research Archives
Researchers show that file-change notification systems can leak keystroke timing, browsing activity, and WhatsApp media events.

It is in this spirit that we are launching Scan for Good , an initiative that uses AI - coupled with human security researchers - to uncover public exposures and complex attack paths across public services, critical infrastructure, and nonprofits.
A vulnerability named ‘AI Agent Traps’ allows attackers to manipulate, deceive, and exploit visiting agents via malicious web content.
Through our collaboration with the Google DeepMind team, Gemini 3.8 Flash Cyber’s frontier cybersecurity performance is helping uncover complex attack paths in foundational AI and cloud technology, and fueling Wiz as we work with public services, nonprofits, and other critical infrastructure providers to ensure they stay ahead of AI-powered adversaries.
Our partners at Google DeepMind were critical to both initiatives: the AI-powered tooling behind Scan for Good is powered by the Gemini family of models, especially the new Gemini 3.8 Flash Cyber.
Scan for Good helps defenders secure vital systems before malicious actors can exploit them .
For example, a partner's security agent investigating a suspicious Issue can pull the full Issue context from Wiz mid-investigation - the affected resources, the toxic combination behind it, the blast radius, and the attack path - without the customer ever leaving the partner's platform.
September 30, 2026 Update: Our Scan for Good initiative now uses Gemini 4 Argon , alongside Gemini 3.8 Flash Cyber.
Researchers show that file-change notification systems can leak keystroke timing, browsing activity, and WhatsApp media events.
Instead of batch API calls, your agent uses MCP tools to pull Wiz context such as Issues, Findings, and resources on demand as it works, directly from customer tenants.
It can emerge from the combination of configurations, permissions, identities, APIs, and application behaviors that may appear benign individually but create dangerous attack paths when connected.
What happened
It is in this spirit that we are launching Scan for Good , an initiative that uses AI - coupled with human security researchers - to uncover public exposures and complex attack paths across public services, critical infrastructure, and nonprofits.
A vulnerability named ‘AI Agent Traps’ allows attackers to manipulate, deceive, and exploit visiting agents via malicious web content.
What changed
Through our collaboration with the Google DeepMind team, Gemini 3.8 Flash Cyber’s frontier cybersecurity performance is helping uncover complex attack paths in foundational AI and cloud technology, and fueling Wiz as we work with public services, nonprofits, and other critical infrastructure providers to ensure they stay ahead of AI-powered adversaries.
Our partners at Google DeepMind were critical to both initiatives: the AI-powered tooling behind Scan for Good is powered by the Gemini family of models, especially the new Gemini 3.8 Flash Cyber.
Who is affected
Scan for Good helps defenders secure vital systems before malicious actors can exploit them .
For example, a partner's security agent investigating a suspicious Issue can pull the full Issue context from Wiz mid-investigation - the affected resources, the toxic combination behind it, the blast radius, and the attack path - without the customer ever leaving the partner's platform.
Why it matters
September 30, 2026 Update: Our Scan for Good initiative now uses Gemini 4 Argon , alongside Gemini 3.8 Flash Cyber.
Researchers show that file-change notification systems can leak keystroke timing, browsing activity, and WhatsApp media events.
Technical details
Instead of batch API calls, your agent uses MCP tools to pull Wiz context such as Issues, Findings, and resources on demand as it works, directly from customer tenants.
It can emerge from the combination of configurations, permissions, identities, APIs, and application behaviors that may appear benign individually but create dangerous attack paths when connected.
Scan for Good brings these capabilities to organizations where successful exploitation could have an outsized impact, including critical infrastructure, public services, healthcare, and nonprofits.
Response
Our efforts spent validating findings and collaborating with the affected organizations on remediation have uncovered hundreds of public exposures that were fixed as a result of Scan for Good.
Every potential finding will be reviewed and validated by a human researcher.
What security teams should do
The agent gets richer context, the investigation is faster, and the customer gets a more complete picture from the tools they're already using.
Attribution
SecurityWeek: Researchers show that file-change notification systems can leak keystroke timing, browsing activity, and WhatsApp media events.
Wiz Research: September 30, 2026 Update: Our Scan for Good initiative now uses Gemini 4 Argon , alongside Gemini 3.8 Flash Cyber.
Wiz Research: Securing AI requires more than scanning models and flagging misconfigurations.
What to watch next
Watch for updated vendor guidance and fixed-version details.