Wiz Launched Initiative to Secure Critical Infrastructure

The company has introduced a new scanning service to identify and remediate vulnerabilities in essential digital systems.

Updated on Sept. 24, 2026 in Cybersecurity

Isometric editorial illustration of a secure data center hall with clean, rectilinear server cabinets rendered in a muted palette.
Cybersecurity firm Wiz has launched its 'Scan for Good' initiative to proactively identify and fix critical vulnerabilities in essential internet-facing infrastructure worldwide. AI Illustration. Upload story photo >

Live Poll

Do you trust that using AI to hunt for security flaws increases your digital safety?

Wiz has launched the Scan for Good initiative to identify critical security flaws within internet-facing infrastructure. The program leverages AI research tools to help operators remediate vulnerabilities before they can be exploited by attackers.

Why it matters

By proactively scanning public-facing assets, the initiative aims to prevent large-scale cyberattacks on essential services. It provides a structured method for operators to patch exposures across diverse platforms like railroads and healthcare systems.

The scanning initiative has identified 475 critical or high-severity vulnerabilities and secured 500 production container images. The process utilizes Google's Gemini models, specifically the 3.8 Flash Cyber tool, to examine APIs, websites, and applications.

The players

Wiz

Wiz is a cybersecurity firm that specializes in cloud security solutions and vulnerability assessment.

Cybersecurity and Infrastructure Security Agency

The Cybersecurity and Infrastructure Security Agency is a United States federal agency tasked with protecting national critical infrastructure.

The details

Operators apply to the program to authorize the scanning of their digital environments, which Wiz then analyzes using the Wiz Red Agent and proprietary AI research capabilities. The project has already successfully assisted a railroad operator in securing an exposed database and helped hospitals fix remote-code-execution flaws.

Timeline

  1. September 24, 2026: Wiz published a blog post announcing the launch of the initiative.

The Tech Race

This initiative follows the pattern set by the Cybersecurity and Infrastructure Security Agency's vulnerability disclosure framework by formalizing how private sector entities identify and report systemic risks. It shifts the industry focus from reactive patching to proactive, AI-driven identification of widespread infrastructure threats.

Infrastructure operators and organizations utilizing cloud platforms may benefit from more secure environments as these critical flaws are remediated. The initiative also aims to provide broader research insights into AI-driven exploit patterns, potentially informing future security standards.

The takeaway

Proactive collaboration between security firms and infrastructure operators is essential for mitigating systemic digital risks. Organizations should regularly audit their public-facing assets to stay ahead of evolving AI-based exploit techniques.

Further reading

Learn more about the latest developments in the field of Cybersecurity.

Source note: This article includes information reported by Cybersecurity Dive.

Live Poll

Do you trust that using AI to hunt for security flaws increases your digital safety?