-to-exploit privilege escalation vulnerabilities in the OverlayFS module in Ubuntu affecting 40% of Ubuntu cloud workloads.]]></content:encoded>
            <author>Sagi Tzadik</author>
            <author>Shir Tamari</author>
            <enclosure url="https://www.datocms-assets.com/75231/1690461216-gameoverly.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[ Zenbleed: cross-process infoleak vulnerability in AMD Zen 2 Processors - everything you need to know ]]></title>
            <link>https://www.wiz.io/blog/zenbleed</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/zenbleed</guid>
            <pubDate>Wed, 26 Jul 2023 19:35:06 GMT</pubDate>
            <description><![CDATA[Learn about the impact in cloud environments of CVE-2023-20593, a cross-process information leak vulnerability in AMD Zen 2 Processors.  ]]></description>
            <content:encoded><![CDATA[Learn about the impact in cloud environments of CVE-2023-20593, a cross-process information leak vulnerability in AMD Zen 2 Processors.  ]]></content:encoded>
            <author>Amitai Cohen</author>
            <author>Scott Piper</author>
            <author>Merav Bar</author>
            <enclosure url="https://www.datocms-assets.com/75231/1690401069-image002.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[Top 16 cloud security experts you should follow in 2023]]></title>
            <link>https://www.wiz.io/blog/top-16-cloud-security-experts-you-should-follow-in-2023</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/top-16-cloud-security-experts-you-should-follow-in-2023</guid>
            <pubDate>Tue, 25 Jul 2023 14:09:42 GMT</pubDate>
            <description><![CDATA[Handpicked by our research team: The annual list of 16 thought leaders you need on your feed.]]></description>
            <content:encoded><![CDATA[Handpicked by our research team: The annual list of 16 thought leaders you need on your feed.]]></content:encoded>
            <author>Wiz Team</author>
            <enclosure url="https://www.datocms-assets.com/75231/1690197420-flag2x.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[Compromised Microsoft Key: More Impactful Than We Thought]]></title>
            <link>https://www.wiz.io/blog/storm-0558-compromised-microsoft-key-enables-authentication-of-countless-micr</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/storm-0558-compromised-microsoft-key-enables-authentication-of-countless-micr</guid>
            <pubDate>Fri, 21 Jul 2023 14:01:28 GMT</pubDate>
            <description><![CDATA[Our investigation of the security incident disclosed by Microsoft and CISA and attributed to Chinese threat actor Storm-0558, found that this incident seems to have a broader scope than originally assumed. Organizations using Microsoft and Azure services should take steps to assess potential impact.]]></description>
            <content:encoded><![CDATA[Our investigation of the security incident disclosed by Microsoft and CISA and attributed to Chinese threat actor Storm-0558, found that this incident seems to have a broader scope than originally assumed. Organizations using Microsoft and Azure services should take steps to assess potential impact.]]></content:encoded>
            <author>Shir Tamari</author>
            <enclosure url="https://www.datocms-assets.com/75231/1689885318-research_blog_post_cover.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[Kubernetes API limitations in finding non-standard pods and containers]]></title>
            <link>https://www.wiz.io/blog/kubernetes-api-limitations-in-finding-non-standard-pods-and-containers</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/kubernetes-api-limitations-in-finding-non-standard-pods-and-containers</guid>
            <pubDate>Wed, 19 Jul 2023 14:23:29 GMT</pubDate>
            <description><![CDATA[Gain a deeper understanding of why it's essential to monitor non-standard pods and containers, including static pods, mirror pods, init containers, pause containers, and ephemeral containers within your Kubernetes environment.]]></description>
            <content:encoded><![CDATA[Gain a deeper understanding of why it's essential to monitor non-standard pods and containers, including static pods, mirror pods, init containers, pause containers, and ephemeral containers within your Kubernetes environment.]]></content:encoded>
            <author>Oren Ofer</author>
            <enclosure url="https://www.datocms-assets.com/75231/1689754330-unusualpodscontainers_v3_compressed.gif" length="0" type="image/gif"/>
        </item>
        <item>
            <title><![CDATA[PyLoose: Python-based fileless malware targets cloud workloads to deliver cryptominer]]></title>
            <link>https://www.wiz.io/blog/pyloose-first-python-based-fileless-attack-on-cloud-workloads</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/pyloose-first-python-based-fileless-attack-on-cloud-workloads</guid>
            <pubDate>Tue, 11 Jul 2023 13:39:41 GMT</pubDate>
            <description><![CDATA[PyLoose is a newly discovered Python-based fileless malware targeting cloud workloads. Get a breakdown of how the attack unfolds and the steps to mitigate it.]]></description>
            <content:encoded><![CDATA[PyLoose is a newly discovered Python-based fileless malware targeting cloud workloads. Get a breakdown of how the attack unfolds and the steps to mitigate it.]]></content:encoded>
            <author>Avigayil Mechtinger</author>
            <author>Oren Ofer</author>
            <author>Itamar Gilad</author>
            <enclosure url="https://www.datocms-assets.com/75231/1689079150-pyloose-blog.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[Linux rootkits explained – Part 1: Dynamic linker hijacking]]></title>
            <link>https://www.wiz.io/blog/linux-rootkits-explained-part-1-dynamic-linker-hijacking</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/linux-rootkits-explained-part-1-dynamic-linker-hijacking</guid>
            <pubDate>Wed, 05 Jul 2023 13:34:27 GMT</pubDate>
            <description><![CDATA[Dynamic linker hijacking via LD_PRELOAD is a Linux rootkit technique utilized by different threat actors in the wild. In part one of this series on Linux rootkits, we discuss this threat and explain how to detect it.]]></description>
            <content:encoded><![CDATA[Dynamic linker hijacking via LD_PRELOAD is a Linux rootkit technique utilized by different threat actors in the wild. In part one of this series on Linux rootkits, we discuss this threat and explain how to detect it.]]></content:encoded>
            <author>Avigayil Mechtinger</author>
            <enclosure url="https://www.datocms-assets.com/75231/1688552904-linux.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[How to get rid of AWS access keys – Part 2: Reducing Privileges ]]></title>
            <link>https://www.wiz.io/blog/how-to-get-rid-of-aws-access-keys-part-2</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/how-to-get-rid-of-aws-access-keys-part-2</guid>
            <pubDate>Thu, 29 Jun 2023 15:11:12 GMT</pubDate>
            <description><![CDATA[In the previous post in this series, we discussed how to do some basic cleaning of AWS access keys. In this post, we’ll show how to reduce the privileges in order to mitigate their risk. ]]></description>
            <content:encoded><![CDATA[In the previous post in this series, we discussed how to do some basic cleaning of AWS access keys. In this post, we’ll show how to reduce the privileges in order to mitigate their risk. ]]></content:encoded>
            <author>Scott Piper</author>
            <enclosure url="https://www.datocms-assets.com/75231/1688049301-aws-keys-1.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[How to leverage generative AI in cloud apps without putting user data at risk]]></title>
            <link>https://www.wiz.io/blog/genai-tenant-isolation</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/genai-tenant-isolation</guid>
            <pubDate>Wed, 28 Jun 2023 13:54:17 GMT</pubDate>
            <description><![CDATA[Learn security best practices to deploy generative AI models as part of your multi-tenant cloud applications and avoid putting your customers’ data at risk.]]></description>
            <content:encoded><![CDATA[Learn security best practices to deploy generative AI models as part of your multi-tenant cloud applications and avoid putting your customers’ data at risk.]]></content:encoded>
            <author>Amitai Cohen</author>
            <author>Barak Sharoni</author>
            <enclosure url="https://www.datocms-assets.com/75231/1687956785-ai-blog.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[Kubernetes Grey Zone: Risks in Managed Cluster Middleware]]></title>
            <link>https://www.wiz.io/blog/kubernetes-grey-zone-risks-in-managed-cluster-middleware</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/kubernetes-grey-zone-risks-in-managed-cluster-middleware</guid>
            <pubDate>Mon, 12 Jun 2023 15:42:33 GMT</pubDate>
            <description><![CDATA[Are your managed Kubernetes clusters safe from the risks posed by middleware components? Learn how to secure your clusters and mitigate middleware risks.]]></description>
            <content:encoded><![CDATA[Are your managed Kubernetes clusters safe from the risks posed by middleware components? Learn how to secure your clusters and mitigate middleware risks.]]></content:encoded>
            <author>Shay Berkovich</author>
            <enclosure url="https://www.datocms-assets.com/75231/1686570044-risks-in-managed-clusters-middleware-cover.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[Crying Out Cloud: a magical podcast for cloud security enthusiasts]]></title>
            <link>https://www.wiz.io/blog/crying-out-cloud-podcast</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/crying-out-cloud-podcast</guid>
            <pubDate>Mon, 12 Jun 2023 14:56:28 GMT</pubDate>
            <description><![CDATA[Join us for game-changing news, unique Wiz insights, and battle-tested advice from industry experts. Stay ahead of the cloud curve with our latest episodes and navigate the complex world of cloud security.]]></description>
            <content:encoded><![CDATA[Join us for game-changing news, unique Wiz insights, and battle-tested advice from industry experts. Stay ahead of the cloud curve with our latest episodes and navigate the complex world of cloud security.]]></content:encoded>
            <author>Omer Mosheiov</author>
            <enclosure url="https://www.datocms-assets.com/75231/1686572690-blogpost-1.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[The Big IAM Challenge: Test Your Cloud Security Skills]]></title>
            <link>https://www.wiz.io/blog/the-big-iam-challenge</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/the-big-iam-challenge</guid>
            <pubDate>Tue, 06 Jun 2023 17:22:05 GMT</pubDate>
            <description><![CDATA[Put yourself to the test with our unique CTF challenge and boost your AWS IAM knowledge. Do you have what it takes to win The Big IAM Challenge?]]></description>
            <content:encoded><![CDATA[Put yourself to the test with our unique CTF challenge and boost your AWS IAM knowledge. Do you have what it takes to win The Big IAM Challenge?]]></content:encoded>
            <author>Nir Ohfeld</author>
            <enclosure url="https://www.datocms-assets.com/75231/1686040003-blogpost.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[CVE-2023-34362 RCE vulnerability in MOVEit Transfer exploited in the wild: everything you need to know ]]></title>
            <link>https://www.wiz.io/blog/cve-2023-34362</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/cve-2023-34362</guid>
            <pubDate>Sun, 04 Jun 2023 18:20:05 GMT</pubDate>
            <description><![CDATA[Detect and mitigate CVE-2023-34362, a remote code execution vulnerability in MOVEit Transfer exploited in the wild. Organizations should patch urgently. ]]></description>
            <content:encoded><![CDATA[Detect and mitigate CVE-2023-34362, a remote code execution vulnerability in MOVEit Transfer exploited in the wild. Organizations should patch urgently. ]]></content:encoded>
            <author>Amitai Cohen</author>
            <author>Merav Bar</author>
            <enclosure url="https://www.datocms-assets.com/75231/1685899685-image-5.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[Bridging the Security Gap: Mitigating Lateral Movement Risks from On-Premises to Cloud Environments]]></title>
            <link>https://www.wiz.io/blog/lateral-movement-risks-in-the-cloud-and-how-to-prevent-them-part-4-from-compromis</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/lateral-movement-risks-in-the-cloud-and-how-to-prevent-them-part-4-from-compromis</guid>
            <pubDate>Thu, 25 May 2023 19:20:43 GMT</pubDate>
            <description><![CDATA[This blog post will discuss lateral movement risks from on-prem to the cloud. We will explain attacker TTPs, and outline best practices for cloud builders and defenders to help secure their cloud environments and mitigate risk.]]></description>
            <content:encoded><![CDATA[This blog post will discuss lateral movement risks from on-prem to the cloud. We will explain attacker TTPs, and outline best practices for cloud builders and defenders to help secure their cloud environments and mitigate risk.]]></content:encoded>
            <author>Lior Sonntag</author>
            <enclosure url="https://www.datocms-assets.com/75231/1684740611-on-prem-to-cloud-1.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Exploitable and unpatched KeePass vulnerability: everything you need to know ]]></title>
            <link>https://www.wiz.io/blog/cve-2023-32784-keepass-vulnerability-exploit-released</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/cve-2023-32784-keepass-vulnerability-exploit-released</guid>
            <pubDate>Tue, 23 May 2023 13:49:01 GMT</pubDate>
            <description><![CDATA[Detect and mitigate CVE-2023-32784, a vulnerability in KeePass which allows the extraction of the master password in cleartext from the application's memory.  ]]></description>
            <content:encoded><![CDATA[Detect and mitigate CVE-2023-32784, a vulnerability in KeePass which allows the extraction of the master password in cleartext from the application's memory.  ]]></content:encoded>
            <author>Merav Bar</author>
            <author>Amitai Cohen</author>
            <enclosure url="https://www.datocms-assets.com/75231/1684851138-keepass-vers-3.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[#BrokenSesame: Accidental ‘write’ permissions to private registry allowed potential RCE to Alibaba Cloud Database Services]]></title>
            <link>https://www.wiz.io/blog/brokensesame-accidental-write-permissions-to-private-registry-allowed-potential-r</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/brokensesame-accidental-write-permissions-to-private-registry-allowed-potential-r</guid>
            <pubDate>Wed, 19 Apr 2023 13:00:06 GMT</pubDate>
            <description><![CDATA[A container escape vulnerability, combined with accidental 'write' permissions to a private registry, opened a backdoor for Wiz Research to access Alibaba Cloud databases and potentially compromise its services through a supply-chain attack]]></description>
            <content:encoded><![CDATA[A container escape vulnerability, combined with accidental 'write' permissions to a private registry, opened a backdoor for Wiz Research to access Alibaba Cloud databases and potentially compromise its services through a supply-chain attack]]></content:encoded>
            <author>Ronen Shustin</author>
            <author>Shir Tamari</author>
            <enclosure url="https://www.datocms-assets.com/75231/1681916715-alibaba_brokensesame-16-9.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[Microsoft April 2023 Patch Tuesday Highlights: everything you need to know]]></title>
            <link>https://www.wiz.io/blog/microsoft-april-2023-patch-tuesday-highlights</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/microsoft-april-2023-patch-tuesday-highlights</guid>
            <pubDate>Thu, 13 Apr 2023 19:20:20 GMT</pubDate>
            <description><![CDATA[Detect and mitigate CVE-2023-28252, EoP vulnerability exploited in the wild, and CVE-2023-21554, a critical RCE vulnerability. Organizations should patch urgently. ]]></description>
            <content:encoded><![CDATA[Detect and mitigate CVE-2023-28252, EoP vulnerability exploited in the wild, and CVE-2023-21554, a critical RCE vulnerability. Organizations should patch urgently. ]]></content:encoded>
            <author>Merav Bar</author>
            <author>Amitai Cohen</author>
            <enclosure url="https://www.datocms-assets.com/75231/1681413599-patch-tuesday-highlights-16_9.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[Intro to forensics in the cloud: A container was compromised. What’s next?]]></title>
            <link>https://www.wiz.io/blog/intro-to-forensics-in-the-cloud-a-container-was-compromised-whats-next</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/intro-to-forensics-in-the-cloud-a-container-was-compromised-whats-next</guid>
            <pubDate>Thu, 06 Apr 2023 15:43:50 GMT</pubDate>
            <description><![CDATA[Learn what tools and data sources you need to use in cloud forensics investigation and how they come into practice in a real-life example.]]></description>
            <content:encoded><![CDATA[Learn what tools and data sources you need to use in cloud forensics investigation and how they come into practice in a real-life example.]]></content:encoded>
            <author>Avigayil Mechtinger</author>
            <enclosure url="https://www.datocms-assets.com/75231/1680708461-compromised-container_blog-cover.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[BingBang: How a simple developer mistake could have led to Bing.com takeover]]></title>
            <link>https://www.wiz.io/blog/bingbang</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/bingbang</guid>
            <pubDate>Wed, 29 Mar 2023 16:18:54 GMT</pubDate>
            <description><![CDATA[How a misconfiguration in a Microsoft Bing.com application allowed Wiz Research to modify Bing’s search results – and potentially compromise the private data of millions of Bing users]]></description>
            <content:encoded><![CDATA[How a misconfiguration in a Microsoft Bing.com application allowed Wiz Research to modify Bing’s search results – and potentially compromise the private data of millions of Bing users]]></content:encoded>
            <author>Raaz Herzberg</author>
            <author>Shir Tamari</author>
            <author>Hillai Ben-Sasson</author>
            <enclosure url="https://www.datocms-assets.com/75231/1680541711-bingbang.gif" length="0" type="image/gif"/>
        </item>
        <item>
            <title><![CDATA[BingBang: AAD misconfiguration led to Bing.com results manipulation and account takeover]]></title>
            <link>https://www.wiz.io/blog/azure-active-directory-bing-misconfiguration</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/azure-active-directory-bing-misconfiguration</guid>
            <pubDate>Wed, 29 Mar 2023 16:18:47 GMT</pubDate>
            <description><![CDATA[How Wiz Research found a common misconfiguration in Azure Active Directory that compromised multiple Microsoft applications, including a Bing management portal]]></description>
            <content:encoded><![CDATA[How Wiz Research found a common misconfiguration in Azure Active Directory that compromised multiple Microsoft applications, including a Bing management portal]]></content:encoded>
            <author>Hillai Ben-Sasson</author>
            <enclosure url="https://www.datocms-assets.com/75231/1680542287-bingbang.gif" length="0" type="image/gif"/>
        </item>
        <item>
            <title><![CDATA[Using Service Control Policies to protect security baselines ]]></title>
            <link>https://www.wiz.io/blog/using-service-control-policies-to-protect-security-baselines</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/using-service-control-policies-to-protect-security-baselines</guid>
            <pubDate>Mon, 20 Mar 2023 17:19:41 GMT</pubDate>
            <description><![CDATA[Service Control Policies (SCPs) can be a great way to prevent actions from happening in AWS accounts. In this post, we will illustrate a specific use case of SCPs that protects the security baseline, or landing zone, configuration you’ve created for accounts]]></description>
            <content:encoded><![CDATA[Service Control Policies (SCPs) can be a great way to prevent actions from happening in AWS accounts. In this post, we will illustrate a specific use case of SCPs that protects the security baseline, or landing zone, configuration you’ve created for accounts]]></content:encoded>
            <author>Scott Piper</author>
            <enclosure url="https://www.datocms-assets.com/75231/1679240261-artboard_63_copy_133x.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[CVE-2023-25610 a critical RCE vulnerability in FortiOS: everything you need to know ]]></title>
            <link>https://www.wiz.io/blog/cve-2023-25610</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/cve-2023-25610</guid>
            <pubDate>Mon, 13 Mar 2023 12:39:58 GMT</pubDate>
            <description><![CDATA[CVE-2023-25610 is a critical RCE vulnerability in FortiOS. This vulnerability is a buffer underwrite bug in the administrative interface which could allow a remote unauthenticated attacker to execute code using specially crafted requests. Affected customers should patch immediately.]]></description>
            <content:encoded><![CDATA[CVE-2023-25610 is a critical RCE vulnerability in FortiOS. This vulnerability is a buffer underwrite bug in the administrative interface which could allow a remote unauthenticated attacker to execute code using specially crafted requests. Affected customers should patch immediately.]]></content:encoded>
            <author>Merav Bar</author>
            <enclosure url="https://www.datocms-assets.com/75231/1678705517-fortios-blog-cover.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[From Pod Security Policies to Pod Security Standards – a Migration Guide]]></title>
            <link>https://www.wiz.io/blog/from-pod-security-policies-to-pod-security-standards-a-migration-guide</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/from-pod-security-policies-to-pod-security-standards-a-migration-guide</guid>
            <pubDate>Thu, 09 Mar 2023 17:27:05 GMT</pubDate>
            <description><![CDATA[Pod Security Policies were removed in Kubernetes v1.25 — learn how to migrate from Pod Security Policies to Pod Security Standards]]></description>
            <content:encoded><![CDATA[Pod Security Policies were removed in Kubernetes v1.25 — learn how to migrate from Pod Security Policies to Pod Security Standards]]></content:encoded>
            <author>Shay Berkovich</author>
            <author>Amir Lande Blau</author>
            <enclosure url="https://www.datocms-assets.com/75231/1678358574-image-12.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[Redirection Roulette: Thousands of hijacked websites in East Asia redirecting visitors to other sites]]></title>
            <link>https://www.wiz.io/blog/redirection-roulette</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/redirection-roulette</guid>
            <pubDate>Thu, 02 Mar 2023 16:20:21 GMT</pubDate>
            <description><![CDATA[Since early September 2022, tens of thousands of websites aimed at East Asian audiences have been hacked, redirecting hundreds of thousands of their users to adult-themed content.]]></description>
            <content:encoded><![CDATA[Since early September 2022, tens of thousands of websites aimed at East Asian audiences have been hacked, redirecting hundreds of thousands of their users to adult-themed content.]]></content:encoded>
            <author>Amitai Cohen</author>
            <author>Barak Sharoni</author>
            <enclosure url="https://www.datocms-assets.com/75231/1677773083-redirection_roulette_logo.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[Lateral movement risks in the cloud and how to prevent them – Part 3: from compromised cloud resource to Kubernetes cluster takeover]]></title>
            <link>https://www.wiz.io/blog/lateral-movement-risks-in-the-cloud-and-how-to-prevent-them-part-3-from-compromis</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/lateral-movement-risks-in-the-cloud-and-how-to-prevent-them-part-3-from-compromis</guid>
            <pubDate>Thu, 23 Feb 2023 16:22:45 GMT</pubDate>
            <description><![CDATA[In this third blog post, we will discuss lateral movement risks from the cloud to Kubernetes. We will explain attacker TTPs, and outline best practices for cloud builders and defenders to help secure their cloud environments and mitigate risk.]]></description>
            <content:encoded><![CDATA[In this third blog post, we will discuss lateral movement risks from the cloud to Kubernetes. We will explain attacker TTPs, and outline best practices for cloud builders and defenders to help secure their cloud environments and mitigate risk.]]></content:encoded>
            <author>Lior Sonntag</author>
            <enclosure url="https://www.datocms-assets.com/75231/1677173472-1673540368-lateral-movement-2x.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[Ransomware attacks targeting VMware ESXi servers: everything you need to know ]]></title>
            <link>https://www.wiz.io/blog/ransomware-attacks-targeting-vmware-esxi-servers-everything-you-need-to-know</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/ransomware-attacks-targeting-vmware-esxi-servers-everything-you-need-to-know</guid>
            <pubDate>Tue, 07 Feb 2023 12:26:52 GMT</pubDate>
            <description><![CDATA[Recent attacks leverage CVE-2021-21974 to install ransomware on VMWare ESXi servers. Security teams are advised to patch and stay vigilant for indicators of compromise. ]]></description>
            <content:encoded><![CDATA[Recent attacks leverage CVE-2021-21974 to install ransomware on VMWare ESXi servers. Security teams are advised to patch and stay vigilant for indicators of compromise. ]]></content:encoded>
            <author>Merav Bar</author>
            <enclosure url="https://www.datocms-assets.com/75231/1675785490-esxi-16_9-1.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[The State of the Cloud 2023]]></title>
            <link>https://www.wiz.io/blog/the-top-cloud-security-threats-to-be-aware-of-in-2023</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/the-top-cloud-security-threats-to-be-aware-of-in-2023</guid>
            <pubDate>Mon, 06 Feb 2023 16:59:42 GMT</pubDate>
            <description><![CDATA[Wiz's State of the Cloud 2023 report provides analysis of trends in cloud usage such as multi-cloud, use of managed services and more. In addition, the report highlights notable cloud risks based on insights from 30% of Fortune 100 enterprise cloud environments]]></description>
            <content:encoded><![CDATA[Wiz's State of the Cloud 2023 report provides analysis of trends in cloud usage such as multi-cloud, use of managed services and more. In addition, the report highlights notable cloud risks based on insights from 30% of Fortune 100 enterprise cloud environments]]></content:encoded>
            <author>Scott Piper</author>
            <author>Amitai Cohen</author>
            <enclosure url="https://www.datocms-assets.com/75231/1675700566-state-of-the-cloud-blog-cover.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[Enhancing Kubernetes security with user namespaces]]></title>
            <link>https://www.wiz.io/blog/enhancing-kubernetes-security-with-user-namespaces</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/enhancing-kubernetes-security-with-user-namespaces</guid>
            <pubDate>Mon, 23 Jan 2023 15:29:10 GMT</pubDate>
            <description><![CDATA[Learn how to improve cluster security with user namespaces, a new feature introduced in Kubernetes v1.25.]]></description>
            <content:encoded><![CDATA[Learn how to improve cluster security with user namespaces, a new feature introduced in Kubernetes v1.25.]]></content:encoded>
            <author>Shay Berkovich</author>
            <author>Arik Nemtsov</author>
            <enclosure url="https://www.datocms-assets.com/75231/1674480661-enhancing-kubernetes-security-with-user-namespaces-16x9.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[CVE-2022-44877, critical RCE in CentOS Control Web Panel exploited in the wild: everything you need to know]]></title>
            <link>https://www.wiz.io/blog/cve-2022-44877-critical-rce-in-centos-control-web-panel-exploited-in-the-wild</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/cve-2022-44877-critical-rce-in-centos-control-web-panel-exploited-in-the-wild</guid>
            <pubDate>Tue, 17 Jan 2023 13:17:11 GMT</pubDate>
            <description><![CDATA[Detect and mitigate CVE-2022-44877, a CentOS Control Web Panel (CWP) unauthenticated RCE exploited in the wild. Security teams are advised to patch urgently. ]]></description>
            <content:encoded><![CDATA[Detect and mitigate CVE-2022-44877, a CentOS Control Web Panel (CWP) unauthenticated RCE exploited in the wild. Security teams are advised to patch urgently. ]]></content:encoded>
            <author>Merav Bar</author>
            <enclosure url="https://www.datocms-assets.com/75231/1673954513-centos-16_9.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[Hunting for signs of persistence in the cloud: an IR guide following the CircleCI incident ]]></title>
            <link>https://www.wiz.io/blog/hunting-for-signs-of-persistence-in-the-cloud-an-ir-guide</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/hunting-for-signs-of-persistence-in-the-cloud-an-ir-guide</guid>
            <pubDate>Thu, 12 Jan 2023 17:04:40 GMT</pubDate>
            <description><![CDATA[Learn how to detect malicious persistence techniques in AWS, GCP & Azure after potential initial compromise, like with the CircleCI incident]]></description>
            <content:encoded><![CDATA[Learn how to detect malicious persistence techniques in AWS, GCP & Azure after potential initial compromise, like with the CircleCI incident]]></content:encoded>
            <author>Lior Sonntag</author>
            <enclosure url="https://www.datocms-assets.com/75231/1673544263-circleci-security-incident-blog-cover-copy_2.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[Lateral movement risks in the cloud and how to prevent them – Part 2: from compromised container to cloud takeover]]></title>
            <link>https://www.wiz.io/blog/lateral-movement-risks-in-the-cloud-and-how-to-prevent-them-part-2-from-k8s-clust</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/lateral-movement-risks-in-the-cloud-and-how-to-prevent-them-part-2-from-k8s-clust</guid>
            <pubDate>Thu, 05 Jan 2023 17:00:04 GMT</pubDate>
            <description><![CDATA[In this second blog post, we will discuss lateral movement risks from Kubernetes to the cloud. We will explain attacker TTPs, and outline best practices for security practitioners and cloud builders to help secure their cloud environments and mitigate risk.]]></description>
            <content:encoded><![CDATA[In this second blog post, we will discuss lateral movement risks from Kubernetes to the cloud. We will explain attacker TTPs, and outline best practices for security practitioners and cloud builders to help secure their cloud environments and mitigate risk.]]></content:encoded>
            <author>Lior Sonntag</author>
            <enclosure url="https://www.datocms-assets.com/75231/1673540368-lateral-movement-2x.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[Malicious PyTorch dependency 'torchtriton' on PyPI: everything you need to know ]]></title>
            <link>https://www.wiz.io/blog/malicious-pytorch-dependency-torchtriton-on-pypi-everything-you-need-to-know</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/malicious-pytorch-dependency-torchtriton-on-pypi-everything-you-need-to-know</guid>
            <pubDate>Tue, 03 Jan 2023 13:10:27 GMT</pubDate>
            <description><![CDATA[The developers of PyTorch (a popular machine-learning framework) recently identified a malicious dependency confusion attack on the open-source project. Security teams are advised to check for infected resources and rotate any exposed keys. ]]></description>
            <content:encoded><![CDATA[The developers of PyTorch (a popular machine-learning framework) recently identified a malicious dependency confusion attack on the open-source project. Security teams are advised to check for infected resources and rotate any exposed keys. ]]></content:encoded>
            <author>Merav Bar</author>
            <enclosure url="https://www.datocms-assets.com/75231/1672750586-blog-cover.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[Introducing PEACH, a tenant isolation framework for cloud applications]]></title>
            <link>https://www.wiz.io/blog/introducing-peach-a-tenant-isolation-framework-for-cloud-applications</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/introducing-peach-a-tenant-isolation-framework-for-cloud-applications</guid>
            <pubDate>Wed, 14 Dec 2022 14:15:22 GMT</pubDate>
            <description><![CDATA[A step-by-step framework for modeling and improving SaaS and PaaS tenant isolation by reducing your cloud applications’ attack surface]]></description>
            <content:encoded><![CDATA[A step-by-step framework for modeling and improving SaaS and PaaS tenant isolation by reducing your cloud applications’ attack surface]]></content:encoded>
            <author>Amitai Cohen</author>
            <enclosure url="https://www.datocms-assets.com/75231/1671012949-artboard_53_copy_4_3x.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[Secret-based cloud supply-chain attacks: Case study and lessons for security teams]]></title>
            <link>https://www.wiz.io/blog/secret-based-cloud-supply-chain-attacks-case-study-and-lessons-for-security-teams</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/secret-based-cloud-supply-chain-attacks-case-study-and-lessons-for-security-teams</guid>
            <pubDate>Tue, 13 Dec 2022 19:28:25 GMT</pubDate>
            <description><![CDATA[CI/CD pipelines, as an essential part of the software development process, are an attractive target to malicious actors. Based on our research of cloud environments, we share common misconfigurations and provide tips on how to remediate them in order to prevent supply-chain attacks.]]></description>
            <content:encoded><![CDATA[CI/CD pipelines, as an essential part of the software development process, are an attractive target to malicious actors. Based on our research of cloud environments, we share common misconfigurations and provide tips on how to remediate them in order to prevent supply-chain attacks.]]></content:encoded>
            <author>Alon Schindel</author>
            <author>Shir Tamari</author>
            <enclosure url="https://www.datocms-assets.com/75231/1670960710-supplychainattacks-final-01.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[Hell’s Keychain: Supply-chain vulnerability in IBM Cloud Databases for PostgreSQL allows potential unauthorized database access]]></title>
            <link>https://www.wiz.io/blog/hells-keychain-supply-chain-attack-in-ibm-cloud-databases-for-postgresql</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/hells-keychain-supply-chain-attack-in-ibm-cloud-databases-for-postgresql</guid>
            <pubDate>Thu, 01 Dec 2022 15:00:28 GMT</pubDate>
            <description><![CDATA[How IBM Cloud caught us exploring its infrastructure and how a hardcoded secret eventually led to build artifact access and manipulation]]></description>
            <content:encoded><![CDATA[How IBM Cloud caught us exploring its infrastructure and how a hardcoded secret eventually led to build artifact access and manipulation]]></content:encoded>
            <author>Ronen Shustin</author>
            <author>Shir Tamari</author>
            <enclosure url="https://www.datocms-assets.com/75231/1669108105-image.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[Lateral movement risks in the cloud and how to prevent them – Part 1: the network layer (VPC)]]></title>
            <link>https://www.wiz.io/blog/lateral-movement-risks-in-the-cloud-and-how-to-prevent-them-part-1-the-network-layer</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/lateral-movement-risks-in-the-cloud-and-how-to-prevent-them-part-1-the-network-layer</guid>
            <pubDate>Thu, 13 Oct 2022 17:43:22 GMT</pubDate>
            <description><![CDATA[In this first blog post, we will introduce lateral movement as it pertains to the VPC. We will discuss attacker TTPs, and outline best practices for security practitioners and cloud builders to help secure their cloud environment and reduce risk.]]></description>
            <content:encoded><![CDATA[In this first blog post, we will introduce lateral movement as it pertains to the VPC. We will discuss attacker TTPs, and outline best practices for security practitioners and cloud builders to help secure their cloud environment and reduce risk.]]></content:encoded>
            <author>Lior Sonntag</author>
            <enclosure url="https://www.datocms-assets.com/75231/1665673990-lateral-movement-blog-cover.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[AttachMe: critical OCI vulnerability allows unauthorized access to customer cloud storage volumes]]></title>
            <link>https://www.wiz.io/blog/attachme-oracle-cloud-vulnerability-allows-unauthorized-cross-tenant-volume-access</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/attachme-oracle-cloud-vulnerability-allows-unauthorized-cross-tenant-volume-access</guid>
            <pubDate>Tue, 20 Sep 2022 12:57:00 GMT</pubDate>
            <description><![CDATA[Before it was patched, #AttachMe could have allowed attackers to access and modify any other users' OCI storage volumes without authorization, thereby violating cloud isolation. Upon disclosure, the vulnerability was fixed within hours by Oracle. No customer action was required. ]]></description>
            <content:encoded><![CDATA[Before it was patched, #AttachMe could have allowed attackers to access and modify any other users' OCI storage volumes without authorization, thereby violating cloud isolation. Upon disclosure, the vulnerability was fixed within hours by Oracle. No customer action was required. ]]></content:encoded>
            <author>Elad Gabay</author>
            <enclosure url="https://www.datocms-assets.com/75231/1663648486-attachme-social-cars.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[The cloud has an isolation problem: PostgreSQL vulnerabilities affect multiple cloud vendors]]></title>
            <link>https://www.wiz.io/blog/the-cloud-has-an-isolation-problem-postgresql-vulnerabilities</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/the-cloud-has-an-isolation-problem-postgresql-vulnerabilities</guid>
            <pubDate>Thu, 11 Aug 2022 18:20:01 GMT</pubDate>
            <description><![CDATA[How Wiz Research uncovered multiple related vulnerabilities in PostgreSQL-as-a-Service offerings from GCP, Azure, and others.]]></description>
            <content:encoded><![CDATA[How Wiz Research uncovered multiple related vulnerabilities in PostgreSQL-as-a-Service offerings from GCP, Azure, and others.]]></content:encoded>
            <author>Ronen Shustin</author>
            <author>Shir Tamari</author>
            <author>Nir Ohfeld</author>
            <author>Sagi Tzadik</author>
            <enclosure url="https://www.datocms-assets.com/75231/1660205465-postgresql-blog.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[Securing Azure middleware agents with new auto-patching capabilities]]></title>
            <link>https://www.wiz.io/blog/auto-patching-for-omi</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/auto-patching-for-omi</guid>
            <pubDate>Fri, 05 Aug 2022 05:55:47 GMT</pubDate>
            <description><![CDATA[Wiz finds Azure customers remain unpatched from cloud middleware vulnerability and collaborates with Microsoft to introduce an auto-patching solution against cloud middleware security issues and make the cloud safer]]></description>
            <content:encoded><![CDATA[Wiz finds Azure customers remain unpatched from cloud middleware vulnerability and collaborates with Microsoft to introduce an auto-patching solution against cloud middleware security issues and make the cloud safer]]></content:encoded>
            <author>Alon Schindel</author>
            <enclosure url="https://www.datocms-assets.com/75231/1659937963-wiz-azure-blog-post-blog-cover.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[Revisiting OMI: Analysis of CVE-2022-29149, a privilege escalation vulnerability in Azure OMI]]></title>
            <link>https://www.wiz.io/blog/omi-returns-lpe-technical-analysis</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/omi-returns-lpe-technical-analysis</guid>
            <pubDate>Fri, 05 Aug 2022 05:51:58 GMT</pubDate>
            <description><![CDATA[Affected organizations are required to update installed agents that use the OMI cloud middleware software]]></description>
            <content:encoded><![CDATA[Affected organizations are required to update installed agents that use the OMI cloud middleware software]]></content:encoded>
            <author>Nir Ohfeld</author>
            <author>Rotem Zarin</author>
            <enclosure url="https://www.datocms-assets.com/75231/1659937629-blog_the-return-of-omi.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[Wiz Research discovers "ExtraReplica"— a cross-account database vulnerability in Azure PostgreSQL]]></title>
            <link>https://www.wiz.io/blog/wiz-research-discovers-extrareplica-cross-account-database-vulnerability-in-azure-postgresql</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/wiz-research-discovers-extrareplica-cross-account-database-vulnerability-in-azure-postgresql</guid>
            <pubDate>Fri, 29 Apr 2022 05:12:16 GMT</pubDate>
            <description><![CDATA[Wiz Research discovers a chain of critical vulnerabilities in the widely used Azure Database for PostgreSQL Flexible Server.]]></description>
            <content:encoded><![CDATA[Wiz Research discovers a chain of critical vulnerabilities in the widely used Azure Database for PostgreSQL Flexible Server.]]></content:encoded>
            <author>Ronen Shustin</author>
            <author>Sagi Tzadik</author>
            <author>Nir Ohfeld</author>
            <author>Shir Tamari</author>
            <enclosure url="https://www.datocms-assets.com/75231/1659934983-new-replica.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[Hardening your cloud environment against LAPSUS$-like threat actors]]></title>
            <link>https://www.wiz.io/blog/hardening-your-cloud-environment-against-lapsus-like-threat-actor</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/hardening-your-cloud-environment-against-lapsus-like-threat-actor</guid>
            <pubDate>Sat, 26 Mar 2022 04:56:44 GMT</pubDate>
            <description><![CDATA[Learn how to harden your cloud environment against LAPSUS$-like threat actors]]></description>
            <content:encoded><![CDATA[Learn how to harden your cloud environment against LAPSUS$-like threat actors]]></content:encoded>
            <author>Amitai Cohen</author>
            <enclosure url="https://www.datocms-assets.com/75231/1659934372-integration-blog-cover-1.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[The top cloud security threats to be aware of in 2022]]></title>
            <link>https://www.wiz.io/blog/2022-cloud-security-threats</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/2022-cloud-security-threats</guid>
            <pubDate>Tue, 18 Jan 2022 05:36:08 GMT</pubDate>
            <description><![CDATA[As more organizations move to the cloud, so do attackers. What can you do to better protect your cloud environment in 2022? Wiz Research has compiled the most pressing cloud security threats and how you can protect against them.]]></description>
            <content:encoded><![CDATA[As more organizations move to the cloud, so do attackers. What can you do to better protect your cloud environment in 2022? Wiz Research has compiled the most pressing cloud security threats and how you can protect against them.]]></content:encoded>
            <author>Alon Schindel</author>
            <enclosure url="https://www.datocms-assets.com/75231/1659933319-threat-report-blog-cover.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[NotLegit: Azure App Service vulnerability exposed hundreds of source code repositories]]></title>
            <link>https://www.wiz.io/blog/azure-app-service-source-code-leak</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/azure-app-service-source-code-leak</guid>
            <pubDate>Tue, 21 Dec 2021 05:08:25 GMT</pubDate>
            <description><![CDATA[Read about the NotLegit vulnerability discovered by the Wiz Research Team, where the Azure App Service exposed hundreds of source code repositories.]]></description>
            <content:encoded><![CDATA[Read about the NotLegit vulnerability discovered by the Wiz Research Team, where the Azure App Service exposed hundreds of source code repositories.]]></content:encoded>
            <author>Shir Tamari</author>
            <enclosure url="https://www.datocms-assets.com/75231/1659931538-notlegit-post-by-wiz.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[Log4Shell 10 days later: Enterprises halfway through patching]]></title>
            <link>https://www.wiz.io/blog/10-days-later-enterprises-halfway-through-patching-log4shell</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/10-days-later-enterprises-halfway-through-patching-log4shell</guid>
            <pubDate>Tue, 21 Dec 2021 04:52:06 GMT</pubDate>
            <description><![CDATA[Wiz and EY (Ernest & Young) analyzed more than 200 enterprise cloud environments with thousands of cloud accounts. The results were striking: While 93% of all cloud environments are at risk from Log4Shell, on average organizations have patched 45% of their vulnerable cloud resources by Day 10.]]></description>
            <content:encoded><![CDATA[Wiz and EY (Ernest & Young) analyzed more than 200 enterprise cloud environments with thousands of cloud accounts. The results were striking: While 93% of all cloud environments are at risk from Log4Shell, on average organizations have patched 45% of their vulnerable cloud resources by Day 10.]]></content:encoded>
            <author>Ami Luttwak</author>
            <author>Alon Schindel</author>
            <enclosure url="https://www.datocms-assets.com/75231/1659930405-log4shell-by-the-numbers-cover.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[ChaosDB explained: Azure's Cosmos DB vulnerability walkthrough]]></title>
            <link>https://www.wiz.io/blog/chaosdb-explained-azures-cosmos-db-vulnerability-walkthrough</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/chaosdb-explained-azures-cosmos-db-vulnerability-walkthrough</guid>
            <pubDate>Thu, 11 Nov 2021 03:57:43 GMT</pubDate>
            <description><![CDATA[This is the full story of the Azure ChaosDB Vulnerability that was discovered and disclosed by the Wiz Research Team, where we were able to gain complete unrestricted access to the databases of several thousand Microsoft Azure customers.]]></description>
            <content:encoded><![CDATA[This is the full story of the Azure ChaosDB Vulnerability that was discovered and disclosed by the Wiz Research Team, where we were able to gain complete unrestricted access to the databases of several thousand Microsoft Azure customers.]]></content:encoded>
            <author>Nir Ohfeld</author>
            <author>Sagi Tzadik</author>
            <enclosure url="https://www.datocms-assets.com/75231/1659925598-chaos-az-0.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[How we broke the cloud with two lines of code: the full story of ChaosDB]]></title>
            <link>https://www.wiz.io/blog/how-we-broke-the-cloud-with-two-lines-of-code-the-full-story-of-chaosdb</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/how-we-broke-the-cloud-with-two-lines-of-code-the-full-story-of-chaosdb</guid>
            <pubDate>Thu, 11 Nov 2021 03:18:38 GMT</pubDate>
            <description><![CDATA[A summary and recording of Wiz's talk at BlackHat Europe 2021: the full extent of ChaosDB, the impact it had, and the questions it raises about security in managed cloud services.]]></description>
            <content:encoded><![CDATA[A summary and recording of Wiz's talk at BlackHat Europe 2021: the full extent of ChaosDB, the impact it had, and the questions it raises about security in managed cloud services.]]></content:encoded>
            <author>Nir Ohfeld</author>
            <author>Sagi Tzadik</author>
            <enclosure url="https://www.datocms-assets.com/75231/1659925016-chaos-0.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[Protecting cloud environments from the new critical Apache HTTP Server vulnerability]]></title>
            <link>https://www.wiz.io/blog/protecting-cloud-environments-from-the-new-critical-apache-http-server-vulnerability</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/protecting-cloud-environments-from-the-new-critical-apache-http-server-vulnerability</guid>
            <pubDate>Fri, 08 Oct 2021 02:13:12 GMT</pubDate>
            <description><![CDATA[Learn how to protect cloud environments from the new critical Apache HTTP Server vulnerability.]]></description>
            <content:encoded><![CDATA[Learn how to protect cloud environments from the new critical Apache HTTP Server vulnerability.]]></content:encoded>
            <author>Alon Schindel</author>
            <enclosure url="https://www.datocms-assets.com/75231/1659924126-http-0.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[OMIGOD: Critical Vulnerabilities in OMI Affecting Countless Azure Customers]]></title>
            <link>https://www.wiz.io/blog/omigod-critical-vulnerabilities-in-omi-azure</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/omigod-critical-vulnerabilities-in-omi-azure</guid>
            <pubDate>Tue, 14 Sep 2021 17:21:46 GMT</pubDate>
            <description><![CDATA[Wiz Research recently found 4 critical vulnerabilities in OMI, which is one of Azure's most ubiquitous yet least known software agents and is deployed on a large portion of Linux VMs in Azure.]]></description>
            <content:encoded><![CDATA[Wiz Research recently found 4 critical vulnerabilities in OMI, which is one of Azure's most ubiquitous yet least known software agents and is deployed on a large portion of Linux VMs in Azure.]]></content:encoded>
            <author>Nir Ohfeld</author>
            <enclosure url="https://www.datocms-assets.com/75231/1659892020-omigod-8.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[“Secret” Agent Exposes Azure Customers To Unauthorized Code Execution]]></title>
            <link>https://www.wiz.io/blog/secret-agent-exposes-azure-customers-to-unauthorized-code-execution</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/secret-agent-exposes-azure-customers-to-unauthorized-code-execution</guid>
            <pubDate>Tue, 14 Sep 2021 17:05:30 GMT</pubDate>
            <description><![CDATA[Wiz Research recently discovered a series of alarming vulnerabilities that highlight the supply chain risk of open source code, particularly for customers of cloud computing services.]]></description>
            <content:encoded><![CDATA[Wiz Research recently discovered a series of alarming vulnerabilities that highlight the supply chain risk of open source code, particularly for customers of cloud computing services.]]></content:encoded>
            <author>Nir Ohfeld</author>
            <author>Alon Schindel</author>
            <enclosure url="https://www.datocms-assets.com/75231/1659891634-omigod-0.jpeg" length="0" type="image/jpeg"/>
        </item>
        <item>
            <title><![CDATA[ChaosDB: How to discover your vulnerable Azure Cosmos DBs and protect them]]></title>
            <link>https://www.wiz.io/blog/protecting-your-environment-from-chaosdb</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/protecting-your-environment-from-chaosdb</guid>
            <pubDate>Sun, 29 Aug 2021 16:52:07 GMT</pubDate>
            <description><![CDATA[Wiz Research found an unprecedented critical vulnerability in Azure Cosmos DB. The vulnerability gives any Azure user full admin access (read, write, delete) to another customers Cosmos DB instances without authorization.]]></description>
            <content:encoded><![CDATA[Wiz Research found an unprecedented critical vulnerability in Azure Cosmos DB. The vulnerability gives any Azure user full admin access (read, write, delete) to another customers Cosmos DB instances without authorization.]]></content:encoded>
            <author>Alon Schindel</author>
            <enclosure url="https://www.datocms-assets.com/75231/1659890751-chaosdb-5.jpeg" length="0" type="image/jpeg"/>
        </item>
        <item>
            <title><![CDATA[ChaosDB: How we hacked thousands of Azure customers’ databases]]></title>
            <link>https://www.wiz.io/blog/chaosdb-how-we-hacked-thousands-of-azure-customers-databases</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/chaosdb-how-we-hacked-thousands-of-azure-customers-databases</guid>
            <pubDate>Thu, 26 Aug 2021 16:42:14 GMT</pubDate>
            <description><![CDATA[As part of building a market-leading CNAPP, Wiz Research is constantly looking for new attack surfaces in the cloud. Two weeks ago we discovered an unprecedented breach that affects Azure’s flagship database service, Cosmos DB.]]></description>
            <content:encoded><![CDATA[As part of building a market-leading CNAPP, Wiz Research is constantly looking for new attack surfaces in the cloud. Two weeks ago we discovered an unprecedented breach that affects Azure’s flagship database service, Cosmos DB.]]></content:encoded>
            <author>Nir Ohfeld</author>
            <author>Sagi Tzadik</author>
            <enclosure url="https://www.datocms-assets.com/75231/1659890296-chaosdb-0.jpeg" length="0" type="image/jpeg"/>
        </item>
        <item>
            <title><![CDATA[Is your organization leaking sensitive Dynamic DNS data? Here’s how to find out]]></title>
            <link>https://www.wiz.io/blog/is-your-organization-leaking-sensitive-dynamic-dns-data-heres-how-to-find-out</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/is-your-organization-leaking-sensitive-dynamic-dns-data-heres-how-to-find-out</guid>
            <pubDate>Fri, 06 Aug 2021 16:25:58 GMT</pubDate>
            <description><![CDATA[At Black Hat on Wednesday, Wiz researchers disclosed a vulnerability in DNS hosting services that affects millions of corporate endpoints.]]></description>
            <content:encoded><![CDATA[At Black Hat on Wednesday, Wiz researchers disclosed a vulnerability in DNS hosting services that affects millions of corporate endpoints.]]></content:encoded>
            <author>Ami Luttwak</author>
            <enclosure url="https://www.datocms-assets.com/75231/1659889492-dynamic-dns-0.jpeg" length="0" type="image/jpeg"/>
        </item>
        <item>
            <title><![CDATA[Black Hat 2021: How isolated is your AWS cloud environment?]]></title>
            <link>https://www.wiz.io/blog/black-hat-2021-aws-cross-account-vulnerabilities-how-isolated-is-your-cloud-environment</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/black-hat-2021-aws-cross-account-vulnerabilities-how-isolated-is-your-cloud-environment</guid>
            <pubDate>Wed, 04 Aug 2021 16:21:53 GMT</pubDate>
            <description><![CDATA[Last November, Wiz Research mapped all the services in AWS that allow access from other accounts to see if any of them might inadvertently expose customers and discovered 3 vulnerabilities in different AWS services that allowed anyone to read or write into the accounts of other AWS customers.

]]></description>
            <content:encoded><![CDATA[Last November, Wiz Research mapped all the services in AWS that allow access from other accounts to see if any of them might inadvertently expose customers and discovered 3 vulnerabilities in different AWS services that allowed anyone to read or write into the accounts of other AWS customers.

]]></content:encoded>
            <author>Ami Luttwak</author>
            <enclosure url="https://www.datocms-assets.com/75231/1659889098-isolated-aws-0.jpeg" length="0" type="image/jpeg"/>
        </item>
        <item>
            <title><![CDATA[Black Hat 2021: DNS loophole makes nation-state level spying as easy as registering a domain]]></title>
            <link>https://www.wiz.io/blog/black-hat-2021-dns-loophole-makes-nation-state-level-spying-as-easy-as-registering-a-domain</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/black-hat-2021-dns-loophole-makes-nation-state-level-spying-as-easy-as-registering-a-domain</guid>
            <pubDate>Wed, 04 Aug 2021 16:15:35 GMT</pubDate>
            <description><![CDATA[Wiz CTO Ami Luttwak discusses a new class of vulnerabilities discovered by Wiz Research, which exposed valuable dynamic DNS data from millions of endpoints worldwide.]]></description>
            <content:encoded><![CDATA[Wiz CTO Ami Luttwak discusses a new class of vulnerabilities discovered by Wiz Research, which exposed valuable dynamic DNS data from millions of endpoints worldwide.]]></content:encoded>
            <author>Shir Tamari</author>
            <enclosure url="https://www.datocms-assets.com/75231/1659888489-dns-loophole-0.jpeg" length="0" type="image/jpeg"/>
        </item>
        <item>
            <title><![CDATA[82% of companies unknowingly give 3rd parties access to all their cloud data]]></title>
            <link>https://www.wiz.io/blog/82-of-companies-unknowingly-give-3rd-parties-access-to-all-their-cloud-data</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/82-of-companies-unknowingly-give-3rd-parties-access-to-all-their-cloud-data</guid>
            <pubDate>Tue, 02 Feb 2021 17:39:49 GMT</pubDate>
            <description><![CDATA[Cloud identity permissions are complex. So complex that innocent looking permissions provided to 3rd party vendors can lead to unintended exposure of all of your data.]]></description>
            <content:encoded><![CDATA[Cloud identity permissions are complex. So complex that innocent looking permissions provided to 3rd party vendors can lead to unintended exposure of all of your data.]]></content:encoded>
            <author>Shir Tamari</author>
            <enclosure url="https://www.datocms-assets.com/75231/1657643653-admin-settings.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[Recent Linux sudo vulnerability affects a major percent of cloud workloads]]></title>
            <link>https://www.wiz.io/blog/recent-linux-sudo-vulnerability-affects-a-major-percent-of-cloud-workloads</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/recent-linux-sudo-vulnerability-affects-a-major-percent-of-cloud-workloads</guid>
            <pubDate>Tue, 02 Feb 2021 13:00:00 GMT</pubDate>
            <description><![CDATA[With an estimated 90% of cloud workloads running Linux based OS, with sudo being common across distributions, many Linux cloud assets are at risk and may be affected. Versions released as far back as 2011 are affected by this vulnerability.]]></description>
            <content:encoded><![CDATA[With an estimated 90% of cloud workloads running Linux based OS, with sudo being common across distributions, many Linux cloud assets are at risk and may be affected. Versions released as far back as 2011 are affected by this vulnerability.]]></content:encoded>
            <author>Ami Luttwak</author>
            <enclosure url="https://www.datocms-assets.com/75231/1657645300-sudo-1.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[The SolarWinds Attack]]></title>
            <link>https://www.wiz.io/blog/the-solarwinds-attack</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/the-solarwinds-attack</guid>
            <pubDate>Mon, 01 Feb 2021 12:52:22 GMT</pubDate>
            <description><![CDATA[SolarWinds attack explained by Wiz CTO Ami Luttwak]]></description>
            <content:encoded><![CDATA[SolarWinds attack explained by Wiz CTO Ami Luttwak]]></content:encoded>
            <author>Ami Luttwak</author>
            <enclosure url="https://www.datocms-assets.com/75231/1657577547-solar_winds.png" length="0" type="image/png"/>
        </item>
    </channel>
</rss>