ICYMI: June 2026 @AWS Security
Read all about the latest AWS security features, compliance updates, and hands-on resources in our new, monthly digest posts. You’ll find expert blog posts, new…
Read all about the latest AWS security features, compliance updates, and hands-on resources in our new, monthly digest posts. You’ll find expert blog posts, new…
Infrastructure-as-Code (IaC) is a gift to engineers. By centralizing infrastructure definitions in Terraform, teams can standardize, review, and reuse patterns across every environment. HashiCorp has…
We are excited to share that Wiz for Government has achieved FedRAMP® High authorization. This milestone reinforces Wiz’s commitment to helping U.S. public sector organizations…
On July 14, 2026, an attacker opened 37 pull requests to the AsyncAPI generator repository. Almost all attempted to add a fake charity donation page.…
Recently there have been a few malicious campaigns involving attacker payloads that invoked AI. AI has been used by threat actors for all sorts of…
We are pleased to announce the publication of a new AWS compliance implementation guidance: HITRUST i1 Compliance on AWS: Customer Implementation Guidance with an Illustrative…
A scan can find risks, but without context, it is impossible to know which ones truly matter. A vulnerability may look critical, but if it…
Every security domain has a number that tells you how much of it is under control. Identity has MFA adoption. Patching has mean time to…
The Wiz Research team is proud to launch zeroday.cloud, a first-of-its-kind cloud hacking competition with a prize pool totaling up to about $4.5 million in…
AI is changing the way organizations build, ship, and interact with software. And with it comes a new security reality. As more teams adopt generative…
Intro In recent years, attackers have increasingly turned to “malware-less” Living-off-the-Land operations against cloud and SaaS environments. This trend has also extended to extortion and…
Wiz Research has uncovered a critical Remote Code Execution (RCE) vulnerability, CVE-2025-49844 which we’ve dubbed #RediShell, in the widely used Redis in-memory data structure store.…