Yuval Avrahami is a vulnerability researcher with seven years of hands-on experience in offensive and defensive security, currently focused on cloud and container risk at Wiz. He has a proven track record from the Israeli Air Force to industry-leading teams at Twistlock and Palo Alto Networks, and spent time as an independent bug bounty hunter honing real-world exploit discovery. Yuval contributes to open-source security tooling—most notably adding Kubernetes RBAC checks to the widely used Checkov project—to reduce misconfigurations and privilege escalation risks in infrastructure-as-code. Comfortable working from low-level research to production-ready detection, he blends exploit creativity with pragmatic, test-driven mitigations.
Prevent cloud misconfigurations and find vulnerabilities during build-time in infrastructure as code, container images and open source packages with Checkov by Bridgecrew.
Role in this project:
Security Engineer
Contributions:1 review, 10 commits, 3 PRs in 26 days
Contributions summary:Yuval primarily contributed to enhancing the security posture of the project by introducing and refining Kubernetes RBAC checks. They implemented multiple checks that specifically address vulnerabilities related to overly permissive roles and cluster roles, specifically focusing on controlling webhooks, approving certificate signing requests, and binding or escalating roles. These changes involved defining RBAC operations and creating corresponding test cases to ensure proper functionality. The user also made minor updates to the project's versioning.
Find and Hire Top DevelopersWe’ve analyzed the programming source code of over 60 million software developers on GitHub and scored them by 50,000 skills. Sign-up on Prog,AI to search for software developers.