Skip to content

Wiz Takes Red Agent to General Availability After Four-Month Preview

Wiz has made Red Agent, its AI-driven penetration-testing agent for APIs and cloud environments, generally available after four months in public preview.

Wiz logo inside a crystal ball held by illustrated hands, framed by pink stage curtains
Credit: Wiz

Wiz made its Red Agent penetration-testing agent generally available on July 29, ending a four-month public preview for the AI system built to hunt logic flaws in APIs and AI-generated code that conventional vulnerability scanners cannot reason about.

The tool began as an RSA Conference reveal in March, moved into public preview in April, and now reaches general availability with three purpose-built modules in place of the single crawler-and-attacker pair Wiz described when it first introduced the agent. The premise hasn't changed: an autonomous system that maps an organization's APIs, including the forgotten or undocumented ones, then reasons about how each endpoint could be abused and chains multi-step exploits the way a human tester would, rather than matching known signatures.

Per Wiz, the general-availability release adds three named modules: a Web API Crawler that analyzes client-side code to surface shadow and forgotten endpoints, an API DAST Attacker that continuously probes live applications for logic-driven vulnerabilities such as broken authorization, and a Secrets Blast Radius module that tests whether credentials exposed in code or on public sites are still active. Findings from all three route into Wiz's existing Green Agent for remediation guidance and into Wiz Workflows for assignment, so a flaw doesn't just sit in a backlog.

Wiz credits the preview period with more than 10,000 validated, externally exploitable findings across its customer base and says 70% of organizations that turned the agent on found a high or critical vulnerability they didn't know existed, with more than a third confirming their first critical finding within an hour of activation. At peak load, Wiz says, Red Agent scanned 350,000 assets and processed 480 billion tokens in a single day. Those are Wiz's own reported figures, not independently audited results.

Wiz's own case studies from the preview period include a Google Cloud Run application where Red Agent chained a path-restriction bypass into a full read of the host's local filesystem and live service-account credentials, and an airline GraphQL API where cycling through sequential ID values exposed two years of passenger records. Whether Red Agent's reasoning holds up against real adversaries as well as it did in Wiz's own test environments is a question only paying customers, not Wiz's own case studies, will be able to answer.

Share this story

Daniel Brandt

Daniel Brandt covers threats, malware, and vulnerability disclosure for techshooked, from active exploit campaigns to the patch cycles that follow. His standard is operational: name the affected versions, separate a proof of concept from in-the-wild exploitation, and tell readers which fix to apply first.