threat_intelligence1540 wordsRead on Huntaegis

Introducing Wiz AI SAST: Application Security that Understands Your Code and Your Infrastructure

Introducing Wiz AI SAST: Application Security that Understands Your Code and Your Infrastructure Find, validate, and fix complex business logic flaws with an AI code scanner backed by Wiz Research, operationalized within your existing security program. We’re excited to announce that Wiz AI SAST is available as a Public Preview capability, bringing frontier-grade vulnerability discovery to all Wiz Code customers. AI models have become highly adept at finding complex flaws in application code that traditional scanners often miss. Security teams historically addressed this gap with manual reviews and quarterly pentesting, but neither of those approaches scale in a world where code is written and exploited at machine speed. Wiz AI SAST addresses this gap by analyzing how your application actually behaves to uncover a broader range of weaknesses (CWEs) that typically go undetected by rules-based scanners. It's powered by the Atlas harness we shared earlier this year, grounded in Wiz Research, and continuously refined by our investments in AI security. Code findings are correlated with what is actually running in production on the Wiz Security Graph, so teams instantly understand which vulnerabilities matter most. Prioritized findings flow through the existing policy, ownership, and remediation workflows AppSec teams already use, making AI-powered vulnerability detection part of your existing program rather than another tool to manage. As a core part of our AI Threat Readiness Framework, Wiz AI SAST complements a broader portfolio of solutions designed to help organizations stay ahead of cyberthreats in the AI era. Frontier Grade Code Analysis without the Overhead Running AI code scanning in production takes far more than a capable model. Teams have to build a harness that turns that model into a capable security researcher, evaluate new models as they ship, and manage the lifecycle of findings into security workflows. Done in-house, it requires a significant, ongoing investment from skilled security and engineering teams. Wiz AI SAST handles all of that out-of-the-box so organizations can operationalize AI code scanning quickly to improve their risk posture. A Harness Backed by Research and Results Wiz AI SAST shares the same underlying technology as Atlas, a research initiative we shared earlier this year. At the time, Atlas held the number one spot on CyberGym and uncovered more than 200 vulnerabilities in widely used open source software. We continuously tune our harness with learnings from real-world vulnerability research, attacker techniques, and scanning across Wiz's cloud security footprint. Organizations benefit from our expertise without having to build and maintain the complex AI infrastructure required for security specific use cases. Model Selection Driven by Continuous Benchmarking Our work on the Cyber Model Arena shows that AI security performance isn't a property of the model alone. It depends on the model and harness together. That makes evaluation a moving target: every new model release means retesting every pairing against real-world security tasks. As an AI vendor-agnostic platform, we continuously run these evaluations and swap the strongest—and most efficient—model into the AI SAST harness. This includes cutting edge cybermodels made available to us through our partnership with Google DeepMind. For security teams, the value is simple: you don’t need to constantly track new model releases, benchmark them against security tasks, or decide which model to use. We handle that complexity behind the scenes, ensuring your code and applications are always scanned with the best model. Turning Non-Deterministic AI into a Scalable Security Program Delivering an enterprise-grade AI AppSec program requires managing the full lifecycle of vulnerability discovery, starting with deciding what to scan. AI code analysis is resource intensive and not every asset requires the investment of AI reasoning. Using Mika AI, security teams can prioritize the critical repositories that warrant AI code scanning by drawing on context such as cloud exposure, access to sensitive data, and business criticality. Once those prioritized scans are running, Wiz addresses the next phase of the lifecycle: the outputs. Because Large Language Models (LLMs) are inherently non-deterministic, they can generate different results from one run to the next. This creates a major operational challenge for security teams who need consistency in findings. To solve this we supplement the AI scan engine with automated lifecycle management to maintain finding states across scans: Retest: Before scanning for new risks, the engine re-examines existing findings to confirm they're still valid. If the code has been fixed, the finding is automatically marked resolved. Deduplicate: Rather than matching on line numbers or file paths, the engine correlates new findings with existing ones using security context and code semantics. Even if the AI changes a bug's title or description, our AI SAST recognizes the underlying root cause and reconciles it into a single, stable finding. Wiz handles this lifecycle between scans automatically, ensuring teams work with stable findings that can be assigned, tracked, remediated, and closed—not a new, disconnected set of AI outputs after every scan. As a result customers get the deep detection benefits of AI without giving up the predictable workflows they expect from enterprise security tools. By eliminating the manual burden of managing non-determinism, this built-in continuity dramatically reduces the Total Cost of Ownership (TCO) of AI-powered security. Click through the feature tour See how Wiz AI SAST works Visibility into a New Class of CWEs Wiz AI SAST extends detection coverage into the logic-based vulnerabilities that have always been hardest to catch, like broken access control, flawed input validation, and misapplied cryptography. Finding them requires a semantic understanding of what the code is supposed to do, which is something AI does exceptionally well. A practical example can be found below. Wiz AI SAST detected an Insecure Direct Object Reference (IDOR) flaw in an E-commerce basket endpoint, where any authenticated user could read another user's cart by changing the ID in the URL. Rules based engines would miss this type of risk because the syntax of the code is fine but it's the missing ownership check that makes it exploitable. The practical takeaway for AppSec teams is that AI analysis doesn’t replace rules based scanning completely, but rather it extends it. Deterministic scanning provides fast, cost-effective coverage for syntax based flaws, while AI SAST adds the deep reasoning needed to catch intent-dependent flaws like the IDOR above. Together, they give AppSec teams broader coverage of risk across the entire application attack surface. Prioritize Prioritize Exploitable Risks with Code-to-Infrastructure Context The best AI models in the world are ultimately limited by their access to relevant context. A model evaluating code in a vacuum is blind to how that application actually operates in the real world. By grounding our AI SAST engine in the Wiz Security Graph, the model investigates your code with full awareness of your infrastructure, identity configurations, and runtime environment. This context serves two critical purposes: Uncovering Hidden Risk: It allows the AI to discover complex vulnerabilities that only exist at the intersection of application logic and infrastructure flaws that standalone AI code scanners cannot detect. Prioritizing True Attack Paths: It drastically reduces triage fatigue by correlating code weaknesses with additional context to surface critical attack paths that matter most for remediation. That same deep context is what allows our Red Agent to validate exploitability from the outside in, testing these AI-discovered findings against your live environment exactly the way an attacker would. Remediate at Machine Speed with the Green Agent Detecting and validating risk at machine speed only pays off if remediation keeps up. The Wiz Green Agent investigates the underlying findings and builds a remediation plan grounded in the full context of your code, pipeline, infrastructure, and runtime, going beyond the generic guidance a standalone model produces. It pinpoints the right owner, maps the steps to fix the root cause, and can even share context with an AI coding agent like Claude Code to carry out the fix in code. And with Wiz Workflows, teams can turn Green Agent’s intelligence into multi-step automated response chains tailored to their DevSecOps playbooks. Get Started In the AI era, the best form of defense is to use AI on ourselves before threat actors can. Wiz AI SAST gives defenders a scalable solution to apply that philosophy against application code. But, it’s just one component of our broader vision for Agentic Code Security where specialized AI agents work alongside security teams to autonomously investigate, prioritize, and remediate risk across the entire AI development lifecycle. Wiz AI SAST is available now in Public Preview. If you’re an existing Wiz Code customer, get started by visiting our documentation. If you’re new to Wiz, request a demo to experience frontier-grade vulnerability discovery first hand. Secure your Kubernetes supply chain with WizOS Helm Charts. Eliminate hidden CI/CD risks and unmaintained dependencies with hardened, signed, and CVE-scanned charts for seamless Kubernetes deployment. See how the Blue Agent investigated a multi-platform attack in minutes, following evidence across AWS and GitHub to uncover compromised credentials, stolen source code, and custom data exfiltration tooling Get a personalized demo Ready to see Wiz in action? "Best User Experience I have ever seen, provides full visibility to cloud workloads." David EstlickCISO "Wiz provides a single pane of glass to see what is going on in our cloud environments." Adam FletcherChief Security Officer "We know that if Wiz identifies something as critical, it actually is." Greg PoniatowskiHead of Threat and Vulnerability Management

How it works

Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content — general knowledge won't be enough. Score 70+ to count toward your certificate.

Questions are cached — you'll always get the same 5 for this article.