AI scanning tools found security gaps at rail operator and hospitals, Wiz says

https://cdn.nextgov.com/media/img/cd/2026/09/23/GettyImages_1221311412/open-graph.jpg

bjdlzx/Getty Images

ByDavid DiMolfetta,
Cybersecurity Reporter, Nextgov/FCW

September 24, 2026 09:00 AM ET

Researchers discovered access to rail administration systems, a hospital alert channel and sensitive records in a new effort aimed at organizations with limited cyber resources.

Artificial intelligence-enabled security testing tools developed by Google-owned cybersecurity company Wiz uncovered weaknesses that exposed a public rail operator’s administrative systems and gave outsiders a way to control a public hospital’s mobile alert channel, the company said Thursday.

At the rail operator, a leaked database exposed active administrator sessions, enabling access to routes, schedules, service announcements and management accounts. Researchers worked with the operator to secure the system “before public transportation could be disrupted,” Wiz officials said.

At the hospital, missing access restrictions exposed staff contact information and allowed anyone online to control a systemwide mobile alert channel. Additionally, a separate private hospital’s appointment-booking website contained...

Copyright of this story solely belongs to www.nextgov.com. To see the full text click HERE

Read more