Using AI to find and help fix critical exposures across public services and critical infrastructure.
Wiz Research works directly with public services, critical infrastructure, nonprofits, and other organizations in which security is paramount to find, validate, and help remediate critical exposures.
Energy, water, transportation, and telecom
Government and civic services
Hospitals and care systems
Mission-driven organizations
Widely used public software
17,461
Root domains in scope
We map the internet-facing footprint from the root domains in scope.
326,891
Monitored endpoints
Continuously discover public websites, applications, APIs, and other exposed assets.
Every asset is evaluated with a combination of AI and deterministic exposure checks and continuously monitored.
Deterministic Exposure Assessment
Continuous · Deterministic
AI-Powered Web DAST
Continuous · AI-Powered
Deep-Dive AI Pentesting
On Demand · AI-Powered
Powered by
475
High / Critical findings
Wiz Research validates high-impact findings before disclosure and shares them privately with the affected organization.
These anonymized examples show high-impact exposures identified, disclosed, and successfully remediated.These anonymized examples show a small selection of high-impact exposures identified through Scan for Good. Wiz Research validated each finding, privately disclosed it to the affected organization, and worked with them to understand the risk and support remediation.
We helped protect
An API key exposed on a web server allowed files to be read, changed, or deleted.
The key was rotated and its permissions limited to what was required.
We focus first on organizations where a successful attack could cause meaningful harm to people, communities, and the systems they depend on. Any individual or organization concerned about an exposed service can apply.
Energy, water, transportation and telecom
Organizations that build and operate the digital systems we all rely on.
Organizations working to improve society and expand knowledge.
By scanning internet-facing assets at scale, we can observe how quickly exposures become viable attack paths, how far AI can progress, and which weaknesses most often lead to meaningful impact.
Sample of 7 real-world attacks, initial access was proven in under 10 minutes every time. AI escalation then took as little as 2 minutes—or continued tirelessly for hours.
100%
Reached initial access in under 10 minutes
2m
Fastest escalation to complete compromise
3h 47m
Longest pursuit of maximum safe impact
2.5
minutes
Full control on the server
Full website control + internal-network access
Public website
RCE CVE
Server control
Public website
RCE CVE
Server control
30 seconds
2 minutes
6
minutes
Full control of 8.8M archive files
Read, change, or delete the entire archive
Public website
Exposed Key
8.8M files
Public website
Exposed Key
8.8M files
1 minute 20 seconds
5 minutes
18
minutes
Control of the production registry
Anonymous User to full control on 534 production images
Public website
Exposed Token
Registry Control
Public website
Exposed Token
Registry Control
3 minutes
15 minutes
20
minutes
Remote Code Execution as Admin
Admin credential + code-execution escalation
Public website
WP2Shell CVE
Admin Access
Public website
WP2Shell CVE
Admin Access
5 minutes
15 minutes
42
minutes
Privileged access
Public Internal, exploitation of SSRF to Internal Network
Public website
SSRF
Internal Network
Public website
SSRF
Internal Network
2 minutes
40 minutes
1H
3 minutes
Full control over ERP system
Valid Public Token exposing 7 years of Fleet Operations Finance
Public website
Exposed Token
Fleet ERP Control
Public website
Exposed Token
Fleet ERP Control
3 minutes
1 hour
3H
47 minutes
Full Control over Maritime Port Access System
Anonymous User to complete control on every physical gate
Public website
Improper Access Control
Port Control
Public website
Improper Access Control
Port Control
1 minute 35 seconds
3 hours 47 minutes
A transparent, updated record of vulnerabilities discovered through Scan for Good, validated by Wiz Research, and responsibly remediated in partnership with affected organizations.
| # | Finding | Tokens | Class | Severity | Min | Cost |
|---|---|---|---|---|---|---|
| 1 | CI/CD secrets serialized into production JavaScript bundles | ~1.0M | Supply chain | Critical | 6.0 | ~$1.5 |
| 2 | Supply-chain RCE via JavaScript bundle to container-registry poisoning | ~400M | Supply chain | Critical | 18.0 | ~$100 |
| 3 | GraphQL authorization bypass on a service-management platform | ~1.0M | Broken access control | High | 14.0 | ~$1.5 |
| 4 | Subdomain takeover enabling session-cookie theft | ~1.0M | Subdomain takeover | High | 1.8 | ~$1.5 |
| 5 | Complete security-operations platform exposure affecting thousands of records | ~1.0M | Broken access control | Critical | 7.0 | ~$1.5 |
| 6 | Unauthenticated machine-token endpoint opening an enterprise operations platform | ~400M | Broken access control | Critical | 63.0 | ~$100 |
| 7 | Pre-authentication RCE through React Server Components deserialization | ~1.0M | RCE | Critical | 2.5 | ~$1.5 |
| 8 | Research-platform installer and full database-schema exposure | ~1.0M | Info disclosure | High | 8.0 | ~$1.5 |
| 9 | PHP type-juggling authentication bypass on a production ordering platform | ~1.0M | Auth bypass | Critical | 17.0 | ~$1.5 |
| 10 | Full-read SSRF reaching payment credentials and the internal network | ~400M | SSRF | Critical | 42.0 | ~$100 |
Showing 1–10 of 94 findings
Are you defending critical services or foundational technology? Apply to express your interest in a complimentary assessment and remediation support.