IT Brief Asia - Technology news for CIOs & IT decision-makers
Asia
Wiz says many cloud alerts are not real attack paths

Wiz says many cloud alerts are not real attack paths

Thu, 27th Aug 2026 (Today)
Mark Tarre
MARK TARRE News Chief

Wiz has published its State of Cloud Risk 2026 report, which argues that most high-severity cloud security findings do not create a real attacker path.

It says cloud security teams face two linked pressures: expanding attack surfaces and less time to respond when vulnerabilities are disclosed. Wiz Research, citing ZeroDayClock data, said the average period between disclosure and active exploitation has fallen from more than two years to 21.5 days.

That shift increases pressure on companies already handling large volumes of alerts across cloud estates spanning thousands of software products. Speed matters, the report says, but response efforts are often misdirected when teams treat every alert as equally urgent.

Context over volume

Wiz assessed high-priority alerts in enterprise environments before and after applying what it described as critical risk criteria, including external reachability, combinations of permissions that could increase risk, and access to sensitive data.

According to the findings, that contextual analysis removed more than half of the initial findings across four major risk categories. Many alerts that appear severe in isolation do not amount to an exploitable route unless they are combined with internet exposure, paths for lateral movement, or nearby high-privilege identity and access management roles.

The study makes a broader point about how cloud risk should be assessed. Rather than focusing on severity scores alone, defenders should examine whether separate weaknesses combine into a usable chain that would let an attacker move through an environment.

Perimeter focus

The report also argues that the traditional emphasis on defending entry points is no longer enough in cloud environments. Wiz said 30% of the cloud environments it observed had at least one externally exposed machine linked to high-impact lateral movement paths.

That matters because the initial foothold may be less important than the access an attacker can gain after entering a system. The report identifies privilege and reachability as the main factors that determine whether a breach can grow into a wider compromise.

By contrast, software remote code execution accounted for only 9% of the findings observed in telemetry reviewed by Wiz Research. This suggests that exploitability in practice is more heavily concentrated around exposed access pathways, credentials, and secrets than around software vulnerabilities alone.

Patch priorities

The report also challenges broad patching programmes that try to address every alert at once. Wiz said exploitable risk is concentrated in a relatively small set of technologies and exposures rather than spread evenly across the cloud stack.

That concentration means security teams can reduce a large share of overall risk by directing resources towards a core group of technologies associated with critical and weaponised exploits. The report presents this as an argument for narrower, more selective remediation rather than campaigns driven by total alert volume.

Wiz frames the findings as a response to a cloud security environment in which reconnaissance is increasingly automated and exploitation timelines are shrinking. In that setting, the difference between a routine issue and a serious incident often depends on whether a flaw sits alongside reachable systems, excessive privilege, or exposed credentials.

For security teams, the practical lesson is that not every serious-looking finding warrants the same level of urgency. The analysis suggests many high-severity alerts remain isolated and do not offer attackers a workable route unless they intersect with access and privilege in the same environment.

The report concludes that cloud security teams need to identify what it calls the toxic intersections of access and privilege, rather than rely on patching alone to manage expanding cloud attack surfaces.