Cloud Threat Highlights: H1 2026
Cloud and AI threat activity tracked by Wiz Research and CIRT, January through June 2026
Cloud and AI threat activity tracked by Wiz Research and CIRT, January through June 2026
Wiz Research is actively investigating an ongoing software supply chain attack affecting multiple keyv/cacheable npm packages.
S3 compatible services carry many of the same concerns as the original S3 service. This article highlights which assumptions break and what risks remain.
A critical vulnerability chain in Azure Cosmos DB enabled full read and write access to every Cosmos DB database.
How unauthenticated Model Context Protocol (MCP) servers are opening doors to sensitive cloud data, IAM, and command execution.
Mapping appliances event logs to real-world campaigns: A step-by-step researcher’s guide to continuous agentless monitoring.
How Agentless Workload Detection exposes hidden threats in virtual appliances and modern cloud networks.
Wiz Research has identified exploitation of "wp2shell", a critical pre-auth RCE vulnerability chain impacting WordPress Core (CVE-2026-63030 & CVE-2026-60137). Attackers are deploying persistent webshells on vulnerable servers. Organizations should prioritize patching or applying WAF mitigations.
Part 3: How the Red Agent bypassed a credit and paywall system by changing a single client-side value from false to true.
Detect and mitigate malicious @asyncapi npm packages linked to the latest npm supply chain attack.
Verizon's latest DBIR highlights how attackers are exploiting familiar weaknesses at increasing speed and scale. Here's what Wiz research reveals about vulnerabilities, trust relationships, and AI in modern cloud environments.
Uncovering a category-level blind spot in modern AI coding assistants, and why the Human-in-the-Loop safety model fails against this classic threat