Wiz Launched Security Initiative for Critical Infrastructure

The initiative leverages AI-driven scanning to identify and patch high-severity vulnerabilities in public-facing assets.

Updated on Sept. 24, 2026 in Cybersecurity

Bold flat-color editorial illustration depicting a complex steel server-strut lattice, symbolizing the protection of digital infrastructure.
Wiz has introduced the Scan for Good initiative, employing AI-driven vulnerability scanning to protect critical public-facing internet infrastructure from cyber threats. AI Illustration. Upload story photo >

Live Poll

Do you trust that using AI to hunt for security flaws increases your digital safety?

Wiz has launched the Scan for Good initiative to identify critical or high-severity vulnerabilities within internet-facing infrastructure. The program utilizes AI research and scanning agents to secure systems before they are exploited by malicious actors.

Why it matters

By proactively scanning public-facing digital assets, the initiative aims to close security gaps in essential services before they are compromised. This effort highlights the role of AI in scaling vulnerability detection across large-scale, complex infrastructure environments.

The initiative identified 475 critical or high-severity vulnerabilities and secured 500 production container images. The scanning process relies on Google's Gemini models, including the 3.8 Flash Cyber tool, to examine websites, APIs, and applications.

The players

Wiz

A cloud security company specializing in agentless scanning and vulnerability assessment for multi-cloud environments.

Cybersecurity and Infrastructure Security Agency

The federal agency tasked with reducing risk to the U.S. cyber and physical infrastructure.

The details

Wiz uses the Wiz Red Agent — a software component that performs security analysis on digital environments — to conduct assessments of public-facing assets. Authorized infrastructure operators apply for the service, which utilizes the Gemini 3.8 Flash Cyber model to analyze attack surfaces for access-control and remote-code-execution flaws. Remote-code-execution (RCE) refers to a class of vulnerabilities that allow an attacker to run arbitrary commands on a target system.

Timeline

  1. September 24, 2026: Wiz published a blog post announcing the launch of the Scan for Good initiative.

The Tech Race

This initiative follows a pattern set by the Cybersecurity and Infrastructure Security Agency's Shields Up program to improve defense posture. It marks a shift toward leveraging large language models to automate the identification of security flaws at a pace previously unattainable through manual auditing.

Infrastructure operators, including hospitals and transport services, can apply to Wiz to have their digital environments scanned for security weaknesses. Participants gain access to prioritized remediation data for identified vulnerabilities without needing to manage the scanning infrastructure themselves.

The takeaway

The initiative demonstrates how AI can accelerate the remediation of high-risk vulnerabilities in public-facing assets. Researchers and industry observers should watch for the upcoming publication of anonymized research detailing vulnerability patterns and the effectiveness of AI-driven exploit analysis.

Further reading

For broader trends in security automation and threat detection, visit Cybersecurity.

Source note: This article includes information reported by Cybersecurity Dive.

Live Poll

Do you trust that using AI to hunt for security flaws increases your digital safety?

Wiz Launched Security Initiative for Critical Infrastructure