256 Newsroom — Uganda's Digital News Infrastructure
Consumer Technology

Wiz’s AI hacker hunter: “I used to hope I found a vulnerability overnight. Today AI tells me it hacked the organization” - calcalistech.com

Share
Wiz’s AI hacker hunter: “I used to hope I found a vulnerability overnight. Today AI tells me it hacked the organization” - calcalistech.com
Image · CTech

What the report says

CTech reported that Gal Nagli, Wiz’s 28-year-old head of offensive security, says artificial intelligence is rapidly changing how vulnerabilities are found and exploited. In an interview with Calcalist, Nagli described a shift from manual bug hunting toward automated systems that can scan, test and adjust attacks across an organization’s environment. He leads Wiz’s Red Agent initiative, which the company says is designed to find and validate customer weaknesses before real attackers do.

Nagli’s path into cybersecurity was unconventional: he told CTech he was rejected by Israel’s Unit 8200, served in the Military Police, taught himself through online courses, joined startup Enso and became a leading bug bounty researcher. He said he earned more than $1 million through vulnerability reward programs before joining Wiz, the cybersecurity company acquired by Google. CTech also cited Wiz CMO and vice president of product strategy Raaz Herzberg as discussing how AI is reshaping the company’s security outlook.

A central concern in the report is that AI tools are widening the pool of people who can create software — and, unintentionally, security gaps. Nagli said many new risks come not only from professional developers but from employees in areas such as marketing, product or data science who build chatbots, websites or internal tools without security expertise. He also said attackers can now use AI to search for sensitive information or weaknesses with far less skill than was required recently.

The report matters because it highlights a broader cybersecurity race: AI can help attackers move faster, but Wiz argues defenders can use similar automation to map attack surfaces and verify real exposure. The claims reflect Wiz’s view of the market and should be read as an interview-based account rather than independent testing of the company’s technology.

Read the full report at CTech →

Loading debate for this article…

Other publishers covering this story

No additional verified coverage is currently clustered with this report.

Related reporting