Google and Wiz launch 'Scan for Good': AI agents to hunt and fix critical-infrastructure exposures
Google and Wiz jointly launch Scan for Good, pairing Google's Gemini 3.8 Flash Cyber with Wiz's Red Agent pentesting agent — validated by human researchers — to find and fix critical exposures at hospitals, transit, municipalities, and nonprofits, with CISA…
On 2026-09-24, Google and Wiz announced Scan for Good, an initiative that pairs Google's bug-hunting model Gemini 3.8 Flash Cyber (attributed by Wiz to Google DeepMind) with Wiz's Red Agent pentesting agent to scan public-facing sites, APIs, and applications of critical infrastructure, public services, and nonprofits. Human researchers validate every finding and make disclosure decisions. CISA endorsed the initiative and provided guidance as it scales globally with no set end date. Documented results include a critical script-injection flaw in Snowflake's snowflake-connector-net GitHub Actions workflow, fixed the same day it was disclosed; an exposed admin key granting read/write/delete access to 8.8 million files at an archive (The Register describes it as a Middle Eastern archive, Wiz as a national archive); and a leaked production database at a public rail operator exposing active administrator sessions that, per Wiz, control routes and schedules. Wiz reports hundreds of exposures already fixed and says the Red Agent has identified thousands of high and critical exposures in production environments.
- Initiative named 'Scan for Good,' announced 2026-09-24 jointly by Google and Wiz, in partnership with Google DeepMind and CISA.
- Uses Google's Gemini 3.8 Flash Cyber bug-hunting model plus Wiz's Red Agent pentesting agent; human researchers validate all findings and make disclosure decisions.
- Scope: public-facing sites, APIs, and applications of critical infrastructure, public services, and nonprofits — including hospitals, transit, and municipalities per The Register.
- Found a critical script-injection flaw in Snowflake's snowflake-connector-net GitHub Actions workflow, fixed the same day it was disclosed.
- Found an exposed admin key granting read/write/delete access to 8.8 million files at an archive; The Register calls it a Middle Eastern archive, Wiz calls it a national archive.
- Found a leaked production database at a public rail operator exposing active admin sessions that Wiz says control routes and schedules.
- Scale per Wiz: hundreds of exposures already fixed; Red Agent has identified thousands of high and critical exposures in production environments.
- CISA endorsed the initiative and provided guidance; the program scales globally with no set end date.
Coverage timelineoldest first · each row is one article
- · 2d agoGoogle to critical infra orgs: Our AI scanners won't be evil, promise
The Register · Security· 58
Google and Wiz launch Scan for Good, using Gemini 3.8 Flash Cyber and Red Agent to autonomously find critical vulnerabilities in hospitals, transit, and municipalities.
- · 2d agoScan for Good: Using AI to discover and fix high-priority exposures across public services and critical infrastructure
Wiz Blog· 55
Wiz launches 'Scan for Good,' pairing its AI Red Agent with Google DeepMind and CISA to find and fix critical public exposures.