Michael Bargury

Co-Founder & CTO at OWASP® Foundation

Israel
email-iconphone-icongithub-logolinkedin-logotwitter-logostackoverflow-logofacebook-logo
Join Prog.AI to see contacts
email-iconphone-icongithub-logolinkedin-logotwitter-logostackoverflow-logofacebook-logo
Join Prog.AI to see contacts

Summary

🤩
Rockstar
🎓
Top School
Michael Bargury is a cybersecurity-focused founder and CTO with 10+ years of experience building secure AI and cloud systems, currently leading Zenity to protect agentic AI at enterprise scale. A former Microsoft Azure security architect and data scientist, he combines product, research and hands-on engineering—contributing backend tooling like power-pwn that demonstrates real-world exploits against Microsoft Copilot and other AI assistants. He uncovered and standardized novel attack vectors for LLMs and agentic AI, co-leads multiple OWASP initiatives (including LCNC and AIVSS), and publishes technical columns and talks at BlackHat and DEFCON. Based in Israel, Michael blends offensive research with pragmatic defenses, and his work uniquely spans tool development, security standards, and public disclosure to drive measurable improvements in AI security.
code11 years of coding experience
job11 years of employment as a software developer
bookBachelor of Science (BSc) Mathematics and Computer Science, Bachelor of Science (BSc) Mathematics and Computer Science at Tel Aviv University
github-logo-circle

Github Skills (20)

api-rest10
python10
api-design10
restful-api10
red10
go10
bypass10
web-security10
rest-api10
pydantic10
http-method10
microsoft9
bug-tracker9
hacking9
bug-reporting9

Programming languages (15)

PowerShellC#C++CSSCTeXGoHTML

Github contributions (5)

github-logo-circle
mbrg/power-pwn

Jun 2022 - Sep 2022

An offensive/defense security toolset for discovery, recon and ethical assessment of AI Agents
Role in this project:
userBack-end Developer
Contributions:10 releases, 4 reviews, 62 commits in 2 months
Contributions summary:Michael primarily contributed to the backend functionality of a security toolset focused on Microsoft 365 and related platforms. Their commits show the development of a command-line interface (CLI) using Python, implementing features to execute commands using different languages like Python, PowerShell, and Javascript. The contributions include the design of data models (using Pydantic) to handle input and output, as well as adding new features such as cookie and Power Automate token retrieval.
ai-agentsecuritypentestingredteamlowcode
devploit/nomore403

Sep 2022 - Sep 2022

🚫 Advanced tool for security researchers to bypass 403/40X restrictions through smart techniques and adaptive request manipulation. Fast. Precise. Effective.
Role in this project:
userBack-end Developer
Contributions:7 commits, 1 PR in 1 day
Contributions summary:Michael's primary contribution involves modifying and enhancing the functionality of a tool designed to bypass 403/40X response codes. Their commits focused on adding and refining the implementation of HTTP methods, as well as adjusting the configuration of request handling within the tool. The user added features for custom headers and HTTP method selection. They made iterative changes, demonstrating an understanding of request construction and response handling to circumvent web server access restrictions.
securitywaf-bypasspentestingwebsecbugbounty
Find and Hire Top DevelopersWe’ve analyzed the programming source code of over 60 million software developers on GitHub and scored them by 50,000 skills. Sign-up on Prog,AI to search for software developers.
Request Free Trial