Rust Supply Chain Attack on arrayref: Significant Overlap with DPRK Campaigns
Malicious versions of the arrayref Rust crate (and others) executed a backdoor at compile time. The campaign's infrastructure overlaps with recent DPRK supply chain attacks, including Mastra and axios...
Wiz 渗透测试发现功能正式发布,统一多源安全测试结果
Wiz 宣布渗透测试发现功能正式 GA,将漏洞赏金、第三方审计、内部红队演练和 AI 扫描结果统一到一个平台。支持 PDF 报告 AI 解析、Mika AI 交互式创建发现项、MCP 协议接入外部 AI 扫描工具,以及 Green Agent 自动分配负责人和生成修复建议。 

如何识别并阻止恶意设备加入 Entra ID
Wiz 发现攻击者正利用 AI 生成看似正常的设备名称和 User-Agent 字符串,绕过 Entra ID 的静态检测规则。文章提出通过行为分析(命名异常检测、设备码钓鱼与后续注册关联)来识别这类攻击,并建议为设备注册强制开启 MFA。 

2026 Wiz 合作伙伴联盟奖获奖名单公布
Wiz 在 Build with Wiz 合作伙伴峰会上公布 2026 年合作伙伴联盟奖获奖名单,覆盖美洲、EMEA 及澳新地区。Accenture 三地区均获奖,AWS、Microsoft 分获 CSP 相关奖项,Deloitte、Devoteam、Versent 获 AI 安全卓越奖。 

GitHub Copilot Autofix 引入漏洞,Snowflake Jira 敏感数据遭入侵
Wiz Red Agent 独立发现并 exploits GitHub Copilot Autofix 引入的 GitHub Actions 漏洞,无需人工干预即可访问 Snowflake 内部 Jira 的敏感数据。 AI 自动修复代码反而引入安全漏洞,CI/CD 流水线安全性引发关注。
Wiz 闭环修复手册:用 AI 对抗 AI 威胁
Wiz 发布闭环修复手册,提出用 Red Agent 发现攻击路径、Green Agent 生成修复方案、Remediation and Response 执行修复、Wiz Workflows 编排全流程的五步框架。 文章引用 2026 Verizon DBIR 数据称未修补漏洞中位修复时间为 47 天,并提及 Hugging Face 事件作为 AI 自动化攻击案例。全文以产品功能介绍为主,含 Fireblocks 客户引语。 

Wiz 内部 FinOps 团队如何用 Wiz Cloud Cost 管理云成本
Wiz 内部 FinOps 团队用自己的 Wiz Cloud Cost 产品管理云成本,将基础设施图谱、Cloud Events 操作日志和财务数据三层信息整合,实现从账单异常到根因代码的快速定位。 实测案例:某月 S3 ListBucket API 调用量从日均 200 万飙升至 1 亿,Mika AI 结合 Cloud Events 在几分钟内定位到是一个 feature flag 开启后触发了新的物化视图查询路径。 成本优化与安全降低存在重叠场景,如清理超过 90 天未使用的密钥和影子存储,仅此两项每年节省数十万美元。成本异常还可作为安全事件早期预警信号,如未授权挖矿、日志摄入异常等。 

AI时代的数据安全:从分类到真实风险评估
Wiz发布AI时代数据安全指南,核心观点是AI改变了数据访问方式,传统分类工具不够用,需要结合身份、权限、漏洞等上下文判断真实风险。 文章介绍了Wiz的Red Agent和Green Agent功能,但整体是产品营销文,没有新事实或独特观点。 

How to Investigate GitHub PAT Compromise: Lessons From a Multi-Organization Campaign
A practical playbook for investigating GitHub token compromise, drawn from Wiz CIRT's response to a coordinated multi-organization campaign.
关闭供应链安全盲区:保护开发者的个人代码仓库
企业安全程序通常只扫描组织内部的代码仓库,但开发者在个人GitHub账号中维护的公开仓库同样可能泄露公司凭证。Wiz研究发现,56%影响公司的密钥泄露发生在员工个人仓库中,65%的Forbes AI 50企业存在已验证密钥泄露。 AI辅助开发加速了密钥传播,前五大最常泄露的已验证密钥中有四个来自AI服务。传统密钥扫描无法覆盖组织边界外的个人仓库,Wiz通过关联开发者身份与个人公开仓库、验证密钥是否可被实际利用来填补这一盲区。 

Metabase SQL注入漏洞深度解析:已在野外被利用
Wiz Research逆向分析了Metabase 1.58+版本的零日SQL注入漏洞,该漏洞已在野外被实际利用。约13%的云环境部署了自托管Metabase实例,其中25%完全暴露在互联网上。 漏洞根因是Clojure的merge函数不剥离额外key,配合HoneySQL的:raw关键字特性,攻击者可通过/api/session/reset_password接口注入任意SQL。 PoC已公开,受影响用户需立即升级。 

2026 上半年云安全威胁汇总
Wiz Research 和 CIRT 发布了 2026 年上半年云与 AI 威胁活动汇总报告,涵盖 1 至 6 月期间追踪到的主要云安全威胁事件。
Wiz Brings Automated DISA STIG Assessment to Amazon Linux 2023 and Windows Server 2025
Automating DISA STIG Compliance for Amazon Linux 2023 and Windows Server 2025, giving defense and federal teams immediate and continuous hardening validation.
Keyv与Cacheable npm包遭供应链攻击
Wiz Research发现npm生态Keyv/Cacheable多个包遭供应链攻击,攻击者通过盗取的GitHub维护者账号发布含恶意代码的版本。恶意载荷属于"Mini" Shai-Hulud家族,目标窃取云凭证、AI配置文件和加密货币钱包,数据通过新建GitHub仓库外泄。 受影响包超40个,包括keyv 6.0.0、cache-manager 7.2.10等。安全团队需立即移除受影响版本、重建系统、轮换凭证并监控IOCs。 

Wiz at Black Hat 2026: Driving AI Threat Readiness
Announcing new capabilities that help organizations prepare for the AI era by expanding visibility and accelerating response, so security teams can defend at machine speed.
Introducing the Wiz Sensor for Developer Workstations to Protect Endpoints in the AI Era
As AI expands who builds software, the developer workstation is becoming a new security perimeter. AI and third-party software increasingly operate with access to your most sensitive credentials and c...
S3 Clones in the Neoclouds
S3 compatible services carry many of the same concerns as the original S3 service. This article highlights which assumptions break and what risks remain. 

Rethinking Scanning for the AI Era: Wiz’s Agentic Code Security System
Enterprise AI AppSec requires more than powerful models. It requires a system that balances speed, depth, and cost across the software lifecycle. 

CosmosEscape:接管 Azure Cosmos DB 中的每一个数据库
<p>Azure Cosmos DB 中的一个关键漏洞链允许对每个 Cosmos DB 数据库进行完全的读写访问。</p> 

Wiz’s First 6 Months as Part of Google
Fast gets even faster: redefining security for the AI era and doubling down on our multicloud commit 

The Wiz Red Agent is Now Generally Available
Continuously uncover complex, exploitable risks to stay ahead in the AI Threat Era with the Red Agent 
