Cyber Commandos: The Bug Hunters of Tech Giants
In the rapidly changing digital landscape, elite security research units act as "digital warfare units," examining services through the lens of potential attacks to discover vulnerabilities before malicious actors do.

“Our perspective is truly different from that of a developer,” says Roi Nisimi, lead security researcher at the cloud-based application protection platform Orca Security. “A developer looks at services and asks themselves: 'How can I use this for my benefit, for my programming, for the product?'. We ask: 'How can these services be misused to hack into people's computers and steal their sensitive information?'”.
In the rapidly changing digital landscape, an elite specialized unit is growing from the shadows of software development: security researchers. Unlike developers who focus on building products, these researchers act as “digital warfare units” that examine services through the question of how they can be misused, hacked, and exposed for vulnerabilities — even before someone else discovers them. Several incidents in recent days — such as the case where OpenAI and Anthropic models “escaped” by mistake to the open internet, precisely during tests by an Israeli security company — reminded everyone that there are entire units working behind the scenes without much noise. Usually, these are small teams of about five to seven people, whose sole role is to think like hackers — and sometimes literally impersonate them — to catch the vulnerabilities before someone less friendly gets to them first.
“In a cyber company that has a cyber product, 90%-95% of R&D employees are software people,” continues Nisimi. “Only about 5% are people who really know cyber in depth, those who can mimic a hacker and find what a hacker would find. They know how to follow his tracks because they know how to actually hack into systems and find vulnerabilities and attack vectors”.
“Research is a tool for deepening,” explains Ofir Hamam, head of offensive security at the AI-agent-based offensive security platform, Terra Security. “It is a tool intended for use when you want to treat something from the root” — and for that, significant investment is required to reach “as deep as possible”.
The PR front
Another characteristic of security researcher groups is that they are often at the forefront of the company's public relations: the reports and exposures they publish help the company gain prestige, increase brand value, and build an authoritative image in a crowded market. For example, the international cyber giant Palo Alto Networks recently published findings from its research division, Unit 42, which revealed that attackers are currently using advanced AI to identify security vulnerabilities and exploit them within minutes. The Israeli cyber company Zenity Labs recently revealed a new type of vulnerability affecting leading AI-based browsers, and earlier this week, the Israeli DevOps company JFrog Security announced that its security team identified a supply chain attack targeting the popular cache library npm.
“There are many different areas of research in cyber, simply because there are different levels of protection that you might want to defend against,” explains Yonatan Alkabetz, a security researcher at Semperis, whose team conducts focused research on identity providers in the Microsoft ecosystem. “We know there is a whole game of red team versus blue team,” he notes, referring to attack simulations designed to improve defenses. Beyond that, security researchers span a wide range of specialties: vulnerability research and exploit development, reverse engineering, cloud and container security, AI and machine learning security, cryptography, and more. And as Alkabetz summarizes, “in these areas, there are many niches”.
The team: a combat unit
The accelerated reality that is shaking the cyber world requires more and more from security research teams, who play an integral role in fortifying defense lines. “The research team — we are a combat unit,” says Nisimi, who works in a team of six to seven people. As a former soccer player, Nisimi likens the dynamics of an elite security research team to that of Paris Saint-Germain, the Champions League winner: “They don't have superstars. The team is so strong together because everyone loves each other, respects each other, and wants each other's growth — and that is what builds success. The best teams are not those with the best players, but those where everyone works together as a team”.
Alkabetz, who manages a team of five people, notes that “each of them has a specialization in a different field”. When a new task comes in, he explains, the first action is “to think who are the team members who will do it in the best way”. Hamam describes a similar workflow in his team at Terra Security, which also consists of five members. “Our first task when we face a question is actually to try to explain it to ourselves first,” he says. “What is the maximum we can do here, and where in this flow should agents participate?”. The “boutique” nature of such lean teams, he argues, carries advantages and disadvantages: “The advantage is that we do everything in terms of research within the organization, and grow as individuals significantly”.
Competition within the sector
To maintain cooperation in such a charged environment, says Nisimi, the team invests a lot in fostering a sense of community. “We have dedicated days where we as a group just focus and try to hack the same technology and find vulnerabilities,” he says. “We did it last month and achieved a few thousand dollars in bug bounty” — which, according to him, the team will donate. However, this goodwill does not necessarily extend to the entire sector. In fact, the greatest enemy of a security researcher can be another researcher. “It's really a matter of money and ego,” agrees Alkabetz, referring to the urge of some researchers to publish their hacks and exploits. “People want to prove themselves and show that they are productive. They want to publish that post on LinkedIn that says 'Look, I succeeded'”.
On this point, there is no consensus. Hamam argues that such arrogance is relatively rare: “I don't feel it, but that's just me. When I see people who brag, they are usually less technical than those who come very humble. What I like about the research community is that it is a global community, which everyone comes to so humble. There is a very open community of learning from each other”.
The Israeli advantage
In the Israeli high-tech industry, and especially in cyber, everyone basically knows everyone. Although the industry is huge, the size of the country and the common military background that most professionals have gone through make the arena a small world — and precisely because of that, also a place where friendly competition develops naturally. Alkabetz notes that his team is composed of people who “have more or less the same background”, who came straight from the IDF as “cyber defenders or cyber attackers”. The common military background provides security research teams in Israel with a unique and advantageous training ground. “I think the one thing the IDF teaches you is to set the bar very high,” continues Alkabetz, who also describes a sense of capability: “The ability to say, 'I can achieve this', 'We can do this'”. Even when a new vulnerability is published, he says, the reaction in the team is: “Okay guys, we have a few days to cover this from end to end, let's do it”.
Nisimi notes that 90% of his team comes from a military background, mainly from Unit 8200. “I think what was instilled in my mentality is: you can do everything, and you can do everything fast, with minimum resources. We don't complain, we do things fast. We stay positive and curious”. Ultimately, he adds, “we are digital warriors — that is what we do”. However, the transition to the private sector is not without glitches. “You take someone who comes with a lot of technical knowledge and experience, but you also have to adapt them to the business world, because the army and business don't work the same way,” explains Hamam.
The AI era
As in the entire business world, this field has also changed beyond recognition in recent years with the advent of AI, which has significantly accelerated the pace of research (and also attacks) and, ultimately, fundamentally changed the daily routine of security researchers. “We work faster because of AI,” says Nisimi. “You need a really good reason to grow in manpower”.
“In the past, most of our time was spent literally writing code,” notes Alkabetz. “I haven't written a line of code in the last year and a half or two, I think. There is no need — AI can write code much better than me”. These changes inevitably raise questions about the future size of security research teams. According to Alkabetz, “AI can never replace human interaction” — he describes how many organic breakthroughs come from “sitting in a room with another person and just saying, 'Hey, I think I found something'”. Hamam adds a similar angle: “AI models are trained on human data. In order for the model to be better, we must retrain it on additional research papers that humans write”.
The mental price
Beyond the technical and existential challenges posed by AI, the life of a security researcher also brings with it organizational and psychological considerations. A recurring example is the difficulty of conveying to the company's management the value in research: explaining why a team needs to spend “two weeks, a month of research in a specific area” can be hard to sell. “In the companies I worked for before, there was a lot of micromanagement from the financial level,” recalls Hamam. “You had to use every hour in a way that brings money to the company, and when you do that — you don't have time to deepen”.
In general, “it is a very heavy job mentally, because the peaks are high and the low points are low,” admits Nisimi. When a researcher experiences a period of “drought” in findings, he adds, “your self-confidence can drop”.





