Security1 distinct publisher2 min readPublished
The 39 percent comes from Wiz research with no published sample or method, and it bounds the hardened-image pitch as much as it supports it, since most critical container findings sit above the base layer.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
Base image CVEs are findings in packages the application team never chose and often cannot read, which makes them both the most expensive to triage and the cheapest to remove [10]. Swapping a base image is one line in a manifest. Fixing the same CVEs in place means a developer reading upstream changelogs for software nobody on the team owns. On triage economics alone, image selection is the first lever, and Wiz's recommendation to standardize on hardened components follows from that [11].
It is also a bounded one. Wiz research puts base images at 39 percent of critical and high severity CVE findings on production containers [1]. Subtract that from the whole and 61 percent of those findings sit elsewhere [1]: application dependencies, runtimes the build pulls in, and first-party code. No base image reaches them.
The post attributes the 39 percent to "Wiz research" without stating a sample, a timeframe, or the rule used to assign a finding to the base layer rather than the application layer [14]. The benchmark carries the same caveat. The 94 percent median CVE reduction is Wiz testing Wiz images against variants it selected as equivalent [3], and the same test reports 48 percent average cuts in image size and in package count [4][5].
Package count is the number worth banking. A component that is not installed cannot carry the next disclosure at all, whatever the response window looks like. The CVE figure is a count of findings, and the post does not break out how many of the removed CVEs were reachable at runtime, which is the number that would say what the swap buys in exposure rather than in dashboard rows.
On provenance, Wiz says WizOS images are built directly from source in a hardened pipeline with no internet connectivity [8], rebuilt daily, and signed with verifiable cryptographic provenance [7]. That is a hedge against the pattern Wiz cites from the past year, in which attackers compromised CI/CD systems such as GitHub Actions to inject malware into open source components [12]. Signing establishes where a build came from. It says nothing about whether the source it was built from was clean.
Priced on triage economics, image selection is worth doing whether or not the 39 percent survives publication of its method. It leaves the larger share of critical and high findings exactly where it was, owned by the team that wrote the code.
Ranked by verification strength, evidence, and original report placement.
Wiz maintains SLAs for CVE remediation in WizOS images of 7 days for critical CVEs and 14 days for high and medium, and says images are patched without requiring action from the customer's team.
Wiz says WizOS images are rebuilt daily and every build is signed with verifiable cryptographic provenance.
Wiz says WizOS images are built directly from source code in a hardened build pipeline that is isolated with no connectivity to the internet, which it says prevents inherited risk from pre-built upstream artifacts.
Wiz's stated adoption path is a pull-through cache or mirroring pipeline from the WizOS container registry into the customer's own private artifact registry, after which the customer updates its manifest to reference the new patched version or triggers its CI pipeline daily.
Wiz says base images pulled from public repositories frequently carry unnecessary packages and unpatched CVEs, putting the burden on development teams to understand and apply patches in code they did not write.
In its published framework for AI threat readiness, Wiz recommends that organizations standardize on hardened components and base images to reduce constant patching.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · September 4, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
security
Mythos's method, not its zero-day count, is what breaks CVE-keyed vuln management1 distinct publisher
build
Twenty-three security checks, zero coverage: AI coding agents as build-pipeline attack surface1 distinct publisher
security
Frontier AI can find the bugs faster. The patch queue is the number nobody published.1 distinct publisher
build
The Mini Shai-Hulud worm passed provenance checks by running inside the release pipeline1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One vendor post, no method
Every quantity here traces to a single Wiz blog post that names no scan population, no timeframe, no scanner, and no image list. The 39% claim needs a rule for deciding whether a CVE finding belongs to the base layer or to the application above it, and that rule is never stated. What is genuinely verifiable is the material Wiz defines by fiat: its remediation SLA, its daily rebuild and signing practice, and the mirroring steps for consuming the images.
Nothing on the user side
Wiz shipped capabilities, including a page that ranks migration candidates by image type, and that is the extent of what can be observed. No customer, registry pull figure, or third-party account of a WizOS migration appears anywhere in this reporting, and a shipped feature only tells us the vendor built it.
Figures outrun their method
Reductions are quoted to the percentage point with no method attached, and the post's own arithmetic limits the pitch it supports: at 39%, hardening the base image leaves the larger share of critical and high findings exactly where they were. The 7-day critical SLA also sits awkwardly next to the hours-to-days exploitation window Wiz uses to open the argument.
Vendor grading its own product
Wiz researched the problem, supplies the fix, and published both in a post that ends in migration tooling and a suggestion engine pointing at WizOS images. The comparison set is 'equivalent open source image variants', which is also the thing WizOS is meant to displace.
Clear read on a thin base
What Wiz claims and what it withholds are both plain in the text, so the shape of this assessment is firm. Whether the measurements themselves hold is not something one self-published test can settle, and no second account exists to move the number either way.