{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/wiz/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Wiz Cloud Security Platform"],"_cs_severities":["high"],"_cs_tags":["vulnerability-management","cloud-security","wiz"],"_cs_type":"advisory","_cs_vendors":["Wiz"],"content_html":"\u003cp\u003eThe Elastic-authored detection rule identifies cloud assets with an elevated number of vulnerabilities reported by Wiz, serving as an indicator of weak security posture, potential patching failures, or active exposure. The rule leverages Wiz telemetry to flag assets that demonstrate a significant security risk through three primary criteria: a high volume of distinct vulnerabilities (10 or more), the presence of at least one known exploitable vulnerability combined with a moderate volume of findings, or the presence of high-to-critical severity vulnerabilities across multiple findings. This detection is intended to prioritize remediation efforts for cloud-based infrastructure that is most susceptible to exploitation, reducing the attack surface by highlighting assets that require urgent investigation and maintenance.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of assets flagged by this rule could result in unauthorized initial access to cloud environments, lateral movement, or data exfiltration. By identifying assets with known exploitable vulnerabilities and a lack of patch management, organizations can proactively address security gaps before threat actors leverage techniques like T1190 (Exploit Public-Facing Application) to compromise high-value infrastructure.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize remediation for assets identified by this detection, focusing specifically on those flagged with exploitable vulnerabilities or critical-severity findings.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eReview the affected asset details via \u003ccode\u003ewiz.vulnerability.vulnerable_asset.name\u003c/code\u003e to confirm ownership and criticality.\u003c/li\u003e\n\u003cli\u003eUse the \u003ccode\u003eEsql.vuln_id_values\u003c/code\u003e field provided by the detection to audit specific CVEs present on the host.\u003c/li\u003e\n\u003cli\u003eValidate the \u003ccode\u003ewiz.vulnerability.has_exploit\u003c/code\u003e field to confirm if an asset is currently at risk of known exploit chains and prioritize these for immediate patching.\u003c/li\u003e\n\u003cli\u003eReview vulnerability management processes to ensure assets are included in scheduled scanning and that patch SLAs are being met.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-19T13:16:52Z","date_published":"2026-09-19T13:16:52Z","id":"https://feed.craftedsignal.io/briefs/2026-09-wiz-vulnerability-exposure/","summary":"This brief describes a detection capability designed to identify cloud assets exhibiting poor security posture by correlating high volumes of vulnerabilities, exploitable findings, and critical-severity bugs reported by the Wiz Cloud Security Platform.","title":"Detection of Assets with Elevated Vulnerability Exposure via Wiz","url":"https://feed.craftedsignal.io/briefs/2026-09-wiz-vulnerability-exposure/"}],"language":"en","title":"CraftedSignal Threat Feed - Wiz","version":"https://jsonfeed.org/version/1.1"}