Amir Shavit, Head of Research, Zafran.
Security Researchers: Digital Fighters Series

Zafran: “AI is the biggest force multiplier security researchers have ever had”

Amir Shavitt, Head of Research at Zafran, explains how the balance of power between attackers and defenders is changing as part of CTech’s Security Researchers series.

“AI is the biggest force multiplier security researchers have ever had, and it is already changing how the work gets done day to day,” says Amir Shavitt, Head of Research at Zafran, a cyber company that raised $130 million from investors including Sequoia Capital, Cyberstarts, and Menlo Ventures. Shavitt, who holds a B.Sc. in Mathematics and Computer Science from Tel Aviv University, came into the discipline off the back of an acute interest in mathematics. Today, he works as part of a team of six researchers hailing from elite cyber units including Unit 81, Unit 8200, and the Joint Cyber Defense Directorate, boasting a variety of backgrounds across offensive and defensive cyber.
Within Israel’s cyber companies are small, highly specialized teams trained to think like attackers, find vulnerabilities and stay ahead of a threat landscape increasingly accelerated by AI. In this series, we meet the individuals and teams who make up this frontline of cyber: the digital fighters.
1 View gallery
Amir Shavit Zafran
Amir Shavit Zafran
Amir Shavit, Head of Research, Zafran.
(Photo: Omer Hacohen)
While he acknowledges AI has irrevocably changed the research field, Shavitt asserts, “what has not changed is where the good questions come from. Deciding what to chase is often a bet you make before you have the evidence, and that instinct is still human.”
You can read the entire interview below.
ID Card Company name: Zafran Security Founders: Sanaz Yashar and Ben Seri Year of founding: 2022 Current number of employees: 150
Company Description:
Zafran Security is an AI-native Threat Exposure Management company that helps enterprises identify and stop the vulnerabilities and attack paths most likely to lead to a breach. The platform combines vulnerability data, threat intelligence, runtime context, and existing security defenses to understand what is actually exploitable and take action before attackers can.
Zafran works with Fortune 500 companies across highly regulated industries including financial services, healthcare, and energy, and collaborates with leading technology and security companies including Google Cloud.
About Zafran's Security Research Team:
Zafran’s research team is made up of six researchers with backgrounds across offensive and defensive cybersecurity, including threat intelligence, vulnerability research, exploitation, and reverse engineering. The team brings experience from elite Israeli cyber units, including Unit 81, Unit 8200, and the Joint Cyber Defense Directorate.
Researchers typically work independently or in pairs, but constantly move between projects and initiatives depending on the problem at hand. Each researcher brings a different area of expertise, and those skills complement one another. That mix is important because the problems we work on rarely fit neatly into one discipline.
A vulnerability research project can quickly turn into an exploitation problem, a threat intelligence question, or require looking at the defensive side to understand how an organization could actually stop the attack.
What is your background in cyber, and what led you to specialize in security research?
I came to security research through mathematics. I spent years solving math olympiad problems, and in some ways I never really left that behind, the problems just got messier. What has always pulled me in is a hard problem, and security is full of complex systems that behave in ways nobody planned for. The most interesting work often lives in the edge cases and the gaps between components that were never designed to work together. It is still a puzzle, except now there is someone on the other side of it.
I started my cybersecurity career in the IDF, where I spent more than five years as a researcher and later a Research Team Leader. Much of my work focused on reverse engineering complex systems and low-level vulnerability research in embedded systems. I later spent two years as a researcher at KayHut before joining Zafran in 2023, first as a Senior Software Engineer, then Team Lead, and today as Head of Research.
What does your security research team look like in action?
Zafran's research works on three fronts, and the ideas feeding it come from two directions: our view of where enterprise security is heading, and what we see in real customer environments at scale.
The first front is public research, the work we disclose to the community and present at the major conferences, focused on technologies enterprises are adopting quickly and where new security gaps are starting to emerge. Recently that has included AI infrastructure, open source frameworks and software supply chains.
The second goes directly into the product, where our researchers and the engineering teams work closely together, and that exchange shapes how the platform reasons about vulnerabilities, threat intelligence, security controls, and how all of it connects.
The third is longer horizon research, work aimed at problems the industry has not solved yet and that we believe will define how enterprises defend themselves in the future.
How does the research team influence your company at large?
Zafran was built by researchers, and research has a direct impact on what we build and how we bring it to customers. Researchers are part of roadmap discussions, working alongside product and engineering to turn new findings into capabilities that ship. In one case, a line of research grew into an entirely new part of the platform.
That impact continues beyond the product itself. The researcher who discovers something is often the same person helping shape how we respond to it, joining conversations with prospects and customers, and working with marketing to bring the insight to the broader market. Research at Zafran is not a separate function. It directly influences the product, the customer conversation, and where the company goes next.
What has been your team’s most significant security discovery to date?
One of Zafran Labs’ most significant research efforts is Project DarkSide, an ongoing investigation into the security risks emerging across widely adopted AI infrastructure. As part of the project, the team has uncovered vulnerabilities across platforms and frameworks including Chainlit, Dify, and Hugging Face, showing how weaknesses in the infrastructure around AI can create serious risks for the organizations adopting it.
The research points to a broader problem: as companies move quickly to build and deploy AI, attackers are increasingly able to target the frameworks, libraries, and software supply chains that sit around the models. Project DarkSide is focused on finding those weaknesses before they can become a new path into enterprise environments.
Who or what is your 'Moby Dick'?
Our Moby Dick is the attack chain that no one sees because none of its links look dangerous on their own: a medium-severity vulnerability, a minor misconfiguration, a gap in a security control that never raises an alarm.
Individually, none of them gets much attention. Together, they can create a path into an organization. Finding those combinations before an attacker does is what we keep coming back to. AI is becoming central to that challenge because it is exceptionally good at finding weaknesses and connecting them at scale, both for defenders and for whoever is on the other side.
Ultimately, we want to get to a point where the moment a vulnerability is published, we already know how to break the attack chain around it. That might mean figuring out how to use a security control the organization already has to stop it, or developing a new mitigation technique. Attackers operate in the window between disclosure and patching. Our goal is to close that window, not just make it shorter.
How would you characterize the competition between research teams today?
Security research is competitive, but it is also unusually collaborative. Every team wants to be the first to uncover an important vulnerability or new attack technique, but ultimately researchers are dealing with the same adversary. The more interesting shift today is that the playing field is getting bigger. AI, cloud infrastructure, open source, and increasingly complex software supply chains are creating entirely new areas to investigate. That means there are more opportunities for research teams to specialize and differentiate themselves, while responsible disclosure still requires researchers, vendors, and the broader security community to work together.
What is your take on the future of the human security researcher?
AI is the biggest force multiplier security researchers have ever had, and it is already changing how the work gets done day to day. What started as rubber duck debugging has become something much closer to a research partner. AI can handle manual work, investigate data, and run experiments continuously, giving you feedback in minutes on things that used to take days or even a week. That does more than speed up research. It lets researchers spend more time directing the work, following interesting leads, and deciding what to investigate next.
What has not changed is where the good questions come from. Deciding what to chase is often a bet you make before you have the evidence, and that instinct is still human. AI can make a strong researcher dramatically more productive, but it does not tell you what to be curious about.
On the balance between attackers and defenders, every major new technology sets off a similar cycle. The advantage moves back and forth, but early on it usually favors attackers because they have fewer constraints and can afford to be wrong nine times out of ten. That is roughly what we have seen with AI. Defenders are catching up quickly, though, and I would not assume today's balance of power will hold.