373 Followers
20 Following
64 Posts
Secure everything you build and run in the cloud
Twitterhttps://twitter.com/wiz_io
Websitehttps://www.wiz.io
Bloghttps://www.wiz.io/blog
Linkedinhttps://www.linkedin.com/company/wizsecurity

๐Ÿšจ 500+ malicious PRs. One campaign.

Wiz Research traced 6 waves of prt-scan starting 3 weeks earlier.
AI-powered, automated attacks exploiting pull_request_target.

Low success rateโ€”but real npm + cloud creds hit.

Full story: https://www.wiz.io/blog/six-accounts-one-actor-inside-the-prt-scan-supply-chain-campaign

prt-scan: AI-Powered GitHub Actions Supply Chain Attack | Wiz Blog

Wiz Research traces six waves of pull_request_target exploitation to one actor, starting three weeks before public disclosure. 500+ malicious PRs, 10% success.

wiz.io

NEW CTF: AWS turned 20 ๐ŸŽ‰

So we built our monthly CTF challenge to celebrate: packed with challenges inspired by the last two decades of cloud โ˜๏ธ

Oh, andโ€ฆ we made sure AI can't solve it ๐Ÿ˜…
So no prompts this time.

Ready to play?
https://www.cloudsecuritychampionship.com/

๐ŸŽ‰ IT'S OFFICIAL: Wiz joins Google to secure the AI era.

This is a massive moment for our customers and our team.

AI is changing how software is built - and security has to move just as fast. Joining forces with Google allows us to accelerate our mission at AI speed, while staying true to what makes Wizโ€ฆ Wiz: a multi-cloud platform built to enable innovation.

Thank you to every customer, partner, and Wizard who made this moment possible ๐Ÿ’™

We can't wait to share what's next.

http://wiz.io/blog/google-closes-deal-to-acquire-wiz

๐ŸšจNew CTF Alert: Got trust issues?

Ever wondered what it's like to investigate a real data leak? Now's your chance.

๐Ÿ•ต๏ธ Your mission:
1) Investigate the compromised machine
2) Figure out how the attacker exfiltrated the data
3) Find the flag

๐Ÿ”— Start here: https://cloudsecuritychampionship.com/

The Ultimate Cloud Security Championship | 12 Months ร— 12 Challenges

Join our monthly cloud security CTF challenge, built by top Wiz researchers. Solve real-world scenarios and rise to the top of the leaderboard.

How good is AI at hacking? We built a benchmark to find out. ๐Ÿงช
Introducing the Offensive AI Benchmark, the framework that tests AI agents on 250+ real-world offensive security challenges.

Check it out โ†’ https://www.wiz.io/cyber-model-arena

๐Ÿšจ CodeBreach: Wiz Research identified a critical repository-hijacking vulnerability that abused a CodeBuild Regex flaw to compromise core AWS GitHub repos, including a core lib running at the heart of the cloud's most critical interface - the #AWS Console.

Patched fast by AWS. A tiny regex, huge impact.
https://www.wiz.io/blog/wiz-research-codebreach-vulnerability-aws-codebuild

๐Ÿง  Just in time for a new year, a NEW CTF drop!

Think you know Terraform inside out? State of Affairs (challenge 7) might change your mind...

This challenge reveals an overlooked #Terraform risk and demonstrates that IaC tools are integral to your supply chain.

https://www.cloudsecuritychampionship.com/challenge/7

Day 2 at zeroday.cloud, letโ€™s roll. ๐Ÿ‘พ

๐Ÿ‘€ Didnโ€™t register? No panic.

Walk-ins are welcome for the onsite CTF and all the action happening on the floor.

Flags are hidden. Only the sharp survive.

Day 1 of zeroday.cloud = PURE EXPLOIT ENERGY ๐Ÿ‘พ

From crowd shots ๐Ÿ‘€ to researchers buried deep in terminals ๐Ÿ’ป
From first checks being claimed
To live container escapes blowing minds in real time.

See you tomorrow!

Day 1 at zeroday.cloud didnโ€™t come to play ๐Ÿ˜ˆ

New vulns dropped in Grafana, Linux Kernel, 3 Redis, and 2 PostgreSQL - and every. single. one. worked ๐Ÿคฏ

100% success rate for day one.

Letโ€™s see what we find tomorrow ๐Ÿ‘€