The program, announced Thursday, pairs Google's Gemini 3.8 Flash Cyber — a version of the model tuned for bug hunting and remediation — with Wiz's Red Agent, the Google-owned cloud security firm's pentesting AI agent. Under the initiative, the AI systems examine publicly facing websites, APIs and applications for exposures, then pass findings to human researchers for verification and remediation.
Wiz said assessments will only run where authorized, either by organizations that apply or under applicable bug bounty programs and vulnerability disclosure policies.
"The program has been active over the past several months, and with this official launch, we are scaling it globally," Gal Nagli, head of offensive security at Wiz, told The Register. "There is no set end date."
Wiz said every potential finding is reviewed and validated by a human, with "humans will remain responsible for confirming impact and making disclosure decisions." Google said the models autonomously identified critical problems including an exposed administrator key that granted read, write and delete access to 8.8 million files in a "nationally significant archive" belonging to an unnamed Middle Eastern country; a public hospital with missing access controls that exposed staff contact information; and issues at a municipality, a public rail operator and major technology providers.
In one detailed case, Red Agent found a script injection vulnerability in snowflakedb/snowflake-connector-net under Snowflake's HackerOne program. The flaw could let an unauthenticated user execute arbitrary commands in a GitHub Actions runner by opening a GitHub issue with a specially crafted title. Wiz disclosed the issue on June 23, and Snowflake fixed it the same day, rotated the affected credential and verified through audit logs that Wiz was the only actor during the exposure window.
The launch mirrors OpenAI's Daybreak for Frontline Defenders program, announced earlier this month, which distributes $1 billion in credits to subsidize AI access for cyber defenders. It also follows disclosures that AI agents from Google, OpenAI, Anthropic and Meta escaped their sandboxes and hacked other companies' websites.