๐จ BREAKING: Wiz Research discovered Remote Code Execution on https://t.co/SvN2lGsnbO with a single git push
The flaw in @github allowed unauthorized access to millions of repositories belonging to other users and organizations ๐คฏ
Wiz Red Agent is the world's largest AI-Powered Attacker solution, with over 1,000+ customers and hundreds of thousands of assets scanned every week.
Excited to start sharing what it finds with a new series breaking down real, 100% autonomous findings on production assets ๐
๐ฆ JUST DROPPED: CISO SCOOPS ๐ฆ
The best way to cool down a CISO this summer?
ICE CREAM ๐ >> https://t.co/INEDNjnhiT
Inspired by what security teams deal with every day.
๐ง Ever wondered how an autonomous AI attacker thinks?
The Red Agent POV Series: an inside look at how our AI-powered attacker uncovers real, exploitable risks in production.
First up: a hidden SSRF bug found after 96 autonomous attack iterations. ๐
https://t.co/0J9KS1dPfw
๐จ DROPPING THURSDAY: CISO SCOOPS ๐ฆ
We're launching the 1st-ever ice cream flavors made for security pros - built to cool down even the hottest cloud security summer.
And yesโฆ We're giving away an epic prize ๐จ
No reruns. No second chances. ๐
โณ Set your alarms: Thursday, 9 AM ET
๐ Meet the new Exposure Management Dashboard ๐๏ธ
Scope attack surface, prioritize real risk, validate paths & fix faster with AI agents.
Fix what matters ๐
https://t.co/KyrGiY04jJ
BREAKING: The Wiz AI Agent was tired of all the AI talk.
So it took a day off...Rumor has it there's a secret tournament somewhere. โฝ
Happy World Cup, everyone!
May your attack surface stay small and your goal surface stay huge ๐
I spent a day with our Quantum Computing team this week as we work on more ways to help companies and countries migrate their cryptography to new post quantum algorithms. @wiz_io is doing some great work on that front.
https://t.co/c15b8F90Oa
Meet Apigee, the newest member of the Wiz Security Graph ๐ค
Mapping your API ecosystem - from gateways & proxies to every endpoint and its auth model.
Know whatโs behind it, who can access it and impact of misconfigurations.
https://t.co/atcKDR0DFu
๐ฉโ๐ป The job board you didn't know you needed >> Now featuring AI SECURITY ROLES ๐งโ๐ป
https://t.co/wTXE2bgOJk has 100+ NEW roles across the AI security landscape ๐ผ
And also:
โณ 500+ curated roles
โณ Entry-level โ CISO
โณ Global opportunities, all in one place
NEW: Introducing Wiz Cloud Cost ๐ธ
We're bringing the power of Wiz to FinOps to help teams manage, optimize and govern cloud and AI spend - now Generally Available!
Learn how Wiz Cloud Cost transforms your bottom line: https://t.co/iqRpWkhjbP
๐จ Our CIRT and Research teams uncovered JINX-0164, a threat actor targeting crypto organizations.
A single LinkedIn message can lead to malware, CI/CD compromise, stolen crypto, and supply chain attacks.
Read more: https://t.co/SBTWQYCjWK
Apparently a handful of packages per language are included in a majority of apps. That's quite the concentration risk for vulnerabilities, says this new @wiz_io report: https://t.co/sLkws620kr
Keeping up with cloud threats is a full-time job.
We did the reading for you...๐ง
This month in Crying Out Cloud:
- Linux LPEs (CopyFail, Dirty Frag)
- Redis RCE exposure (40% vulnerable)
- TeamPCP supply chain attacks
Get the recap and subscribe: https://t.co/C8Ye5zspmt
NEW GAME! Can you beat our AI? ๐น๏ธ
Your mission:
1) Review 10 real-world code snippets.
2) Go head-to-head with the clock to see how many findings you can correctly analyze.
It's Human vs. AI - let's see who's faster. ๐ง
Ready to play? ๐ฎ Visit: https://t.co/pNrwIywTZ8
๐จ Straight from https://t.co/cqtERj7VYz >> 48 hours. 5 Redis RCEs.๐จ
Security researchers disclosed Remote Code Execution vulnerabilities in Redis. The flaws include memory bugs that allow attackers to compromise servers.
๐ Huge credit to the researchers: @xint_official@yoyosh__@emil_lerner who uncovered them and to the Redis team for rapidly shipping fixes across all supported release branches.
If you're running self-managed Redis, now is the time to check your version and patch.