
Wiz’s AI hacker hunter: “I used to hope I found a vulnerability overnight. Today AI tells me it hacked the organization”
Former bug bounty researcher Gal Nagli describes how AI is replacing manual security research with automated attacks and defenses.
Artificial intelligence is changing cybersecurity so quickly that some of the industry's leading researchers believe the balance of power may finally be shifting away from attackers.
For decades, hackers held a structural advantage. They needed to find only a single weakness, while defenders had to secure everything. Now, according to executives at Wiz, the Google-owned cybersecurity company, AI is beginning to reverse that equation by allowing defenders to automate the work of their best researchers at a scale that was previously impossible.
Few people have watched that transformation more closely than Gal Nagli, Wiz's 28-year-old Head of Offensive Security. Rejected by Israel's elite Unit 8200, Nagli instead served as a combat soldier and commander in the Military Police before teaching himself cybersecurity, becoming one of the world's top bug bounty researchers and earning more than $1 million discovering software vulnerabilities. Today, he leads the team behind Wiz's Red Agent, an AI-powered system designed to identify and exploit customers' weaknesses before attackers can.
In a conversation with Calcalist, Nagli explains how AI is changing hacking, why today's biggest security risks often come from employees deploying AI tools rather than professional developers, and why he believes defenders may, for the first time, be gaining the upper hand. Raaz Herzberg, Wiz's CMO and Vice President of Product Strategy, also discusses how AI is reshaping the company's view of cybersecurity.
You come from Kiryat Haim, and you didn't follow the traditional path into high tech. How did you end up at Wiz?
"I always loved computers, but I wasn't accepted into Unit 8200. Instead, I enlisted as a combat soldier and later commanded a checkpoint platoon in the Military Police before becoming commander of a Military Police detention center.
"After the army, I became the first employee at startup Enso. Around the same time, I entered the world of bug bounty programs, where companies like Meta invite security researchers to find vulnerabilities and reward them financially if the findings are legitimate.
"I eventually ranked among the top five researchers in the world and earned more than $1 million through bug bounty programs. Later, I bootstrapped a company that turned what I had learned into a commercial product. That's how I met Ami Luttwak, one of Wiz's founders. It turned out to be a great fit, and I've now been here for almost two years leading threat detection."
So your job is essentially to attack companies and look for weaknesses?
"Exactly. We proactively attack our customers' environments to understand their attack surface before real attackers do. I lead our Red Agent initiative.
"AI has changed everything. Anyone can now build software, and the models themselves have become incredibly capable. It's no longer about finding one specific vulnerability.
"In one bug bounty competition in Las Vegas, three other researchers and I shared a $125,000 prize. Only about 30 people in history have earned more than $1 million through bug bounty programs. It sounds like a lot of money, but it's insignificant compared to the damage those vulnerabilities could have caused."
How did you discover you had this talent? Where have you been most surprised to find security flaws?
"While I was in the army, I spent countless hours teaching myself from Stanford courses on YouTube. I loved the challenge of figuring things out on my own.
"The truth is that vulnerabilities exist everywhere. Usually, within five minutes of hearing a company's name, I can estimate whether it will be relatively easy or difficult to break into.
"The challenge today is that tomorrow morning someone inside an organization can deploy a chatbot, and suddenly the company's entire security posture changes. That's why I focused on automation. If someone changes a configuration today, it could create a vulnerability tomorrow.
"New technologies appear constantly. Today, I can assess whether something is exploitable by looking at an organization's entire attack surface. That's a huge change."
Who is mainly responsible for these vulnerabilities? Developers releasing software without proper testing?
"There are two common scenarios. One is when you rely on third-party software that already contains a vulnerability. In that case, you're exposed through no fault of your own.
"The second has become much more common since 2023. We call them 'model champions', people in marketing, product or data science who suddenly build websites or AI chatbots without understanding security. I've seen countless vulnerabilities created this way.
"Some companies run formal bug bounty programs. Others simply tell researchers to send an email if they find something. Many still don't understand that they need a structured vulnerability disclosure program with financial incentives."
Do you still participate in bug bounty programs in your spare time?
"Today I mainly do this work through Wiz. One of the biggest differences is that we proactively prove to customers that a vulnerability is real, so they don't waste time chasing false positives."
How much has AI changed your work?
"With AI coding tools, everything has become more accessible. There are far more applications and websites that can potentially be attacked.
"We often say the latest generation of AI models fundamentally changed the landscape. Today, someone can simply ask an AI model, 'Can you hack this website?' and the model will immediately begin looking for weaknesses.
"That reinforces something we've known for years. Attackers can now use AI to find vulnerabilities much more efficiently. That's why we tell customers they need AI to defend themselves as well.
"Six months ago you needed significant expertise. Today someone targeting an organization can ask a model to identify sensitive information almost immediately.
"For example, I once discovered a vulnerability at the FIA, the governing body of international motorsport, where simply pressing Enter on the keyboard allowed access to people's licenses."
What does a hacker's daily work look like today?
"It has changed completely.
"I used to wake up hoping I'd manually found a vulnerability overnight. Today AI tells me, 'I've compromised the organization. Here are all the secrets.'
"It can also change its attack strategy in real time based on how servers respond.
"One morning I saw someone calling himself 'Bob the Hacker' posting online that he was bored, so he hacked FIFA and claimed he could control parts of its broadcasting schedule."
So what exactly does your technology do?
"The most important step is discovering the entire attack surface.
"At Wiz, we connect to all of an organization's cloud environments and feed everything into our attack management platform. Red Agent identifies the assets most likely to be vulnerable and attacks them proactively.
"We scan roughly 200 environments every week, and about 30% of our customers, including 65% of the Fortune 100, trust us to do this automatically.
"We identify thousands of critical vulnerabilities every week that could potentially be exploited from outside the organization.
"AI still hallucinates sometimes, so you can't simply leave everything to the machine. You still need deep expertise."
Do companies realistically have a chance to keep up as AI evolves so quickly?
"Absolutely.
"Before AI, one person couldn't realistically understand an organization the size of Wiz. Today you can build an agent whose capabilities exceed those of the best researchers in the world.
"Attackers still face an important disadvantage. They first have to figure out what's exposed. The organization already has all the internal information and context.
"Companies that want to defend themselves need to be able to identify and respond to vulnerabilities within an hour.
"Ami often says we're moving toward a world where there may eventually be no vulnerabilities at all."
Last week we also saw reports about OpenAI's AI agent escaping containment during testing. Doesn't that point in the opposite direction?
"The era in which AI can independently attack systems has already begun, and advanced models currently in training represent the next leap forward.
"But for the first time, defenders also have a built-in advantage. In that particular case, an open-source AI model helped identify and close the vulnerability."
Are these becoming more difficult times for independent bug bounty researchers?
"There's a new term: AI slop.
"People ask an AI model to generate 100 vulnerabilities so they can submit them and collect rewards. The problem is that many of those vulnerabilities don't exist. The AI invents them, creating enormous amounts of spam that companies spend days filtering.
"So yes, it's becoming harder. But the best researchers will adapt. Or they'll simply join companies like Wiz.
"As for bug bounty researchers becoming cybercriminals, it usually happens the other way around. I know many people who were once black-hat hackers, even served prison sentences, and later moved into legitimate security research. The reverse is extremely rare."
Raz Herzberg, as Wiz's CMO and Vice President of Product Strategy, how do you see these changes?
"We're living through the most fascinating period cybersecurity has ever experienced.
"Every major technological shift creates new risks, but for the first time we genuinely believe defenders have an opportunity to gain an advantage over attackers.
"For decades, every organization assumed it had vulnerabilities. The difference today is that AI becomes dramatically better when it's given more information and more context.
"Organizations possess vastly more information about their own environments than outside attackers ever will. They can use advanced models to automate tasks the industry has dreamed about for years.
"The model finds the vulnerability, understands it, and then fixes it automatically, and it can do that at enormous scale.
"For the first time, defenders may actually be in a stronger position."
How does Gal's work fit into that vision?
"Gal approaches every customer exactly like an external attacker. He has no internal visibility. Everything Red Agent finds is, by definition, among the most critical risks because it's exposed to the outside world.
"In the past, this kind of work couldn't be automated. You needed exceptionally talented researchers spending days or weeks looking manually.
"Now an AI system can do it continuously, 24 hours a day, seven days a week.
"That fundamentally changes how organizations think about external risk.
"It's also changing the role of security leaders. Suddenly they're responsible for risks that simply didn't exist before.
"Customers tell us, 'We thought our security program was complete, and suddenly AI changed everything.'
"Attackers will always look for the easiest path. Even the largest technology companies have discovered entirely new attack vectors because of AI.
"Everyone is worried about what AI enables. But those same AI tools are also becoming the best defense."















