Skip to content
snailsploit[$]Adversarial · Research
Co-Founder · Offensive Security Researcher · Red Team Architect

Sahar Shlichove

aka mixbanana

sahar shlichove (mixbanana) started in defense. senior SOC analyst, malware analyst — the kind who takes a binary apart until there's nothing left to learn from it.

then he crossed to offense and never looked back. supply-chain infrastructure, cloud-native environments, adversarial AI — wherever the high-value targets are, that's where he operates. kubernetes clusters, container escapes, cloud tenancy boundaries, AI guardrails. hands-on at every layer.

if you ask kai and avraham, he's the most dangerous hacker they know.

that's why he's at snailsploit. same thesis. same instinct. different substrate.

Origin

sahar and avraham shemesh have been friends since childhood — teen hackers who grew up breaking things together. i met them both through a previous role, and we clicked. we've been researching together since. each one of us is an undeniable piece of the chain. and if you ask me and avraham, sahar is the most dangerous hacker we know.

sahar and avraham built their own saas at 16 — sold it to buy their first car.

The Record

before offense, defense: senior SOC analyst at TrustNet, malware analyst professional (levels 1 & 2) through uriel kosayev's TrainSec academy. now runs offensive operations against supply-chain infrastructure at scale. also a sharp automation engineer.

Vendor Acknowledgments

eight vendor security teams have credited him by name for vulnerabilities he found and responsibly disclosed:

vendoracknowledgment
appleweb server security acknowledgments, february 2026 · support.apple.com ↗
IBMPSIRT disclosures, 2026 · ibm.com ↗
palo alto networksPSIRT and SOC researcher acknowledgments · paloaltonetworks.com ↗
red hatmultiple findings, 2026 · access.redhat.com ↗
broadcomconfirmed security issues, april 2026
apacheleaked 3rd-party service token, 2024
onasecurity acknowledgments, 2025 · ona.com ↗
Israel National Cyber DirectorateVDP reporter ranking — score 210 · gov.il ↗

apple. IBM. palo alto. red hat. broadcom. apache. and the Israeli national cyber directorate's own VDP leaderboard. that's not a list — it's a pattern. he finds what internal teams miss, across codebases they built, in infrastructure they operate.

Vulnerability Research

CVE-2023-40297 — directory traversal in stakater forecastle 1.0.127 (CVSS 7.5). kubernetes app-discovery component. arbitrary file read → service-account tokens → cluster. discovered, disclosed, published.

microsoft excel URI scheme RCE — discovered a vulnerability in windows protocolhandler.exe allowing remote code execution by bypassing environment variable filters. full exploit chain published.

shodan broken access control — IDOR exposing membership-tier features to unauthenticated users. acknowledged by shodan.

Bug Bounty

ID-verified HackerOne profile (mixbanana), active on AWS and MUFG VDPs, submitting to NVIDIA via intigriti.

On Stage
AWS gen AI loft · tel aviv 2026

demo track speaker alongside orel bitan and itay meller (AWS). live demonstration: transforming a research blog into a fully functional attack environment in AWS using AI. not a slide deck — a live attack.

event details ↗
Adversarial AI

authored the chatgpt-red-team structural prompt framework and published research on bypassing GPT-5 guardrails. the same thesis that runs through snailsploit — prompt injection and social engineering are the same attack class, executed against different substrates — runs through his work.

provided the foundational offensive security checklists behind claude-red, snailsploit's autonomous AI red-teaming operator. credited in the published papers social engineering framework and position: AI systems are inherently vulnerable.

Published Research

when multi-tenant isolation completely falls apart — the assumption that tenant boundaries hold under adversarial pressure

CORS end-to-end — the full attack surface of cross-origin misconfiguration

Tooling
chatgpt-red-team · Shodan-IDOR · MalwareBot_Israel · decoded-whmcs
Focus
supply-chain security · cloud-native attack surfaces · adversarial AI · vulnerability research
LinkedIn ↗GitHub ↗Medium ↗

same attack. different substrate.