Wiz Research Blog
wiz-blog · B · active
Cloud security research; strong on cloud-native CVEs, container escapes, and misconfiguration. Promoted from candidate → active 2026-05-08 after 2026-05-08 audit returned 5 dated 2026-05-06/08 items including Dirty Frag and Akamai integration. (v2.55: rss_url verified, use `python3 tools/fetch_source.py feed https://www.wiz.io/api/feed/cloud-threat-landscape/rss.xml [N]`) | 2026-06-20 full audit (v2.62): live=Y, drill=Y. FETCH → webfetch https://www.wiz.io/blog (listing) then webfetch per-article wiz.io/blog/<slug> URL; RSS at https://www.wiz.io/api/feed/cloud-threat-landscape/rss.xml (cloud-threat-landscape slice only). AVOID: Listing renders the article hero IMAGE url first and the real link as a relative /blog/<slug> path, resolve it against www.wiz.io. The documented RSS only covers the cloud-threat-landscape slice, not all blog posts.. | 2026-07-05 admiralty audit: B, original cloud-security research from Wiz Research, but the blog feed mixes in marketing and policy re-reporting; resolve slugs against www.wiz.io. No status change.
Cited in 16 entries
Citation cadence
Citation days per ISO week (19 weeks of coverage span, total 15).
- CVE-2026-42016 + CVE-2026-42018, JFrog Artifactory: chaining two previously-patched token flaws turns an unauthenticated request into full administrative control in two API calls, confirmed exploited since mid-August2026-09-12
- CVE-2026-82329, JFrog Artifactory: an unauthenticated attacker gets administrative access under default configuration (CVSS 9.8)2026-09-01
- Wiz's autonomous AI red-teaming agent found and exploited a GitHub Actions command-injection flaw in Snowflake's public connector repo, exfiltrating live Jira credentials via an out-of-band callback2026-08-28
- A hijacked crates.io account added the first dependency arrayref has taken in ten years, and that dependency ran a backdoor at compile time; every machine that built an affected project during a ninety-minute window must be treated as compromised2026-08-23
- Wiz Cloud Threat Highlights H1 2026: LiteLLM had four separate security events in six months, unauthenticated MCP endpoints turned up across hundreds of environments, and a new extortion actor goes after service accounts rather than people2026-08-08
- AsyncAPI npm packages backdoored via a GitHub Actions pull_request_target token theft, delivering a multi-stage IPFS implant (M-RED-TEAM)2026-07-14
- GhostApproval (CVE-2026-12958, CVE-2026-50549), symlink + confirmation-UI misrepresentation lets a malicious repo write outside six AI coding assistants' workspace sandbox2026-07-09
- CVE-2026-12957, Amazon Q Developer auto-loaded workspace MCP configs, enabling repo-planted code execution and AWS credential theft (Wiz)2026-06-27
- CVE-2026-52806, Gogs self-hosted Git server: argument injection to OS command execution (BSI critical batch)2026-06-20
- TeamPCP open-sources its Mini Shai-Hulud framework, spawning a new "Phantom Gyp" derivative2026-06-09
- "Miasma" worm backdoors 32 Red Hat Cloud Services npm packages via OIDC trusted-publishing abuse2026-06-02
- Wiz CIRT names JINX-0164, LinkedIn-recruiter lures, AUDIOFIX macOS infostealer, MINIRAT npm pivot into CI/CD2026-05-29
- CVE-2026-46300, Linux kernel: local privilege escalation via xfrm ESP-in-TCP ("Fragnesia"), PoC public2026-05-15
- Mini Shai-Hulud's GitHub Actions Pwn-Request → OIDC Token Theft Chain2026-05-13
- CVE-2026-43284 / CVE-2026-43500, Linux "Dirty Frag": deterministic LPE chain via page-cache write primitives in xfrm-ESP and RxRPC, active exploitation confirmed2026-05-09
- CVE-2025-68670, xrdp pre-authentication stack overflow, arbitrary code execution2026-05-09