Gadi Evron
Sources: Mythos-ready paper (lead author); OpenAnt announcement (Knostic CEO); Knostic org page (referenced via Knostic’s product family).
Who
CEO of Knostic; CISO-in-Residence for AI at the Cloud Security Alliance. Lead author of the April 2026 multi-org strategic briefing The “AI Vulnerability Storm”: Building a “Mythos-ready” Security Program — published jointly with SANS, [un]prompted, and OWASP Gen AI Security Project. In September 2025, with Heather Adkins (CISO, Google), issued an industry warning that autonomous vulnerability discovery and exploitation were ~6 months away — joined by Bruce Schneier in October 2025 to introduce the VulnOps (Vulnerability Operations) concept.
Relevance to This Wiki
Three load-bearing positions on the wiki:
- VulnOps co-introducer (October 2025, with Heather Adkins and Bruce Schneier) — the long-horizon function staffed-and-automated-like-DevOps for autonomous vulnerability research and remediation.
- Lead author of the Mythos-ready strategic briefing (April 2026) — community-consensus strategic briefing assembled with Rich Mogull (CSA) and Robert T. Lee (SANS) plus 17 contributing authors and 75+ named reviewers.
- CEO of Knostic, which ships Kirin (coding-agent runtime security) and OpenAnt (open-source LLM vulnerability discovery; March 2026). Knostic’s product family is the operational instrument set behind the Mythos-ready briefing’s recommendations.
Adjacent / Open
- Biographical detail, prior affiliations beyond Knostic / CSA, and publication history pending primary-source confirmation. Treat as seed page.