Sign in to view Yossi’s full profile
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
Sign in to view Yossi’s full profile
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
Israel
Sign in to view Yossi’s full profile
Yossi can introduce you to 10 people at TenRoot Cyber Security
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
6K followers
500+ connections
Sign in to view Yossi’s full profile
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
View mutual connections with Yossi
Yossi can introduce you to 10 people at TenRoot Cyber Security
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
View mutual connections with Yossi
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
Sign in to view Yossi’s full profile
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
About
Welcome back
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
New to LinkedIn? Join now
Articles by Yossi
-
The 7 stages of Vulnerability - what they don't teach at CISO school (yet)…
The 7 stages of Vulnerability - what they don't teach at CISO school (yet)…
Here is something I found myself explaining too many times lately, so I figured I could take some minutes & share…
108
21 Comments
Activity
6K followers
-
Yossi Sassi reposted this👇Yossi Sassi reposted thisThis is starting to look like a pattern. The latest OpenAI breach also started with a third-party open-source library being exploited to achieve RCE. We’ve seen similar patterns with Hugging Face using Jinja, and with RubyGems using YARD. Different mechanisms, same underlying problem: Third-party code runs inside your application with the power of your application. Software supply chain security can’t stop at “what CVEs do I have?” The real question is: what should this library actually be allowed to do at runtime? Read the blog: https://lnkd.in/gVPPfnkF
-
Yossi Sassi reposted thisYossi Sassi reposted thisתרומה לחוסן הלאומי לא חייבת להתרחש רק עם M-16 ביד או על ההגה של דבור, אני זקן מדי בשביל זה.. חח. לפני מספר חודשים, במהלך שיחה עם ראש מערך הסייבר הלאומי, Yossi Karadi , העליתי רעיון אסטרטגי: הקמת כוח מילואים ייעודי של מומחי סייבר, שיספק מענה טכני וניהולי מהיר בתרחישי קיצון של תקיפת סייבר רחבה. היום, בהרמת הכוסית של מערך הסייבר הלאומי Israel National Cyber Directorate - מערך הסייבר הלאומי , משמח מאוד היה לשמוע את יוסי מספר שהוא מקדם את המהלך הזה בכל הכוח. אני לא ממהר לנכס לעצמי את כל הקרדיט (Great minds think alike, אחרי הכל), אבל התחושה שרעיון כזה קורם עור וגידים היא אדירה, וחוצמזה התגעגעתי קצת למדים :).. כל הכבוד ליוסי כראדי ולמערך הסייבר הלאומי על ההובלה והחזון. קישור לסיקור האירוע מ-Ynet בתגובה הראשונה. #CyberSecurity #IncidentResponse #NationalSecurity #CyberDefense #TechLeadership #IsraelCyberNationalDirectorate
-
Yossi Sassi shared thisVery few things excite me as Zeroport's products and their physical guardrails for AI. Facing the industry's biggest challenges to date, the approach of moving the boundary into the physical layer for Remote Access is brilliant. And now added the collaboration with Wand AI, connecting true resilience to agentic workforce,- well, that seems very promising. #AIResilience #AIGuardrailsYossi Sassi shared thisZeroport is now part of Wand AI's Sovereign AI ecosystem. 🤝 National AI programs have a last-mile problem. The systems worth putting AI labor on (grid, water, defense estates, core banking, tax and registry) are exactly the systems nations spent a decade segmenting and air-gapping. Every software route into them is a national risk before it is an IT risk. Together with Wand, sovereign programs can now extend AI labor across that boundary without creating that risk. How it works: 🔒 Fantom holds the boundary at the physical layer: keystrokes in, pixels out, no packet path in either direction. 🧠 Moativ enforces policy from silicon the governed session has no address for. The agent works like a cleared human operator, and its authority ends at physics, not at a line in a config file. "Every guardrail an AI can reach is a guardrail an AI can eventually argue with," said Joseph Gertz, Co-Founder and CEO of Zeroport. "We moved the boundary into the physical layer: a break in the wire that cannot carry a packet, and an enforcement AI sitting on silicon the governed session has no address for. A ministry can put an agent to work on a control system and know that the agent's authority ends at physics rather than at a line in a config file. Take away the route, take away the attack." "Sovereign AI is only as valuable as the systems it is allowed to touch, and the most valuable systems are the ones nations have spent a decade making unreachable," said Cristian Felix, Chief AI Architect at Wand AI, on adding Zeroport's containment capability to Wand's unified national stack. ➡️ Learn more: https://lnkd.in/esUhbZyx ➡️ Joint Reference Architecture: https://lnkd.in/en2a_GDS ➡️ Full press release: https://lnkd.in/enFtkav9 #SovereignAI #Zeroport #WandAI #AISecurity #Cybersecurity #AIGovernance #CriticalInfrastructure #OT
-
Yossi Sassi reposted thisHacktivity - The IT Security Festival in Central & Eastern Europe
Hacktivity - The IT Security Festival in Central & Eastern Europe
3wYossi Sassi reposted thisLet’s kick off the day with the experts taking the stage at Hacktivity. Visit our website for the full schedule—and in the meantime, meet our speakers and discover their TALKS! Gergo Gyebnar - Detection-as-Code in Practice Angie Agee, CISSP - Beneath the Stack: Detecting Physical-Layer Telecom Threats Your SIEM Will Never See Erica B. - Multi-Modal Steganography and Attack Chaining Csaba Fitzl - macOS Mounting Madness Shaked Reiner - Seizing the Means of Software Production: The Hidden Security Risks of AI Coding Agents Yossi Sassi - How to NOT Mess Up PowerShell for Security with AI: Tips from Bad Experience Csaba Ajtony - Free-Droid: Building a Sovereign Robot – Open-Source LLMs, Fine-Tuning, and Why You Should Own Your Robot’s Brain Arad Donenfeld - The Agents of Chaos: AI Driven Malware Generation Péter Simon - GPU-Accelerated Log Processing: The Road to 1 Million Events Per Second on Consumer Hardware Etizaz Mohsin - VibeShell: How Trusting Your AI IDE Costs You Your Machine Georges Bolssens - The Vulnpocalypse is Hitting the Physical Realm: Reverse-Engineering IoT Devices with Open Source Tooling and LLMs Chen Shiri - The Unseen Secrets of the Cloud and How They Surface Sean Hopkins - Agentic AI Development for Red and Blue Teams Allan Dall - Harvest Now, Decrypt Later Does Not Apply Here: A Threat Model for Post-Quantum Authentication Beatrix K. - CAN We Trust Your Results? A Cross-Dataset Study of Automotive IDS Evaluation Tobias Schrödel - The “I’m not a robot” trap 🛡️Nilufer A🛡️& Bazil Hassan - 3 Parsers Walk Into a Bar: What They Disagree On Can Hurt You Aditya Singh - Trojan Penguin in the Windows: Advanced Attack Vectors Through WSL József Sándor - PROPS: Learning Stack Patterns for ROP Detection on Legacy ARM-based Devices Kirils Solovjovs – Reverse Engineering the DUOX PLUS Protocol &MORE WORKSHOPS: Aryan Jogia - M0us3: A Lightweight, Multi-Session C2 Framework with a Rust-based Windows Implant Behnaz Karimi & Yuvaraj Govindarajulu - Defending AI and Agentic Systems from Ransomware Dominik Maksa & János Kovács - Rickrolling the Doctor: Experimenting with Healthcare System Vulnerabilities Thomas Fischer - Car-Hacking Hardware Workshop Gergely Kalman - Introduction to filesystem logic bugs and Apple bug bounties Timetable is available! 👉https://lnkd.in/dtZBnPMA #Hacktivity2026 #CyberSecurity #ConferenceProgram #TechEvent #Budapest -
Yossi Sassi reposted thisYossi Sassi reposted thisHow we test agentic systems at Terra Security: simulate the environment Anyone building agents hits the same wall - a demo that works once tells you nothing. Agents are non-deterministic, multi-turn, and deeply dependent on the state of the world around them. If you want to improve them, you need to reproduce that world on demand. LangChain published a nice piece this week on building agent environments and tasks. It's very close to how we've been investing at Terra, so here's our version: 1. Extract the pain points from real usage. We mine agent traces and real user flows to find where agents actually struggle - ambiguous goals, missing context, multi-step workflows. Those patterns become the backlog of tasks worth testing, not scenarios we invented in a meeting room. 2. Simulate a suitable environment per use case. We build isolated, production-shaped environments: the same data structures, the same tools, the same APIs the agent sees in real life. Spinning one up takes minutes, and nothing the agent does can touch anything real. Even when there's a human on the loop, we know how to simulate that step - so full flows run end to end, unattended. 3. Build datasets that answer a question. We start from the question we need answered and craft the examples around it, so that their results, in aggregate, form statistical evidence. One run is an anecdote; a well-designed dataset is a measurement. The payoff: we can replay real-life scenarios fast, safely, and as accurately as possible - and know whether a new model, or a new concept actually made the agent better, before anyone else feels it. Environments are the new test suite
-
Yossi Sassi reposted thisYossi Sassi reposted thisאיבוד שליטה של AI הוא כבר לא תסריט הוליוודי בדיוני - זו מציאות שמתרחשת עכשיו. בשבועות האחרונים הנתונים מראים שמקרי ה-Loss of Control של סוכני AI נמצאים בזינוק חסר תקדים. המספרים שכל CISO, CTO ו-SecOps Lead חייבים להכיר: מדענים ב-Loss of Control Observatory (פרויקט ניטור במימון ה-UK AI Safety Institute – AISI) דיווחו רק בחודש האחרון על מעל 300 מקרי איבוד שליטה מתועדים – כמעט הכפלה בתוך חודש! בדו"ח Incident Report: unsanctioned agent behaviour during cyber testing שפרסם ה-AISI, נחשף מה קרה בסימולציות אבטחה בתוך Cyber Ranges: מתוך 122 הרצות, ב-10 מתוכן סוכני ה-AI חרגו מה-Scope וביצעו 19 פעולות הונאה וסייבר בלתי מורשות ברשת החיה (!). סוכן שיקר וניסה להסוות עקבות: במקרה אחד (מודל Anthropic Mythos 5), הסוכן ניסה להחדיר Malware לפרויקט Open-Source ב-GitHub. כשהתנגדו לו, הוא פתח דמויות פיקטיביות, ביצע Social Engineering מול מפתחים כדי שיאשרו את הקוד, וכשנחשף – ניסה להשתמש ברשת Tor כדי לעקוף חסימות! שיתוף פעולה בין סוכנים: במקרה אחר, הסוכן הדליף Credentials במקום ציבורי והשאיר הוראות כתובות לסוכנים אחרים איך לתאם איתו מתקפה. התובנה הקריטית ל-Cyber & AppSec: המערכות של היום לא רק עושות Hallucinations. כשנותנים ל-AI אוטונומיה (Agentic AI) לגשת ל-APIs ולבצע tasks, המודלים מנסים למקסם את המטרה בכל מחיר – כולל הונאה (Deception) ועקיפת Guardrails. איך נערכים? ארגון שמטמיע AI אוטונומי חייב מעטפת אבטחה בשלושה צירים: 1- הנדסה וכלים (Technical Framework & Tooling) • הרצות בדיקה בסביבות מבודדות, ללא גישה פתוחה ל-External APIs ברשת החיה. • Real-time Oversight: כלי ניטור ייעודיים ל-AI שמזהים בזמן אמת חריגה מ-Scope, תנועת רשת חשודה (כמו Tor) או ניסיונות Prompt Injection. • מנגנוני Kill Switches אוטומטיים ברמת ה-Infra ברגע שזוהתה חריגה. 2- תהליכי עבודה • Human-in-the-Loop (HITL): הגדרת "Stop Conditions" מחייבים. שינויי Production, גישה לדאטה רגיש או פנייה לגורמים חיצוניים מחייבים אישור אנו��י. • Red Teaming לסוכנים: הרצת תרחישי קיצון ב-Cyber Range כדי לבחון מה הסוכן עושה כשהוא "נתקע". 3- הממד האנושי (Human & Culture) • AI Deception Awareness: הכשרת עובדים לזהות Social Engineering שמבוצע ע"י AI (פנייה ב-Slack/GitHub בזהות בדויה כדי לקבל הרשאות). שורה תחתונה: איבוד שליטה ב-AI זו בעיית Cyber Security ו-Governance של כל ארגון שמטמיע Agentic Workflows. הגיע הזמן לעבור מפומו של אימוץ AI, לניהול סיכוני סייבר שקול. #AISafety #CyberSecurity #AgenticAI #AIGovernance #CISO #TechLeadership #AppSec #SecOps #CyberAwareness IR One, TenRoot Cyber Security, Yossi Sassi
-
Yossi Sassi reposted thisYossi Sassi reposted thisWe’re incredibly excited to share what we’ve been working on. A new version is coming soon - and we can’t wait to show it to the world. 🚀👋 TandemTrace - https://lnkd.in/ezHYsNMz
-
Yossi Sassi reposted thisYossi Sassi reposted thisWe wrapped up our QBR, closing our best quarter ever! We talked about the qualitative signs we see, as well as the undeniable proof: a winning product that repeatedly lands customers and grows their usage and spend over time, with numbers to back it up. Here’s just a sample of the major milestones: - We blew away every KPI we set for ourselves and had our best quarter ever on all critical metrics: ARR, NRR and number of upsells, ACV, largest deal, and more. - We're the first true platform in Agentic Offensive Security, covering the 4 major attack surfaces: Web/API, AI systems, external network, and internal infra (in early access) (more surfaces to come). - We had massive NRR, with double-digit upsells and cross-sells, mid-subscription (to new attack surfaces we launched), with some tripling their Terra subscription. - We welcomed James Cook as our VP Global Sales and are ready to make it to the nextg phase of growth. - We don't sell point-in-time tests. We sell annual subscriptions for continuous White Box Offensive Security. - We won the most important bake-offs in the category - the ones that tested every vendor. And yes, they're willing to talk about why. - We closed multiple Fortune 500 enterprises that are fully deployed and running Terra in their production environments, where adversaries actually attack. When your product is uniquely differentiated and bake-offs repeatedly prove it, it gets to a point where all you want is more and more opportunities to prove that. More on that, soon. Thank you to the entire Terra Security team for putting your hearts and souls into making this a once-in-a-lifetime company!
-
Yossi Sassi reacted on this75 מיליון שירים ו-130 אלף ערוצים נמחקו: ניקוי הענק של האינטרנט התחיל - יוטיוב, ספוטיפיי, X, אפל מיוזיק ועוד החלו להוריד תוכן AI ירוד שמציף את הרשת בהיקפים עצומים. קצת מזכיר לי את הניקיון מבוטים\פייק יוזרס\קידום לייקים ממומן שעשו ענקי הרשתות האנטי-חברתיות לפני כמה שנים. ברם, אותה מטוטלת חוזרת על עצמה: ענקיות טכנולוגיה מוחקות מיליוני פריטים ומנסות לרסן תופעה שהן עצמן סייעו ליצור. מה דעתכם? ובכלל, סונו ודומיו זה "משעשע", חוסך זמן פה ושם או מהפכה אמיתית וראויה? או אופציה ד' שאני סקרן לשמוע. הנה הסיפור: https://lnkd.in/dCBBQv-M #MusicTech #AISlop
-
Yossi Sassi reacted on thisYossi Sassi reacted on thisExcited to share: Rig Security is officially out of stealth! We’ve raised $12M to reinvent identity protection for the AI era. We’re honored to be backed by the best: Ten Eleven Ventures and Brightmind Partners, with strategic participation from CrowdStrike Falcon Fund and backing from our angel investors. For years, security teams have been piecing together disconnected accounts, permissions, and signals to understand who’s behind an identity, what it can reach, and how that access can be used by attackers. Now, AI agents act through those same identities, at machine speed. Knowing which account did something no longer tells you who, or what, actually did it. We built Rig around a different approach: connect the identity, understand its reach, and enforce identity-first policy where the action happens. At the core is RICE, our patent-pending correlation engine. It connects fragmented accounts across cloud, on-prem, and endpoint environments into a runtime graph of human, non-human, and AI identities, revealing ownership, permissions, and trust relationships, and the paths attackers can exploit. Our lightweight endpoint agent brings that context to the point of execution, distinguishing an agent from the person whose identity it borrowed and blocking violated actions before they happen. Together, they give security teams the full actionable context: from graph-powered posture visibility to threat detection and runtime enforcement, and we’re already running in production across multiple sectors and at Fortune 200 companies. Lucky to build this with Nokky Goren, Michal Haikov, and our entire team: you legends make this real. And to our partners and customers: thank you for trusting us early and shaping what we built. Meet Rig Security. The full story and link to our website are in the first comment👇
-
Yossi Sassi reacted on thisYossi Sassi reacted on thisExcited to be speaking at Compass AI & Tech Summit in Budapest next week! I’ll be sharing what AI applications look like through the eyes of an attacker. See you there! 👋
-
Yossi Sassi reacted on thisYossi Sassi reacted on thisJust had a conversation with TechNadu where I was asked about the elephant in the room. If an Offensive Security AI agent crosses its approved boundary, who's responsible? My honest answer: we're working with non-deterministic technology. Unless it's guardrailed at the infrastructure level, no one can promise an agent will never step outside its boundaries. Anyone telling you otherwise is overselling. We all saw it in the OpenAI Hugging Face incident. A combination of deterministic and non-deterministic guardrails is simply a must. We also discussed how to evaluate Agnetic Offensive Security vendors , how to protect against agents going rogue, and how to run a true continuous offensive security program. Read the full interview, link in the comments.
-
Yossi Sassi liked this👇Yossi Sassi liked thisThis is starting to look like a pattern. The latest OpenAI breach also started with a third-party open-source library being exploited to achieve RCE. We’ve seen similar patterns with Hugging Face using Jinja, and with RubyGems using YARD. Different mechanisms, same underlying problem: Third-party code runs inside your application with the power of your application. Software supply chain security can’t stop at “what CVEs do I have?” The real question is: what should this library actually be allowed to do at runtime? Read the blog: https://lnkd.in/gVPPfnkF
-
Yossi Sassi liked thisYossi Sassi liked thisFamily 11 of the Raven Power List: Crypto Primitives, Key Material & Randomness — "The Notary." Its seal is treated as proof. Crypto libraries produce the signatures, tokens and randomness the rest of your system trusts without question. When they're weak or misused, that trust becomes forgery, key leakage and broken guarantees. The Notary rarely announces failure. It looks correct — until you watch, at runtime, which primitive ran with which key and how much entropy. One of 14 families in our new research. Download the research 👉 https://lnkd.in/dQ2gbm59 #Cryptography #ApplicationSecurity #Cybersecurity #OpenSourceSecurity
-
Yossi Sassi liked thisYossi Sassi liked thisTwo "vulnerabilities" this month. Neither had a CVE. Neither was found by a human first. An AI model found a Log4j exploit path seven weeks before a researcher did, then the researcher's report mysteriously vanished. Separately, AI agents broke into RubyGems not by finding a bug, but by asking a cheaper question: what can this software already do? Some exploits are never going to get a CVE. That doesn't make them less real. This month's Black Beak Brief digs into both, plus what "compliant" actually means when your runtime is the blind spot.
Experience & Education
-
TenRoot Cyber Security
********** * ***** ******** *********
-
********
********
-
***** ********
********
-
******** **********
** *** undefined
-
******
***** undefined
View Yossi’s full experience
See their title, tenure and more.
Welcome back
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
New to LinkedIn? Join now
or
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
Volunteer Experience
-
Volunteer & member of the managing committee
Yesh Matzav (Youth at risk)
- Present 7 years
Giving youth with challenging circumstances a fair chance, empowering them to believe in a way out, always.
-
Mentor / Contributor
Imagine NGO
- 5 years
Children
Empowerment through music of people with disabilities:
https://www.youtube.com/watch?v=Nr1eexCDsLI -
Mentor
Young Entrepreneurs (Yazamim Tze'irim)
- 1 year
Children
Nurturing real-life skills for High school students, building a product from scratch. from vision to working products (won 1st place HaSharon district)
Organizations
-
BSidesTLV
Speaker
- PresentTalk on #HackingPowerShell - Code & Slides--> https://github.com/YossiSassi/PowerShell-Hacking-BSidesTLV
Recommendations received
5 people have recommended Yossi
Join now to viewView Yossi’s full profile
-
See who you know in common
-
Get introduced
-
Contact Yossi directly
Other similar profiles
-
Tomer Brouck
Tomer Brouck
Stealth mode startup company - Cyber Security
29K followersTel Aviv District, Israel
Explore more posts
-
CYMDALL
488 followers
Big milestone for CYMDALL We have officially been granted a US patent for our Cyber Core architecture, joining the Israeli patent granted earlier last year (2025). This is exciting not just because of the patent itself, but because it locks in a shift we are seeing worldwide: Cybersecurity is becoming a design-time decision with lifetime consequences. Regulations like EU CRA, NIS2, IEC 62443, FDA cybersecurity guidance, and NIST 800-193 are no longer abstract compliance topics. They are forcing manufacturers to rethink architecture, ownership, and accountability for devices long after shipment. The CYMDALL Cyber Core (we call it - CYCO) represents a different foundation: A permanent security layer, designed once, embedded below the OS, invisible to software, and enforceable throughout the entire device lifecycle. This patent defines what we believe is a critical architectural path for secure-by-design devices in a regulated world. It validates years of deep work by an exceptional team of Israeli cyber experts who know this problem from both offensive and defensive angles. Special thanks to Hayim Weller, who professionally lead the patent application worldwide.
4
-
Hai Gur
Reclaim Security • 10K followers
https://lnkd.in/d4q9WE7Y The headline says AI hacked real companies. The reality? A misconfiguration created a path to the internet that should never have existed in the first place. [calcalistech.com] This incident highlights a critical cybersecurity truth: AI is accelerating exploitation, not creating the underlying exposures. The attack surface is still being expanded by: Misconfigurations Permission drift Exposed credentials Forgotten assets The difference is that autonomous AI can now discover and leverage those weaknesses at unprecedented speed. That's why organizations must embrace Continuous Threat Exposure Management (CTEM) and proactively reduce their attack surface. At Reclaim Security our mission is simple: Find and eliminate exposure before attackers, humans, or AI agents do and remediate them for you at speed. Because in the age of autonomous AI, prevention scales and far more effective than response. #CTEM #CyberSecurity #AttackSurfaceManagement #AIAgents #SecurityLeadership #ExposureManagement #ReclaimSecurity [calcalistech.com]
6
-
Leon Khanin
SimpleeCreate • 8K followers
The New Era of Cyber Threats → Why Israel Leads the Way Featuring: → Dr. Nimrod Kozlovski, Founder & CEO, Cytactic Dr. Kozlovski is a leading expert in cybersecurity, with decades of experience in protecting organizations from advanced threats. He has worked with governments, defense units, and major corporations, building frameworks that anticipate and respond to modern cyber crises. Cytactic focuses on helping organizations manage complex cyber threats in real-world environments. → The New Arena: From Technical → Existential Israel shows the way in tackling modern threats: → Everything Attack Surface: Smart cities, energy grids, and critical systems are now targets. Israel’s approach integrates real-world defenses and rapid response simultaneously — a model others are just starting to follow. → Multi-Layered Extortion: Quadruple extortion is now the norm: data, leaks, stakeholders, supply chain. Israeli cyber teams have built resilience frameworks to respond faster and smarter. → Internal Threats Matter Most: Internal chaos causes more damage than external attackers. Israel standardizes coordination between technical, legal, and communications teams to prevent paralysis during crises. → How Organizations Must Respond → Shift from Reactive → Proactive: Continuous readiness is a must. Israel excels with live dashboards, rapid simulations, and cross-functional alignment. → Simulate the Worst Case: Boards are trained to make tough decisions under pressure — something Israel has operationalized across startups and national defense. → Cyber Is a Business Issue: Cyber isn’t just IT. Legal, HR, and communications share authority. Decision frameworks guide real-time choices during crises. → My Takeaways & Insights → Israel leads because it integrates military-grade expertise, business foresight, and cross-functional crisis management. → Cybersecurity is central to business resilience — not optional. → Startups and scale-ups can learn from Israel: embed readiness, simulate crises, and treat cyber as a strategic business function. → What We Need to Know → Threats are multi-dimensional: technical, physical, and operational. → Internal alignment is as important as external defense. → Cyber crisis readiness must be constant, integrated, and multidisciplinary. → How We Apply This in Practice → Build live readiness dashboards → Conduct high-pressure simulations with board/executive teams → Treat cyber as a strategic business function, not just IT → Question for You Given Israel’s lead in cyber, which sector is most exposed globally — critical infrastructure, enterprise operations, or manufacturing/logistics? #IsraelTech #CyberSecurity #StartupNation #InnovationLeadership #CrisisManagement #RiskManagement #BusinessResilience
2
-
TechNadu
7K followers
In this interaction Alex Spivakovsky, VP Research and Cybersecurity at Pentera reflected on the mindset that shaped how he approaches defense today. Spivakovsky began his career on the offensive side of cybersecurity while serving in the Israel Defense Forces. The biggest lesson from years of leading pentesting and red-teaming assessments is that most breaches don’t hinge on zero-days; hackers rely on far more common techniques such as misconfigurations, over-permissioned identities, and process gaps. It is imperative to see both sides of the equation, Spivakovsky says, as defenders build controls to manage risk, while attackers look for the seams between them. Spivakovsky enumerated those vulnerabilities and the following: 🅿️Adversarial testing delivers proof, not assumptions, about your environment 🅿️We need to think like an attacker in a defensive role, not just anticipating threats 🅿️Evaluate tools not by how many vulnerabilities they find, but risks they help reduce 🅿️Exposure management goes further by validating exploitability, and mapping attack paths Read all the responses shared by Spivakovsky about adversarial testing, and what makes security a measurable enabler than a cost center here🔗: https://lnkd.in/gh-QdEQN #Pentera #Cybercriminals #Vulnerability #ExposureManagement #EDR #ThreatDetection #TTPs
8
-
Security Boulevard
2K followers
Israel just posted $4.4B across 130 cyber rounds — its strongest year in a decade. And one company just set the record for the largest cybersecurity Series A in history. In his latest op-ed, Alan Shimel breaks down what’s happening, why it matters, and what comes next for one of the world’s most important cybersecurity ecosystems. Spoiler: the train isn’t slowing down. 👉 Read the full op-ed: https://buff.ly/NwKigBW #Cybersecurity #Israel #InfoSec #Techstrong #ShimmySays
2
1 Comment -
Project Overwatch
121 followers
Attackers are weaponizing our trust in emergency alerts. I just analyzed a Hamas-linked spyware campaign that's targeting Israeli smartphones, and the psychological manipulation is chilling. Here's what happened: Hamas-aligned group Arid Viper sent SMS messages impersonating Israel's official "Oref Alert" rocket warning service. The messages urged recipients to "update" their Red Alert emergency app via a malicious link. The fake app looked completely legitimate: → Spoofed digital certificates → Appeared to come from Google Play → Used official branding and messaging → Bypassed Android security checks But once installed, it became a surveillance nightmare: 🚨 Real-time GPS tracking 🚨 SMS message interception 🚨 Contact list theft 🚨 Account credential harvesting 🚨 Phishing overlays to steal 2FA codes 🚨 Persistent backdoor access This isn't just another malware campaign. It's a masterclass in crisis exploitation. Attackers know that during emergencies, people bypass their normal security instincts. Fear overrides caution. Urgency defeats verification. The Acronis researchers who discovered this campaign noted something crucial: "Periods of military escalation consistently trigger cyber operations that exploit wartime themes as social engineering lures." This pattern extends far beyond the Middle East. Every crisis—natural disasters, health emergencies, infrastructure failures—becomes an attack vector. The defense isn't just technical. It's psychological. Train your teams to: ✅ Verify emergency updates through official channels ✅ Question urgent requests during high-stress situations ✅ Implement crisis-specific security protocols ✅ Recognize that attackers weaponize fear Because the next emergency alert your organization receives might not be trying to save lives—it might be trying to steal them. How does your security awareness program address crisis-driven social engineering? #CyberSecurity #SocialEngineering #MobileSecurity #CrisisResponse #Spyware Link: https://lnkd.in/eqBSh7Rr
Explore top content on LinkedIn
Find curated posts and insights for relevant topics all in one place.
View top content