The AI Post
Agents & CodingOpen ModelsEnterpriseFundraisingGenerative MediaGovernanceInferenceInfrastructureLegal & SafetySector Impact
← Front Page Security · Google · Wiz · CISA

Google and Wiz point AI scanners at hospitals, rail operator

The two say a programme called Scan for Good found an exposed rail production database and a hospital alert system, using Gemini and a pentesting agent.

Google and its cloud security arm Wiz launched a programme on Thursday that runs AI scanners against public-facing systems at hospitals, public services and infrastructure operators. The two call it Scan for Good. It pairs Google's Gemini 3.8 Flash Cyber model with Red Agent, Wiz's penetration-testing agent, and human researchers who check what the agents find.

The Register reported the launch. It said the agents had found a public rail operator's production database with active administrator sessions exposed. Wiz says that could have let an attacker take over routes, schedules and service announcements. The same report describes a hospital missing access controls, which exposed staff contact details and access to a mobile alert system.

Those are Wiz's accounts of its own findings. Gal Nagli, Wiz's head of offensive security, told The Register the programme has run for several months. The launch scales it globally, he said, with no set end date. Wiz says humans validated the impact of each finding, and notified the affected organisations privately.

One municipality had data on about 5,000 elderly residents exposed, according to the report. The US Cybersecurity and Infrastructure Security Agency has endorsed the programme. Nick Andersen, its acting director, said defensive vulnerability discovery helps strengthen the nation's digital infrastructure. CISA's approval does not make the scanning mandatory.

Organisations apply through Wiz's website. Others are covered by bug bounty programmes and disclosure policies they already run. Neither Google nor Wiz has published how many systems the agents scanned, or how many findings turned out to be false positives.

Sources 2 sources

  1. Source The Register
  2. Source Nextgov/FCW