AI: Cybersecurity’s Double-Edged Sword

0
3

Key Takeaways

  • Semperis, founded in 2015, protects enterprise identity systems (Active Directory, Entra ID, Okta, Ping) with a globally distributed team of ~645 employees, ~145 of whom are based in Israel.
  • The company’s security‑research team consists of roughly ten specialists who drive vulnerability discovery, open‑source tooling, and product‑level threat intelligence.
  • Tomer Bar, AVP of Security Research, built Israel’s first national Red Team for critical infrastructure and brings a diverse background—gaming, combat unit service, computer‑science BA, MBA, and a decade in the Prime Minister’s Office cyber‑research unit.
  • Notable research achievements include the ResetNightmare and KerberLoss vulnerabilities, disclosed to Microsoft and presented at Black Hat USA and DEFCON 2024.
  • The team views AI as both a force‑multiplier for automation and a growing threat, as non‑human identities now outnumber human users in many customer environments.
  • Semperis measures its research impact through conference acceptances, CVE counts, CVSS scores, and competition results; in H1 2025 it ranked among the top 20 global teams with six Microsoft vulnerability disclosures.
  • Looking ahead, the group aims to help customers inventory and secure AI agents and other machine identities, projecting they could reach ten times the number of human identities in the near future.

Company Overview and Mission
Semperis is an identity‑centric cyber‑resilience and crisis‑response firm headquartered in Hoboken, New Jersey, with its primary R&D hub in Israel. Established in 2015 by Mickey Bresman (CEO), Guy Teverovsky (CTO), and Matan Liberman (General Manager Israel), the company now employs about 645 people worldwide, roughly 145 of whom work in Israel. Its core mission is to safeguard the identity platforms that enterprises rely on—Microsoft Active Directory, Entra ID, Okta, and Ping—by delivering products that span the full lifecycle of identity‑based attacks, from posture assessment to real‑time detection and secure recovery. In addition to commercial offerings, Semperis maintains a suite of free community tools used by more than 65,000 organizations globally, underscoring its commitment to broader defensive knowledge sharing.


Background of Tomer Bar, AVP Security Research
Tomer Bar’s path to leading Semperis’ security‑research team is unconventional. He began as an avid gamer, served in a combat unit during his military service (not a technical specialty), and later earned a BA in computer science followed by an MBA. Prior to joining Semperis, Bar spent over a decade in the Prime Minister’s Office conducting cybersecurity research—work that predated the widespread use of the term “cyber.” There he founded and managed Israel’s first national Red Team tasked with testing critical national systems such as power grids, gas networks, water supplies, and rail infrastructure. After that, he devoted roughly twenty years to researching Windows vulnerabilities and advanced persistent threats (APTs) for large enterprises and startups operating in the EDR and breach‑and‑attack‑simulation spaces. His contributions have been recognized at premier conferences: he has spoken at Black Hat and DEFCON four times each and serves on the Black Hat Europe Review Board, which selects the year’s top research for main‑stage presentation.


Structure and Function of the Security Research Team
The Semperis security‑research team comprises approximately ten researchers who are responsible for the scientific foundation behind all of the company’s products. Their work begins on‑premises with Active Directory, where they identify and responsibly disclose critical vulnerabilities that could enable attackers to seize domain controllers used by the majority of S&P 500 firms. Parallel to this, the team releases open‑source tools that CISOs worldwide can leverage to test and improve their security posture. Because many enterprises also operate hybrid or cloud‑first environments, other team members specialize in cloud identity providers such as Entra ID, Okta, and Ping, focusing on detecting potential abuse techniques and developing detection logic tailored to those platforms.


How Research Drives the Wider Organization
Bar likens the research team to the brain of a human body: it interprets the threat landscape, generates actionable intelligence, and feeds that knowledge into the rest of the organization. The product team functions as the heart, translating customer needs into feature priorities, while engineering serves as the hands and legs that build and code the actual solutions. By continuously analyzing emerging attack patterns, the research team produces the content that hardens Semperis’ offerings—enabling real‑time detection, rapid incident response, and secure recovery capabilities. This tight feedback loop ensures that the company’s defenses evolve as quickly as the threats they aim to counter.


Signature Discoveries: ResetNightmare and KerberLoss
Among the team’s most impactful contributions are the ResetNightmare and KerberLoss vulnerabilities, both affecting Microsoft’s Active Directory authentication mechanisms. These flaws were uncovered through prolonged, original research led by team member Shai Laron, an expert in domain controllers and authentication protocols. After responsible disclosure, Microsoft issued patches within a few months, and the findings were presented at Black Hat USA and DEFCON 2024, attracting significant attention from the defensive and offensive security communities. The discoveries exemplify how Semperis’ deep technical focus can yield high‑severity CVEs that directly improve the security posture of thousands of enterprises worldwide.


Defining the Team’s “Moby Dick”
When asked about the team’s ultimate adversarial challenge, Bar describes a five‑headed foe: nation‑state threat actors originating from China, Russia, Iran, and North Korea, combined with financially motivated cyber‑crime groups. Understanding the motives, tactics, and techniques (TTPs) of these actors allows Semperis to anticipate attacks and craft protective measures for its customers’ most valuable assets—often referred to as their “crown jewels.” By studying this diverse threat ecosystem, the research team can prioritize efforts where they will yield the greatest defensive payoff.


Benchmarking Research Competitiveness
Bar views the global research community as allies rather than enemies, noting that constructive competition pushes the entire field forward. He suggests that objective benchmarks include the number of conference talk acceptances, total CVEs discovered (and subsequently fixed), the average CVSS severity of those vulnerabilities, and performance in recognized contests such as Capture‑the‑Flag (CTF) events, Pwn2Own, and the Pwnie Awards. In the first half of 2025, Semperis reported six Microsoft‑related vulnerabilities, placing the firm among the top 20 security‑research teams worldwide—a testament to its productivity and impact despite its relatively small size.


The Future Role of Human Security Researchers in an AI‑Augmented World
Bar asserts that artificial intelligence is simultaneously the greatest facilitator and the most potent threat facing modern security teams. The Semperis research group already employs AI agents to automate large portions of its workflow: a fully autonomous pipeline ingests threat data, prioritizes risks, generates security indicators and real‑time detection logic, validates the output, and forwards it for final human expert review. This augmentation dramatically scales the team’s analytical capacity. Conversely, AI also introduces a new class of risk—non‑human identities such as service accounts, bots, and autonomous agents are now present in greater numbers than human users in many customer environments, with projections suggesting they could outnumber humans ten‑fold in the coming years. Consequently, the team’s current mission includes developing methods to discover, inventory, and secure these machine identities, ensuring that AI‑driven assets are managed with the same rigor applied to human accounts.


Conclusion: Sustaining an Edge in Identity‑Centric Defense
Semperis exemplifies how a focused, expert‑driven research team can punch far above its weight in the cybersecurity arena. By blending deep technical expertise in Windows and cloud identity systems with a strategic use of AI for automation, the group continues to uncover high‑impact vulnerabilities, produce widely adopted defensive tools, and shape product development that protects enterprises worldwide. As the threat landscape evolves—propelled by nation‑state actors, cyber‑criminal syndicates, and proliferating machine identities—the synergy between human ingenuity and machine efficiency will remain critical. Bar’s vision of treating the research team as the “brain” of the organization, complemented by the “heart” of product management and the “hands and legs” of engineering, offers a resilient model for staying ahead of adversaries in an increasingly AI‑laden world.

SignUpSignUp form

LEAVE A REPLY

Please enter your comment!
Please enter your name here