Wiz AI Security ยท July 29, 2026

The Wiz Red Agent is Now Generally Available

Why it matters

Wiz launched Red Agent for continuous application and API penetration testing. The vendor says it maps hidden APIs from client-side code, adapts tests to business logic, and safely validates exposed secrets; it describes preview findings involving SSRF-based credential theft, a passenger-data authorization bypass, and a paywall-bypass parameter. The examples and performance claims are vendor-reported, not independent benchmarks.

My takeaway: Use this as a candidate for scoped continuous validation, not proof that autonomous penetration testing is safe or complete. A pilot should require target allowlists, non-destructive test policies, credential isolation, reproducible exploit traces, human triage, coverage and false-positive measures, and tested stop and rollback controls before production access.