🚨 Everything you need to know about #CodeBreach with Yuval Avrahami On this episode of Crying Out Cloud, Eden Naftali & Amitai Cohen sit down with Wiz researcher Yuval Avrahami to unpack a major supply-chain flaw that put cloud environments at risk ↓ - Misconfigured CodeBuild instances used by AWS themselves - One small regex mistake, huge consequences - How an SDK used by the AWS Console could have been hijacked (!) - The CI/CD controls that can mitigate this risk You don't want to miss this. 🎧 Listen now: https://lnkd.in/dmGqMRtn
Wiz
Computer and Network Security
New York, NY 382,176 followers
Protect everything you build and run in the cloud
About us
Organizations of all sizes and industries use Wiz to rapidly identify and remove the most critical risks in AWS, Azure, GCP, OCI, Alibaba Cloud and Kubernetes so they can build faster and more securely.
- Website
-
https://www.wiz.io
External link for Wiz
- Industry
- Computer and Network Security
- Company size
- 501-1,000 employees
- Headquarters
- New York, NY
- Type
- Privately Held
- Founded
- 2020
Locations
-
Primary
Get directions
One Manhattan West
New York, NY 10001, US
-
Get directions
3 Daniel Frish st
Tel Aviv, IL
Employees at Wiz
Updates
-
🚨 CodeBreach: A deep dive into the CodeBuild regex flaw that threatened the entire cloud. The Wiz Research team identified a critical repository-hijacking vulnerability that allowed attackers to compromise key AWS GitHub repos, including the AWS JS SDK, a core library at the heart of the AWS Console. A tiny regex slip. Two missing characters. Massive potential impact. Amazon Web Services (AWS) acted fast and patched the issue ✅. We also highlighted simple, effective steps to secure CI/CD pipelines and prevent untrusted builds from running. This is a powerful example of why supply-chain attacks are so subtle and why hardening your CI/CD is critical. Read the full story and see how Wiz uncovered it: https://lnkd.in/eTfhXacG
-
-
Meet the Wiz Partner Alliance 🤝 It's a global program built for the way partners actually work. Sell. Build. Integrate. Advise. All with 1 goal >> helping customers move faster in the cloud. Securely. What partners get? • Flexible models that fit real businesses • Strong enablement and GTM support • Rewards tied to real impact • A dedicated Services Program for hands-on delivery Big things happen when the right partners team up 👉 Learn more about the Wiz Partner Alliance: https://lnkd.in/eSvQ68pp
-
-
🎁 GIVEAWAY: The 26' edition of the Wiz Research Newspaper is officially out 🗞️ Real paper. Fresh research. Puzzles, games, and more... Want a REAL copy? Drop a Cloud Security haiku for when a small misconfig causes a big problem. The best comments will WIN the full newspaper delivered to your door 👀 https://lnkd.in/dn4tvZt7
-
-
-
-
-
+6
-
-
We know. "Product updates" doesn't sound fun. This one actually is.🍿 The NEW Wiz Rundown just dropped >> Here's a taste: 1) Wiz Attack Surface Management (ASM) 2) Wiz AI Agents 3) Wiz SAST 4) Wiz for Microsoft 365 5) Posture Issues 👀 Watch Shaked Rotlevi talking about all you need to know ↓ https://lnkd.in/emHkhrTF
-
Your AI is talking. Who's listening? 👂 From Vibe Coding experiments to MCP-powered agents, AI keeps adding new front doors to your environment. And most teams don't see half of them. That's why Wiz AI Security can now show live AI application endpoints in one place. Not guesses. Not configs. Real, reachable endpoints. What's new? • Visibility across Vibe Coding, MCP, pipelines, models, and AI services • Proof an endpoint is actually exposed at runtime • Full context: data, identities, workloads, and attack paths So when a "quick test API" hits prod… you'll know. And you can fix it fast. Learn more: https://lnkd.in/eSWKT-6t
-
-
Post-Quantum Cryptography isn't sci-fi anymore.🔮 It's a real shift every security team needs to plan for, calmly, early, and smart. Good news! You don't need a crystal ball. Start with visibility. Know where quantum-vulnerable crypto lives. Upgrade the easy wins first (TLS, SSH). Build a plan from there. At Wiz, we're helping teams get quantum-ready without panic or pain: • Discover at-risk encryption across cloud environments • Track PQC-ready standards (the real NIST ones) • Reduce "harvest now, decrypt later" risk, today. Learn more in our blog by Scott Piper >> https://lnkd.in/emH82D5N
-
-
Introducing a brand new job board for cloud security professionals >> cloudsecurity.jobs 💼 We re-built the first dedicated job board just for you - by the community, for the community. ↳ 500+ curated roles ↳ Entry-level → CISO ↳ Global opportunities, all in one place Your next cloud security role? It's already here :) cloudsecurity.jobs Tag someone below that is looking for a job 🪄
-
-
🎁 WIN our exclusive CISO Mixtape - yes, it actually plays! 🎶 What's inside? Two sides: 🌴 side a: CISoasis >> chill beats to unwind 🎭 side b: CISO Musical >> hype tracks to celebrate How to win? Comment below your go-to breach-song 👇 ONE winner gets the exclusive record player & mixtape for *FREE*. https://lnkd.in/d8UhDuzb
-
Wiz has been named a Customers' Choice in the 2025 Gartner Peer Insights™ Voice of the Customer for CNAPP, based on feedback from real practitioners evaluating their day-to-day experience with cloud security platforms. 🏆 'With 96% of reviewers willing to recommend as of 31st October 2025, Wiz customers cite strong product capabilities and support across modern cloud environments'. 📄 See what your peers are saying in the full report: https://lnkd.in/e_VPwK6v
-