Unpacking the 2025 Gartner Market Guide for CNAPP
At Wiz, our vision for cloud security has always been a unified, collaborative platform that empowers teams across the organization. That’s why we’re excited about…
At Wiz, our vision for cloud security has always been a unified, collaborative platform that empowers teams across the organization. That’s why we’re excited about…
Every developer has been there: moving fast, pushing code, and realizing later that a credential made its way into a repo. It’s a common mistake,…
Cloudflare has deployed new Web Application Firewall (WAF) protections for two critical vulnerabilities affecting WordPress. The protections address an Unauthenticated Remote Code Execution (RCE) vulnerability…
Updated August 29th, 2PM UTC with details on the second phase of the attack On August 26, 2025, multiple malicious versions of the widely used…
Wiz Research has been responding to the s1ngularity incident since news first broke on August 26th. At this point, active attacks seem to have lulled.…
Intro The Wiz Research team continuously monitors trends across the threat landscape using Wiz Defend’s threat detection rules. Our goal is to track attacker tradecraft…
Earlier this year we announced the private preview of WizOS: secured, minimal container images built from source and maintained by Wiz at near-zero CVEs. Today…
What happened? On September 8th, 2025, at around 9AM EST, a threat actor had managed to gain control of the npm account of well-known developer…
As software development accelerates, organizations are rethinking how to secure everything from third-party code and cloud infrastructure to developer pipelines and exposed secrets. The growing…
AI is transforming security. While attackers are experimenting with AI to scale phishing, fraud, and automation, defenders are focused on how it can help them…
The European Union’s Digital Operational Resilience Act (DORA) is reshaping cybersecurity in the financial sector by introducing a regulatory framework aimed at strengthening the resilience…
On September 15, 2025, malicious versions of multiple popular packages were published to npm. They contained a post-install script that harvested sensitive data and exfiltrated…