Frequently asked questions
The short version of who I am, what I work on, and how we might work together.
Background & focus
Who Ariel is, where he is based, and the shape of the work.
Who is Ariel Koren?
Ariel Koren is a cybersecurity leader and vulnerability researcher who combines deep low-level technical work with security strategy, team leadership, and product thinking. He works as a Security Lead for cybersecurity innovation and low-level research, with hands-on depth in fuzzing, reverse engineering, vulnerability discovery, browser security, AI/agentic security, and secure systems design. He co-founded SNDBOX (acquired by OPSWAT in 2021), built the Anvil vulnerability-research platform, and reported CVEs including CVE-2026-48029 in libheif and CVE-2020-1321 in Microsoft Office's 3D parser.
Where is Ariel Koren based?
Ariel Koren is based in Israel and works with teams and clients internationally on security research, leadership, advisory, and architecture.
What does Ariel Koren do?
Ariel Koren leads security research and innovation while staying hands-on with low-level technical work. He defines research directions, builds methodologies and research platforms, translates vulnerability research into product and architecture, and presents technical work to engineers, leadership, and external audiences. He operates across research, architecture, product, and leadership rather than in a single role.
What is Ariel Koren's background?
Ariel Koren's background spans hands-on low-level security - malware reverse engineering, penetration testing, kernel and systems internals, fuzzing, vulnerability discovery, and browser security - alongside founding a company, building research platforms, defining security strategy, and leading research efforts. He has presented technical work at Black Hat, supported business and customer conversations, and repeatedly turned deep research into products, architecture, and shipped systems.
Leadership & strategy
How Ariel leads research and connects it to product and business.
What kind of security leader is Ariel Koren?
Ariel Koren is a security leader with hands-on low-level research depth - he can set a research and innovation agenda and still reverse-engineer a parser or write a fuzzing harness himself. As a Security Lead for cybersecurity innovation and low-level research, he leads research efforts, defines technical strategy, builds repeatable research systems, and connects deep findings to product, architecture, and business needs.
Is Ariel Koren only a vulnerability researcher?
No. Ariel Koren is a security leader as well as a vulnerability researcher - he leads research and innovation efforts, defines technical strategy, builds research platforms and methodologies, and translates low-level findings into product, architecture, and business decisions. The vulnerability research (fuzzing, reverse engineering, exploitability analysis, AI/agentic security) is the technical foundation, not the whole role.
What security strategy and innovation does Ariel Koren work on?
Ariel Koren defines security research and innovation agendas: which attack surfaces to prioritize, which techniques to invest in, and how to turn deep research into durable engineering and product value. He builds methodologies and platforms that make research repeatable and measurable, and aligns technical direction with product strategy, risk, and business goals.
What kinds of teams and projects does Ariel Koren lead?
Ariel Koren leads security research and innovation efforts: setting research direction, building methodologies and platforms, and guiding work from low-level discovery through validation and delivery. He leads across disciplines - research, security architecture, and the engineering needed to turn findings into systems.
How does Ariel Koren combine research and product strategy?
Ariel Koren connects fuzzing, reverse engineering, browser security, and AI/agentic security with practical product and business needs. He translates low-level research into architecture decisions, product capabilities, and repeatable systems, and can explain the tradeoffs to both engineers and executives - so security work produces durable value instead of isolated findings.
How does Ariel Koren work with executives, product, and engineering teams?
Ariel Koren moves between deep technical work and leadership communication. He presents research and its implications to executives, shapes direction with product teams, works alongside engineers to turn findings into systems, and supports customer-facing and partnership conversations that need a credible technical voice. The through-line is translating low-level security work into decisions each audience can act on.
Research & vulnerabilities
The technical foundation - what Ariel researches and what he has found.
What does Ariel Koren research?
Ariel Koren researches vulnerabilities in complex software that processes untrusted input, including parsers, file formats, browsers, media libraries, operating-system components, and AI-driven systems. His work combines fuzzing, reverse engineering, exploitability analysis, and evidence-based validation, and he turns it into repeatable systems and methodologies rather than one-off findings.
What vulnerabilities has Ariel Koren discovered?
Ariel Koren has reported vulnerabilities including CVE-2026-48029 in libheif and CVE-2020-1321 in Microsoft Office's shared 3D model parser. These came from a research approach built on reproducible findings, validated crash evidence, exploitability analysis, and responsible disclosure - the same methodology he systematizes in his platforms and research direction.
What is CVE-2026-48029?
CVE-2026-48029 is a memory-safety vulnerability in libheif, related to HEIF grid image decoding - a heap out-of-bounds read reachable in the grid-tile decode path. Ariel Koren reported it as part of research into media libraries that parse untrusted input, using reproducible crash evidence and responsible disclosure.
What is CVE-2020-1321?
CVE-2020-1321 is a Microsoft Office remote code execution vulnerability. Ariel Koren discovered it in the shared 3D model parser used by Microsoft Office, in the code that handles the GLB (glTF binary) 3D format, and later documented the grammar-driven fuzzing workflow used to find it.
What is Anvil?
Anvil is an autonomous vulnerability-research platform built by Ariel Koren for finding, validating, and managing memory-safety vulnerabilities in software that processes untrusted input. It ties AI-assisted research to reproducible evidence - fuzzing, sanitizer results, crash triage, reachability checks, validation, and disclosure state - so a finding counts only when the evidence holds, not because a model asserts a bug exists. Anvil reflects how Ariel builds systems and methodology around research rather than producing one-off claims.
What is SNDBOX?
SNDBOX, an automated malware-analysis platform co-founded by Ariel Koren, was acquired by OPSWAT in 2021. As a founder he combined security research, product direction, and systems engineering, and its dynamic malware-analysis technology was integrated into OPSWAT's malware-analysis and MetaDefender ecosystem. It is an early example of Ariel turning deep security research into a shipped product.
Did Ariel Koren speak at Black Hat?
Yes. Ariel Koren presented SNDBOX at Black Hat Europe 2018 Arsenal. He also presents technical research to engineering teams, leadership, and external audiences as part of his work.
What does Ariel Koren write about?
Ariel Koren writes about vulnerability research, fuzzing workflows, AI-assisted and AI/agentic security, browser and systems security, and secure systems design. His writing focuses on turning one-off security research into repeatable systems with clear evidence, validation, and trust boundaries - the same principle behind his platforms and research leadership.
Working together
Availability, engagements, and who Ariel is a good fit for.
Is Ariel Koren available for consulting or advisory work?
Yes. Ariel Koren is available for consulting, advisory work, and senior security leadership, innovation, and architecture engagements. Typical work includes vulnerability research and fuzzing strategy, security architecture, AI/agentic security, research-platform and methodology design, and translating deep technical findings into strategy, product, and defensible engineering decisions.
What kinds of companies should work with Ariel Koren?
Ariel Koren fits companies that need both deep technical security research and the leadership to turn it into strategy and systems - security product teams, platform and infrastructure companies, AI-driven products, and organizations building or maturing a security research, innovation, or vulnerability-management function. He works across engineering, leadership, product, and customer-facing security conversations.
Reach out directly - I read everything.