{"id":603109,"date":"2026-08-24T12:48:11","date_gmt":"2026-08-24T12:48:11","guid":{"rendered":"https:\/\/www.newsbeep.com\/ie\/603109\/"},"modified":"2026-08-24T12:48:11","modified_gmt":"2026-08-24T12:48:11","slug":"newcore-the-openai-and-hugging-face-incidents-signal-where-things-are-heading","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/ie\/603109\/","title":{"rendered":"NewCore: \u201cThe OpenAI and Hugging Face incidents signal where things are heading\u201d"},"content":{"rendered":"<p>\u201cThere&#8217;s a specific kind of satisfaction in uncovering a flaw that could affect thousands of systems,\u201d says Ido Hoorvitch, Security Researcher at identity platform NewCore. \u201cNot just for the thrill of the hunt, but because of the massive real-world impact of patching it.\u201d Hoorvitch\u2019s curiosity in the field was ignited at age 17, \u201cthanks to a family friend who was a hacker and gave me private lessons.\u201d Today at NewCore, he works as part of a team of three senior researchers, each with over a decade in vulnerability research.<\/p>\n<p>Within Israel\u2019s cyber companies are small, <a id=\"HJA0HrFj2Yvfg\" href=\"https:\/\/www.calcalistech.com\/ctechnews\/article\/h1u3uqzizl\" target=\"_blank\" rel=\"nofollow noopener\">highly specialized teams trained to think like attackers<\/a>, find vulnerabilities and stay ahead of a threat landscape increasingly accelerated by AI. In this series, we meet the individuals and teams who make up this frontline of cyber: the digital fighters.<a class=\"gelleryOpener\" aria-label=\"open article gallery\" data-image-id=\"ArticleImageData.BJglr00KtDGl\" id=\"image_ArticleImageData.BJglr00KtDGl\"><\/p>\n<p>1 View gallery <\/p>\n<p><img decoding=\"async\" id=\"ReduxEditableImage_ArticleImageData.BJglr00KtDGl\" src=\"https:\/\/www.newsbeep.com\/ie\/wp-content\/uploads\/2026\/08\/Sk11zMxmDfx_0_101_1023_576_0_x-large.jpg\" alt=\"Ido Hoorvitch NewCore\" title=\"Ido Hoorvitch, Security Researcher, NewCore.  (Photo: Niros) \" aria-hidden=\"false\"\/><\/a><img decoding=\"async\" id=\"ReduxEditableImage_ArticleImageData.BJglr00KtDGl\" src=\"https:\/\/www.newsbeep.com\/ie\/wp-content\/uploads\/2026\/08\/Sk11zMxmDfx_0_101_1023_576_0_x-large.jpg\" alt=\"Ido Hoorvitch NewCore\" title=\"Ido Hoorvitch, Security Researcher, NewCore.  (Photo: Niros) \" aria-hidden=\"false\"\/><\/p>\n<p>Ido Hoorvitch, Security Researcher, NewCore. <\/p>\n<p>(Photo: Niros)<\/p>\n<p>While Hoorvitch describes how \u201cour team can operate with ten times the efficiency,\u201d as a result of the AI revolution, he warns that \u201cthe recent incidents involving OpenAI and Hugging Face clearly signal where things are heading.\u201d With autonomous AI agents already acting as hacker teams, he argues that \u201ccompanies must now adopt continuous security assessment as the new standard.\u201d<\/p>\n<p>You can read the entire interview below. <\/p>\n<p>ID Card<br \/>\nCompany name: NewCore<br \/>\nFounders: Zohar Alon, Amihai Neiderman, Erez Yarkoni<br \/>\nYear of founding: 2025<br \/>\nCurrent number of employees: 60<\/p>\n<p>NewCore is the next-gen IdP for humans and AI agents. Rebuilt securely from the ground up, it converges every human and agentic identity into one platform that authenticates, authorizes, and governs them, from access to audit.<\/p>\n<p>About NewCore\u2019s Security Research Team: <\/p>\n<p>Our security research team has three senior researchers with over a decade each in vulnerability research.<\/p>\n<p>What is your background in cyber, and what led you to specialize in security research?<\/p>\n<p>I say it started with the IDF, some say it\u2019s destiny. My curiosity for hacking ignited when I was 17, thanks to a family friend who was a hacker and gave me private lessons. It was a different world back then compared to today, where cyber is part of the high school curriculum. He taught me networking and OS internals, introducing me to tools like Cain &amp; Abel, WebGoat and Wireshark. <\/p>\n<p>I served for five years in Unit 81, first as a security researcher and later as a team lead after becoming an officer. Following my service, I spent six years at CyberArk Labs where I was researching vulnerabilities, then I spent time as a product manager in a cyber startup before returning to my true passion at the forefront of security research.<\/p>\n<p>What does your security research team look like in action?<\/p>\n<p>Our research focuses on a deep analysis of our own internal systems and widely used technologies in the industry to better understand innovative attack vectors and potential security gaps. <\/p>\n<p>Our &#8220;AI-first&#8221; approach goes beyond just using new gadgets; it\u2019s about supercharging our researchers\u2019 core strengths. By automating our workflows for vulnerability research and code auditing, our team can operate with ten times the efficiency. This allows us to focus our human expertise on the complex, creative problem-solving that really moves the needle.<\/p>\n<p>How does the research team influence your company at large?<\/p>\n<p>Our research team is deeply embedded in every facet of the company. We review every feature at the RFC phase before a single line of code is written. We follow this up with architecture reviews and continuous red teaming. We also work closely with the product team every day to brainstorm the next security features that will raise the bar for attackers.<\/p>\n<p>What has been your team\u2019s most significant security discovery to date?<\/p>\n<p>We\u2019ve uncovered several critical zero-days, but as they are currently under responsible disclosure, I can\u2019t share specific details just yet. To date, we have identified multiple vulnerabilities across various prominent identity platforms currently on the market and used by the majority of enterprises.<\/p>\n<p>Who or what is your &#8216;Moby Dick&#8217;?<\/p>\n<p>My &#8220;Moby Dick&#8221; is identifying those fundamental vulnerabilities that have the potential to impact organizations at scale. There&#8217;s a specific kind of satisfaction in uncovering a flaw that could affect thousands of systems \u2013 not just for the thrill of the hunt, but because of the massive real-world impact of patching it. <\/p>\n<p>Beyond finding bugs, my true passion is innovating the security features that prevent them from existing in the first place. We&#8217;re building an identity platform and holding the &#8220;keys to the kingdom,&#8221; and there&#8217;s no greater motivation than making sure that infrastructure is truly resilient. <\/p>\n<p>How would you characterize the competition between research teams today?<\/p>\n<p>The level of cyber research coming out of Israel is impressive, which you can see by how often Israeli researchers are leading sessions at major global conferences. Globally, teams like Google&#8217;s Project Zero or Wiz are doing great work and setting a high bar for the industry. <\/p>\n<p>Personally, I don&#8217;t see the research community as being in competition with one another \u2013 we&#8217;re all working toward a safer ecosystem. When it comes to the market, NewCore is built as a security-first company, which is a different approach from competitors that started as IT solutions. Because of that, I don&#8217;t feel we are really competing in the same space.<\/p>\n<p>What is your take on the future of the human security researcher?<\/p>\n<p>The recent incidents involving OpenAI and Hugging Face clearly signal where things are heading. The reality of autonomous AI agents acting as hacker teams is already here. This shift means that software built in an older era is no longer enough and often puts customers at risk. Today\u2019s software demands constant internal audits and analysis. Just as companies have adopted continuous integration and deployment (CI\/CD), they must now adopt continuous security assessment as the new standard. When agents attack continuously, findings need to become enforcement rather than reports, which is where identity and governance come in.<\/p>\n","protected":false},"excerpt":{"rendered":"\u201cThere&#8217;s a specific kind of satisfaction in uncovering a flaw that could affect thousands of systems,\u201d says Ido&hellip;\n","protected":false},"author":2,"featured_media":603110,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[61,60,80],"class_list":["post-603109","post","type-post","status-publish","format-standard","has-post-thumbnail","category-technology","tag-ie","tag-ireland","tag-technology"],"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/posts\/603109","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/comments?post=603109"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/posts\/603109\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/media\/603110"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/media?parent=603109"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/categories?post=603109"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/tags?post=603109"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}