About

Elad Beber

Hey, my name is Elad and I’m a vulnerability researcher. My background is in low-level reverse engineering (IDA, Ghidra, GDB) and Android internals (Jadx, Frida). Day to day I break cloud platforms like Azure, AWS and GCP, Kubernetes clusters, and lately AI coding tools and agents like Claude Code and Codex CLI. I’ve been playing CTFs with CamelRiders for years.

Experience

Senior Security Researcher @ Cymulate
  • Design and build agentic AI workflows with LangChain and LangGraph that generate realistic attack scenarios for security-control validation across Azure, AWS and GCP.
  • Research emerging attack surfaces in AI coding assistants, MCP servers, cloud infrastructure, identity systems and Windows enterprise-management products.
  • Turn research findings into reproducible attack techniques and validation content for Cymulate’s Breach and Attack Simulation platform.
Vulnerability Researcher @ Cymulate
  • Conducted vulnerability research across Azure, AWS and GCP, focusing on cloud services, identity boundaries, guest agents and privilege-escalation paths.
  • Designed and implemented proof-of-concept attack scenarios for Cymulate’s BAS platform across Windows, Linux and cloud environments.
  • Built Kubernetes scanning and exploitation mechanisms for testing managed and on-premises clusters.
  • Developed tooling for Cymulate’s Attack Surface Management capabilities to identify and validate exposures across organizational assets.
Mobile Security Researcher @ Matrix

Offensive mobile security research on Android internals and mobile reverse engineering. Designed security and recruiting challenges.

Education

B.Sc. Computer Science, graduated with honors, Holon Institute of Technology (HIT)

Certifications

Cybersecurity Program · Kernelios — Cyber Academy

Press & mentions

CybersecurityNews One-Click RCE in Azure Windows Admin Center Lets Attackers Execute Arbitrary Commands
CybersecurityNews Azure Identity Token Vulnerability Enables Tenant-Wide Compromise in Windows Admin Center
GBHackers Azure Identity Token Flaw Exposes Windows Admin Center to Tenant-Wide Breaches
CybersecurityNews Windows Admin Center Vulnerability (CVE-2025-64669) Lets Attackers Escalate Privileges
XPN InfoSec Blog (Adam Chester) An Evening With Claude Code — “a fantastic writeup of a code exec vulnerability”
Cyberpress Security Flaw in Claude Lets Attackers Abuse AI to Run Unauthorized Commands
CybersecurityNews Claude Vulnerabilities Let Attackers Execute Unauthorized Commands With its Own Help
Embrace The Red Anthropic Filesystem MCP Server: Directory Access Bypass — “shout out to Elad Beber, who reported it to Anthropic first”
GBHackers Claude AI Flaws Let Attackers Execute Unauthorized Commands Using the Model Itself
SQ Magazine Claude's AI Assistant Helped Hackers Exploit Its Own Weaknesses
tl;dr sec Anthropic MCP research featured (issue #293)
CybersecurityNews Anthropic's MCP Server Vulnerability Allowed Attackers to Escape Sandbox and Execute Code
GBHackers Anthropic MCP Server Flaw Allows Sandbox Escape and Code Execution
SecurityOnline Anthropic MCP Server Flaws: Path Traversal & Symlink Attacks Allow RCE
The Hacker News Critical MCP-Remote Vulnerability
CybersecurityNews AWS Systems Manager Plugin Vulnerability Lets Attackers Execute Arbitrary Code
GBHackers AWS Systems Manager Plugin Flaw Allows Arbitrary Code Execution
The Hacker News Amazon EC2 SSM Agent Flaw Patched After Disclosure
Forbes Microsoft Issues Mandatory 2FA Login Deadline Alert (Double Agent research)
SC Media Microsoft Entra ID bug lets attackers impersonate any synched user
The Hacker News Double Agent research coverage