LATEST NEWS

For years, they hacked organizations for a living. Then they switched sides

The three founders of Mars Security spent years trying to break into organizations without being caught. What they found was that getting in was often the easy part.

During offensive cyber operations, Shahaf Galili says his teams could often tell when they had left traces behind. They moved between systems, used credentials and carried out actions that should have raised alarms. What puzzled them was how often nobody reacted.

“We were making all these mistakes,” Galili says. “We’re trying to be stealthy and crafty, but we’re still doing all these bad things that are creating all that noise, and they just don’t see us.” Galili spent 22 years in cyber and intelligence roles before leaving the military. His Mars Security co-founders, Ran Lerer, the company’s CTO, and Matan Caspi, its chief architect, also came from hands-on cyber backgrounds. The three eventually moved to the other side of the equation: helping companies detect attackers rather than evade detection themselves.

For Galili, that experience changed the way he thinks about cybersecurity. In many cases, he says, getting into an organization is not the hardest part. “My only fear was, am I going to get caught?” he says. “Breaching, usually that’s easy. Moving laterally, getting the information and not being caught, that is very hard.” That distinction became one of the ideas behind Mars Security, which the three founders launched in 2025.

The cybersecurity industry has spent years making it harder for attackers to get through the front door. Galili’s argument is that no preventive layer is guaranteed to hold forever. Once an attacker is inside, the challenge shifts from keeping them out to recognizing what they are doing before they reach what they came for.

A modern intrusion may begin with a stolen identity, move through an employee’s laptop, jump into a cloud account and reach a SaaS platform or another high-value system. The attacker sees one continuous path; defenders may see the same activity scattered across several different security products. “Attackers don’t care that you have an EDR or a firewall or an identity solution,” Galili says. “They’re going to move laterally to where they can until they get to what they’re looking for.”

That fragmentation becomes even more important as attackers rely less on traditional malware or software vulnerabilities. Stolen credentials, legitimate administrative tools, API tokens and cloud identities can let an intruder move through an environment without dropping the kind of obviously malicious software defenders once expected to find. The signals are still there, but they may be spread across different systems. The danger is not that the signals are missing. It is that by the time someone connects them, the attacker may already be several steps ahead.

Mars is designed to close that gap. Its platform works across the security systems an organization already uses, analyzes current threat intelligence, turns attacker behavior into hunts and detection logic, and checks whether those same patterns are appearing in the customer’s own environment.

Today, much of that work still falls to security teams. When researchers publish details of a new campaign, analysts may need to determine whether it is relevant, translate the attacker’s behavior into queries, adapt those queries to their own tools, test them and turn the results into working detections. Mars uses AI agents alongside human threat hunters and detection engineers to compress that process. Company materials cite a tenfold increase in weekly hunts and new detections.

AI is adding speed and scale to cyberattacks, but Galili is skeptical of predictions about autonomous AI “super-hackers.” Attackers can already use AI to rewrite code, tailor phishing messages, set up infrastructure, analyze targets and automate work that once required larger teams or deeper expertise. A smaller group can now operate with capabilities that previously demanded far more people. But faster attacks, Galili argues, do not necessarily become harder to detect.

“The modus operandi is the same,” he says. Infrastructure can change faster, malware can be rewritten and command-and-control servers can rotate more quickly, but the underlying behavior often remains familiar. Galili is therefore less interested in imagining a perfect AI-powered attacker than in recognizing the imperfect attacks already happening. After more than two decades in cyber, his view is that attackers innovate, but they also reuse patterns. Techniques evolve. Tools change. The tradecraft often rhymes.

After leaving the military, Galili did not rush to start a company. He spent several years in civilian cybersecurity roles, including at Claroty and later as vice president of product at Attribute, and has described the transition as having to rebuild himself as a civilian after more than two decades in uniform. When he eventually founded Mars with Lerer and Caspi, they brought that experience into the company they were building.

For Galili, the attacker’s greatest advantage is initiative. Attackers choose when to move, where to probe and how quickly to change direction. Defenders rarely get that luxury. The challenge is to shrink the time between what the security world already knows about an attack and what an individual organization is actually looking for inside its own systems.


Photo: Mars Security

Galia

Recent Posts

Texas Instruments Introduces Multiaxial Coreless Current Sensor for EV Traction Inverters

Texas Instruments has introduced the TMCS2100-Q1, a new multiaxial coreless Hall-effect current sensor designed for…

1 hour ago

SK hynix Charts Co-Packaged Optics Roadmap for Next-Generation AI Infrastructure

SK hynix has highlighted a new technology roadmap for co-packaged optics (CPO) published in Nature…

1 hour ago

AMD Brings UCIe Connectivity to Versal Adaptive SoCs for Chiplet-Based Systems

AMD has announced plans to add native UCIe 1.1 connectivity to select Versal adaptive SoCs,…

1 hour ago

NVIDIA Groq 3 LPX Enters Full Production for Ultra-Fast Agentic AI Inference

NVIDIA has announced that its Groq 3 LPX interactive AI inference accelerator is now in…

2 hours ago

Infineon to Acquire C2i Semiconductors to Advance AI Data Center Power Delivery

Infineon Technologies has announced the acquisition of C2i Semiconductors, a Bangalore-based specialist in software-defined multiphase…

2 hours ago

Infineon supplies silicon carbide technology to Fox ESS, enhancing efficiency of residential energy storage systems

Infineon Technologies AG (FSE: IFX / OTCQX: IFNNY) supplies silicon carbide (SiC) power semiconductors to…

24 hours ago