Sign in to view Avi’s full profile
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
Sign in to view Avi’s full profile
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
Sydney, New South Wales, Australia
Sign in to view Avi’s full profile
Avi can introduce you to 10+ people at Orca Security
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
5K followers
500+ connections
Sign in to view Avi’s full profile
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
View mutual connections with Avi
Avi can introduce you to 10+ people at Orca Security
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
View mutual connections with Avi
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
Sign in to view Avi’s full profile
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
About
Welcome back
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
New to LinkedIn? Join now
Activity
5K followers
-
Avi Shua reposted thisAvi Shua reposted thisשמח ונרגש לשתף שהספר שלי,"חוכמת השווקים: מה השווקים הפיננסיים מספרים לנו על (כמעט) הכול", יוצא לאור בהוצאת פרדס וכבר זמין למכירה מוקדמת! הספר עוסק ברעיון פשוט אך עוצמתי: מחירים בשווקים הפיננסיים אינם משקפים רק ערך כלכלי, אלא גם מידע. דרך סיפורים, מחקרים ודוגמאות מהעולם האמיתי, אני מראה כיצד אפשר להשתמש בשווקים כדי להבין טוב יותר אירועים פוליטיים, כלכליים וחברתיים, לייצר תחזיות ואף לחשוף מידע סמוי. כתיבת הספר הייתה הזדמנות עבורי לחבר בין עולם המחקר, שוק ההון וקבלת ההחלטות, ולהנגיש לקהל רחב תובנות שבדרך כלל נשארות בין דפי מאמרים אקדמיים. תודה לכל מי שליווה, עודד, קרא והעיר לאורך הדרך. 📖 המכירה המוקדמת פתוחה כאן: https://lnkd.in/g-zFfhPW אשמח אם תשתפו! #ספרחדש #כלכלה #שוקההון #Finance #Economics #CapitalMarkets #BookLaunch #הוצאתפרדסחוכמת השווקים: מה השווקים הפיננסיים מספרים לנו על (כמעט) הכולחוכמת השווקים: מה השווקים הפיננסיים מספרים לנו על (כמעט) הכול
-
Avi Shua shared thisHonored to be featured in Ynet's Disrupt40 – highlighting 40 innovators shaping the future of Israeli tech; Thank you for the recognition and for sharing our journey with SideScanning and Orca Security – from an ambitious idea to a global cloud security standard. גאה להיכלל ברשימת Disrupt40 של ynet – רשימת 40 האנשים שמובילים את תעשיית ההייטק הישראלית קדימה. תודה על ההכרה ועל ההזדמנות לשתף את הדרך שעשינו עם SideScanning ו־Orca Security – מטכנולוגיה פורצת דרך לרף חדש באבטחת ענן. https://lnkd.in/dvaYvTQUDisrupt 40 - האנשים המובילים חדשנות, חזון והשפעה בהייטקDisrupt 40 - האנשים המובילים חדשנות, חזון והשפעה בהייטק
-
Avi Shua reposted thisAvi Shua reposted thisWe're #FedRAMP®️ Moderate Authorized! 🏛️ The Orca Cloud Security Platform meets the U.S. government's stringent security requirements – setting a new standard in federal cloud protection. We’re now serving federal agencies and contractors with: ✓ Zero trust cloud security ✓ Rapid FedRAMP deployment ✓ Flexible deployment options ✓ Continuous compliance monitoring When your security needs to be government-grade, choose Orca. Learn more: https://lnkd.in/gMxg5TQ9 #CloudSecurity #GovSecurity #PublicSectorOrca Cloud Security Platform Earns FedRAMP AuthorizationOrca Cloud Security Platform Earns FedRAMP Authorization
-
Avi Shua reposted thisAvi Shua reposted this2024 State of Cloud Security Report is here. Billions of cloud assets analyzed to under the top themes and risks. Check it out.
-
Avi Shua shared thisGreat case study on how Tripledot Studios uses Orca Security to secure their growing cloud estate. Lior Shiff ☁️ Rob Osborn ☁️Tripledot Studios & Orca Security – Amazon Web Services (AWS)Tripledot Studios & Orca Security – Amazon Web Services (AWS)
-
Avi Shua shared thisSuper thrilled to be on @CNBC's 11th annual Disruptor 50 list of startups. This recognition is a testament to the incredible work and innovation by our entire team at Orca Security. Check out to read more list: https://lnkd.in/d33tEgKA We're just getting started!Avi Shua shared thisWe’re thrilled to be #24 on CNBC's 11th annual Disruptor 50 list of private, venture-backed companies transforming industries! This recognition is a testament to the incredible work and innovation by our entire team at Orca Security. Check out the full list: https://lnkd.in/graF6A5A #CNBC #award #cloudsecurity #cybersecurity #Disruptor50 #OrcaSecurity
-
Avi Shua shared thisAt RSA? Always dreamt of cuddling with a huge Orca? Your dream can come true at booth 527!
-
Avi Shua shared thisAvi Shua shared thisAvi Shua, Chief Innovation Officer & Co-Founder of Orca Security talks about the importance of security in organizations. Four years ago, there was no good way to answer the most fundamental question about security - what are the risks in the organization? But now, with the help of Orca’s philosophy and a dedicated team, customers can identify the most important attack before it provides a real risk for the organization in minutes, with no agent and no change to the organization configuration. Orca’s team works around the clock to make the customer journey in the cloud more secure. Thanks to their partnership with the Google Cloud Marketplace, their customers can get started without longer procurement and legal hassles. Focus on securing the environment, not paperwork! Watch to learn more ↓ #CyberSecurity #CloudSecurity #GoogleCloudMarketplace
-
Avi Shua posted thisIt’s been more than 4 years since I co-founded Orca Security and came with the invention of SideScanning. It’s been an incredible journey taking an idea, growing that idea into a category leading company and securing a patent for our side-scanning technology. Since then, I’ve worked with the bright people at Orca to build the worlds’ leading cloud security platform - leadership that is based on innovating. We haven’t slowed down since, and we have continued to bring many unique innovations that transformed the cloud security market - Attack Path Analysis, Integrated API Security, and many more. After more than four years of focusing on building Orca, I have decided to focus on my passion by assuming a new position, chief innovation officer & co-founder at Orca Security. A core part of Orca’s DNA has been to push the boundaries of how cloud security operates and in my new role, innovation will be my primary focus. I’m thrilled to announce that Gil Geron, Orca CPO and co-founder, will take the role of CEO & Co-Founder. Gil has been an integral part of the ideation and a key executive at Orca and I can’t wait to watch and see what he’ll accomplish in his new role. https://lnkd.in/gG87_jTr
-
Avi Shua liked thisAvi Shua liked thisשמח ונרגש לשתף שהספר שלי,"חוכמת השווקים: מה השווקים הפיננסיים מספרים לנו על (כמעט) הכול", יוצא לאור בהוצאת פרדס וכבר זמין למכירה מוקדמת! הספר עוסק ברעיון פשוט אך עוצמתי: מחירים בשווקים הפיננסיים אינם משקפים רק ערך כלכלי, אלא גם מידע. דרך סיפורים, מחקרים ודוגמאות מהעולם האמיתי, אני מראה כיצד אפשר להשתמש בשווקים כדי להבין טוב יותר אירועים פוליטיים, כלכליים וחברתיים, לייצר תחזיות ואף לחשוף מידע סמוי. כתיבת הספר הייתה הזדמנות עבורי לחבר בין עולם המחקר, שוק ההון וקבלת ההחלטות, ולהנגיש לקהל רחב תובנות שבדרך כלל נשארות בין דפי מאמרים אקדמיים. תודה לכל מי שליווה, עודד, קרא והעיר לאורך הדרך. 📖 המכירה המוקדמת פתוחה כאן: https://lnkd.in/g-zFfhPW אשמח אם תשתפו! #ספרחדש #כלכלה #שוקההון #Finance #Economics #CapitalMarkets #BookLaunch #הוצאתפרדסחוכמת השווקים: מה השווקים הפיננסיים מספרים לנו על (כמעט) הכולחוכמת השווקים: מה השווקים הפיננסיים מספרים לנו על (כמעט) הכול
-
Avi Shua liked thisAvi Shua liked this🚀 Big news: Orca Security's Runtime AI Security is now Generally Available. Most security teams know what AI tools their developers want to use. Far fewer know what's actually running in production, and what it's doing. Runtime AI Security closes that gap, with full visibility across your entire AI environment. All inside the Orca Platform. No more blind spots. No more guesswork. Just continuous, cloud-native protection built for the age of AI. 👉 Learn more: https://lnkd.in/ggz-ZkdZ
-
Avi Shua liked thisAvi Shua liked this🚨 NEW RESEARCH: High-severity stored XSS → account takeover in pretalx. Novee Security research disclosed a vulnerability in pretalx, the open-source platform that powers CFPs across the technical conference world. Any registered user could plant HTML in a submission title and have it execute in an organizer's browser the moment their application got called up in a search. Total session hijack, and a quick way to spin up an agent to speed-run the CFP cycle, and get auto-accepted to 40 events. Each individual link in the takeover is something scanners catch on its own and file as low-risk. Composed, they're a high-severity exploit. This kind of chain requires reasoning about how the application is supposed to work, how primitives compose, and what an attacker can do with the workflow around the bug. That's what offensive AI is for. Huge thanks to the pretalx team and creator Tobias Kunze for the rapid, cooperative disclosure. Credit to Elad Meged on Novee's research team for the discovery. 🔗 Full write-up in the comments below.
-
Avi Shua liked thisAvi Shua liked thisBig News! 📣Today we're introducing Agentic Fix: a new Novee capability that turns validated exploits into implemented, verified fixes in one click, using the same AI coding tools engineering teams already trust. Fewer handoffs, less friction, and faster resolution. AI coding assistants help engineering teams deploy new software every day. Unfortunately, that also means AI helps draft the exploitable vulnerabilities that keep security teams backlogged with remediation requests. It’s time to put that same AI to work fixing them. See the flow below 👀 👇 Agentic Fix integrates natively with major AI coding agents, including Claude, Code, Copilot, Cursor, and Devin. No workflow to replace. The same AI that understood the attack deeply enough to exploit it, is the one briefing the fix – which means fewer incomplete patches and a shorter window between discovery and resolution. Attack and defense, in a single loop. Read more here: https://lnkd.in/dPUqaYp4
-
Avi Shua liked thisAvi Shua liked thisWhat a blast in Sydney! 🇦🇺 The #Gartner Security & Risk Management Summit was the perfect stage to showcase our expanded Orca Security Australian team and host our co-founder and Chief Innovation Officer, Avi Shua, who is officially local and living here in Australia! I loved the deep dives into #AppSec, Agentless #AI observability and cloud risk management. Also, our "Orkie" plushies were a total hit! 🐳 If you didn’t manage to snag one at the booth, don’t worry, visit us next time or just drop us a note and we’ll ship one your way! :-)) #OrcaSecurity #CloudSecurity #GartnerSEC David Wang Ryan Tucker Dung Hua Paul Stephens Kuhoo Maharishi Desmond O'Connor
-
Avi Shua liked thisAvi Shua liked thisAfter a decade at Aqua Security, I am closing a defining chapter. I don’t often stop to write posts like this, but it felt like a moment worth marking. Aqua has been a defining part of my professional life, and closing this chapter brings a mix of gratitude, perspective, and emotion. We started Aqua with a simple idea: securing Docker containers. This was very early on, when it wasn’t at all obvious that containers would even need security. Raising capital was tough. We heard many “no”s and plenty of “let us get back to you”. Then one YES made it all real. Seeing Aqua grow from a handful of people sharing a tiny space into a global company that helped define cloud-native security has been one of the most meaningful experiences of my career. But beyond the scale or the category, what mattered most was the culture we built and the people who brought it to life. I’m deeply thankful to the colleagues, investors, partners and customers I had the chance to work with along the way. You helped turn an early conviction into something real, impactful, and lasting. Aqua will always be part of my story, and I’ll be rooting for it as it moves forward. As for what’s next - I’ll be updating my LinkedIn headline 🚀
-
Avi Shua liked thisAvi Shua liked thisI’m thrilled to share that I’m starting a new position as a Software Developer at Orca Security! 🐋 ☁️
Experience & Education
-
Orca Security
***** ********** ******* * **********
-
** ********
*******
-
***** ***** ******** ************* ****
***** ************* ****** **********
-
*** ****** ********** ** *********
*** ******** ******* * ********** undefined
-
View Avi’s full experience
See their title, tenure and more.
Welcome back
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
New to LinkedIn? Join now
or
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
Patents
-
Simultaneous screening of untrusted digital files
Issued US 9208317B2
Recommendations received
3 people have recommended Avi
Join now to viewView Avi’s full profile
-
See who you know in common
-
Get introduced
-
Contact Avi directly
Explore more posts
-
Tim Callan
7K followers
In this Root Causes Podcast episode, Jason Soroko and I define Cryptographic Bill of Materials (CBOM), which is more than a list of your cryptography and where it is. A CBOM need also include information about the PQC readiness of environments, availability of updates, and the importance of secrets. Audio: https://lnkd.in/gJC5y3at Video: https://lnkd.in/gHuXd69B
22
2 Comments -
Adrian Sanabria
7K followers
Adjacent to the RSAC talk I'm delivering tomorrow alongside 😷 Adam Shostack, The Defenders Initiative has posted the first in a series of deep dives on how breaches happen. The first one is on MGM's 2023 breach. We usually know how attackers got in. We usually know what they got away with. But what about everything in-between? Why didn't the security team detect the attack? Why didn't they prevent it? Which security controls failed? What happened to defense in depth? These are just some of the questions we aim to answer with this series. Obviously, this level of breach detail isn't common place, but there are more details out there than you would think (if you know where to look). Oh, and I'll tell you where to look for breach details in tomorrow's RSAC talk as well. Link to the post in the comments.
24
1 Comment -
Netpublik.id
64 followers
A new report from Splunk reveals that 92% of CISOs are now using AI to review more security events daily. But as defense gets smarter, so do the attackers. With 86% of leaders worried about AI-powered social engineering. Find the article here: https://lnkd.in/gAVnwgX3 #splunk #cybersecurity #ciso #AI #technews
-
Alex Reid
acuCyber • 17K followers
Some interesting experimentation today... spun up an Elastic container and tested out the UDRL/Sleepmask combo from my new ZPS course. I was expecting to trigger this (https://lnkd.in/gei3CYZE) rule concerning suspicious networking DLL's like Wininet.dll being loaded into a process with a call stack containing unbacked memory, as commonly found when shellcode is injected into memory allocated with things like VirtualAlloc. This was the case for my test scenario, where I used a simple loader program to execute my UDRL, which in turn maps the Cobalt Strike Beacon DLL into memory and resolves its imports, to include loading Wininet.dll into the process. Strangely, the alert did not fire. After attaching a debugger and setting a breakpoint on the NtMapViewOfSection call made by LdrLoadDll to map Wininet.dll into the process, the call stack was examined in Process Hacker. While unbacked memory addresses were present in the call stack, there was also an entry for gpvsvc.dll- this is a random address leaked from the stack as a result of the underlying code residing in unbacked memory, not an actual return address. All the same it is enough to break the detection rule's logic, which expects the matching call stacks to begin either with an ntdll address or an unbacked one- not an address from another DLL that happens to be mistakenly parsed as part of the call stack. While the tooling currently bypasses this detection rule by sheer luck / random chance, it's better to have a reliable method for doing so- one that is currently being engineered and will be added to the UDRL and Sleepmask course as part of the first update. Had a great conversation with Joe Desimone about this who confirmed my suspicions. Huge shoutout to the Elastic team, their open-sourcing of detection rules provides an incredible resource to develop offensive tooling around and otherwise generally does a lot to push the security industry forward. Hope others find things like this interesting too! #malware #edr #cobaltstrike #cybersecurity #Windows #redteam
212
2 Comments -
Cole Grolmus
Strategy of Security • 24K followers
Catching up on Zscaler's Q2'26 earnings report... This was a solid report all around, but the market took their stock price for a ride. It was immediately down ~9% (even after a beat-and-raise), but has corrected nicely since January. Analysts are mostly bullish, too. The headline narrative was all about AI (naturally), but the current growth engine is a lot more meat-and-potatoes. AI revenue is still immaterial (for a company of Zscaler's size). Totally fine, but the market priced its their skepticism over the timeline. The real driver of Zscaler's business right now is Zero Trust Everywhere. Philosophically, they're betting architectural coherence can beat out portfolio breadth as we get further into the AI era. Several thoughts: → Zero Trust Everywhere is the current growth engine. Customers adopting Users, Branch, and Cloud grew from 130 to 550 in one year (4x growth), which drives 2-3x ARR uplift on conversion. This is the Zscaler-flavored way of platform building: A very specific vision of architecture gets adopted across large, complex customers and displaces established networking products. Zero Trust Branch replaces SD-WAN and MPLS, Zero Trust Cloud replaces virtual firewalls...you get the idea. Good quote from Jay Chaudhry that sums this up nicely: "I don't find any Zscaler customer who says 'I love my SD-WAN.' They all want to replace SD-WAN for cost reasons and for security reasons." → Z-Flex creates multiyear commitments with built-in upsell mechanics. Zscaler has continued to make pretty good progress on Z-Flex: $290M TCV in Q2 alone (up 65% QoQ), $650M total since launch ~1 year ago, average deal is 8-figure TCV, ~4-year term. The point of tension people picked up on was that Z-Flex deals are back-weighted. Revenue ramps over 6-12 months, creating short-term ARR headwinds even as long-term visibility strengthens. This is just part of the deal when you're in a relatively mature market segment trying to displace entrenched incumbents. Zscaler is doing what it has to do, even if investors don't love it right now. → Good news for everyone on AI budgeting? Brian Essex asked a great question, summarized as: where is AI security money coming from? Jay Chaudhry's answer was that it's coming from both existing security budgets *and* new AI project budgets. He specifically mentioned $4-6 on security per $100 AI spend. If AI security revenue is partially incremental (pulled from AI budgets) rather than entirely reallocated (competing for flat security budget share), this is excellent news for all of cybersecurity, not just Zscaler. --- Zscaler did exactly what they needed to do for the midpoint of their fiscal year. This was a clean beat-and-raise quarter with strong execution. The theme to watch for the rest of the year is how their AI story materializes (and SecOps, ofc).
121
2 Comments -
Gal Tal-Hochberg
7K followers
I recently talked with a CISO of a big organization who said something that stuck with me: he's not just measuring MTTR, he's also measuring time to RCA (Root Cause Analysis). It made me think about how much gets buried in MTTR. Detection, investigation, containment, remediation. It all blends into one number, and you lose sight of how long it actually took to investigate. And that's a shame, because there's a lot you can do to optimize that part specifically. When you start paying attention to investigation time, you notice where the hours actually go. The back-and-forth between tools to answer one question. Manually enriching IPs with context that should already be there. Data that's technically there, but not in a shape you can actually use. But if you're measuring time to RCA, it stops being invisible. You start asking: what slowed the investigation down, and more importantly, how do we fix it.
19
-
Opal Security
8K followers
🚀 Big things landed at Opal last month. Identity risk is growing fast, and security teams need more than visibility—they need control, speed, and confidence. Our latest updates do exactly that. What’s new: 🔎 Explore Graph: investigate “who has access to what” with ease. 📝 More Context for User Access Reviews: richer insights for faster, smarter approvals. ‼️ Max User Limits: safely cap access to particular resources. 📬 Jira Service Management Integration: streamline requests where work already happens. 👥 Active Directory Support: manage on-prem users and groups. 📊 DataStax Integration: fine-grained access control in your database platform. More clarity. More control. Less risk. Read more on what we've been up to 👉 https://lnkd.in/gjrvN_uG
38
3 Comments
Explore collaborative articles
We’re unlocking community knowledge in a new way. Experts add insights directly into each article, started with the help of AI.
Explore More