2 Sources
[1]
JFrog Partners with Wiz to Accelerate AI-Era Threat Remediation
The JFrog-Wiz integration is designed to close this gap by connecting both halves of the picture in real time. The integration operates through an API-based data workflow. JFrog Ltd the system of record for trusted software artifacts announced a new integration with Wiz, now part of Google Cloud, that closes a critical gap in AI-Era security: shrinking the time between risk detection and verified code fixes. The JFrog Platform serves as the single source of truth for all software artifacts - from build to production - while the Wiz cloud and AI security platform adds instant cloud runtime visibility. Together, the integration enables security and engineering teams with a unified view of what's running, where it came from, whether it's trusted, and how to fix it - enabling teams to keep pace with frontier AI models that move faster than most organizations can respond. . "Today's enterprise security teams are caught between two sources of information: AppSec teams see what was built but lose visibility once software ships. Cloud security teams see what is running but lack the supply chain context to understand the real risks," said Gal Marder, Chief Strategy Officer, JFrog. "Our partnership and integration with Wiz solves this by delivering a unified view from build to production - so teams can move from detection to remediation in hours vs. days." . In the Frontier AI era, the threat landscape has shifted fundamentally. Attackers now weaponize vulnerabilities faster than defenders can respond - the median time to exploit is now under a day, according to recent Forrester research. Yet Mean Time to Remediate (MTTR) - already a critical metric - has become even more consequential. Previously, teams measured remediation in days; now, the difference between hours and days can determine whether an organization is breached. . The bottleneck is no longer detection - it is manual investigation. AppSec teams see what was built and scanned; cloud security teams see what is running. That visibility gap forces teams to manually stitch together context across disconnected tools, turning threat response into a weeks-long investigation rather than a hours-long fix. . The JFrog-Wiz integration is designed to close this gap by connecting both halves of the picture in real time. The integration operates through an API-based data workflow. Wiz identifies vulnerable and exposed workloads across cloud environments and JFrog traces each workload back to its source artifact in JFrog Artifactory, enriches it with JFrog Advanced Security vulnerability findings, Contextual Analysis, and AppTrust provenance data. Together, security teams get a unified view and full control: what's running, where it came from, whether it's trusted, and how to fix it - without building custom dashboards or manual correlation. The result: teams spend less time reconstructing context and more time remediating. . The JFrog integration with Wiz delivers: . Faster risk-to-fix motion: What previously took days of manual investigation now takes hours. Security teams see Wiz findings and JFrog supply chain context in one unified view on the Wiz Security Graph with no manual correlation required. Continuous compliance instead of periodic audits: JFrog AppTrust cryptographic verification confirms every running workload matches what was signed and approved. This creates an environment for continuous compliance validation rather than snapshot-based periodic assessments. Ownership clarity and automatic routing: Every artifact carries the team, build pipeline, and individual who promoted it. When a threat is identified, ownership routes automatically - no time wasted chasing down who owns the fix. Automatic detection of untrusted deployments: Untrusted images running from unapproved registries are flagged automatically. Remediation paths trace directly to the build pipeline, with fix availability confirmed against existing Artifactory artifacts. Zero-friction integration: Based on an API connection, the integration requires no new agents, no cluster instrumentation, and no elevated cloud permissions. Customers running both JFrog Advanced Security and Wiz can operationalize this integration in just minutes. . "We're happy to collaborate with JFrog to bring cloud runtime visibility and software supply chain context together in one unified view," said Oron Noah, VP of Product, Extensibility & Partnerships at Wiz. "This integration helps customers spend less time on manual correlation and more time remediating risk." . The JFrog-Wiz integration is available to customers immediately and ships as part of JFrog Advanced Security. To learn more and see the integration in action visit www.jfrog.com/jfrog-and-wiz. .๐๐ญ๐๐ฒ ๐ข๐ง๐๐จ๐ซ๐ฆ๐๐ ๐ฐ๐ข๐ญ๐ก ๐จ๐ฎ๐ซ ๐ฅ๐๐ญ๐๐ฌ๐ญ ๐ฎ๐ฉ๐๐๐ญ๐๐ฌ ๐๐ฒ ๐ฃ๐จ๐ข๐ง๐ข๐ง๐ ๐ญ๐ก๐ WhatsApp Channel now! ๐๐ฒ๐ญ๐๐๐๐๐ ๐ถ๐๐ ๐บ๐๐๐๐๐ ๐ด๐๐ ๐๐ ๐ท๐๐๐๐ฌ ๐ Facebook, LinkedIn, Twitter, Instagram
[2]
JFrog Partners with Wiz to Close the Gap on AI-Era Threats, Keeping Global Businesses Secure
The leader in software supply chain collaborates with the leading cloud and AI security platform to deliver a single source of truth from code to cloud to runtime - giving teams the visibility and speed to remediate threats before attackers exploit them JFrog Ltd today announced a new integration with Wiz, now part of Google Cloud, that closes a critical gap in AI-Era security: shrinking the time between risk detection and verified code fixes. The JFrog Platform serves as the single source of truth for all software artifacts - from build to production - while the Wiz cloud and AI security platform adds instant cloud runtime visibility. Together, the integration enables security and engineering teams with a unified view of what's running, where it came from, whether it's trusted, and how to fix it - enabling teams to keep pace with frontier AI models that move faster than most organizations can respond. "Today's enterprise security teams are caught between two sources of information: AppSec teams see what was built but lose visibility once software ships. Cloud security teams see what is running but lack the supply chain context to understand the real risks," said Gal Marder, Chief Strategy Officer, JFrog. "Our partnership and integration with Wiz solves this by delivering a unified view from build to production - so teams can move from detection to remediation in hours vs. days." In the Frontier AI era, the threat landscape has shifted fundamentally. Attackers now weaponize vulnerabilities faster than defenders can respond - the median time to exploit is now under a day, according to recent Forrester research. Yet Mean Time to Remediate (MTTR) - already a critical metric - has become even more consequential. Previously, teams measured remediation in days; now, the difference between hours and days can determine whether an organization is breached. The bottleneck is no longer detection - it is manual investigation. AppSec teams see what was built and scanned; cloud security teams see what is running. That visibility gap forces teams to manually stitch together context across disconnected tools, turning threat response into a weeks-long investigation rather than a hours-long fix. The JFrog-Wiz integration is designed to close this gap by connecting both halves of the picture in real time. The integration operates through an API-based data workflow. Wiz identifies vulnerable and exposed workloads across cloud environments and JFrog traces each workload back to its source artifact in JFrog Artifactory, enriches it with JFrog Advanced Security vulnerability findings, Contextual Analysis, and AppTrust provenance data. Together, security teams get a unified view and full control: what's running, where it came from, whether it's trusted, and how to fix it - without building custom dashboards or manual correlation. The result: teams spend less time reconstructing context and more time remediating. The JFrog integration with Wiz delivers: * Faster risk-to-fix motion: What previously took days of manual investigation now takes hours. Security teams see Wiz findings and JFrog supply chain context in one unified view on the Wiz Security Graph with no manual correlation required. * Continuous compliance instead of periodic audits: JFrog AppTrust cryptographic verification confirms every running workload matches what was signed and approved. This creates an environment for continuous compliance validation rather than snapshot-based periodic assessments. * Ownership clarity and automatic routing: Every artifact carries the team, build pipeline, and individual who promoted it. When a threat is identified, ownership routes automatically - no time wasted chasing down who owns the fix. * Automatic detection of untrusted deployments: Untrusted images running from unapproved registries are flagged automatically. Remediation paths trace directly to the build pipeline, with fix availability confirmed against existing Artifactory artifacts. * Zero-friction integration: Based on an API connection, the integration requires no new agents, no cluster instrumentation, and no elevated cloud permissions. Customers running both JFrog Advanced Security and Wiz can operationalize this integration in just minutes. "We're happy to collaborate with JFrog to bring cloud runtime visibility and software supply chain context together in one unified view," said Oron Noah, VP of Product, Extensibility & Partnerships at Wiz. "This integration helps customers spend less time on manual correlation and more time remediating risk."
Share
Copy Link
JFrog has partnered with Wiz, now part of Google Cloud, to bridge a critical security gap in the AI era. The integration connects software supply chain context with cloud runtime visibility, enabling security and engineering teams to remediate threats in hours instead of days as attackers exploit vulnerabilities faster than ever.
JFrog Ltd has announced a strategic integration with Wiz, now part of Google Cloud, designed to dramatically reduce time between risk detection and remediation in an era where AI-era threats evolve faster than traditional security responses. The partnership connects JFrog's software supply chain context with Wiz's cloud runtime visibility, creating a unified view of software supply chains that enables security and engineering teams to move from detection to fix in hours rather than days
1
2
.
Source: CXOToday
"Today's enterprise security teams are caught between two sources of information: AppSec teams see what was built but lose visibility once software ships. Cloud security teams see what is running but lack the supply chain context to understand the real risks," said Gal Marder, Chief Strategy Officer at JFrog. "Our partnership and integration with Wiz solves this by delivering a unified view from build to production - so teams can move from detection to remediation in hours vs. days"
1
.The threat landscape has shifted fundamentally as frontier AI models enable attackers to weaponize vulnerabilities at unprecedented speed. According to recent Forrester research, the median time to exploit is now under a day
2
. This acceleration makes Mean Time to Remediate (MTTR) more consequential than ever. Previously, teams measured threat remediation in days; now, the difference between hours and days can determine whether an organization suffers a breach. The bottleneck has shifted from detection to manual investigation, as teams struggle to stitch together context across disconnected tools, turning threat response into weeks-long investigations rather than hours-long fixes1
.The integration operates through an API-based data workflow that connects both halves of the security picture in real time. Wiz identifies vulnerable and exposed workloads across cloud environments, while JFrog traces each workload back to its source artifacts in JFrog Artifactory. The system enriches this data with JFrog Advanced Security vulnerability findings, Contextual Analysis, and AppTrust provenance data
2
. Security teams gain full control over what's running, where it came from, whether it's trusted, and how to fix itโwithout building custom dashboards or performing manual correlation. What previously required days of manual investigation now takes hours, as teams see Wiz findings and JFrog supply chain context in one unified view on the Wiz Security Graph1
.Related Stories
The partnership enables continuous compliance validation rather than snapshot-based periodic assessments. JFrog AppTrust cryptographic verification confirms every running workload matches what was signed and approved, creating an environment for ongoing compliance rather than periodic audits
2
. Every artifact carries metadata identifying the team, build pipeline, and individual who promoted it. When a threat is identified, automatic ownership routing eliminates time wasted chasing down who owns the fix. The system also enables detection of untrusted deployments, automatically flagging untrusted images running from unapproved registries and tracing remediation paths directly to the build pipeline1
.The zero-friction integration requires no new agents, no cluster instrumentation, and no elevated cloud permissions. Customers running both JFrog Advanced Security and Wiz can operationalize this integration in just minutes
2
. "We're happy to collaborate with JFrog to bring cloud runtime visibility and software supply chain context together in one unified view," said Oron Noah, VP of Product, Extensibility & Partnerships at Wiz. "This integration helps customers spend less time on manual correlation and more time remediating risk"1
. The integration is available to customers immediately and ships as part of JFrog Advanced Security, positioning organizations to respond to vulnerabilities at the speed required in an era where attackers leverage AI to move faster than traditional defenses can counter.Summarized by
Navi
11 Mar 2026โขBusiness and Economy

10 Sept 2024

22 Nov 2024โขBusiness and Economy

1
Technology

2
Policy and Regulation

3
Technology
