As a cybersecurity guy...
There are a lot of cybersecurity people that really know nothing about actual security and just rely on what their tools tell them. And products like Wiz love to "prove" their value by raising tons of red flags.
This is especially true for vulnerability management, which is basically Boy-Who-Cried-Wolf as a Service. The entire CVE ecosystem used to be great, but now it's turned into resume-driven-development where people exaggerate the severity of a vulnerability in order to have a CVSS 9.8 on their resume.