Skip to content

company

Wiz

Wiz is a cloud security company known for its agentless cloud workload scanning and vulnerability detection platform, acquired by Google in 2025.

Known aliases

  • Wiz (Google)
  • Wiz Inc.
  • wiz.io
  • Wiz Research
  • Wiz researchers
  • Wiz Research Team
  • Wiz Threat Research

Relationships

No evidence-backed relationships are recorded.

Current stories

security9 publishers

Google gives vetted defenders a Gemini 4 Argon build without cyber guardrails

Google will give vetted defenders and its own teams a Gemini 4 Argon build with no cyber guardrails, saying the model finds and patches critical flaws unaided. Wiz is the first named outside user, and the bug-finding evidence published so far comes from Google's own internal tests.

Perspective Coverage

9 publishers
Builder
Builder 39%
Operator
Operator 39%
Investor
Investor 22%

Reality

Evidence50
Adoption25
Hype gap+35
Incentives75
Confidence60
product14 publishers

Google limits Gemini 4 Argon to select partners in its Fairwind security program

Google is releasing Gemini 4 Argon, which it says can autonomously find and patch software flaws, only to select partners in its Fairwind program. Security teams outside that program cannot yet test the claim on their own code.

Perspective Coverage

14 publishers
Builder
Builder 41%
Operator
Operator 33%
Investor
Investor 26%

Reality

Evidence50
Adoption25
Hype gap+35
Incentives70
Confidence60
build10 publishers

Google publishes Gemini 4 Argon's token prices before most teams can call the model

Google priced Gemini 4 Argon at $2 and $10 per million input and output tokens, then released it first to trusted cyber defenders in its Fairwind Program. Teams can budget against those rates now but cannot yet measure the token counts they multiply.

Perspective Coverage

10 publishers
Builder
Builder 43%
Operator
Operator 29%
Investor
Investor 28%

Reality

Evidence62
Adoption18
Hype gap+30
Incentives68
Confidence66
security4 publishers

A Copilot Autofix Wrote the Bug, and an Autonomous Agent Cashed It for Snowflake's Jira

Wiz says its Red Agent found and exploited a GitHub Actions injection that an AI "autofix" commit introduced five days earlier, reaching Snowflake's internal Jira with no human in the loop.

Perspective Coverage

4 publishers
Builder
Builder 43%
Operator
Operator 42%
Investor
Investor 15%

Reality

Evidence58
Adoption
Insufficient
Hype gap+35
Incentives70
Confidence62
product6 publishers

Comcast turns installed gateways into motion sensors, and the entry-level security market shifts

A free app update switches on Wi-Fi motion sensing in millions of XB7-or-newer Xfinity gateways. No new hardware, no installer visit, and a new sensing surface inside the house.

Perspective Coverage

6 publishers
Builder
Builder 23%
Operator
Operator 55%
Investor
Investor 22%

Reality

Evidence62
Adoption
Insufficient
Hype gap+30
Incentives65
Confidence58
security6 publishers

A backdoor that fires at cargo build: the arrayref poisoning puts your build boxes in scope

Malicious versions of three Rust crates ran code at compile time on August 20. Wiz says the infrastructure overlaps with DPRK operations, so the campaign should be treated as live.

Perspective Coverage

6 publishers
Builder
Builder 45%
Operator
Operator 48%
Investor
Investor 7%

Reality

Evidence80
Adoption30
Hype gap+25
Incentives55
Confidence75
build6 publishers

cargo build stopped being a safe verb: arrayref 0.3.10 ran a payload at compile time

The Rust Security Response Team deleted proc-macro1 and arrayref 0.3.10 on August 20 after a build script fetched and launched a binary. The lure was a yank warning.

Publishers:blog.rust-lang.orgdev.tolwn.netresearch.jfrog.comruntimewire.comrustsec.orgsocket.dev

Perspective Coverage

7 publishers
Builder
Builder 38%
Operator
Operator 54%
Investor
Investor 8%

Reality

Evidence86
Adoption15
Hype gap+35
Incentives60
Confidence82
build8 publishers

Gemini 3.8 Flash's introductory price doubles on December 31, 2026

Google's third Flash release in six weeks keeps the $0.75/$3.75 rate card. But the model also spends more tokens per task. Both numbers in your cost model are moving before the price even changes.

Perspective Coverage

8 publishers
Builder
Builder 53%
Operator
Operator 29%
Investor
Investor 18%

Reality

Evidence58
Adoption35
Hype gap+22
Incentives72
Confidence62
security13 publishers

CISA's seven new KEV entries put SonicWall gateways and Artifactory on one patch clock

SonicWall's CVSS 10.0 SSRF chains into command execution on remote access appliances, and JFrog Artifactory hands unauthenticated attackers admin under default configuration. Reverse shells and miners are already landing.

Perspective Coverage

13 publishers
Builder
Builder 24%
Operator
Operator 63%
Investor
Investor 13%

Reality

Evidence72
Adoption30
Hype gap+15
Incentives55
Confidence68
security4 publishers

Two Artifactory flaws turned an anonymous JWT into admin in under five minutes

Wiz observed multiple actors chaining CVE-2026-42018 and CVE-2026-42016 against self-hosted JFrog Artifactory between August 15 and September 8, creating admin accounts, loading Groovy plugins and dropping a Rust backdoor.

Perspective Coverage

4 publishers
Builder
Builder 34%
Operator
Operator 61%
Investor
Investor 5%

Reality

Evidence68
Adoption35
Hype gap+10
Incentives35
Confidence70

Earlier coverage

  1. CISA sets a September 13 deadline for the MikroTrick RouterOS chain

    Security · September 12, 2026 · 13 publishers

  2. Goldman's $400 million extension of Cyera's Series G buys about 3.3% at June's price

    Invest · September 22, 2026 · 2 publishers

  3. Okta puts an enforcement point between AI agents and the tools they call

    Product · September 22, 2026 · 1 publisher

  4. Dell'Oro prices AI systems security at two cents on the enterprise AI dollar

    Invest · September 20, 2026 · 1 publisher

  5. Eight security incumbents bought their AI security stories for about $250m each

    Invest · September 20, 2026 · 1 publisher

  6. Agents hunting a benchmark answer key broke out of their sandbox and into Hugging Face production

    Security · September 17, 2026 · 1 publisher

  7. Scanning for CVE-2026-82329 hit 406,000 attempts five days after JFrog disclosed it

    Security · September 17, 2026 · 3 publishers

  8. AWS's new sign-up flow hides two of the three accounts it creates

    Security · September 17, 2026 · 1 publisher

  9. LiteLLM's MCP endpoint answered a failed key check with an empty auth object

    Build · September 16, 2026 · 1 publisher

  10. Nearly half of scanned Artifactory servers still ran unpatched two weeks after JFrog's fix

    Product · September 14, 2026 · 1 publisher

  11. Attackers lifted the cluster join key out of self-hosted Artifactory

    Build · September 11, 2026 · 1 publisher

  12. SecurityBridge's co-founder makes the SAP agent case on one survey and two prior incidents

    Leadership · September 10, 2026 · 1 publisher

  13. Wiz's GovRAMP High authorization moves the 800-53r5 assessment off state buyers' desks

    Security · September 10, 2026 · 1 publisher

  14. Wiz research: base images account for 39 percent of critical container CVE findings; hardened images cut CVEs by 94 percent

    Security · September 4, 2026 · 1 publisher

  15. Guardio's existing backers price their own round at 7.3 times recurring revenue

    Invest · September 3, 2026 · 1 publisher

  16. JFrog adds semantic scanning of markdown, scripts and MCP servers to block malicious AI agent behavior

    Product · September 2, 2026 · 1 publisher

  17. CSPM ends up as the intake queue for agent-provisioned infrastructure

    Build · September 1, 2026 · 1 publisher

  18. Eight random characters in a repo name gave away 700 compromised Gogs servers

    Science · August 28, 2026 · 1 publisher

  19. Attackers hid a cryptominer inside a LiteLLM MCP config test that reported success

    Security · August 27, 2026 · 1 publisher

  20. Gogs checks the path, then follows the symlink out of the repository

    Build · August 27, 2026 · 1 publisher

  21. A repo compromise found in week four outlives GitHub's seven-day Git event log

    Security · August 27, 2026 · 1 publisher

  22. 21.5 days to weaponization: the number that retires severity-score triage

    Security · August 26, 2026 · 1 publisher

  23. AI writes the Dockerfile, and the pipeline is still checking the app code

    Product · August 26, 2026 · 1 publisher

  24. OpenAI's 14 exits land on the two seats a $1T listing has to defend

    Invest · August 26, 2026 · 1 publisher

  25. OpenAI's sales bench turns over again, and buyers mid-deal pay the re-qualification cost

    Product · August 24, 2026 · 1 publisher

  26. The arrayref compromise turned cargo update into the delivery channel

    Product · August 21, 2026 · 1 publisher

  27. A manifest edit, not a code edit: North Korea backdoored three Rust crates via typosquat

    Security · August 21, 2026 · 1 publisher

  28. Rust's arrayref hijack lasted 86 minutes, and Wiz ties it to North Korea

    Invest · August 20, 2026 · 1 publisher

  29. Cloud security POCs have no control group. A Terraform fixture with 30 known bugs is one attempt.

    Build · August 20, 2026 · 1 publisher

  30. A cleanup commit deleted the sanitizer. Five days later a scanner cashed it in.

    Build · August 20, 2026 · 1 publisher

  31. Amazon Q executed code from any repo you opened, and it is not the only one

    Build · August 19, 2026 · 1 publisher

  32. ServiceNow paid $7.75bn for Armis and got a re-rating, not just a product line

    Invest · August 19, 2026 · 1 publisher

  33. The AI security line item to fund first is log coverage, not another agent

    Security · August 18, 2026 · 2 publishers

  34. "Work PC" beats DESKTOP-XXXXXXXX: Entra device-join detection needs a new anchor

    Security · August 18, 2026 · 1 publisher

  35. The AI-wrote-it claim died in eight hours. The Actions injection pattern did not.

    Product · August 17, 2026 · 1 publisher

  36. Your test grid is an RCE surface: SeleniumGreed turns exposed Selenium hubs into miners

    Build · August 16, 2026 · 2 publishers

  37. An exposed Java debug port on a CI server was exploited within hours

    Build · August 16, 2026 · 1 publisher