Oligo Cyber Security
Oligo Cyber Security (Oligo Security) is an Israeli cybersecurity organization headquartered in Tel Aviv.[1] Its platform uses eBPF-based sensors to detect and prevent exploits on production applications and identify vulnerabilities and threats in real time.[2]
History
[edit]Oligo Security was founded in 2022 by Nadav Czerninski, Gal Elbaz and Avshalom Hilu, who had previously served as officers in Israeli military intelligence units.[3][4]
Oligo appeared from stealth mode in February 2023 after raising $28 million in seed and Series A funding.[1] In January 2025, Oligo Security raised $50 million in a Series B funding round.[5]
In November 2025, Oligo launched Runtime AI Security to identify AI software in use, and protect against rogue agents and agent drift.[6]
In February 2026, Oligo was named one of the launch partners for AWS Security Hub Extended, a service introduced by Amazon Web Services.[7]
In April 2026, it introduced a runtime exploit blocking mechanism for preventing application-layer exploitation attempts.[4]
In August 2026, Oligo raised $60 million, bringing its total funding to $140 million.[8]
Security Research
[edit]Oligo Security has conducted security research into vulnerabilities affecting widely used software and AI infrastructure. In October 2023, Oligo researchers disclosed a set of critical vulnerabilities in TorchServe, a model-serving framework for PyTorch, which they named "ShellTorch". The vulnerabilities could be chained to achieve unauthenticated remote code execution and affected thousands of publicly exposed instances.[9][10] One of the vulnerabilities, CVE-2023-43654, received a CVSS score of 9.8. Amazon and Meta, which maintain TorchServe, released security advisories and patches following the disclosure.[11][9]
In March 2024, Oligo researchers reported an attack campaign targeting publicly exposed Ray clusters, which they named "ShadowRay". The campaign exploited CVE-2023-48022, a disputed vulnerability in Ray, an open-source framework for distributed computing and AI workloads.[12] Attackers used compromised systems for cryptocurrency mining and accessed sensitive data and credentials. MITRE ATT&CK tracks the activity as the ShadowRay campaign (C0045), with activity beginning in September 2023.[13]
In April 2025, Oligo researchers disclosed "AirBorne", a set of vulnerabilities affecting Apple's AirPlay protocol and AirPlay Software Development Kit (SDK). The vulnerabilities affected Apple devices and third-party devices using the AirPlay SDK, and included flaws that could allow remote code execution. The vulnerabilities were assigned 17 CVE identifiers.[14]
In November 2025, Oligo researchers reported an ongoing attack campaign targeting publicly exposed Ray infrastructure, which they named "ShadowRay 2.0". The campaign used compromised Ray clusters for cryptocurrency mining, data theft and distributed denial-of-service (DDoS) attacks, and used the clusters to propagate the malware to other exposed systems. Oligo's researchers identified more than 230,000 Ray servers accessible from the internet.[15]
In November 2025, Oligo researchers disclosed five vulnerabilities in Fluent Bit, an open-source logging and telemetry tool used in cloud and Kubernetes environments. The vulnerabilities could allow authentication bypass, log manipulation, denial-of-service attacks, and, in some configurations, remote code execution. Oligo disclosed the vulnerabilities in coordination with the Fluent Bit maintainers and AWS.[16]
See also
[edit]References
[edit]- 1 2 Lardinois, Frederic (2023-02-15). "Oligo raises $28M to secure open source libraries at runtime". TechCrunch. Retrieved 2026-09-29.
- ↑ "Critical 'ShellTorch' Flaws Light Up Open Source AI Users, Like Google". Dark Reading. Retrieved 2026-09-29.
- ↑ "Oligo Security raises $20 million Series A to secure open-source libraries". ctech. 2023-02-15. Retrieved 2026-09-29.
- 1 2 Riley, Duncan (2026-04-14). "Oligo Security moves beyond CVE prioritization with real-time application-layer exploit blocking". SiliconANGLE. Retrieved 2026-09-29.
- ↑ Orbach, Meir (2025-01-29). "Oligo Security raises $50M Series B to stop cloud application attacks in real time". ctech. Retrieved 2026-09-29.
- ↑ "Oligo delivers runtime-native security for models and agents". Help Net Security. 20 November 2025. Retrieved 30 September 2026.
- ↑ "AWS Security Hub Extended offers full-stack enterprise security with curated partner solutions | AWS News Blog". aws.amazon.com. 2026-02-26. Retrieved 2026-09-29.
- ↑ "Oligo Raises $60M to Extend Runtime Security to AI Agents". BankInfoSecurity. Retrieved 30 September 2026.
- 1 2 Toulas, Bill. "ShellTorch flaws expose AI servers to code execution attacks". BleepingComputer. Retrieved 2026-09-29.
- ↑ "AWS warns of 'ShellTorch' issue affecting code related to AI models". therecord.media. Retrieved 2026-09-29.
- ↑ "Warning: PyTorch Models Vulnerable to Critical Remote Code Execution Attacks". The Hacker News. October 2023. Retrieved 30 September 2026.
- ↑ "ShadowRay, Campaign C0045 | MITRE ATT&CK®". attack.mitre.org. Retrieved 2026-09-29.
- ↑ Brewster, Thomas. "Hackers Breached Hundreds Of Companies' AI Servers, Researchers Say". Forbes. Archived from the original on 2026-02-28. Retrieved 2026-09-29.
- ↑ Newman, Lily Hay; Greenberg, Andy (2025-04-29). "Millions of Apple Airplay-Enabled Devices Can Be Hacked via Wi-Fi". Wired. ISSN 1059-1028. Retrieved 2026-09-29.
- ↑ "Hackers Make an AI-Powered, Self-Replicating Cyberattack". Forbes. 18 November 2025. Retrieved 30 September 2026.
- ↑ Lyons, Jessica (2025-11-24). "Years-old bugs in open source took out major clouds at risk". theregister. Retrieved 2026-09-29.