Gadi Evron

Sources: Mythos-ready paper (lead author); OpenAnt announcement (Knostic CEO); Knostic org page (referenced via Knostic’s product family).

Who

CEO of Knostic; CISO-in-Residence for AI at the Cloud Security Alliance. Lead author of the April 2026 multi-org strategic briefing The “AI Vulnerability Storm”: Building a “Mythos-ready” Security Program — published jointly with SANS, [un]prompted, and OWASP Gen AI Security Project. In September 2025, with Heather Adkins (CISO, Google), issued an industry warning that autonomous vulnerability discovery and exploitation were ~6 months away — joined by Bruce Schneier in October 2025 to introduce the VulnOps (Vulnerability Operations) concept.

Relevance to This Wiki

Three load-bearing positions on the wiki:

  1. VulnOps co-introducer (October 2025, with Heather Adkins and Bruce Schneier) — the long-horizon function staffed-and-automated-like-DevOps for autonomous vulnerability research and remediation.
  2. Lead author of the Mythos-ready strategic briefing (April 2026) — community-consensus strategic briefing assembled with Rich Mogull (CSA) and Robert T. Lee (SANS) plus 17 contributing authors and 75+ named reviewers.
  3. CEO of Knostic, which ships Kirin (coding-agent runtime security) and OpenAnt (open-source LLM vulnerability discovery; March 2026). Knostic’s product family is the operational instrument set behind the Mythos-ready briefing’s recommendations.

Adjacent / Open

  • Biographical detail, prior affiliations beyond Knostic / CSA, and publication history pending primary-source confirmation. Treat as seed page.