This website uses cookies

Read our Privacy policy and Terms of use for more information.

This week's issue is backed by Maze and Quantro Security.

Hope you had a great weekend!

You know we live in interesting times when the frontier AI labs keep having strange events like "unprecedented cyber incident(s)” of escaping containment and attacking other companies, a meltdown about open-weight models tanking their dominance, increased lobbying efforts from AI labs, and just generally threatening to be the doom of all work and economies due to cyber attacks. What a time to be alive! 🍿 👀

Oh yeah, and something new happened on the financial side of the cyber house last week. We had not one, not two, but THREE new cyber unicorns minted 🦄 🦄 🦄, and one of which just came out of stealth!

If you know, you know

I even had to update the Unicorn & Decacorn Timeline chart on The Signal so you can zoom in now. 😳

All these events should make for some really interesting Black Hat US booths, talks, and hallway conversations, and I’ll be there for it all. My schedule looks like the game of Tetris when you lose, but please reach out and say hello if you’re going or see me out at the conference.

Let us all get this bread, family. 🥐

PARTNER

Code security you trust

Legacy SCA and SAST scanners match patterns and bury engineers in noise. That's why we built Maze Code: AI agents that understand your code and dependencies.

AI agents investigate every finding with context from your code and cloud, close false positives, and catch business logic flaws other tools miss. Then they help you fix what's left, right in your IDE or coding agent.

Finally, inbox zero for your code and cloud vulnerabilities is possible.

😎 Vibe Check

Click the options below to vote on whether you are a practitioner, founder, or investor. Leave a comment, and I'll anonymously feature the best takes in the next issue!

Which security category will be a feature, not a company, in two years?

Login or Subscribe to participate

Last issue’s vibe check:
What layer of the security stack is most valuable to acquire right now?
🟨⬜️⬜️⬜️⬜️⬜️ Data/observability platforms
🟨⬜️⬜️⬜️⬜️⬜️ SecOps/detection platforms
🟨🟨🟨⬜️⬜️⬜️ Vulnerability prioritization platforms
🟩🟩🟩🟩🟩🟩 Agent identity platforms

Agent identity platforms handily won the vibe check last week, which likely comes as no surprise to the folks reading this. Outside of the standard [open-weight AI models / zero-day exploit speed / frontier AI escaping sandboxes], agent identity is what the industry has been placing the most emphasis on over the last 6 months.

When you step back and think about why the industry is doing this, it makes a lot of sense. When you look at the last 5-7 years’ worth of breach reports, they’re almost always identity-related. The industry seems to always forget that, however, and we’ve been temporarily blinded by the Vulnpocalypse. However, since we know AI agents help create “bad decisions at machine speed,” it only makes sense to extend that identity challenge we have had in the past to this new persona. At least that’s what “feels” right.

But is that the right rabbit to chase? The jury is still out on that one for me, but I’m skeptical that it’s the most important part of the problem to focus on right now. Discovery? Yes. Observability? Absolutely. Hard guardrails for agents? Without a doubt. CI/CD hardening and open source rigor? 100%. I think identity will have its time, but I’m not convinced that time is right now as a standalone “thing.”

These are opinions, of course. I am very happy to have challenged, and would love to be educated and proven wrong, so reply back and just heck me up, or let’s talk through it at Black Hat.

Some of the top comments from last week’s vibe check:

💬 “Ugh so wrong. Those that think agentic identity platforms are the most important right now are way off. We still can't do the basics of reducing risk; we should be focused on something emerging that has yet to show up with real enterprise threats. Focus on fixing what works - eliminating vulnerabilities in an automated way (the only way we can catch up).”

💬 “I don't think agents can ever truly have an "identity," so I think companies operating in this space will die out and/or be acquired sooner rather than later, simply as a way to capture more customers to sell the next-next thing to.”

💬 "With the way the Greek twins blew open vulnerabilities, detection platforms become critical.”

💰 Market Summary

Private Markets

  • 13 companies from 3 countries raised $474.1M across 11 unique categories

  • Average disclosed deal size was $43.1M (median: $25.0M)

  • 92% of funded companies were product companies

  • 3 companies from 2 countries were acquired across 3 unique categories

  • 67% of acquired companies were product companies

Public Markets

  • No public cyber companies had an earnings report last week, and everyone had a no-good, down-bad, not-nice week due to rising inflation concerns, the expanding war between the US and Iran, and AI spending fears from the hyperscalers

📸 YoY Snapshot

Rolling 13-week charts that compare funding and acquisitions week over week, year over year, comparing 2025 to 2026

$8.1B across 151 deals over the past quarter, down 14% from the same time period a year ago, but closing the year’s gap with these huge rounds.

78 acquisitions over the past quarter, down 32% from the same time period a year ago. Down half that amount for the full year-to-date, however.

PARTNER

A working exploit now costs under $3 and takes ~11 minutes

We pointed an autonomous harness at real CVEs and published the receipts

Quantro Security's exploit harness builds and verifies working exploits for real CVEs, autonomously. Paste in the CVEs you're tracking and see which ones an AI could weaponize today, and what it'd cost.

No signup. Then read the research on the collapsing economics of vulnerability exploitation with AI.

🧩 Funding By Product Category

  • $190.0M for Continuous Automated Red Teaming (CART) across 2 deals

  • $100.0M for Endpoint Protection across 1 deal

  • $75.0M for Security Operations across 1 deal

  • $40.1M for Email Security across 2 deals

  • $25.0M for Threat & Vulnerability Management (TVM) across 1 deal

  • $25.0M for Security Analytics across 1 deal

  • $12.7M for Remote Browser Isolation across 1 deal

  • $3.6M for Managed Security Services Provider (MSSP) across 1 deal

  • $2.6M for Software Supply Chain Security across 1 deal

  • An undisclosed amount for Threat and Risk Prioritization across 1 deal

  • An undisclosed amount for Governance Risk and Compliance (GRC) across 1 deal

🏢 Funding By Company

» Interact with all the data in real-time on The Signal dashboard or via the MCP.

Product Companies:

Service Companies:

SEC filings may reflect partial or interim fundraising and can understate the final round numbers.

🌎 Funding By Country

  • $367.8M for the United States across 10 deals

  • $100.0M for Israel across 1 deal

  • $6.3M for the United Kingdom across 2 deals

🤝 Mergers & Acquisitions

Product Companies:

  • Embrace, a United States-based user and data observability platform, was acquired by Palo Alto Networks for an undisclosed amount. Embrace had previously raised $77.0M in funding. (more)

  • SafeHouse, an Israel-based mobile app focused on consumer cybersecurity and privacy, was acquired by TAC Security for an undisclosed amount. SafeHouse had previously raised $8.2M in funding. (more)

Service Companies:

  • SimpliMeta, a United States-based professional services firm focused on managed cyber risk management and penetration testing, was acquired by Xtel Communications for an undisclosed amount. SimpliMeta has not previously disclosed funding. (more)

🤘 IPO-h Yeah

  • None

🪦 Stop, Drop, Shut’em Down…

  • None 😮‍💨

Layoffs

  • None 😮‍💨

📚 Great Reads

  • What 239 Products Reveal About the Shape of AI Security - The security-for-AI market is young and lopsided. Incumbents quickly extended their products into the AI versions of assets they already secured, while the more distinct AI assets drew startups and incumbents alike into markets that stay active and contested.

  • Zero risk isn't the job: a CISO's guide to agentic AI - Anthropic's Deputy CISO, Jason Clinton, shares his team's lessons learned adopting agentic AI, and the risk assessment framework they've developed for building and deploying agents securely.

*Sponsored

🧪 Labs

If you’re into AI, you should NOT be sleeping on Scotland 😤 🏴󠁧󠁢󠁳󠁣󠁴󠁿

🫡 Signing Off

Have questions, comments, or feedback? Just reply back directly, I’d love to hear from you.

If you find this newsletter useful and know others who would, I'd really appreciate it if you'd forward it to them!

Mike P

P.S. Feel free to connect with me on LinkedIn.

Reply

Avatar

or to participate

Keep Reading