Google cybersecurity subsidiary Wiz has launched Scan for Good, an AI-driven initiative that has already uncovered critical security exposures at a public hospital and a private hospital.
The program pairs Wiz’s AI-powered Red Agent penetration-testing tool with Google DeepMind’s Gemini 3.8 Flash Cyber model to scan public-facing websites, APIs and applications for exploitable weaknesses at critical infrastructure, public services, healthcare organizations and nonprofits. Wiz, which Google acquired earlier this year for $32 billion, built Scan for Good in partnership with Google DeepMind and the Cybersecurity and Infrastructure Security Agency.
At one public hospital, missing access controls exposed staff contact information and let anyone online control the hospital’s mobile alert channel, Wiz said in a Sept. 24 blog post. At a private hospital, an unsecured upload feature on a public appointment-booking site let attackers control a hospital server and expose patient identifiers, clinical records and consent signatures. Wiz worked with both organizations to fix the flaws before publishing the findings and did not name either hospital.
“Defensive vulnerability discovery helps strengthen the nation’s digital infrastructure,” stated acting CISA Director Nick Andersen.
Beyond healthcare, Scan for Good has also flagged exposures at a national archive, a municipal data system, a public rail operator and several major technology platforms, according to Wiz. The company plans to publish anonymized findings on vulnerability patterns as the program expands.