AI-Accelerated Security
Put AI to work inside your pipeline, speeding up secure development and cutting the time from finding to fixing.
- AI-assisted code and config review
- Automated triage and remediation
- Security context where developers work
Senior Principal Security Architect
I help teams secure what they build with AI and defend the AI workloads they run, with guardrails that hold across the software and AI development lifecycles.
01 Services
AI-security engagements that keep your teams moving and your AI safe.
Put AI to work inside your pipeline, speeding up secure development and cutting the time from finding to fixing.
Guardrails and enforcement for AI, wired into your SDLC and ADLC so safe defaults ship automatically.
Threat modeling and hardening for LLM apps and AI agents, from prompt-injection to the model supply chain.
The architecture foundation: hardened AWS accounts and least-privilege access your AI systems can build on.
02 About
I'm Avishay Bar, a Senior Principal Security Architect at Palo Alto Networks, where I've spent the past eight years. I work on securing AI: helping teams adopt it safely and defend the AI systems they ship, while using AI to make security itself faster. I hold a patent for securing the development lifecycle with AI, and I spend my days where new AI risk meets real-world engineering.
03 Work
Projects and vulnerable-by-design labs, current work pinned first, then ordered by stars - pulled live from GitHub.
Installable Agent Skill that turns your coding agent (Claude Code, Cursor) into a software supply-chain security engineer for your repo and CI/CD — evidence-based findings, safe verified remediation, no scanner service.
DVAH — Damn Vulnerable Agent Harness: a patch-the-runtime security lab for AI-agent platforms. Exploit a real architectural bug, trace it, patch the harness, and prove the security invariant holds.
React Native Package With One Purpose: To Restart Your React Native Project
Repository demonstrating the Capital One breach on your AWS account
Vulnerable by Design AWS Cloud Development Kit (CDK) Infrastructure
Tool for signing and verifying the integrity of CloudFormation templates
04 Posts & Notes
Short takes from LinkedIn and longer pieces from the blog, in one place.
תארו לעצמכם שה-IDE שלכם פותח פתאום Reverse Shell לשרת צד שלישי בלי לבקש? הייתם מכריזים מיד על אירוע אבטחה חמור. אבל איך אנחנו מתייחסים לאירוע כשקלוד בעצמם עושים את זה? דיווחים אחרונים בקהילה של Claude Code מצביעים על כך שיכולת ה-Remote Control שלו (הפקודה /rc) הופעלה אוטומטית עבור חלק מהסשנים… read more →
If you're an open source maintainer, security engineer or even a developer, you've probably been dealing a lot lately with supply chain security. I've been as well. So I built an AI skill to help and now I decided to open source it. Please meet AttestArc, an open source security… read more →
How many times did you hear about a new AI open source tool with "gazillion stars in 3 days", right? We know GitHub stars are a flawed metric for software supply chain maturity, especially in the AI tooling ecosystem. A few months ago, data from the StarScout project flagged millions… read more →
I've just finished the AI Security Engineer Foundations track at aisecurity.engineer and passed the assessment. This is one of the better AI security resources I've gone through recently, made by Snyk. It moves quickly beyond the usual "prompt injection and jailbreaks" discussion into the problems security teams are actually starting… read more →
חוקרי אבטחה של קבוצת Dream חשפו קמפיין תקיפה נגד תשתיות בטייוואן, שבו תוקפים השתמשו בעד 8 AI Agents בלולאות עבודה מקבילות כדי למפות מערכות, לבדוק פגיעויות ולהסתגל מול 21 יעדים ממשלתיים. - נפרצו Credentials של 85 חשבונות ממשלתיים, ו-84 מהם אפשרו גישה למערכות פנימיות. - נגנבו יותר מ-2,500 רשומות כוח… read more →
במשך זמן רב (בקצב של היום, מספר חודשים 😉 ), אחת משכבות ההגנה המרכזיות של ספקי מודלים כמו Anthropic ו-OpenAI הייתה היכולת של המודל לזהות בקשות מסוכנות ולסרב להן (כן, כמו ה-״לא״ בסגנון המוכר של פוסטים מג׳ונרטים בלינקדאין 😆). ההכרזה האחרונה של OpenAI על GPT-5.6-Cyber מראה עד כמה המודל הזה… read more →
05 Speaking
A hands-on walkthrough of hardening a real AWS account: the identity and network fixes you can ship the same day.
Moving security controls into CI/CD so issues are caught before they ever reach production.
Book a free 30-minute intro call and leave with a clear next step.
06 Follow
Latest posts