Overview
Wiz is a cloud security company known for cloud-native vulnerability research and the Wiz Security Graph. Wiz Research regularly discloses high-impact cloud and developer-tool vulnerabilities.
Recent Developments
- 2026-08-04: Published analysis of keyv/cacheable shai-hulud-worm compromise; tracked 400+ packages; IOC
Bun/1.3.13,npm-cache[.]com(2026-08-04-wiz-keyv-cacheable-npm-attack) - 2026-07-08: Disclosed ghostapproval — systematic symlink trust-boundary flaw in six AI coding assistants (Claude Code, Cursor, Amazon Q, Google Antigravity, Augment, Windsurf); CVE-2026-12958, CVE-2026-50549 (2026-07-09-ghostapproval-wiz-primary)
- 2026-06-26: Discovered CVE-2026-12957 in amazon-q-developer — MCP auto-execution from
.amazonq/mcp.jsonenabling AWS credential theft (2026-06-26-amazon-q-wiz-research-blog) - 2026-04-20: Reported Amazon Q MCP vulnerability to AWS; coordinated disclosure through May fix and June public release
Related
- amazon-q-developer
- amazon
- mcp
- ai-agent-security
- supply-chain-security
- ghostapproval
- coding-agents
- shai-hulud-worm
- snyk
- socket