# AI scanning tools found security gaps at rail operator and hospitals, Wiz says

> Source: <https://www.nextgov.com/cybersecurity/2026/09/ai-scanning-tools-found-security-gaps-rail-operator-and-hospitals-wiz-says/416181/>
> Published: 2026-09-24 13:00:00+00:00

# AI scanning tools found security gaps at rail operator and hospitals, Wiz says

## Researchers discovered access to rail administration systems, a hospital alert channel and sensitive records in a new effort aimed at organizations with limited cyber resources.

Artificial intelligence-enabled security testing tools developed by Google-owned cybersecurity company Wiz uncovered weaknesses that exposed a public rail operator’s administrative systems and gave outsiders a way to control a public hospital’s mobile alert channel, the company said Thursday.

At the rail operator, a leaked database exposed active administrator sessions, enabling access to routes, schedules, service announcements and management accounts. Researchers worked with the operator to secure the system “before public transportation could be disrupted,” Wiz officials said.

At the hospital, missing access restrictions exposed staff contact information and allowed anyone online to control a systemwide mobile alert channel. Additionally, a separate private hospital’s appointment-booking website contained an unsafe file-upload feature that enabled control of a server and exposed patient identifiers, clinical information and consent signatures.

The findings are among the early results of the firm’s new Scan for Good initiative that pairs AI tools with in-person researchers to identify and help fix security weaknesses affecting public services, critical infrastructure and nonprofits. Wiz says the effort has helped organizations fix hundreds of exposures and that humans were involved in validating their impact and privately notifying affected groups.

The cases show how digital weaknesses in public-facing websites and applications can open a path to sensitive systems, and how AI tools can help rapidly identify those entry points. Several involved exposed credentials or missing permission checks that allowed researchers to gain broader access without discovering a previously unknown software flaw.

They also underscore how fast evolving cyber-focused AI tools can benefit defenders and attackers alike. Access to these systems in the wrong hands could have allowed cyber intruders to steal patient records, send false hospital alerts or alter transit service information.

Both of those domains have been real-world cyber victims. A May 2024 [hack](https://www.hipaajournal.com/ascension-cyberattack-2024/) on the Ascension health system disrupted access to electronic patient records and forced some hospitals to divert ambulances. Last year, a [Russian cyberattack](https://www.kyivpost.com/post/49656) knocked Ukraine’s state railway ticketing system offline.

Wiz did not identify the affected rail operator, hospitals or other organizations described in its release that outlined Scan for Good’s early testing results. The company-described exposures have been addressed and did not say those openings were leveraged by hackers.

Other discoveries involved sensitive government records, in which a municipal data service exposed personal, health and financial information from about roughly 5,000 elderly residents. In another case, an exposed administrator key also permitted reading, modifying and deleting 8.8 million files in a national archive in an unnamed Middle Eastern country.

The company also uncovered risks at technology providers whose products support other organizations. At one cloud provider, a credential exposed in public website code could have allowed hackers to publish malicious software across more than 500 production container images supporting a flagship AI service, Wiz said without naming the entities involved.

“Historically, finding and understanding these paths at scale required significant time, expertise, and manual investigation,” said Wiz executives Ami Luttwak and Gal Nagli. “AI is changing that, making it dramatically easier to discover exposed systems, understand how they behave, and connect weaknesses into real attack paths.”

Scan for Good uses Wiz’s “Red Agent” penetration-testing tool and other internal research capabilities backed by Google DeepMind’s Gemini models. Google completed its acquisition of Wiz in March, bringing the company into Google Cloud. DeepMind has separately launched [Fairwind](https://blog.google/innovation-and-ai/technology/safety-security/fairwind-program/), which provides select groups, including governments and healthcare providers, early access to advanced cyber models. 

Fairwind comes after Anthropic earlier this year launched [Project Glasswing](https://www.nextgov.com/cybersecurity/2026/04/anthropics-glasswing-initiative-raises-questions-us-cyber-operations/412721/), giving selected companies and developers access to its restricted Mythos model to find and fix software vulnerabilities before similar capabilities became widely available. What followed was a federal push to assess advanced models’ hacking capabilities and expand their use for cyberdefense.

Wiz said the Cybersecurity and Infrastructure Security Agency also provided collaboration and guidance on its Scan for Good initiative, without detailing the agency’s operational role. *Nextgov/FCW* has asked Wiz and CISA for more details on the agency’s involvement.

The launch of Mythos has intensified efforts by global governments and technology companies to assess AI’s hacking capabilities and give defenders access to tools that could also help attackers break into sensitive systems.

In recent weeks, concerns about losing control of advanced AI tools have [gained urgency](https://www.nextgov.com/artificial-intelligence/2026/09/hawley-launches-committee-investigation-openais-breach-hugging-face/415910/) following disclosures that some models took unauthorized actions on real computer systems during testing. Australian Prime Minister Anthony Albanese [disclosed Wednesday](https://www.politico.com/news/2026/09/23/openai-australia-government-breach-01091069?utm_source=dlvr.it&utm_medium=twitter) that an OpenAI agent gained unauthorized access to a government health statistics portal in June.

A June [executive order](https://www.nextgov.com/artificial-intelligence/2026/06/trump-signs-ai-executive-order-after-postponement-last-month/413912/) directed federal agencies to expand access to AI cybersecurity tools for state and local governments and critical infrastructure operators, including rural hospitals and local utilities. It also called for classified assessments of advanced models’ hacking capabilities and a voluntary process for developers to provide government access before releasing them to other trusted partners. 

U.S. spy agencies are pursuing their [own uses for AI](https://www.nextgov.com/artificial-intelligence/2026/04/cia-plans-ai-coworkers-deputy-director-says/412744/), including for offensive cyber operations, network defense scanning, data analysis and intelligence report creation, among other cases.
