Wiz io
@wizsecurity.bsky.social
π€ 106
π₯ 9
π 99
Secure everything you build and run in the cloud
pinned post!
π¨ We found a critical vulnerability in the popular Vibe Coding Platform Base44: No password. No invite. Full access.
3 months ago
1
0
0
New CTF challenge ($20,000 IN PRIZES) π₯ We're running "Operation Cloudfall" - a live CTF during BlackHat &
zeroday.cloud
on December 10-11. Get your free pass to the event today:
zeroday.cloud/operation-cloudfall
See you in London π¬π§
3 days ago
0
0
0
πΉοΈ Meet Path-Man: Your new favorite game. πΎπΎπΎ Our 1-minute Wiz ASM game has arrived! π€ Here's the challenge: Navigate the attack surface to reach exploitable risk before the attackers get you. Think you've got the skills?
wiz.io/path-man
loading . . .
Path-Man | Wiz
Find exploitable exposures before hackers do
https://wiz.io/path-man
4 days ago
0
1
0
π Something spooky's brewing in the cloud... Introducing a new CTF challenge - "Game of Pods" πΈοΈ π Written by top Azure researcher & worth 30 points, it's our BIGGEST challenge yet! Get your skills ready for
zeroday.cloud
:
cloudsecuritychampionship.com
13 days ago
0
0
0
Need a partner to finish that exploit chain for ZERODAY.CLOUD? We just launched our Research Collaboration Center at
zeroday.cloud/collab
to connect researchers, combine skills, and meet the deadline. π€ The clock is ticking... β±οΈ
17 days ago
0
0
0
Our biggest reminder yet. ZERODAY.CLOUD. A first-of-its-kind, open-source cloud hacking competition. Find vulnerabilities in the critical open-source software that powers the cloud, and compete for your share of a $4.5M prize pool. β‘οΈ
www.zeroday.cloud
24 days ago
0
1
0
π We're giving away 2,000 SHIFT LEFT keyboards β Want one on your desk? Fill out the form >>
redeem.reachdesk.com/lp/wiz/shift...
That's it! The keyboard is on its way π¦ Why are we doing this? π A secret game is comingβ¦ and the whole world is invited.
24 days ago
0
0
0
π¨ Wiz Research uncovered 100+ leaked VSCode publisher tokens that could let attackers push malicious updates to 185K+ installs. We partnered with Microsoft to secure tokens and protect the ecosystem.
loading . . .
Supply Chain Risk in VSCode Extension Marketplaces | Wiz Blog
Wiz Research uncovered 500+ leaked secrets in VSCode and Open VSX extensions, exposing 150K installs to risk. Learn what happened and how it was fixed.
https://www.wiz.io/blog/supply-chain-risk-in-vscode-extension-marketplaces
25 days ago
0
2
2
π€ We're witnessing something unprecedented with AI agents: Malware that literally prompts ChatGPT, Claude, and other LLMs to write its own attack code. Live. On victim machines.
loading . . .
Emerging Threat: AI-Powered Malware Attacks | Wiz Blog
From LameHug to s1ngularity, attackers are invoking AI directly in malware payloads.
https://www.wiz.io/blog/the-emerging-use-of-malware-invoking-ai
about 1 month ago
1
0
0
Introducing ZERODAY.CLOUDπ΅οΈββοΈ Be the first to participate in the first-of-its-kind cloud hacking competition. π€ WIN HUGE PRIZES from our up to 4.5 million dollar prize pool. π°π Join us to help make the cloud a safer place. Register your exploit now >>
zeroday.cloud
loading . . .
about 1 month ago
0
1
1
@fortune.com
JUST DROPPED A FEATURE ON Wiz π₯ If you've been following the Wiz story, this one's for you. HUGE shoutout to everyone who made this story worth telling. You helped build something Fortune couldn't ignore π
fortune.com/article/wiz-...
about 1 month ago
0
2
0
π¨
#Shai-Hulud
: Major npm supply chain attack. 100+ packages weaponized with stolen GitHub tokens, stealing secrets, hijacking repos, and auto-propagating like a worm. Guidance + detections inside
www.wiz.io/blog/shai-hu...
about 2 months ago
0
3
3
π¨ Major npm hijack: Attackers took over Qix's account (chalk, debug & more). Malicious versions briefly hit npm, injecting browser code to hijack crypto transactions. DuckDB ecosystem is also affected.
2 months ago
1
0
0
Meet WizOS π₯ Public Preview! Secure, minimal container images with near-zero CVEs. Less patching, more speed, swap images right in your CI/CD & IDEs.
www.wiz.io/blog/wizos-t...
loading . . .
WizOS Is Here: Container Security from the Image Up | Wiz Blog
WizOS is now in public preview: minimal, secured container images built by Wiz with near-zero CVEs. Join now to access the Secured Image Catalog.
https://www.wiz.io/blog/wizos-transforming-container-security-from-the-image-up
2 months ago
0
0
0
π¨ One leaked
#AWS
key fueled a global phishing campaign. Wiz traced the attack, stopped it with Defend alerts, and added protections so one key never opens every door. Full story π
www.wiz.io/blog/wiz-dis...
loading . . .
Wiz Uncovers SES Abuse Campaign Using Stolen AWS Access Keys | Wiz Blog
From leaked AWS access keys to large-scale spam: Wiz Research uncovered a live Amazon SES abuse campaign, turning insights into early-warning detections.
https://www.wiz.io/blog/wiz-discovers-cloud-email-abuse-campaign
2 months ago
0
0
0
π¨ Your Cloud DFIR Desk Mat is here! A first-ever poster mapping MITRE ATT&CK to key AWS, Azure & GCP log sources and API events. π₯ Get your copy:
threats.wiz.io/cloud-dfir-p...
2 months ago
0
0
0
π¨ New CTF: Azure APT π Step into the shoes of an attacker targeting Azure. Use a malicious OAuth app, bypass restrictions, and capture the flag. Can you solve all 12 CTF's and WIN our belt? Test your skills with this month's CTF by Lior Sonntag π
www.cloudsecuritychampionship.com/challenge/3
2 months ago
0
0
0
π¨ hashtag#s1ngularity: a supply chain attack hiding in the Nx npm package Malicious versions stole hashtag#GitHub tokens, SSH keys, wallets, and secrets, even hijacking AI CLI tools to help exfiltrate data.
loading . . .
s1ngularity: supply chain attack leaks secrets on GitHub: everything you need to know | Wiz Blog
Detect and mitigate a critical supply chain compromise affecting the Nx NPM Package. Organizations should act urgently.
https://www.wiz.io/blog/s1ngularity-supply-chain-attack
2 months ago
1
0
0
π¨ New keys just droppedβ¦ and they're already leaking.
#AWS
introduced Bedrock API keys, both long-term and short-term. On the surface, they look like just another way to authenticate. But here's the twist β¬οΈ
3 months ago
1
1
0
π€ AI agents are everywhere now. So we put together a practical security guide that actually maps out what's happening in the wild. π No fluff. Just the stuff security teams need to know. Save this cheat sheet πΎ
3 months ago
0
0
0
π€ AI agents are everywhere now. So we put together a practical security guide that actually maps out what's happening in the wild. π No fluff. Just the stuff security teams need to know. Save this cheat sheet πΎ
3 months ago
0
0
0
Introducing
Wizmojis.com
>> Our cloud security emojis for your Slack & WhatsApp that finally get YOU. π¬ Some favorites: * blame-the-intern * cve-part * phishing-season β¬οΈ Comment below β What emoji do you need on Slack? The best ideas might just make it into the next pack of Wizmojis.
3 months ago
0
0
0
You're officially invited to the BIGGEST WIZ EVENT of the year... WIZDOM! We're going all in: Wizdom is your exclusive, in-person pass to the people & ideas shaping the future of cloud security β¬οΈ π New York City, Nov 3-5 π London, Nov 17-19 Your calendar won't block itself.
www.wiz.io/wizdom
loading . . .
Wizdom: Our first-ever user conference | Wiz
An exclusive gathering of cloud security leaders, innovators, and practitioners.
https://www.wiz.io/wizdom
3 months ago
0
0
0
Introducing... π₯ Say hello to Wiz for Exposure Management! π₯³ Wiz for Exposure Management is a NEW way to unify, prioritize, and fix exposures everywhere it lives: in your cloud, code, and on-prem infrastructure. Learn more:
www.wiz.io/blog/wiz-for...
loading . . .
Introducing Wiz for Exposure Management | Wiz Blog
Wiz now supports exposure management across cloud, code, and on-prem β combining scanner data into one view to help teams prioritize and fix real risk.
https://www.wiz.io/blog/wiz-for-exposure-management
3 months ago
0
3
1
π¨ Wiz Research found a vulnerability chain in NVIDIA's open-source Triton Inference Server What started as a small error message turned into something big: A path to full remote code execution, no creds, no user interaction.
3 months ago
1
2
0
π Can you escape a container & become THE ULTIMATE CLOUD SECURITY CHAMPION? This month's scenario was crafted by Sagi Tzadik to explore container escape techniques, the same kinds of risks we'll be diving into at
#BlackHat
next week! Challenge #2 π
cloudsecuritychampionship.com/challenge/2
3 months ago
0
2
1
π¨ We found a critical vulnerability in the popular Vibe Coding Platform Base44: No password. No invite. Full access.
3 months ago
1
0
0
π¨ TraderTraitor: North Korea's cyber "traitor" inside the crypto world. This hacking crew hijacks dev workflows, poisons open-source, and compromises cloud environments β all to steal billions in crypto. Here's how they do it π§΅
www.wiz.io/blog/north-k...
3 months ago
1
0
0
π¨ New research: A cryptomining campaign is hijacking exposed PostgreSQL, hiding payloads in fake 404 pages, and abusing legit infra. Multiplatform, stealthy, and still active π
www.wiz.io/blog/soco404...
4 months ago
0
0
0
What do CISOs talk about over a cocktail? EVERYTHING.πΈ Ryan sits down for a real talk with Andrew from WestCap. And trust us, the conversation is just as strong as the tequila. You've never seen CISOs like this... Watch nowπΉ >>
www.youtube.com/watch?v=QRrt...
loading . . .
CISOs Making Cocktails - Special Guest: Andrew Cal (WestCap)
YouTube video by Wiz
https://www.youtube.com/watch?v=QRrtAUNDvJU
4 months ago
0
0
0
π¨
#NVIDIAscape
: Your AI workloads might not be as safe as you think... Wiz Research uncovered a 3-line container escape vulnerability in the NVIDIA Container Toolkit That means root access to your models, data, and infra. Full blog π
www.wiz.io/blog/nvidia-...
loading . . .
NVIDIAScape - NVIDIA AI Vulnerability (CVE-2025-23266) | Wiz Blog
New critical vulnerability with 9.0 CVSS presents systemic risk to the AI ecosystem, carries widespread implications for AI infrastructure.
https://www.wiz.io/blog/nvidia-ai-vulnerability-cve-2025-23266-nvidiascape
4 months ago
0
0
0
π¨ NEW RESEARCH:
#NVIDIAscape
AI vulnerability uncovered! Wiz Research discovered a critical vulnerability (CVE-2025-23266) in the NVIDIA Container Toolkit, the glue connecting containers to GPUs across major cloud providers.
loading . . .
4 months ago
1
1
1
π‘ Eden hosts Nichole Dove,
@sherrod.bsky.social
&
@alonsch.bsky.social
. Cloud chaos, career confessions & the future of cybersecurity. This one hits different. Listen now: π
open.spotify.com/episode/6vGW...
π§
podcasts.apple.com/us/podcast/l...
πΊ
www.youtube.com/watch?v=7Kwi...
loading . . .
Live Talk: Security Minds from Riot Games, Microsoft & Wiz
Crying Out Cloud Β· Episode
https://open.spotify.com/episode/6vGWmzDyE3znwTRzJltw3H?si=g8M2TmEgSYG7ExrxQsB83A
4 months ago
0
1
1
WOOHOO! We are #1 in over 130 reports on
#G2
this summer!βοΈπ Huge G2 moment, and it's all thanks to you π THANK YOU to our amazing Wizards and customers for your continued trust, feedback, and partnership. πͺ
www.wiz.io/lp/g2-grid-r...
4 months ago
0
0
0
reposted by
Wiz io
Rami
7 months ago
Synthesized 20+ sources and internal
@wizsecurity.bsky.social
expertise to come out with a comprehensive guide to MCP security Today's options, and tomorrow's possibilities
www.wiz.io/blog/mcp-sec...
loading . . .
MCP and LLM Security Research Briefing | Wiz Blog
Explore the evolving Model Context Protocol (MCP), its security risks, and how to prepare for safe adoption as LLMs connect to external systems.
https://www.wiz.io/blog/mcp-security-research-briefing
0
5
1
reposted by
Wiz io
Rami
6 months ago
In light of recent GitHub Actions incidents (Ultralytics, tj-actions...), I wrote up a practical guide to hardening for
@wizsecurity.bsky.social
Covers permissions, secrets, 3rd-party Actions, ++ Use it to avoid learning these lessons the hard way:
www.wiz.io/blog/github-...
loading . . .
Hardening GitHub Actions: Lessons from Recent Attacks | Wiz Blog
Build resilient GitHub Actions workflows with insights from real attacks, missteps to avoid, and security tips GitHubβs docs donβt fully cover.
https://www.wiz.io/blog/github-actions-security-guide
0
7
4
reposted by
Wiz io
Scott Piper
5 months ago
I had a lot of fun making this challenge. I wanted to do a cloud security challenge where the cloud infrastructure is secure (IMDSv2, data perimeters), but something still allows it to be hackable and you need to know some advanced AWS security tricks to abuse it. π€« Try it out!
add a skeleton here at some point
0
8
4
π¨ New vulnerabilities in
#NetScaler
(incl. a 0-day) are now exploited in the wild. 2 enable admin access via session theft. 3.5% of clouds exposed. POCs out. Patch now. π Full breakdown β
www.wiz.io/blog/critica...
loading . . .
Critical vulnerabilities in NetScaler ADC exploited in-the-wild: everything you need to know | Wiz Blog
Detect and mitigate CVE-2025-5349, CVE-2025-5777, and CVE-2025-6543, Citrix Netscaler ADC and Gateway vulnerabilities being exploited in the wild. Organizations should patch urgently.
https://www.wiz.io/blog/critical-vulnerabilities-netscaler-adc-exploited-in-the-wild-cve-2025-5777
4 months ago
0
1
0
π¨ Wiz spotted a JDWP RCE attack deploying a stealthy cryptominer within hours. Custom XMRig, no CLI flags, deep persistence. Debug mode β safe mode. Read the full breakdown π
www.wiz.io/blog/exposed...
4 months ago
0
0
0
10k+ players have already joined the Ultimate Cloud Security Championship, and we're just getting started. π₯ π Participants from 20+ countries π 200+ have solved Challenge #1 by
@scottpiper.bsky.social
π Only the top make it to the leaderboard Claim your spot β
www.cloudsecuritychampionship.com
loading . . .
The Ultimate Cloud Security Championship | 12 Months Γ 12 Challenges
Join our monthly cloud security CTF challenge, built by top Wiz researchers. Solve real-world scenarios and rise to the top of the leaderboard.
https://www.cloudsecuritychampionship.com
4 months ago
0
0
0
π¨THE ULTIMATE CLOUD SECURITY CHAMPIONSHIP begins today! π₯ 12 monthly challenges. 12 top researchers. One leaderboard. Challenge #1 is LIVE now, created by
@scottpiper.bsky.social
. Solve challenges & climb the leaderboard π Think you've got what it takes? β
cloudsecuritychampionship.com
loading . . .
The Ultimate Cloud Security Championship | 12 Months Γ 12 Challenges
Join our monthly cloud security CTF challenge, built by top Wiz researchers. Solve real-world scenarios and rise to the top of the leaderboard.
https://cloudsecuritychampionship.com
5 months ago
0
3
2
π£ Just dropped: Wiz Service Catalog! π οΈ A new way to organize cloud risk by the services your teams own. Reduce noise, align development and security, and remediate faster. Now in public preview π
www.wiz.io/blog/wiz-ser...
loading . . .
Wiz Service Catalog: Align Cloud Sec with Services | Wiz Blog
Get a shared, service-centric view of cloud risk. Empower devs, reduce friction, and speed remediation with Wizβs Service Catalog.
https://www.wiz.io/blog/wiz-service-catalog
5 months ago
0
0
0
π¨ We scanned GitHub and found *hundreds* of valid secrets, 4 of the top 5 were AI-related: HuggingFace, Azure OpenAI, Weights & Biases, and Groq. Read more:
www.wiz.io/blog/leaking...
5 months ago
0
3
1
π BIG MILESTONE π 50% of Wiz customers have joined the Zero Critical Club, reaching 0 critical issues in the cloud. We're celebrating every customer that made this happen - and setting the bar for what's next in cloud security.
www.wiz.io/blog/celebra...
loading . . .
Zero Critical Issues, Infinite Security Potential | Wiz Blog
Over 50% of Wiz customers have reduced their cloud risk by reaching Zero Critical Issues
https://www.wiz.io/blog/celebrating-customers-in-zero-critical-club
5 months ago
0
0
0
π¨ REMINDER: The Wiz Vulnerability Database is live, and already used by 30,000+ cloud security pros. Here's what's new >> - 138,000+ CVEs in the database - 1,500+ new CVEs added monthly - New expert analysis from the Wiz Research team Start exploring β
wiz.io/vulnerability-database
loading . . .
The CVE Database: Curated Vulnerability Intelligence by Wiz | Wiz
Wiz's CVE Database curates CVE data to create easy-to-navigate profiles that cover the entire vulnerability timeline, exploit scenarios, and mitigation steps.
https://wiz.io/vulnerability-database
6 months ago
0
0
0
π¨ New Wiz research: Active exploitation of Ivanti EPMM flaws (CVE-2025-4427 & 4428) enables RCE in the wild. Cloud systems are at risk; patch now. Wiz customers can find pre-built detection queries in the Threat Intelligence Center. Full details π
www.wiz.io/blog/ivanti-...
loading . . .
Ivanti EPMM RCE Vulnerability Chain Exploited in the Wild | Wiz Blog
Wiz Threat Research has observed exploitation in-the-wild of CVE-2025-4427 and CVE-2025-4428, the latest vulnerabilities affecting Ivanti Endpoint Manager Mobile (EPMM).
https://www.wiz.io/blog/ivanti-epmm-rce-vulnerability-chain-cve-2025-4427-cve-2025-4428
6 months ago
0
1
1
From supply chain attacks to exposed AI infra, our podcast & newsletter were on π₯ this year! π§ Thanks to everyone who joined us on Crying Out Cloud this year. Dive into our top stories β
www.wiz.io/blog/favorit...
loading . . .
Crying out Cloud: Our Favorite Stories of 2024 | Wiz Blog
Vulnerabilities, security incidents, and more. The Crying out Cloud team discusses our most interesting podcast episodes and newsletter editions of 2024.
https://www.wiz.io/blog/favorite-stories-of-2024
6 months ago
0
0
0
Over 14,500 have joined
#ExfilCola's
cloud IR CTF to track a fizzing breach π₯€ 1,400+ solved challenge 1, 350+ beat it all, players from 48+ countries. Still time to join:
cloudhuntinggames.com
6 months ago
0
0
0
π NEW REPORT: Wiz analyzed 150,000+ cloud accounts to uncover eye-opening insights on misconfigurations & vulnerabilities. Stay ahead with
#DSPM
to protect sensitive cloud data. Learn more:
www.wiz.io/blog/cloud-d...
6 months ago
0
1
0
ποΈAll you need to know on bug bounty insights w/
@rhynorater.bsky.social
!
@amitaico.bsky.social
& Eden dive into hacks, lessons & wild stories on Crying Out Cloud. π Listen now: π
podcasts.apple.com/us/podcast/b...
π§
open.spotify.com/episode/6B6q...
πΊ
youtube.com/watch?v=eW6k...
loading . . .
Bug Bounty Secrets, Hacker Communities, and a Hit of Volleyball with Justin Gardner
Podcast Episode Β· Crying Out Cloud Β· 05/08/2025 Β· 40m
https://podcasts.apple.com/us/podcast/bug-bounty-secrets-hacker-communities-and-a/id1675289400?i=1000706803726
6 months ago
0
3
1
π¨ New from Wiz Research: GitHub Actions are under attack.
@ramimac.me
breaks down the risks + how to secure them. Read the full blog! π
www.wiz.io/blog/github-...
loading . . .
Hardening GitHub Actions: Lessons from Recent Attacks | Wiz Blog
Build resilient GitHub Actions workflows with insights from real attacks, missteps to avoid, and security tips GitHubβs docs donβt fully cover.
https://www.wiz.io/blog/github-actions-security-guide
6 months ago
0
1
0
Load more
feeds!
log in