Red Agentの視点:いかにして推論を重ねてSSRFへと至ったか
パート1:Red AgentがGCP Cloud Run APIにおいてSSRFからローカルファイル読み取りを可能にする複数ステップの攻撃チェーンをどのように解明したか
Danielle Aminov is a threat researcher at Wiz, specializing in network-based threats, external attack-surface management, and threat intelligence. Backed by a B.S. in Computer Science and more than six years of offensive-security experience - spanning red-team operations and penetration testing - she now designs proactive detection strategies that help large cloud environments map their external exposure and rapidly defend against emerging attack vectors.
パート1:Red AgentがGCP Cloud Run APIにおいてSSRFからローカルファイル読み取りを可能にする複数ステップの攻撃チェーンをどのように解明したか
当社のAI搭載アタッカーであるRed Agentが、実際の環境で複雑かつ悪用可能なリスクをどのように特定するのか、その裏側をご紹介します
Red Agentは、アタックサーフェス全体にわたる悪用可能な複雑なリスクを継続的かつ大規模に発見する、AI搭載でコンテキストを認識するアタッカーです。
Detect and mitigate React2Shell (CVE-2025-55182), critical RCE vulnerability in React and Next.js exploited in the wild. Organizations should patch urgently.
How attackers exploit exposed databases for extortion—and the defenses that work.
Exploring how simple setup flaws become open doors for attackers—and what teams can do to shut them.
A deeper look at the npm debug/chalk supply-chain incident: deobfuscating the wallet-hijacking browser interceptor, quantifying the ~2-hour exposure with Wiz telemetry (~99% package prevalence, ~10% malware presence), and unpacking what made it spread so fast.
The Wiz Threat Research team has identified a widespread cryptojacking campaign targeting commonly used DevOps applications including Nomad and Consul.
Wiz Threat Research investigates misconfigurations in Spring Boot Actuator’s endpoints that can leak environment variables, passwords, and API keys, and even lead to remote code execution.
Supply chain attack in popular lottie-player library compromises websites with malicious Web3 wallet prompts – update or revert the library to avoid the compromised versions.
Detect and mitigate CVE-2024-6387, a remote code execution vulnerability in OpenSSH. Organizations are advised to patch urgently.
Detect and mitigate CVE-2024-3094, a critical supply chain compromise, affecting XZ Utils Data compression library. Organizations should patch urgently.