3 min Security

Wiz scans critical infrastructure before AI can derail it

Wiz scans critical infrastructure before AI can derail it

Protecting IT systems feels like a race against the clock. AI-driven attacks will only get better. Wiz is collaborating with Google DeepMind to identify truly exploitable flaws and vulnerabilities in critical infrastructure through the new “Scan for Good” program.

As part of this effort, Wiz deploys AI agents on publicly accessible systems belonging to government agencies, hospitals, nonprofits, and other critical infrastructure. The focus is on exploits that go beyond simply exploiting an unpatched vulnerability. Instead, Wiz and DeepMind aim to simulate more common types of attacks, such as those where misconfigurations turn a seemingly trivial vulnerability into an extremely effective tool for stealing sensitive data or manipulating systems.

Gemini Cyber

Following in the footsteps of Mythos and GPT-Cyber, there is also a Google model that serves as a cybersecurity variant of its own LLMs. Gemini 3.8 Flash Cyber is the engine behind Scan for Good. Where permitted, Wiz will also utilize its own Red Agent and internal AI research to delve even deeper into identifying sensitive IT infrastructure.

Some organizations collaborate with Anthropic or OpenAI through Project Glasswing or Daybreak, respectively. Scan for Good is an initiative aimed at less privileged parties who may not even have a red team. It sounds more democratizing for the movement toward AI readiness than the aforementioned initiatives, but it does not hand control of the LLMs over to the organizations themselves. Wiz uses AI agents to scan websites, APIs, and applications accessible from the public internet, searches for attack vectors, and privately reports them to the affected party. Wiz Red Agent is an AI penetration tester that, according to the company, has already found thousands of vulnerabilities in production environments.

What the agents found

Wiz cites a few examples of success stories to date. For instance, an exposed admin key granted read, write, and delete permissions on 8.8 million files in a national archive in the Middle East. At an unnamed hospital, anyone could take over the mobile alarm channel online. In another case, a rail operator had a leaked production database that granted access to routes, schedules, and administrator accounts.

Major tech platforms were also among Scan for Good’s early detections. A zero-day vulnerability in a payment service leaked customer names and partial card numbers. Similarly, a major website had a credential in public code that could have spread malicious software across more than 500 container images.

Humans remain ultimately responsible

Wiz only conducts testing where permitted, through a bug bounty program, a disclosure policy, or explicit consent. Every finding is validated by a human researcher. Hypothetical scenarios, therefore, are not escalated to the potentially affected organization.

“Our promise to the organizations we serve through this program: we’ll help you patch vulnerabilities before attackers can exploit them,” said Ami Luttwak, CTO and co-founder of Wiz.

Wiz has been providing occasional glimpses into its own research for quite some time. For example, it discovered DeepSeek’s open ClickHouse database, which was filled with chat logs and API secrets.

Read also: