This week's issue is backed by Origin and SpectorOps.
Hope you had a great weekend!
This week’s issue is coming at you live and direct from Portugal, where, despite it being the first day of fall, it is most certainly not cooling off! 🥵
Also, finally all is right in the Frontier AI lab world when it comes to security, now that all major labs have had agent swarms breach their sandboxes and hack other companies.
I was really starting to get worried there!
In other news, I’ll be at the AppSec Days Portugal conference this week, so please feel free to stop me and say hello if you’re there!
PARTNER
The analyst report that put AI agents on the endpoint security map
A live walk-through with the analyst who wrote it
SACR's Endpoint Control and Prevention report maps five zones for securing the layer where AI agents now work, and Origin sits in the zone that answers what your agents actually did. On October 1 at 11 AM ET, the analyst who wrote the report, Lawrence Pingree, and Origin founder Spencer Thompson walk through it live, then go deep on Origin's zone, the trace, and what you can do with it.
Table of Contents
😎 Vibe Check
Click the options below to vote on whether you are a practitioner, founder, or investor. Leave a comment, and I'll anonymously feature the best takes in the next issue!
Why do security categories converge on the same roadmap within 18 months of inception?
Last issue’s vibe check:
Where is capital in the security industry most obviously overbuilding for the same set of problems?
🟩🟩🟩🟩🟩🟩 AI red teaming
🟨🟨🟨⬜️⬜️⬜️ Agentic runtime security
🟨🟨🟨🟨⬜️⬜️ Agent Identity
🟨🟨🟨🟨🟨⬜️ AI agent governance
🟨⬜️⬜️⬜️⬜️⬜️ Agentic remediation
🟨🟨⬜️⬜️⬜️⬜️ Other (leave a comment)
Strong vote spread last week, and this was closer in a few places than I expected! With more votes than I normally get, I think it’s safe to say the industry has grown a bit tired of hearing about AI.
There’s a growing consensus that AI red teaming is going the way of human pentesting, where “value” and “outcomes” are perceived very differently depending on who is doing the purchasing. Some view it as a compliance checkbox you have to check once a year, while others see it as an invaluable part of a security program that should run continuously.
AI Agent Governance has a wholly different problem. The challenges here are in the perceptual world, rather than the technical one. It comes down to philosophy, your influences, and what you “believe” as a security person or organization. That’s before we even get to the “What can I afford?” part of the story.
I think we’re still early in the game here with understanding how to secure the different parts of AI, and how to use AI for security purposes beyond bug discovery.
Alas, the [AI] horrors persist, and so too must we. 🫡
Some of the top comments from last week’s vibe check:
💬 “AI Agent Governance" - Don't know if I've ever seen our crazy industry hype such a capability so much while actually building so little. The gold rush is real, and we're suffering for it by having to filter through an ever-increasing pile of BS to seek real value.”
💬 “Way too many AI red teaming companies being funded, pivoting, and popping up. Pentesting is the cyber world’s equivalent of needing “taste” to determine what is good vs. what is just a vulnerability scan.“
💰 Market Summary
Private Markets
14 deals from 13 companies across 6 countries raised $462.2M across 12 unique categories
Average disclosed deal size was $38.5M (median: $9.7M)
85% of funded companies were product companies
6 companies from 5 countries were acquired across 3 unique categories
83% of acquired companies were service companies
Public Markets
No pure-play public cyber company had an earnings report
Perhaps counterintuitively, all markets went back up last week because the US Fed chief raised interest rates, which let the bond market and the 10-year Treasury rate drop back down and the AI Trade rebuff deceleration claims.

📸 YoY Snapshot
Rolling 13-week charts that compare funding and acquisitions week over week, year over year, comparing 2025 to 2026

$8.5B across 148 deals over the past quarter, up 9% from a year ago.

92 acquisitions over the past quarter, up 3% from a year ago.
PARTNER
Your AI agents are already part of the attack graph
Attack path management for the hybrid AI enterprise
AI agents are non-human identities with permissions and trust relationships attackers can chain across cloud and SaaS. BloodHound Enterprise maps those paths across AWS, Entra Agent ID, AD, Okta, and more, then pinpoints the choke points where one fix can eliminate up to 17,000 paths. BloodHound Hunter puts that intelligence into trusted AI workflows.
🧩 Funding By Product Category

$270.0M for Internet of Things (IoT) Security across 2 deals
$72.0M for Data Loss Prevention (DLP) across 1 deal
$40.0M for AI Security across 1 deal
$34.0M for Security and Compliance Automation across 1 deal
$19.0M for Threat & Vulnerability Management (TVM) across 1 deal
$14.9M for Secure Access Service Edge (SASE) across 1 deal
$7.5M for AI Governance across 2 deals
$2.5M for Cyber Insurance across 1 deal
$1.4M for Professional Services across 1 deal
$644.5K for Brand Protection across 1 deal
$235.0K for Software Supply Chain Security across 1 deal
An undisclosed amount for Security Operations across 1 deal
🏢 Funding By Company
» Connect Claude, Cursor, or any MCP client to The Signal via the MCP for free.
Product Companies:
Exein, an Italy-based firmware and Internet of Things (IoT) security platform, raised a $270.0M Venture Round from Supernova Invest and also added undisclosed debt financing from JP Morgan. (more) Unicorn Alert 🦄
Mind Security, a United States-based AI-driven data loss prevention and insider risk management platform, raised a $72.0M Series B from Crosspoint Capital Partners. (more)
Artificial Intelligence Underwriting Company, a United States-based security and risk framework and certification body built specifically for AI agents, raised a $40.0M Series A from Ribbit Capital. (more)
Comp AI, a United States-based open-source security and compliance automation platform, raised a $34.0M Series A from Roo Capital and Grand Ventures. (more)
Yige Cloud Technology (formerly Eagle Cloud), a China-based secure access service edge platform, raised a $14.9M Series B from MTR Lab and Northern Light Venture Capital. (more)
Eve Security, a United States-based AI application and agent monitoring and governance platform, raised a $4.5M Seed from Run Ventures. (more)
TigerByte Cyber, a United States-based agentic AI governance platform for edge computing devices in critical national infrastructure and defense applications, raised a $3.0M Seed from Hale Capital Partners. (more)
QueryLift Inc., a Japan-based generative engine optimization (GEO) brand protection service, raised a $644.5K Seed from JAFCO and Z Venture Capital. (more)
Dark Sky Technology (formerly Code 13 Security), a United States-based open-source software supply chain security and risk management platform, raised a $235.0K Angel. (SEC Filing - may be incomplete)
StrikeReady, a United States-based contextual awareness and collaboration platform for security operations, raised an undisclosed Venture Round from Wa'ed Ventures. (more)
Service Companies:
Spectra (formerly SPECTRA Holdings US), a Bermuda-based cyber risk insurance provider for managed service providers (MSPs), raised a $2.5M Seed round. (SEC Filing - may be incomplete)
CounterMeasure Security, a United States-based professional services firm focused on security risk assessments and penetration testing, raised a $1.4M Seed.
SEC filings may reflect partial or interim fundraising and can understate the final round numbers.
🌎 Funding By Country

$270.0M for Italy across 2 deals
$155.2M for the United States across 8 deals
$19.0M for France across 1 deal
$14.9M for China across 1 deal
$2.5M for Bermuda across 1 deal
$644.5K for Japan across 1 deal
🤝 Mergers & Acquisitions

Product Companies:
OpenZeppelin, a United Kingdom-based smart contract security company providing open-source libraries, security audits, and developer tooling for onchain applications, was acquired by S&P Global for an undisclosed amount. OpenZeppelin has not previously disclosed funding. (more)
Service Companies:
Ontinue, a Switzerland-based managed extended detection and response service provider, was acquired by Quorum Cyber for an undisclosed amount. Ontinue has not previously disclosed funding. (more)
Red Alert Labs, a France-based professional services firm specializing in IoT security assessment certification services, was acquired by FIME for an undisclosed amount. Red Alert Labs has not previously disclosed funding. (more)
RedTrace Technologies, a United States-based professional services firm focused on cyber risk management, was acquired by Worldwide NFT for an undisclosed amount. RedTrace Technologies has not previously disclosed funding. (more)
🤘 IPO-h Yeah
None
🪦 Stop, Drop, Shut’em Down…
None 😮💨
❌ Layoffs
None 😮💨
📚 Great Reads
EA Safety - EA promises to solve AI Safety. Now we have two problems.
What we should do about emerging catastrophic AI cybersecurity risks - Joshua Saxe shares his take on what the OpenAI x Hugging Face breach means for the industry, and grapples with some hard questions about where the future of cyber and AI is heading.
*Sponsored
🧪 Labs
Watchamacalling it, and such
🫡 Signing Off
Have questions, comments, or feedback? Just reply back directly, I’d love to hear from you.
If you find this newsletter useful and know others who would, I'd really appreciate it if you'd forward it to them!
Mike P
P.S. Feel free to connect with me on LinkedIn.


