CloudSecurity

Wiz at Black Hat 2026: Driving AI Threat Readiness


In an age where frontier models can autonomously discover zero-day vulnerabilities and chain exploits at machine speed, vulnerabilities will be discovered and disclosed faster than ever before. Organizations face a gap where exploitation happens at AI speed, but defense does not. While the threat is real, we believe that defenders have a fundamental context advantage over attackers, and that machine speed defense is achievable. We created our AI Threat Readiness Framework to help security teams operationalize defense that works at machine speed. 

AI threat readiness is a function of two factors: breadth of visibility and speed of action. In practice, this means being able to answer two questions:

  1. Can you detect and prioritize risks and threats across your entire environment?

  2. Can you respond as quickly as these risks and threats emerge?

At Black Hat, we’re continuing to evolve the Wiz platform to help organizations build for AI Threat Readiness — expanding visibility across the environments where risk exists and accelerating the actions needed to stay ahead of emerging threats.

Breadth of Visibility: Detect and prioritize risk everywhere it exists

AI is fundamentally changing where software is built, how it is deployed, and who — or what — has access to critical systems. The security perimeter now extends beyond cloud workloads to include developer workstations, CI/CD pipelines, AI agents, SaaS applications, and the software supply chain. As these environments become increasingly interconnected, organizations need complete visibility into the assets, identities, data, and risks across their environment to understand their true exposure.

Over the past year, we have significantly expanded the Wiz platform to provide this breadth of visibility across customer environments, including:

  • On-premises and hybrid environments: Extending the Security Graph into on-premises environments via the Sensor Workload Scanner to provide a comprehensive security operating model for hybrid teams.

  • Unified Vulnerability Management: Connecting third-party inventory and risk findings into the Security Graph, enabling unified prioritization across all finding types using Wiz context and attack paths.

  • SaaS Applications: Extending the Security Graph and risk assessment coverage to business critical SaaS applications including M365, closing visibility gaps across the modern enterprise.

But this is only the beginning. As AI widens the security perimeter, we are expanding our coverage to new attack surfaces where organizations need visibility to understand and manage risk.

Extending visibility to developer workstations

Developer workstations are now part of the new security perimeter. Developers hold cloud credentials, publish tokens, and direct access to source code — and AI coding agents now operate with those same permissions at machine speed. According to Wiz’s State of SDLC Security 2026 report, 71% of organizations have at least one AI coding assistant present and 80% use AI IDE extensions, each writing code, calling APIs, and accessing credentials autonomously.

Attackers have taken notice. Wiz Research documented campaigns including Shai-Hulud, Axios, and s1ngularity, each starting at the developer workstation, using malicious packages and compromised IDE extensions to harvest credentials and reach cloud environments, registries, and production systems. Traditional endpoint detection was not built for this threat model — it identifies malicious behavior at the OS level, but cannot continuously understand the developer ecosystem or connect workstation findings to cloud blast radius.

Yesterday, we announced the Wiz Sensor for Developer Workstations in Private Preview for Windows and macOS — giving security teams continuous visibility into every package, IDE extension, and AI tool across the developer fleet, real-time supply chain attack detection, and AI governance to see and control what’s running on every machine.

Uncover complex flaws in code with AI 

AI is also transforming how organizations identify vulnerabilities in their own applications. As software changes continuously, point-in-time code analysis is no longer enough. Security teams need a scalable, continuous and efficient way to get visibility into the vulnerabilities that matter most across their codebase.

To better understand how to deliver AI scanning at scale in an enterprise setting, our research team developed Atlas, an autonomous AI system for vulnerability discovery. Atlas works the way a security research team would: mapping attack surfaces, forming hypotheses, hunting in parallel, and validating every finding with a real, working exploit. By design, it uses a multi-model harness to orchestrate specialized sub agents, routing each stage of an investigation to the best-fit model for the job. And the results speak for themselves: Atlas currently ranks #1 on CyberGym, the public benchmark for AI-driven vulnerability work, with a 90.9% success rate.

While Atlas is not commercially available yet, we’re actively working to incorporate it into our platform to provide security teams with continuous AI analysis within their existing Application Security workflows.

Connecting Google Threat Intelligence to Wiz

Understanding risk requires more than visibility into your own environment—security teams also need context on the evolving threat landscape surrounding their assets, identities, applications, and workloads. By integrating Google Threat Intelligence (GTI) into the Wiz platform, all Wiz customers benefit from the combined intelligence of Mandiant, VirusTotal, and Google, bringing world-class threat research and adversary insights directly into security decisions.

GTI threat intelligence feeds now enrich Wiz risk and threat findings with real-world threat intelligence, helping teams prioritize risks based on active attacker behavior. For malware findings, GTI provides rich context beyond a simple verdict, helping security teams understand the threat and prioritize response before an investigation even begins, powered by one of the industry’s most comprehensive threat intelligence ecosystems. And, as AI introduces new attack surfaces, Wiz now also leverages GTI’s malicious AI Skill intelligence to identify potentially risky open-source skills that AI agents can import, giving organizations greater confidence as they adopt agentic AI.

GTI enrichment for malware and AI Skills is available out of the box to all Wiz customers. By bringing together world-class threat intelligence and the rich context already captured in the Wiz Security Graph, Wiz continues to expand the context available for every security decision—enabling organizations to prioritize and respond consistently across multi-cloud environments.

Speed of Action: Responding at machine speed

Complete visibility lays the foundation for AI Threat Readiness. The same context that helps organizations understand risk should power and accelerate every security decision and response, helping teams build autonomous defense. We see that future state as the self-healing cloud, where AI continuously understands risk, validates exposure, and takes action to reduce it before attackers can. Building towards it requires compressing every step of the response lifecycle with AI agents and automation grounded in the context of your environment, with humans focused on the decisions that require judgment.

With Wiz, you can accelerate your speed of action at every stage of the response cycle:

  • With the Red Agent, now Generally Available, teams can proactively find and validate complex exploitable risks and remove them before attackers find them. While traditional scanners match signatures, Red Agent reasons through business logic to uncover logic-driven vulnerabilities such as OWASP API Top 10 Flaws, logic flaws, authorization bypasses, and more.

  • When threats emerge, teams need to quickly understand what happened, determine impact, and decide how to respond. The Blue Agent accelerates threat investigations by bringing together the context analysts need upfront, helping teams move from alert to understanding to action fast. 

  • The Green Agent acts as a digital security investigator and remediation engine, analyzing every Issue against proven methodologies before applying fixes or selecting layer-appropriate remediations. Remediation and Response, now in Public Preview, is embedded within Green’s recommendation, surfacing tailored response actions from pre-built templates in Wiz, executed in customer cloud environments for immediate fixes with one-click execution. 

Wiz Workflows, now Generally Available, orchestrates this full response end-to-end, turning those insights into repeatable processes that scale with the pace of AI-enabled development. It serves as a centralized control plane where teams can chain together actions across the Wiz platform including Wiz AI Agents, Remediation and Response actions, and integrations into multi-step workflows that accelerate response at scale.

These capabilities represent the first steps toward a self-healing cloud—where security teams can implement machine speed automation and build towards the AI-led future.

Build AI Threat Readiness with Wiz

As the threat landscape continues to evolve, organizations can begin building AI Threat Readiness today by enabling and operationalizing capabilities that help them understand risk, accelerate action, and continuously strengthen their security posture. On Wiz, this can look like:

  • Enabling the Red Agent: Focus on the highest value fixes before attackers can exploit them.

  • Operationalizing AI-powered remediation with Wiz Workflows: Use Workflows to orchestrate investigations, engage the right owners, and execute Remediation and Response actions at speed.

As the threat landscape continues to evolve at AI speed, organizations must evolve how they approach security. The combination of comprehensive visibility, AI-powered decision-making, and automated action provides the foundation for a new security operating model—one built to continuously reduce risk and keep pace with the threats of tomorrow.



Source link