This week's issue is backed by SpecterOps.
Hope you had a great weekend!
As promised from last week, I also got in on the Black Hat happy hour malestrom, onslaught, activities, and am co-hosting an event with my friends at Decibel and my buddy Chris Hughes: https://luma.com/tjehhzxm
Hope to see you out there!
In Signal news, companies can now check whether they are listed in the companies directory, and if they are not, they can get added!
Also, there is still time to get a ticket for the Black Hat Innovators & Investors Summit, and you can use code USAINNOVATE500 for $500 off at checkout.
PARTNER
SpecterOps and OpenAI are showing up together at Black Hat. Meet us there
Identity Attack Path Management for AI and hybrid environments
SpecterOps runs adversarial testing across OpenAI's infrastructure. At Black Hat USA, find both at The Cove, where SpecterOps will show how BloodHound Enterprise maps the identity attack paths that multiply as AI agents spread across hybrid environments, and the handful of fixes that close them. Meeting slots are limited.
Table of Contents
😎 Vibe Check
Click the options below to vote on whether you are a practitioner, founder, or investor. Leave a comment, and I'll anonymously feature the best takes in the next issue!
What layer of the security stack is most valuable to acquire right now?
Last issue’s vibe check:
What does the future of AI & Cyber look like?
🟨🟨⬜️⬜️⬜️⬜️ Closed-source US models
🟨🟨⬜️⬜️⬜️⬜️ Open-source Chinese models
🟩🟩🟩🟩🟩🟩 Local open-source models
⬜️⬜️⬜️⬜️⬜️⬜️ Something else (tell me)
Well, that was a clear winner last week. This may have come as a surprise a few months ago, but the facts on the ground are rapidly changing for attackers and defenders alike.
With the release of KIMI K3 last week, we see, yet again, how a Chinese AI model can send shockwaves through the American tech industry. While this is exciting for AI model competition in general, the fact that open-source AI models are having their day can spell trouble for people on the cyber defense side. Especially if defenders are hamstrung by not being allowed access to the latest and greatest (in a safe way).
I think we are also in a time where businesses can no longer rely solely on an LLM over the Internet via chat, IDE, or API. What if the model is rug pulled? What if the capabilities are nerfed, cyber or otherwise? What if you blast through your weekly allowance investigating a cyber issue and you have to just wait around? This kind of stuff won’t fly for development, and it shouldn’t fly for cyber teams either.
To me, making sure your cyber teams have access to AI in their workflows should be just as important as the need for developers to have the same.
Some of the top comments from last week’s vibe check:
💬 “Local and open-source models are the future, but not just for cyber. Businesses will want greater cost control and more freedom to use models that aren't overly regulated or export-controlled.”
💬 “At the end of the day, frontier models are the ultimate data product... It's going to be hard to keep control and monetize it if it isn't very dependent on being fresh to be useful. And at some point there will be diminishing returns on training new ones on new data, or even negative returns in the case of model collapse. And distillation attacks make it more cost-effective to copy them. So I believe the models will be commoditized, and the real returns will be either in a) selling the infrastructure (think AWS BedRock), or b) in building complete solutions that use the models as just part of something that brings actual business value to customers.”
💰 Market Summary
Private Markets
11 companies from 6 countries raised $189.0M across 11 unique categories
Average disclosed deal size was $18.9M (median: $10.5M)
91% of funded companies were product companies
6 companies from 4 countries were acquired across 5 unique categories
67% of acquired companies were service companies
Public Markets
2 public companies raised a combined $101.1M via Post-IPO Equity
No public cyber companies had an earnings report last week

📸 YoY Snapshot
Rolling 13-week charts that compare funding and acquisitions week over week, year over year, comparing 2025 to 2026

Funding bounced back a bit last week on both pubic and private markets. Deals and dollars are still trending down historically from last year, however.

M&A understood the assignment as well on the rebound, totaling 82 transactions over the past quarter.
🧩 Funding By Product Category

$100.0M for Personal Cybersecurity across 1 deal
$60.0M for Identity Governance & Administration (IGA) across 1 deal
$50.0M for Secure Communications across 1 deal
$33.3M for Software Supply Chain Security across 2 deals
$13.0M for Security Data Observability Platform (SDOP) across 1 deal
$13.0M for Breach & Attack Simulation (BAS) across 1 deal
$8.0M for Cybersecurity Program Management across 1 deal
$5.6M for Deepfake Detection across 1 deal
$3.9M for Crypto-Agility & Migration across 1 deal
$3.0M for Identity Verification across 1 deal
$307.8K for Threat Intelligence across 1 deal
An undisclosed amount for Professional Services across 1 deal
🏢 Funding By Company
» Interact with all the data in real-time on The Signal dashboard or via the MCP.
Product Companies:
Aura, a United States-based identity theft and financial fraud protection platform, raised a $100.0M Post-IPO Equity from Accel, General Catalyst, Hari Ravichandran, and WndrCo. (more)
Valarian Technologies, a United Kingdom-based secure communications infrastructure platform, raised a $50.0M Series A from New Enterprise Associates. (more)
Risk Ledger, a United Kingdom-based third-party software supply chain security platform, raised a $32.2M Series B from Axiom Equity. (more)
Beacon Security, an Israel-based security data pipeline and orchestration platform, raised a $13.0M Seed from Notable Capital. (more)
Casco, a United States-based AI-driven red-teaming for web apps, APIs, and AI systems, raised a $13.0M Series A from Standard Capital. (more)
Pulse Security AI, a United States-based AI-driven cybersecurity operational program management platform for security leaders, raised an $8.0M Seed from Foundation Capital. (more)
Sensity AI, a Netherlands-based deepfake and manipulated media detection platform, raised a $5.6M Grant from the European Innovation Council. (more)
pQCee, a Singapore-based post-quantum cryptography governance platform, raised a $3.9M Seed from Lotus One Investment and SGInnovate. (more)
Argos Identity, a United States-based AI-powered identity verification platform for KYC/AML, raised a $3.0M Seed from BonAngels Venture Partners and Stone Bridge Ventures. (more)
Cybeats Technologies, a Canada-based software bill of materials (SBOM) security platform, raised a $1.1M Post-IPO Equity round. (more)
ZeamiCyberSecurity, a Japan-based security intelligence platform provider, raised a $307.8K Seed from aSTART. (more)
Service Companies:
OBDURIX, a United Kingdom-based professional services firm focused on AI automation and penetration testing services, raised an undisclosed Seed.
SEC filings may reflect partial or interim fundraising and can understate the final round numbers.
🌎 Funding By Country

$124.0M for the United States across 4 deals
$82.2M for the United Kingdom across 3 deals
$73.0M for Israel across 2 deals
$5.6M for the Netherlands across 1 deal
$3.9M for Singapore across 1 deal
$1.1M for Canada across 1 deal
$307.8K for Japan across 1 deal
🤝 Mergers & Acquisitions
Product Companies:
CardinalOps, an Israel-based AI-powered security engineering platform, was acquired by Cribl for an undisclosed amount. CardinalOps had previously raised $24.0M in funding. (more)
Veridas, a Spain-based digital identity verification platform, merged with Fourthline for an undisclosed amount. Veridas had previously raised $16.5M in funding. (more)
Service Companies:
Lookingpoint, a United States-based managed IT and security services provider, was acquired by Presidio for an undisclosed amount. Lookingpoint has not previously disclosed funding. (more)
One Connect, Inc., a United States-based managed IT and security services provider, was acquired by Amplix for an undisclosed amount. One Connect, Inc. has not previously disclosed funding. (more)
🤘 IPO-h Yeah
None
🪦 Stop, Drop, Shut’em Down…
None 😮💨
❌ Layoffs
None 😮💨
📚 Great Reads
Now, defenders are embracing the prompt injection, too - “Context bombing” tricks hacking agents into shutting down before they can do harm.
How to be a security person who doesn't suck at product - It's important to sell a good experience, and I'm personally a huge fan of making the customer experience side of security much more important and visible.
*Sponsored
🧪 Labs
When two of my interests collide and create a masterpiece 🤌 ⚽ 🇪🇸
🫡 Signing Off
Have questions, comments, or feedback? Just reply back directly, I’d love to hear from you.
If you find this newsletter useful and know others who would, I'd really appreciate it if you'd forward it to them!
Mike P
P.S. Feel free to connect with me on LinkedIn.


