Article

    Cyber News / Article / The Wiz Red Agent is Now Generally Available

    The Wiz Red Agent is Now Generally Available
    Sh
    Shaked Rotlevi-2026-07-29

    The Wiz Red Agent is Now Generally Available

    Continuously uncover complex, exploitable risks to stay ahead in the AI Threat Era with the Red Agent

    We are excited to announce thatRed Agentis now generally available (GA). Customers have rapidly adopted our AI attacker to close the widening gap between traditional security scanners and the speed at which adversaries exploit vulnerabilities using AI.

    Its impact was clear during preview:

    Over 10,000validated critical exploitable risks were discovered by the Red Agent- externally facing risks with no authentication- that, if found by attackers, could have led to a significant impact.

    70% of organizationsthat enabled Red Agent discovered a High or Critical vulnerability they were completely unaware of.

    35% of organizationsfound their first verified Critical vulnerability within 1 hour of activating scans.

    Proven scale: At its peak, Red Agent scanned350,000 assetsand processed480B tokensin a single day.

    Behind these numbers are our customers transforming how they defend with AI:

    The Red Agent for attack surface management and automated penetration testing is incredibly valuable. We didn't have coverage over infrastructure-related automated pen testing prior to Wiz.

    Red Agent finds what humans miss. It caught critical authorization flaws across services where traditional testing and our bug bounty program came up short. We had continuous AI-powered attack surface testing on our roadmap. Wiz got there first, and did it better than we would have.

    Attackers are using frontier AI models to scan perimeters, discover zero-days, and weaponize complex application vulnerabilities in hours instead of months. Relying purely on human-paced security workflows against AI-speed adversaries creates a compounding coverage deficit. Staying ahead of this pace requires deploying AI for defense.

    Organizations are prioritizingAI Threat Readinessto outpace automated adversaries, yet existing security security scanning has limitations:

    Static scanners miss logic flaws: Traditional tools rely on known CVEs and signature matching. They cannot reason about custom application workflows, broken access controls, or multi-step logic flaws in modern web applications and AI-generated code.

    Manual penetration testing does not scale: Identifying complex business logic vulnerabilities historically required manual testing. These engagements are expensive, take weeks to execute, and offer limited scope.

    Point-in-time testing creates security gaps: A manual pentest or annual audit captures a single snapshot in time. The moment new code ships or an API updates, new unmonitored security gaps open up.

    Red Agenthelps teams stay ahead by running continuous, autonomous AI pentesting across custom-built software, vibe-coded applications, and APIs. While traditional scanners match signatures, Red Agent reasons through business logic to uncover unknown vulnerabilities such as OWASP API Top 10 Flaws, logic flaws, authorization bypasses, and more.

    An intelligent AI discovery tool that uses client-side code analysis to map API endpoints across your web applications and uncover hidden APIs. It automatically extracts and analyzes API specifications to understand endpoint structures, parameters, and expected behaviors and identifies unlinked or forgotten APIs that expose your organization to risk.

    Continuously uncovers and validates logic-driven exploitable risks by analyzing application behavior rather than following fixed scan patterns and static test cases. It treats target applications as dynamic systems, adapting its strategy in real time to reason about application logic and expose logic-driven risks. It thenprovides proofs of execution so your team receives verified findings, alongside reproduction steps.

    The Red Agent validates the impact of secrets exposed in public websites and APIs, and in public code repositories to test that they are active and determine the exact scope of access they hold. It executes safe, non-disruptive validation checks directly against the respective third-party SaaS provider's APIs to confirm exploitability and determines the precise scope of permissions.

    What sets Red Agent apart isn't just AI speed, it is about it’s deep contextual reasoning and how integrates into your security operations:

    Deep context without manual setup:Red Agent automatically ingests context from different Wiz sources: across API schemas, cloud resources, Runtime Sensor, code repositories, and network layers, and its own AI API Crawler. It being enriched by the Wiz context removes the need to manually configure context, and eliminates blind spots and gives the reasoning engine complete visibility.

    Engineered by Wiz Research:The threat intelligence and expertise of the Wiz Research team is built directly into the harness of the Red Agent, bringing top-tier security research into AI testing.

    Truly continuous discovery:Rather than relying on a fixed schedule against pre-selected target lists, Red Agent continuously discovers and tests both known and unknown applications across your entire footprint by leveraging an up-to-date inventory of your environment from Wiz, removing the need to predefine target groups.

    Automated remediation loop:Paired with Green Agent and Wiz Workflows, Red Agent customers can generate precise fix guidance with the Green Agent and scale response with Wiz Workflows.

    The types of risks Red Agent uncovers remain in the shadows for organizations across every industry. OurRed Agent POVseries documents how Red Agent identified these logic flaws in live environments across airline, financial, and technology companies:

    A GCP Cloud Run application restricted input to valid GitHub URLs ([https://github.com/](https://github.com/)...). Red Agent bypassed the path restrictions to read the host's local filesystem (/proc/self/environ), extracting live GCP service-account credentials and full application source code.

    An airline API generated distinct session tokens for authentication, but downstream GraphQL resolvers failed to validate user roles. Red Agent cycled sequential integer IDs across unprotected resolvers, exposing two years of passenger PII and unlocking controls to modify active flight bookings.

    A B2B directory gated contact data behind a paid credit system. Red Agent identified an unreferenced request parameter accepted by the backend. Appending the flag returned unmasked phone numbers and emails on free-tier requests, bypassing the core monetization model.

    Get started today, reviewthe docs(login required) orbook a live demowith our team. To learn more about the Red Agent findings explore theRed Agent POVblog series.

    How unauthenticated Model Context Protocol (MCP) servers are opening doors to sensitive cloud data, IAM, and command execution.

    Wiz enables organizations to continuously assess environments against the CISA KEV catalog, automating risk prioritization, rapid remediation, and forensic triage workflows.

    See how Wiz built Atlas, an autonomous AI system for vulnerability research that validates every finding with a real, working exploit.

    Get a personalized demo

    ©2026Wiz, Inc.

    StatusPrivacy PolicyTerms of UseModern Slavery StatementCookie Settings

    Original source