Ido Hoorvitch, Security Researcher, NewCore.
Security Researchers: Digital Fighters Series

NewCore: “The OpenAI and Hugging Face incidents signal where things are heading”

Ido Hoorvitch, Security Researcher at NewCore, discusses the double-edged sword of AI agents in security research, as part of CTech’s Security Researchers series.

“There's a specific kind of satisfaction in uncovering a flaw that could affect thousands of systems,” says Ido Hoorvitch, Security Researcher at identity platform NewCore. “Not just for the thrill of the hunt, but because of the massive real-world impact of patching it.” Hoorvitch’s curiosity in the field was ignited at age 17, “thanks to a family friend who was a hacker and gave me private lessons.” Today at NewCore, he works as part of a team of three senior researchers, each with over a decade in vulnerability research.
Within Israel’s cyber companies are small, highly specialized teams trained to think like attackers, find vulnerabilities and stay ahead of a threat landscape increasingly accelerated by AI. In this series, we meet the individuals and teams who make up this frontline of cyber: the digital fighters.
1 View gallery
Ido Hoorvitch NewCore
Ido Hoorvitch NewCore
Ido Hoorvitch, Security Researcher, NewCore.
(Photo: Niros)
While Hoorvitch describes how “our team can operate with ten times the efficiency,” as a result of the AI revolution, he warns that “the recent incidents involving OpenAI and Hugging Face clearly signal where things are heading.” With autonomous AI agents already acting as hacker teams, he argues that “companies must now adopt continuous security assessment as the new standard.”
You can read the entire interview below.
ID Card Company name: NewCore Founders: Zohar Alon, Amihai Neiderman, Erez Yarkoni Year of founding: 2025 Current number of employees: 60
Company Description:
NewCore is the next-gen IdP for humans and AI agents. Rebuilt securely from the ground up, it converges every human and agentic identity into one platform that authenticates, authorizes, and governs them, from access to audit.
About NewCore’s Security Research Team:
Our security research team has three senior researchers with over a decade each in vulnerability research.
What is your background in cyber, and what led you to specialize in security research?
I say it started with the IDF, some say it’s destiny. My curiosity for hacking ignited when I was 17, thanks to a family friend who was a hacker and gave me private lessons. It was a different world back then compared to today, where cyber is part of the high school curriculum. He taught me networking and OS internals, introducing me to tools like Cain & Abel, WebGoat and Wireshark.
I served for five years in Unit 81, first as a security researcher and later as a team lead after becoming an officer. Following my service, I spent six years at CyberArk Labs where I was researching vulnerabilities, then I spent time as a product manager in a cyber startup before returning to my true passion at the forefront of security research.
What does your security research team look like in action?
Our research focuses on a deep analysis of our own internal systems and widely used technologies in the industry to better understand innovative attack vectors and potential security gaps.
Our "AI-first" approach goes beyond just using new gadgets; it’s about supercharging our researchers’ core strengths. By automating our workflows for vulnerability research and code auditing, our team can operate with ten times the efficiency. This allows us to focus our human expertise on the complex, creative problem-solving that really moves the needle.
How does the research team influence your company at large?
Our research team is deeply embedded in every facet of the company. We review every feature at the RFC phase before a single line of code is written. We follow this up with architecture reviews and continuous red teaming. We also work closely with the product team every day to brainstorm the next security features that will raise the bar for attackers.
What has been your team’s most significant security discovery to date?
We’ve uncovered several critical zero-days, but as they are currently under responsible disclosure, I can’t share specific details just yet. To date, we have identified multiple vulnerabilities across various prominent identity platforms currently on the market and used by the majority of enterprises.
Who or what is your 'Moby Dick'?
My "Moby Dick" is identifying those fundamental vulnerabilities that have the potential to impact organizations at scale. There's a specific kind of satisfaction in uncovering a flaw that could affect thousands of systems – not just for the thrill of the hunt, but because of the massive real-world impact of patching it.
Beyond finding bugs, my true passion is innovating the security features that prevent them from existing in the first place. We're building an identity platform and holding the "keys to the kingdom," and there's no greater motivation than making sure that infrastructure is truly resilient.
How would you characterize the competition between research teams today?
The level of cyber research coming out of Israel is impressive, which you can see by how often Israeli researchers are leading sessions at major global conferences. Globally, teams like Google's Project Zero or Wiz are doing great work and setting a high bar for the industry.
Personally, I don't see the research community as being in competition with one another – we're all working toward a safer ecosystem. When it comes to the market, NewCore is built as a security-first company, which is a different approach from competitors that started as IT solutions. Because of that, I don't feel we are really competing in the same space.
What is your take on the future of the human security researcher?
The recent incidents involving OpenAI and Hugging Face clearly signal where things are heading. The reality of autonomous AI agents acting as hacker teams is already here. This shift means that software built in an older era is no longer enough and often puts customers at risk. Today’s software demands constant internal audits and analysis. Just as companies have adopted continuous integration and deployment (CI/CD), they must now adopt continuous security assessment as the new standard. When agents attack continuously, findings need to become enforcement rather than reports, which is where identity and governance come in.