Wiz ResearchGoogle DeepMind

Scan for Good

Using AI to find and help fix critical exposures across public services and critical infrastructure.

Wiz Research works directly with public services, critical infrastructure, nonprofits, and other organizations in which security is paramount to find, validate, and help remediate critical exposures.

Organization-Linked Domains
17,761
Public Endpoints Monitored
326,891
Critical Exposures Found
475

How Scan for Good works

Who we prioritize

  • Critical infrastructure

    Energy, water, transportation, and telecom

  • Public services

    Government and civic services

  • Healthcare

    Hospitals and care systems

  • Nonprofits

    Mission-driven organizations

  • Open-source

    Widely used public software

How we Scan

  1. 1

    Map the public surface

    17,461

    Root domains in scope

    We map the internet-facing footprint from the root domains in scope.

  2. 2

    External exposures

    326,891

    Monitored endpoints

    Continuously discover public websites, applications, APIs, and other exposed assets.

  3. 3

    AI-powered assessment

    Every asset is evaluated with a combination of AI and deterministic exposure checks and continuously monitored.

    Deterministic Exposure Assessment

    Continuous · Deterministic

    AI-Powered Web DAST

    Continuous · AI-Powered

    Deep-Dive AI Pentesting

    On Demand · AI-Powered

    Powered byGemini 3.8 Flash Cyber

  4. 4

    Validate & disclose

    475

    High / Critical findings

    Wiz Research validates high-impact findings before disclosure and shares them privately with the affected organization.

Examples of risks addressed

These anonymized examples show high-impact exposures identified, disclosed, and successfully remediated.

We helped protect

8.8 millionfiles in a national heritage archive

An API key exposed on a web server allowed files to be read, changed, or deleted.
The key was rotated and its permissions limited to what was required.

Who should apply

We focus first on organizations where a successful attack could cause meaningful harm to people, communities, and the systems they depend on. Any individual or organization concerned about an exposed service can apply.

  • Essential services

    Energy, water, transportation and telecom

    • Public services
    • Healthcare
    • Critical infrastructure
    • Transportation & logistics
    • Utilities & essential systems
  • Digital infrastructure

    Organizations that build and operate the digital systems we all rely on.

    • AI, cloud & compute infra
    • Technology & SaaS
    • Telecommunications
    • Open-source projects
  • Community-serving organizations

    Organizations working to improve society and expand knowledge.

    • Nonprofits & NGOs
    • Education & research
    • International organizations

What defenders can learn from AI-powered internet scanning

By scanning internet-facing assets at scale, we can observe how quickly exposures become viable attack paths, how far AI can progress, and which weaknesses most often lead to meaningful impact.

Autonomous AI Exploitation Is Here

Sample of 7 real-world attacks, initial access was proven in under 10 minutes every time. AI escalation then took as little as 2 minutes—or continued tirelessly for hours.

100%

Reached initial access in under 10 minutes

2m

Fastest escalation to complete compromise

3h 47m

Longest pursuit of maximum safe impact

  • 2.5

    minutes

    Full control on the server

    Full website control + internal-network access

    Public website

    RCE CVE

    Server control

    Public website

    RCE CVE

    Server control

    30 seconds

    2 minutes

  • 6

    minutes

    Full control of 8.8M archive files

    Read, change, or delete the entire archive

    Public website

    Exposed Key

    8.8M files

    Public website

    Exposed Key

    8.8M files

    1 minute 20 seconds

    5 minutes

  • 18

    minutes

    Control of the production registry

    Anonymous User to full control on 534 production images

    Public website

    Exposed Token

    Registry Control

    Public website

    Exposed Token

    Registry Control

    3 minutes

    15 minutes

  • 20

    minutes

    Remote Code Execution as Admin

    Admin credential + code-execution escalation

    Public website

    WP2Shell CVE

    Admin Access

    Public website

    WP2Shell CVE

    Admin Access

    5 minutes

    15 minutes

  • 42

    minutes

    Privileged access

    Public Internal, exploitation of SSRF to Internal Network

    Public website

    SSRF

    Internal Network

    Public website

    SSRF

    Internal Network

    2 minutes

    40 minutes

  • 1H

    3 minutes

    Full control over ERP system

    Valid Public Token exposing 7 years of Fleet Operations Finance

    Public website

    Exposed Token

    Fleet ERP Control

    Public website

    Exposed Token

    Fleet ERP Control

    3 minutes

    1 hour

  • 3H

    47 minutes

    Full Control over Maritime Port Access System

    Anonymous User to complete control on every physical gate

    Public website

    Improper Access Control

    Port Control

    Public website

    Improper Access Control

    Port Control

    1 minute 35 seconds

    3 hours 47 minutes

Disclosure Ledger

A transparent, updated record of vulnerabilities discovered through Scan for Good, validated by Wiz Research, and responsibly remediated in partnership with affected organizations.

Scan for Good disclosure ledger
#FindingTokensClassSeverityMinCost
1CI/CD secrets serialized into production JavaScript bundles~1.0MSupply chainCritical6.0~$1.5
2Supply-chain RCE via JavaScript bundle to container-registry poisoning~400MSupply chainCritical18.0~$100
3GraphQL authorization bypass on a service-management platform~1.0MBroken access controlHigh14.0~$1.5
4Subdomain takeover enabling session-cookie theft~1.0MSubdomain takeoverHigh1.8~$1.5
5Complete security-operations platform exposure affecting thousands of records~1.0MBroken access controlCritical7.0~$1.5
6Unauthenticated machine-token endpoint opening an enterprise operations platform~400MBroken access controlCritical63.0~$100
7Pre-authentication RCE through React Server Components deserialization~1.0MRCECritical2.5~$1.5
8Research-platform installer and full database-schema exposure~1.0MInfo disclosureHigh8.0~$1.5
9PHP type-juggling authentication bypass on a production ordering platform~1.0MAuth bypassCritical17.0~$1.5
10Full-read SSRF reaching payment credentials and the internal network~400MSSRFCritical42.0~$100

Showing 1–10 of 94 findings

Bring Scan for Good to your organization

Are you defending critical services or foundational technology? Apply to express your interest in a complimentary assessment and remediation support.