Like a combat unit: how bug hunters for tech giants work
In Israel's cyber industry, an elite group of security researchers stands out, operating as 'digital warfare units'. They hunt for vulnerabilities in services, helping companies strengthen their reputation. Calcalist's article describes teams of 5-7 people, their methods, and psychological pressures. Experts from Orca Security, Terra Security, and Semperis share their experience, emphasizing the importance of teamwork and deep immersion. Recent incidents with OpenAI and Anthropic highlight the role of such specialists.
In Israel's technology industry, especially in cybersecurity, there is an elite group of specialists—security researchers—who act as 'digital warfare units'. They examine services from the perspective of potential abuse and hacking, helping companies strengthen their reputation and increase brand value. The article, published on August 8 on the Calcalist portal, describes the work of such teams, consisting of five to seven people. Roi Nisimi from Orca Security explains that developers look for how to use a service, while researchers look for how to abuse it. Ofir Hamam from Terra Security emphasizes that research requires deep immersion and significant time investment. Yonatan Elkabetz from Semperis notes that there are many niches in cybersecurity, and his team focuses on researching digital identity providers in the Microsoft ecosystem. Research groups often find themselves on the front lines of a company's public communication; their reports help earn prestige. Recent incidents, including cases with OpenAI and Anthropic models, reminded of the importance of such teams. Nisimi compares his team to the football club Paris Saint-Germain, emphasizing the importance of teamwork. The article also mentions that researchers earn through bug bounty and plan to donate the money received.