Google-owned cloud security firm Wiz said on Thursday that it is using AI tools to identify vulnerabilities in internet-facing critical infrastructure, from operational technology maintained by under-resourced utilities to software packages that are foundational to online activity.
“Where authorized, we will use the Wiz Red Agent and additional internal AI research capabilities to examine publicly facing websites, APIs, and applications,” Wiz’s Ami Luttwak and Gal Nagli wrote in a blog post about the company’s Scan for Good initiative. “This work will help organizations find and fix critical exposures before attackers do, allowing them to stay ahead of adversaries as AI capabilities advance.”
Wiz’s tools have already found 475 critical or high-severity vulnerabilities, according to a project page. The company said it has helped a railroad operator secure an exposed production database containing sensitive information and administrator accounts. It also said it assisted hospitals in fixing access-control and remote-code-execution flaws. In another case, Wiz helped an unnamed country tighten access controls on the website of a “nationally significant archive” to prevent unauthorized users from deleting data.
The initiative has also found vulnerabilities in an e-commerce platform’s payment service, an AI training platform and a cloud infrastructure provider. In the latter case, Wiz said, a publicly exposed password could have let hackers “publish malicious software across over 500 production container images supporting a flagship AI service.”
Wiz also said it has helped a major airline protect passenger and booking data and aided a global sports organization with the protection of passport and contact information.
Race to use AI for defense
Scan for Good is the latest example of a company using advanced AI models to find vulnerabilities in vital but underprotected infrastructure. AI-powered vulnerability-hunting tools have proliferated in recent years, in part as a result of a DARPA competition to develop open-source bug-finding tools.
Wiz is using several of Google’s Gemini models, including its 3.8 Flash Cyber tool. The company said it planned to share more real-world examples of the Scan for Good initiative’s impact, as well as “anonymized research detailing the underlying vulnerability patterns, the impact AI had on practical exploitability, and how organizations can put this into practice in scanning their own environments.”
The company said it worked with the Cybersecurity and Infrastructure Security Agency on the project.