Google Cloud ties Wiz to intel

- Google Cloud said on July 7 it connected Google Threat Intelligence with Wiz ASM so security teams can rank exposed assets using live attacker activity. - Google said the integration helps teams focus on exposures “adversaries are targeting in the wild,” instead of triaging a larger undifferentiated exposure list. - Google is positioning the capability through Wiz ASM and Google Threat Intelligence documentation and related proactive exposure management materials for customers now.

Google Cloud said on July 7 that it has linked Google Threat Intelligence with Wiz ASM, giving customers a way to rank exposed internet-facing assets using live attacker activity rather than static exposure data alone. The integration combines Google’s threat intelligence feed with Wiz’s attack surface management data, which maps domains, IPs, APIs and other exposed assets across cloud, software-as-a-service and on-premises environments. Google said the connection is meant to help security teams “focus on the exposures adversaries are targeting in the wild” and use that signal to prioritize remediation and threat hunting. ### What exactly is Google connecting to Wiz? Google Cloud said the new workflow pairs Google Threat Intelligence with Wiz ASM, the external attack surface management product in the Wiz platform. Google describes its threat intelligence service as a source of real-time visibility into adversary infrastructure and campaign activity, while Wiz ASM inventories exposed assets and validates issues such as exploitable vulnerabilities, misconfigurations, default credentials, exposed secrets and sensitive data. (cloud.google.com) Wiz said on July 8 that its ASM product is designed to cover cloud, AI, SaaS and on-premises environments, and that its Red Agent is used to uncover more complex logic-driven vulnerabilities. Google’s announcement positions the new tie-in as an automated connection between that exposure map and live intelligence on what attackers are actively using. ### What changes for security teams using it? Google said the practical change is prioritization. Instead of working from a raw inventory of exposed systems and findings, customers are being shown which of those exposures line up with infrastructure, techniques or campaigns that Google is seeing in the wild. (cloud.google.com) Google’s proactive exposure management materials make the same pitch more broadly, saying teams can pair real-time infrastructure monitoring with current threat intelligence to harden cloud environments based on “evolving threat actor tactics.” (wiz.io) Google’s H1 2026 Threat Horizons report gives the timing behind that argument. The company said the window between disclosure and active exploitation shrank from weeks to days in the second half of 2025, and recommended more automated defenses as a result. That makes exposure ranking more dependent on current attacker behavior than on severity scoring alone. ### Why is Google emphasizing this now? (cloud.google.com) Google completed its acquisition of Wiz on March 11 and said at the time it would retain the Wiz brand inside Google Cloud. In April, Google used its Next ’26 conference to describe a broader “Agentic Defense” strategy combining Google Threat Intelligence, Security Operations and Wiz’s cloud and AI security platform. The new ASM integration is one of the more specific product links disclosed since that acquisition closed. (services.google.com) Francis deSouza, Google Cloud’s chief operating officer and president of security products, said at Next ’26 that Google and Wiz were expanding coverage for cloud and AI applications across infrastructure environments. Google has also been presenting Wiz as part of a wider security stack that includes Mandiant expertise, threat intelligence and security operations tooling. (cloud.google.com) ### How does this fit the wider cloud security market? Wiz’s own research has argued that familiar cloud entry points still dominate intrusions. In its 2026 retrospective on 2025 incidents, Wiz said vulnerabilities, exposed secrets and misconfigurations remained the most common initial access paths in the cloud. That makes a product that can connect exposed assets to active attacker tradecraft easier to position as an operations tool, not just an inventory tool. (cloud.google.com) Google’s own materials describe the same direction. A Google Cloud solution brief for Wiz Defend says cloud operations teams need products that can correlate identity, data, network, compute and control-plane information to understand posture and respond to threats. That language puts the new integration in a broader industry move toward exposure management systems that are more tightly tied to active attacker telemetry. (wiz.io) Google is surfacing the feature through its July 7 blog post, its Google Threat Intelligence documentation and its proactive exposure management materials, while Wiz is separately expanding ASM coverage in product updates published July 8. (cloud.google.com) (services.google.com)

Get your own daily briefing

Scout delivers personalized news, insights, and conversations tailored to your role and industry.

Download on the App Store

Shared from Scout - Be the smartest in the room.