This week's issue is backed by Speakeasy.
Hope you had a great weekend!
Another week, another string of misaligned AI agents, and another bond market selloff. All of it drives how the tech and cyber industry invests and builds, so there’s no escaping the impacts down the line on cyber.
Meanwhile, the cyber market is putting all its eggs in the offensive basket, betting that the best Defense is good Offensive Security.
PARTNER
82% of enterprises are running AI agents they don't know about
That's from a CSA survey of 418 security teams who reported that 65% of them had already had an AI agent-related incident, most of them causing data exposure.
The Speakeasy AI control plane is the architecture enterprises are adopting to govern agentic actions within their orgs. It ensures that every agent, tool, and MCP server is authenticated, policy-compliant, auditable, and inspected for prompt injection and data exfiltration.
Table of Contents
😎 Vibe Check
Click the options below to vote on whether you are a practitioner, founder, or investor. Leave a comment, and I'll anonymously feature the best takes in the next issue!
What is the security industry's most expensive habit?
Last issue’s vibe check:
Which buys down the most security risk these days?
🟨🟨⬜️⬜️⬜️⬜️ Finding more vulnerabilities
🟨🟨🟨⬜️⬜️⬜️ Fixing what's already there
🟨⬜️⬜️⬜️⬜️⬜️ Proving controls actually work
🟩🟩🟩🟩🟩🟩 Shrinking what's exposed
⬜️⬜️⬜️⬜️⬜️⬜️ Creating fewer security defects
🟨⬜️⬜️⬜️⬜️⬜️ Other (tell me)
Shrinking what is exposed and reducing the existing attack surface was the clear winner in last week’s vibe check. The results are funny to me, because “shrinking exposure” isn’t really an investable domain in the cyber world. I still agree with it being the right approach to take, however.
You can obviously enumerate and identify your exposure better, take steps to secure and patch what’s out there, but shrinking it is a different game altogether. It’s going to require businesses to do things differently from an architectural and go-to-market standpoint.
Some of the top comments from last week’s vibe check:
💬 “Most security spend and energy and effort is focused on reducing risk likelihood. Actions that focus on reducing risk magnitude have a bigger impact at this point, so forensic readiness, incident response planning, exercising, and working stuff out with your insurance carrier and law firm and forensics firm are going to change overall posture more than running faster on the vulnerability hamster wheel …”
💬 “We do NOT need to find more problems. We need to automate the mitigation of the ones we have. Lower risk comes when you give an effort to reduce risk not increase it with findings.”
💰 Market Summary
Private Markets
12 companies from 6 countries raised $419.2M across 12 unique categories
Average disclosed deal size was $41.9M (median: $13.7M)
92% of funded companies were product companies
14 companies from 9 countries were acquired for $33.9M across 8 unique categories
71% of acquired companies were service companies
1 company announced layoffs
Public Markets
No pure-play public cyber company had an earnings report

📸 YoY Snapshot
Rolling 13-week charts that compare funding and acquisitions week over week, year over year, comparing 2025 to 2026

$9.5B across 160 deals over the past quarter, up 112% from a year ago.

108 acquisitions over the past quarter, up 19% from a year ago.
🧩 Funding By Product Category

$255.5M for Continuous Automated Red Teaming (CART) across 1 deal
$55.0M for SaaS Security Posture Management (SSPM) across 1 deal
$38.0M for Network Security across 1 deal
$25.0M for Deepfake Detection across 1 deal
$15.4M for Security and Compliance Automation across 1 deal
$12.0M for Identity Threat Detection and Response (ITDR) across 1 deal
$10.0M for Narrative Intelligence across 1 deal
$7.0M for Red Teaming across 1 deal
$726.7K for Secure Access Service Edge (SASE) across 1 deal
$609.4K for Managed Detection and Response (MDR) across 1 deal
An undisclosed amount for Agentic Runtime Security across 1 deal
An undisclosed amount for Post-Quantum Cryptography (PQC) across 1 deal
🏢 Funding By Company
» Connect Claude, Cursor, or any MCP client to The Signal via the MCP for free.
Product Companies:
Armadin Security, a United States-based automated red-teaming and AI threat hunting platform, raised a $255.5M Series B from Andreessen Horowitz and Accel. (more) Unicorn Alert 🦄
Reco, a United States-based SaaS security posture management platform, raised a $55.0M Series B from AT&T Ventures. (more)
doxx.net, a United States-based private networking and DNS threat protection platform, raised a $38.0M Series A from Andreessen Horowitz. (more)
Modulate, a United States-based AI audio monitoring platform for detecting audio deepfakes and fraud, raised a $25.0M Venture Round from Future Ventures. (more)
Complaion, an Italy-based security and compliance automation platform, raised a $15.4M Seed from Eurazeo and Italian Founders Fund. (more)
Rig Security, an Israel-based identity threat protection and posture management platform for cloud environments, raised a $12.0M Seed from Brightmind Partners and Ten Eleven Ventures. (more)
Osavul, a Luxembourg-based AI-generated disinformation threat detection platform, raised $10.0M in Series A funding from 33N Ventures. (more)
RemoteThreat, a United States-based composable offensive cyber operations platform, raised $7.0 M in Pre-Seed funding from DataTribe and OUP (Osage University Partners). (more)
Zaperon, an India-based secure access service edge platform, raised $726.7K in Seed funding from Inflection Point Ventures. (more)
Ring Zero Security, an India-based kernel-level agentic AI runtime security platform, raised an undisclosed Non-Equity Assistance from DraperU India. (more)
Sanctum SecOps, a United States-based post-quantum certificates-as-a-service platform, raised an undisclosed Pre-Seed.
Service Companies:
CYBR International, a United States-based professional services firm focused on threat detection and response, raised an undisclosed amount in an equity crowdfunding round. (SEC Filing - may be incomplete)
SEC filings may reflect partial or interim fundraising and can understate the final round numbers.
🌎 Funding By Country

$380.5M for the United States across 6 deals
$15.4M for Italy across 1 deal
$12.0M for Israel across 1 deal
$10.0M for Luxembourg across 1 deal
$726.7K for India across 2 deals
$609.4K for Denmark across 1 deal
🤝 Mergers & Acquisitions

Product Companies:
Plurilock, a Canada-based behavioral biometric identity and access management platform, was acquired by Quantum eMotion for $23.9M. Plurilock had previously raised $16.5M in funding. (more)
Riva Labs, a Switzerland-based post-quantum cryptography and wallet infrastructure security for digital assets, was acquired by Project Eleven for an undisclosed amount. Riva Labs has not previously disclosed funding. (more)
Service Companies:
WithNetworks, a South Korea-based managed security services provider, was acquired by ICTK for $10.1M. WithNetworks has not previously disclosed funding. (more)
Aigner Business Solutions, a Germany-based professional services firm focused on data privacy and protection services, was acquired by Sequrio for an undisclosed amount. Aigner Business Solutions has not previously disclosed funding. (more)
Althammer & Kill, a Germany-based professional services firm focused on cloud security, data protection, and compliance, was acquired by Sequrio for an undisclosed amount. Althammer & Kill has not previously disclosed funding. (more)
CyberStrikeAI, a Singapore-based open-source AI penetration testing platform, was acquired by ThreatBook for an undisclosed amount. CyberStrikeAI has not previously disclosed funding. (more)
Myriad360, a United States-based professional services firm focused on cyber and IT advisory, was acquired by One Equity Partners for an undisclosed amount. Myriad360 has not previously disclosed funding. (more)
NetSentries, a United Arab Emirates-based professional services firm focused on offensive security consulting, was acquired by SGS for an undisclosed amount. NetSentries has not previously disclosed funding. (more)
Prescient Security, a United States-based professional services firm focused on compliance audits and penetration testing, was acquired by SGS for an undisclosed amount. Prescient Security has not previously disclosed funding. (more)
Wolfpack Information Risk, a South Africa-based professional services firm focused on security awareness training and incident response support, was acquired by Risk X Group for an undisclosed amount. Wolfpack Information Risk has not previously disclosed funding. (more)
🤘 IPO-h Yeah
None
🪦 Stop, Drop, Shut’em Down…
None 😮💨
❌ Layoffs
📚 Great Reads
The free AI already on your Mac - macOS Tahoe ships with a 3B parameter LLM. apfel gives you CLI access with one brew install. No model downloads, no API keys, no configuration needed, just works. Not an endorsement, I just thought it was really cool.
Security Teams Are Moving Too Slowly for AI Agents - Zach Korman and Chris Hughes discuss the collision between the AI safety conversation and the cybersecurity world, and how that has been playing out since the OpenAI Hugging Face incident.
*Sponsored
🧪 Labs
Neither side stands a chance
🫡 Signing Off
Have questions, comments, or feedback? Just reply back, and let me know.
If you find this newsletter useful and know others who would, I'd really appreciate it if you'd forward it to them!
Mike P
P.S. Feel free to connect with me on LinkedIn.

