OpenAI & Hugging Face Missteps Reveal the Industry’s Future Direction

0
8

Key Takeaways

  • Ido Hoorvitch’s interest in hacking began at 17 through private lessons from a family‑friend hacker, later sharpened by service in Israel’s Unit 81.
  • At NewCore, a three‑person senior research team (each with >10 years of vulnerability work) uses an AI‑first workflow to achieve roughly ten‑times the efficiency of traditional methods.
  • The research team is embedded in every stage of product development, reviewing features at the RFC stage, conducting architecture reviews, continuous red‑teaming, and collaborating daily with product managers to shape security‑first features.
  • While specific zero‑day findings remain under responsible disclosure, Hoorvitch cites the satisfaction of uncovering flaws that could affect thousands of systems and stresses the importance of innovating preventive security controls.
  • He views the global cyber‑research community as collaborative rather than competitive, noting Israel’s strong conference presence and the high bar set by groups like Google’s Project Zero and Wiz.
  • Autonomous AI agents acting as hacker teams are already a reality; Hoorvitch argues that continuous security assessment must become the new standard, with findings turned into enforcement actions via identity and governance mechanisms.

Introduction and Background
Ido Hoorvitch traces his fascination with cybersecurity back to age 17, when a family friend who was a hacker gave him private lessons in networking, OS internals, and tools such as Cain & Abel, WebGoat, and Wireshark. That early exposure sparked a lifelong curiosity that later found a formal outlet in the Israel Defense Forces, where he served five years in Unit 81—first as a security researcher and later as a team leader after attaining officer rank. Following his military service, Hoorvitch spent six years at CyberArk Labs researching vulnerabilities, briefly ventured into product management at a cyber‑security startup, and ultimately returned to his core passion: hands‑on security research at the forefront of threat discovery.


Role at NewCore and Team Composition
Today Hoorvitch works as a senior security researcher at NewCore, an identity platform founded in 2025 by Zohar Alon, Amihai Neiderman, and Erez Yarkoni and now employing roughly 60 people. NewCore describes itself as a “next‑gen IdP for humans and AI agents,” aiming to unify human and agentic identities under a single platform that authenticates, authorizes, and governs access while providing audit capabilities. The company’s security research team consists of three senior researchers, each boasting more than a decade of experience in vulnerability discovery and analysis. This small, highly specialized unit operates with the agility and depth typical of elite Israeli cyber units, focusing on thinking like attackers to stay ahead of an accelerating threat landscape.


Research Methodology and AI‑First Approach
The team’s workflow centers on deep analysis of both NewCore’s internal systems and widely used industry technologies to uncover novel attack vectors and latent security gaps. Hoorvitch emphasizes that their approach is “AI‑first,” meaning they go beyond merely adopting new tools; they use artificial intelligence to automate repetitive aspects of vulnerability research and code auditing. By streamlining tasks such as static analysis, fuzzing, and regression testing, the researchers can achieve roughly ten times the efficiency of a conventional team. This productivity boost frees human expertise to concentrate on the complex, creative problem‑solving that yields high‑impact insights—think of it as letting machines handle the grunt work while analysts focus on strategy and innovation.


Impact on Product Development
Security research at NewCore is not an isolated function; it is woven into every facet of the company’s development lifecycle. Researchers review each feature during the Request for Comments (RFC) phase, ensuring that security considerations are addressed before any code is written. This early involvement is followed by architecture reviews and continuous red‑teaming exercises that simulate real‑world attack scenarios. Moreover, the team collaborates daily with product managers to brainstorm and prototype next‑generation security controls that raise the bar for potential attackers. By embedding security expertise from conception through deployment, NewCore aims to bake resilience into its platform rather than treating it as an afterthought.


Notable Discoveries and Motivations
Although Hoorvitch cannot disclose specifics due to ongoing responsible disclosure processes, he notes that the team has uncovered several critical zero‑day vulnerabilities affecting prominent identity platforms used by the majority of enterprises. The drive behind this work is not merely the thrill of the hunt; it stems from a profound satisfaction in identifying flaws that could impact thousands of systems and enabling their remediation at scale. Hoorvitch describes his personal “Moby Dick” as the pursuit of fundamental vulnerabilities capable of causing widespread harm, coupled with a passion for inventing preventive security features that stop such flaws from existing in the first place. As the steward of the “keys to the kingdom” in an identity platform, he finds motivation in ensuring the underlying infrastructure is truly resilient.


View on Cyber Research Landscape and Competition
Hoorvitch observes that the caliber of cyber research emerging from Israel is impressive, frequently seeing Israeli experts lead sessions at major global conferences. Internationally, he holds groups like Google’s Project Zero and Wiz in high regard for setting rigorous standards. However, he does not perceive the research community as a zero‑sum competition; rather, he views it as a collective effort toward a safer digital ecosystem. From a market perspective, NewCore’s security‑first founding differentiates it from competitors that originated as traditional IT solutions and later layered security on top. Consequently, Hoorvitch feels the company operates in a distinct niche where its proactive security posture is a core value proposition rather than a point of direct rivalry.


Future of Security Research and AI Threats
The recent incidents involving OpenAI and Hugging Face serve as a clear signal of where the threat landscape is heading: autonomous AI agents are already capable of acting as coordinated hacker teams. This development renders legacy software—built without assuming continuous, intelligent adversaries—increasingly risky. Hoorvitch argues that just as enterprises have embraced continuous integration and deployment (CI/CD), they must now adopt continuous security assessment as the new norm. In this model, findings from automated scanners and human analysts are not merely reported; they are translated into immediate enforcement actions. Identity and governance platforms like NewCore play a pivotal role here, providing the policy engine and contextual awareness needed to turn vulnerability data into real‑time protective controls.


Conclusion
Ido Hoorvitch’s journey—from teenage lessons with a hacker‑friend, through elite military service and years of industry experience, to his current position at NewCore—illustrates the blend of curiosity, discipline, and innovation that drives modern vulnerability research. His team’s AI‑enhanced workflow amplifies human expertise, enabling rapid discovery of high‑impact flaws while maintaining a deep commitment to responsible disclosure. By embedding security at every stage of product development, advocating for continuous assessment, and preparing for AI‑driven attacks, Hoorvitch and his peers are helping shape a future where defensive capabilities evolve as swiftly as the threats they confront. The overarching message is clear: proactive, collaborative, and technologically augmented security research is essential to safeguarding the increasingly interconnected world of human and AI identities.

SignUpSignUp form

LEAVE A REPLY

Please enter your comment!
Please enter your name here