Reflectiz

Reflectiz Reflectiz is the AI-powered web exposure company, monitoring everything that runs on live websites.

Explore agentic pentesting, client-side risks, AI agent vulnerabilities, Magecart, supply chain attacks, and PCI DSS gaps most security tools never catch.

Most people talking about agentic pentesting have never🙈 actually run a pentest. Idan has spent his entire career doing ...
07/09/2026

Most people talking about agentic pentesting have never🙈 actually run a pentest. Idan has spent his entire career doing exactly that.

👉 https://hubs.ly/Q04wQlh60

He moved through military cyber intelligence🪖 professional pe*******on testing, and R&D leadership at one of Israel's most prominent offensive security groups before co-founding Reflectiz.

That background is the reason the way Reflectiz built its agentic pentest agent is fundamentally different from everything else in this category.

On September 15 ➡️ Idan is going live with Ysrael Gurt to share what they actually learned from building it, and the real critical finding their agent discovered at a major insurance company with millions of users that no traditional tool had caught.

Two founders. One real case study🔴 Everything the industry needs to hear about where agentic pentesting is actually going.

The CISO did not believe we found a critical😮 So he went to lunch.👉 https://hubs.ly/Q04wPLBJ0We came to that meeting ful...
06/09/2026

The CISO did not believe we found a critical😮 So he went to lunch.

👉 https://hubs.ly/Q04wPLBJ0

We came to that meeting fully prepared and by the time he came back, he understood that millions of his users were completely exposed through a vulnerability⚠️ sitting undetected in production.

That moment changed how he thinks about pentesting forever.

On September 15 our founders are revealing the full story live🔴 for the first time.

What the critical finding actually was. How it was discovered. Why every traditional tool missed it. And why the only reason we caught it is because we test continuously, not periodically.

If you run security at any organization this session you need to hear.

Excuse me, if you could just look right here.🚨👉 https://hubs.ly/Q04wwlK-0Everything you thought you knew about pe*******...
05/09/2026

Excuse me, if you could just look right here.🚨

👉 https://hubs.ly/Q04wwlK-0

Everything you thought you knew about pe*******on testing is about to change.

On September 15 two founders who spent their careers on the offensive side are sharing everything they learned.

What agentic pentesting actually means, why continuous beats periodic every time, and what a real critical finding at a major insurance company🏦 taught them about the gap between what security teams think is covered and what actually is.

Don't forget to sign up✍️

Well if Steve said it...Guess it's right🍏
04/09/2026

Well if Steve said it...Guess it's right🍏

Live Webinar 🔴 Our founders talking about a REAL CASE STUDY and everything you need to know on agentic pentesting.Sign u...
03/09/2026

Live Webinar 🔴 Our founders talking about a REAL CASE STUDY and everything you need to know on agentic pentesting.

Sign up here👉 https://hubs.ly/Q04wwrxv0

Idan Cohen & Ysrael Gurt are gonna cover:
🔹What agentic pentesting actually is and what it is not
🔸Why continuous testing catches what periodic engagements miss
🔹The real OTP finding, how the agent found it, and what it means for your security program.

This session is for CISOs and security leaders who want to understand where this category is going before they make any decisions about it.

FTC Sues👩‍⚖️ Hims & Hers over website tracking pixels leaking PII to advertisers.Read the full breakdown 👉 https://hubs....
02/09/2026

FTC Sues👩‍⚖️ Hims & Hers over website tracking pixels leaking PII to advertisers.

Read the full breakdown 👉 https://hubs.ly/Q04wc2hb0

On July 29, 2026, the FTC, the Utah Attorney General, and Los Angeles County Counsel filed a joint complaint against Hims & Hers. The allegation: tracking pixels🕷️ on sensitive pages were sending visitor health data to Meta, Snap, Microsoft, Pinterest, Reddit, and X, while the company promised customers complete privacy.

Three things make this case bigger than the others.

1. States joined the FTC - Every state privacy law is now another regulator who can bring the same fact pattern to court.

2. HIPAA🏥 was not even needed - The theory is simple: you said "private," your website did something else. Any company that makes privacy promises can be reached this way.

3. The website itself was the evidence - No breach. No hacker. Just the ordinary, day-to-day behavior of marketing pixels on sensitive pages. Regulators can observe your tracker behavior from the outside at any time. Many do.

The uncomfortable question every security and privacy team should be asking right now: do you actually know what your pixels are sending?😓

Cyber community, this one is for you🙌. Or Sahar is speaking at Hackeriot 2026. Hackeriot is a professional community wit...
01/09/2026

Cyber community, this one is for you🙌. Or Sahar is speaking at Hackeriot 2026.

Hackeriot is a professional community with an important agenda: bringing together young women👧 💻 who want to explore the world of cybersecurity from the inside. No matter who you are, all are welcome to learn together.

Or is bringing real, impactful 💥 research that turned heads at BSides Las Vegas, earned a CVE, and changed how everyone thought about Apache Airflow security. Now it is coming to Hackeriot 2026. Stage after stage, Or keeps showing up for the communities that are building the next generation of security professionals.

This is the kind of community involvement we believe in at Reflectiz. The web is safer when more people understand how it gets attacked, and that knowledge📚 should be shared with everyone who needs to hear it.

The more voices in the room, the stronger the industry gets.

Follow our page for more community highlights coming soon.👋

Top 3 ways GRC professionals use Reflectiz 👇1. Turning third-party web risk🕷️ into auditable evidence66% of CISOs say th...
31/08/2026

Top 3 ways GRC professionals use Reflectiz 👇

1. Turning third-party web risk🕷️ into auditable evidence

66% of CISOs say their GRC platforms are not effective at managing third-party cyber risk. The gap is almost always the client-side layer. Reflectiz monitors every third-party script on your live pages and produces timestamped, QSA-ready evidence automatically. No manual exports before audits.

2. Replacing alert counts🚨 with posture reporting

Reflectiz Policies let GRC teams define standards once and enforce them automatically across your entire web environment. Instead of "we handled 200 alerts this week," you tell leadership "we are meeting our Restricted tier requirements, here are the open gaps." That is the shift boards actually understand.

3. Closing the PCI DSS 6.4.3 and 11.6.1 gap💳 before the QSA arrives

Most GRC teams discover client-side compliance gaps during audits, not before. Reflectiz monitors payment page scripts continuously, flags behavioral changes the moment they happen, and generates the exact evidence format your QSA needs. Every published customer audit ended with zero observations.
GRC does not need more alerts. It needs proof, posture, and continuous visibility into what is actually running on your website.

👉https://hubs.ly/Q04vQC9q0

30/08/2026

Our team is focused on strong contribution and development 💻

Are you red🔴 or blue🔵? Don't tell us your grey...😱That's a real stat by the way from this report: https://hubs.ly/Q04vvg...
28/08/2026

Are you red🔴 or blue🔵? Don't tell us your grey...😱

That's a real stat by the way from this report: https://hubs.ly/Q04vvgHH0

Address

Shoham Street 5
Ramat Gan

Alerts

Be the first to know and let us send you an email when Reflectiz posts news and promotions. Your email address will not be used for any other purpose, and you can unsubscribe at any time.

Contact The Business

Send a message to Reflectiz:

Shortcuts

Share