Google and Wiz launched Scan for Good, an AI-assisted vulnerability-discovery initiative for critical infrastructure, public services, nonprofits, and technology providers. Using Gemini 3.8 Flash Cyber and Wiz Red Agent, the program identified serious, previously unexploited weaknesses at hospitals, a public rail operator, a municipality, and a national archive. Reported findings included leaked rail-administrator sessions, unrestricted control over a hospital mobile-alert channel, a hospital booking-site upload flaw that could enable server takeover and patient-data exposure, and exposed records affecting roughly 5,000 elderly residents.
Other remediated issues included administrative access to 8.8 million national-archive files and a cloud-provider credential that could have allowed alteration of more than 500 production container images. Google also cited an autonomously identified critical GitHub Actions script-injection flaw in Snowflake's snowflake-connector-net repository, which Snowflake fixed on the day of disclosure. Google said testing is conducted only with explicit authorization or under applicable disclosure and bug-bounty programs, with human researchers validating findings and coordinating remediation; CISA endorsed the defensive-discovery approach while Wiz cautioned that AI can also accelerate malicious attack-path development.

Track how attackers are adapting to this technology.
10 events from the most recent confirmed update back to the earliest known activity.
Wiz Red Agent identified a critical script-injection flaw in Snowflake's snowflake-connector-net GitHub repository through Snowflake's HackerOne program. Snowflake remediated the issue and rotated the affected credential on the day Wiz disclosed it; its audit review found no activity other than Wiz during the exposure window.
CISA provided guidance and collaboration for the Scan for Good initiative. Acting Director Nick Andersen endorsed defensive vulnerability discovery as a way to strengthen digital infrastructure amid evolving threats.
Google and its Wiz subsidiary launched Scan for Good, an AI-assisted defensive security-testing initiative for critical infrastructure, public services, nonprofits, and technology providers. The program uses Gemini 3.8 Flash Cyber and Wiz Red Agent, requires authorization or applicable disclosure-program coverage, and has human researchers validate findings and coordinate remediation.
Wiz reported that a credential embedded in public website code at an unnamed cloud provider could have allowed malicious software to be published across more than 500 production container images supporting a flagship AI service. The provider and exposure were not identified publicly, and Wiz said reported issues had been addressed.
The initiative discovered a public rail operator production-database exposure that leaked active administrator sessions. The sessions could have enabled control of routes, schedules, service announcements, and administrator accounts; Wiz said it helped secure the system before transit disruption occurred.
Wiz found a public municipal data-service exposure involving personal, health, and financial information for roughly 5,000 elderly residents. Wiz said it confirmed the issue without collecting a bulk data set and that the exposure was addressed.
An unsafe file-upload feature on an unnamed private hospital's public appointment-booking site could have enabled server takeover and exposure of patient identifiers, clinical information, and consent signatures. Wiz reported the issue was addressed before exploitation.
Wiz identified missing access controls at an unnamed public hospital that exposed staff contact details and allowed internet users to control a hospital-wide mobile-alert channel. The issue was addressed before reported exploitation.
The initiative found an exposed administrator key at an unnamed Middle Eastern national archive that allowed reading, modifying, and deleting 8.8 million files. Correcting permissions remediated the exposure.
Google completed its acquisition of Wiz, bringing the cloud-security company into Google Cloud.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.