
Security Researchers: Digital Fighters Series
Novee: “AI turns one strong researcher into something closer to a whole team”
Omri Inbar, Vulnerability Researcher at Novee Security describes how automated offense is raising the bar for defenders across the global cyber landscape as part of CTech’s Security Researchers series.
“Offense is getting automated whether defenders like it or not, and that reframes what's at stake,” says Omri Inbar, Vulnerability Researcher at Novee Security. While AI has acted as a force multiplier for offenders, Inbar notes that it has likewise done so for researchers: “AI turns one strong researcher into something closer to a whole team, and hands that person back the time to spend on the problems only a human can crack.”
Within Israel’s cyber companies are small, highly specialized teams trained to think like attackers, find vulnerabilities and stay ahead of a threat landscape increasingly accelerated by AI. In this series, we meet the individuals and teams who make up this frontline of cyber: the digital fighters.
“For a long time an elite team's edge came down to individual human talent – a few exceptional people who could see what others couldn't,” he continues. “That still counts for an enormous amount, but it isn't the whole game anymore.” According to Inbar, amid this revolution, the researcher teams pulling ahead “are the ones who can take that human tradecraft and turn it into systems that run at a scale and speed no group of individuals can match.”
You can read the entire interview below.
ID Card
Company name: Novee
Founders: Ido Geffen, Omer Ninburg, Gon Chalamish
Year of founding: 2025
Current number of employees: 74
Company Description:
Novee is an AI penetration testing platform training offensive security AI. It combines an elite AI Hacker to continuously uncover vulnerabilities that lead to real breaches, including business logic flaws, authorization issues, and chained attack paths, with an elite AI Defender to prove findings and guide remediation with stack-specific guidance and retesting. At the core is the Novee Gym, where Novee continuously trains, benchmarks, and optimizes its full offensive AI stack, including a proprietary model, frontier models, specialized agents, and a purpose-built harness, for recall, precision, and cost.
About Novee's Security Research Team:
The Novee research team consists of four vulnerability researchers, three of them founding team, and two security researchers.
What is your background in cyber, and what led you to specialize in security research?
I didn’t serve in a technological unit in the military. I started programming after the army and fell in love. I previously worked at Pentera, Checkmarx, and Cye. I have about 20-something Common Vulnerabilities and Exposures (CVEs), and I lectured at OWASP Global AppSec.
What does your security research team look like in action?
We're a small and deliberately senior team. We spend our time on how attackers actually break modern applications, which mostly means business logic abuse, authorization and access-control failures, and the chained attack paths that only surface once you understand how an application is supposed to work. When we find a new technique or exploit class, we encode it into the platform so the agents doing the work inherit it on the next run.
We also work on the Novee Gym, alongside the AI researchers on our staff. We run the full offensive AI system against thousands of real applications, score every exploit through our Offensive Evaluation Engine, and feed the results back into both the model and the harness to get better offensive capability out of our agents.
What we choose to investigate comes from signal more than curiosity: whether attackers are shifting toward a new class of target, where the platform is missing findings a skilled human would have caught, or which flaw classes carry the most real-world impact. Everyone works across the stack, but people go deep in different places. Some live on the offensive side, in exploit development and attack chaining, while others work on the AI side, turning that tradecraft into agent behavior that reasons like an attacker.
How does the research team influence your company at large?
When we discover a new technique, or a class of finding the system was missing, it goes into the platform and gets benchmarked in the Gym before it ships, so a customer's next assessment is sharper than the last without anyone touching their configuration. We also set the bar on validation.
Our "zero false positives by design" standard, where a finding has to clear independent agents, including a blind re-validator that gets no context from the others, before it ever reaches a security team, comes straight out of research judgment about what actually counts as proven.
We shape the roadmap too. Wherever we see attackers moving, whether that's new application types or, increasingly, AI-powered systems as targets, tends to be where the product goes next, and our research is what pushed us toward the AI red teaming capability we shipped for LLM-powered applications. Research is where the definition of attacker-level gets set, and the product is built to deliver on that definition continuously and at scale.
What has been your team’s most significant security discovery to date?
Personally, I worked on the discovery of UXSS in Android WebView. The full details are still under wraps, but I discovered seven UXSS vulnerabilities through manual reverse engineering. Then we formalized the patterns and pointed Novee at 20 Android apps. It found five more, plus a critical account takeover.
Who or what is your 'Moby Dick'?
Universal Cross-Site Scripting (UXSS) in Chrome for non-mobile environments and/or unauthenticated Remote Code Execution (RCE) in Windows.
How would you characterize the competition between research teams today?
For a long time an elite team's edge came down to individual human talent – a few exceptional people who could see what others couldn't. That still counts for an enormous amount, but it isn't the whole game anymore. The teams pulling ahead are the ones who can take that human tradecraft and turn it into systems that run at a scale and speed no group of individuals can match.
Locally, we have an advantage that's hard to overstate, since the density of offensive talent coming out of Israel's elite units keeps the bar for what counts as good punishingly high, and that pressure makes everyone around it better. Globally the same forces are dragging the whole discipline forward, attackers very much included. Offense is getting automated whether defenders like it or not, and that reframes what's at stake.
What is your take on the future of the human security researcher?
Well the job is changing. The parts of the work that were pure grind (re-testing the same surface every release, running known techniques across a portfolio, chasing coverage you can never quite finish) are exactly the parts AI is built to absorb. Losing that work is a relief, and what’s left is the creative part; the intuition for bending a system in ways nobody designed for, and the judgment to tell which findings actually matter from the ones that just look scary. AI can execute attacker tradecraft at scale now, but at the end of the day LLMs or SLMs are just knowledge aggregators. They can’t intuit on their own.
The way I see it, AI turns one strong researcher into something closer to a whole team, and hands that person back the time to spend on the problems only a human can crack. The researchers who do well from here are the ones who point the machine in the right direction rather than trying to outrun it on volume. The right word for what's happening is force multiplication. All of that capability still needs a person to aim it, and that makes the people doing the aiming more valuable, not less.














