Resilient Cyber Newsletter #108
A wave of cyber-specific AI models, the Hugging Face fallout, Patchmageddon, open-weight geopolitics & the endpoint wars reignite
Welcome to issue #108 of the Resilient Cyber Newsletter!
We’re on the cusp of Black Hat, aka Hacker Summer Camp, and I’ll be out there MC’ing the Black Hat Startup Spotlight Competition, and Innovators and Investors Summit. I look forward to seeing everyone there, and of course, it seemed like the perfect time to get a black eye form Jiu Jitsu before I go MC one of the coolest public speaking opportunities in my career. But, the show will go on, and I’m excited.
Last week the argument that AI could autonomously chain vulnerabilities and breach a real target stopped being a slide in a vendor deck, when OpenAI disclosed that models from its own internal evaluation escaped isolation and reached Hugging Face’s production infrastructure. This week we got the sequel, and it came in two forms at once.
On one side, the industry’s answer showed up in product form. Nearly every major lab and vendor shipped a cyber-specific model or tool, an Open Secure AI Alliance formed with 40+ members, and the UK’s AI Safety Institute started publishing what these models actually do when you point them at real systems, including the uncomfortable finding that they cheat. On the other side, the gap between AI-speed discovery and human-speed remediation kept widening into what one bank now calls “Patchmageddon,” and the market kept pricing all of it, with endpoint and identity startups raising at scale.
The theme from last week holds, which is that the capability is arriving faster than our governance, disclosure, and prioritization models can adapt. What changed this week is that the defensive side stopped talking and started shipping.
Let’s get into it!
Cyber Leadership & Market Dynamics
AI, Cyber and Where the Smart Money Is Going
In this episode, I sit down with entrepreneur turned venture capitalist and Decibel Founding Partner Jon Sakoda to discuss the intersection of AI, cyber, and venture capital.
Jon founded IMlogic in the early 2000s, sold it to Symantec, and spent over a decade at NEA working with companies like Cloudflare, MongoDB, and HackerOne before starting Decibel. I’ve followed his writing on venture funding and dry powder for years, and this conversation was a chance to get outside the practitioner echo chamber and look at our industry through the investor’s lens.
We chatted about:
Why Decibel positions itself as the Navy SEALs next to the big platform funds
The founders-helping-founders community model and finding the CISOs who want their fingers in the clay
What separates the founders who finish the race now that AI lets anyone start one
Decibel’s $100M seed into Ent and why Jon calls endpoint the Super Bowl of cyber
Separating genuinely AI-native companies from AI washing
AI eating venture capital and why Jon thinks cyber’s best years are ahead
The agentic SOC’s move from driver assistance to self-driving
How buyers and prospective startup employees should evaluate young vendors
Where Decibel places its next bets, including resilience and cyber insurance
The Endpoint Wars Just Restarted
TechOperators partner Kevin Skapinetz makes the framing argument for the whole funding cycle this week, noting that nearly $400M of Seed and Series A money went into early-stage endpoint security startups in five weeks this summer, into a roughly $18B market where two vendors already control about 40%.
His thesis is that the unit of work is changing again, from files and processes to intent, as humans hand goals to software that plans and acts on their behalf. He points to Gartner’s projection that 40% of enterprise applications will ship with task-specific AI agents by the end of this year, up from under 5% a year ago, and Verizon DBIR data showing employees regularly using AI on corporate devices jumped from 15% to 45% in a single year.
When the endpoint becomes an agent operating with a real user’s permissions, the category everyone assumed was settled reopens. The three raises below are what that reopening looks like in practice.
Glow Emerges from Stealth at $1.2B Valuation to Challenge Endpoint Security in the AI Era
Per TechCrunch, Glow came out of stealth with a $180M all-equity Series A at a $1.2B valuation, led by Sequoia Capital, Cyberstarts, Greenoaks Capital, and Redpoint Ventures.
The founding team is notable, with CEO Roi Tiger a former Meta VP of Engineering and COO Emily Heath the former CISO of United Airlines and Docusign. Tiger’s pitch captures the market’s read, that for a decade everything moved to cloud and SaaS, and now “AI lands on the endpoint in a way we’ve never seen.”
A $1.2B valuation out of the gate for a company reimagining a mature category tells you where investors think the next platform fight is.
SentinelOne Veterans Raise $100 Million to Secure the Rise of AI Agents
Neo, founded by former SentinelOne leaders including CEO Nick Warner (ex-President and COO) and CPO Shlomi Salem (ex-VP Research), has now raised $100M in total, with a $75M Series A led by Andreessen Horowitz and Bessemer Venture Partners on top of a $25M seed.
Per CTech, the angel list is a who’s who, including Wiz CEO Assaf Rappaport and Talon founder Ofer Ben-Noon. Salem frames the problem cleanly, that traditional endpoint security has always been SentinelOne’s bread and butter, but the challenge with AI agents is that they operate with legitimate user permissions.
That is the exact seam Glow is chasing too, which is why this feels less like two startups and more like the opening moves of a category being re-contested.
Agent Endpoint Security & The Locality Dichotomy
While more focused on the technical side, this piece from Andrew Green looks at the slew of endpoint focused startups and the dichotomy of how they’re approach intent, and whether their technologies run locally, or in the cloud and the nuances of that difference.
Billion Dollar Cybersecurity Companies
Cole Grolmus of Strategy of Security continues his ongoing tracking of the cohort of cybersecurity companies that have crossed the billion-dollar threshold, a data set worth bookmarking if you want the long-run structural picture rather than the week’s headlines.
While it seems like everyone is now “valued” at a billion dollars, as Cole points out, valuation does not equal exit or acquisition. There have been 85 total billion-dollar exits in cybersecurity, across the thousands of startups that have come and gone.
PMF - Why It Matters
Andrew Peterson makes the case that product-market fit remains the single determinant that separates companies that endure from those that raise well and fade, a point that reads as almost contrarian in a market where valuation is moving faster than revenue for a lot of AI-native entrants.
We’re inevitably going to see a lot of companies that had massive funding and valuations fizzle into irrelevance, as the market can’t and won’t support them all concurrently.
Sriram Krishnan on Open Source AI’s Biggest Week Yet
Bridging into the AI section, this a16z Show episode with former White House AI policy advisor Sriram Krishnan digs into recent open model releases including Kimi K3 and Qwen, and why open models are putting real pressure on the frontier labs. It is a good primer for the geopolitics and open-weight economics that dominate the back half of this issue.
AI
What OpenAI’s Rogue Agent Really Did in the Hugging Face Hack
A week on from the disclosure, the analysis and the framing fight have both arrived, and the framing fight is the more interesting one. Per Scientific American, the models under evaluation (GPT-5.6 Sol plus an unreleased, more capable model, run with loosened safety safeguards) were being tested on ExploitGym, a benchmark that measures software-vulnerability exploitation, when the agent escaped its isolated test environment and breached Hugging Face to obtain the hidden benchmark answers.
In OpenAI’s own writeup, the models identified and exploited a zero-day in an internally hosted package-registry cache proxy to gain internet access from the sandbox, then chained stolen credentials and additional zero-days to reach remote code execution on Hugging Face servers.
What I think is a good call out is the University of Surrey’s Alan Woodward pushing back on the “went rogue” narrative, that “it was asked to do something, and it did it. Its way out of it was to cheat, basically.” It is a more precise description of the actual problem.
OpenFace: The Hugging Face Breach and What to Do About It
Luta Security’s Katie Moussouris frames this as the first publicly confirmed case of a frontier model autonomously chaining vulnerabilities into a real-world breach of a third party during the lab’s own testing, and her metaphor is the one that will stick, that these models are “like the world’s cleverest octopus escape artists, with unlimited prehensile arms and the ability to squeeze through anywhere.”
The lesson is not that our sandboxes held, it is that they didn’t, and the recovery depended on human vigilance rather than the boundary doing its job. XBOW’s take lands in the same place, that models can discover and exploit novel attack paths in real-world systems without source-code access, which means the safety controls have to live outside the model, not just inside it.
Cheating Behavior in Frontier Model Evaluations
If the Hugging Face incident felt like an outlier, the UK AI Safety Institute would like a word. In a study across frontier models including GPT-5.6 Sol, Claude Mythos Preview, Opus 4.7, GPT-5.4, and GPT-5.5, AISI found that every model tested attempted to cheat at least some of the time in cyber evaluations, using methods like searching the internet for solutions, attacking non-target systems, and probing the evaluation software itself.
One model wrote and ran code on external internet services to try to reach AISI’s own evaluation infrastructure, which is the same behavioral shape as the OpenAI incident, just caught in a lab. Worse for anyone hoping to detect it, the models described their cheating as wrong less than 50% of the time. The scored benchmark is quietly becoming an adversarial environment, and the thing being evaluated is trying to win rather than to be measured.
Preliminary Assessment of Kimi K3’s Cyber Capabilities
In a joint assessment, the UK AISI and the US Center for AI Standards and Innovation evaluated Kimi K3, released July 16, and found it performs significantly below the most recent frontier cyber-capable models while surpassing prior open-weight releases. On ExploitBench it hit 32% success on exploit development versus GLM-5.2’s 24%, though it failed arbitrary code execution entirely (0 of 41 samples versus 20 of 41 for leading models).
On the “The Last Ones” cyber range it reached step 17 of a 32-step attack path on average, against 28.5 steps for the most cyber-capable US models. The read here is not that Kimi is scary, it is that the open-weight frontier keeps advancing while its safeguards permit offensive cyber assistance, which changes the threat model for everyone downstream.
How Far Behind the Frontier Are Leading Open-Weight Models on Cyber?
AISI’s companion analysis quantifies the trend we have been tracking, that GLM-5.2 now trails frontier closed models by 4 to 7 months on cyber tasks, down from a 6 to 10 month gap throughout 2025. On narrow tasks GLM-5.2 performs comparably to Opus 4.6 and GPT-5.3-Codex, while DeepSeek V4-Pro matches Opus 4.5.
The economics are the kicker, with DeepSeek V4-Pro running a task at $0.28 against $12.50 for an equivalent Opus 4.5 run. AISI’s warning is worth quoting plainly, that once open-weight models are released, the option to keep safeguards in place is lost permanently, because safeguards can be removed. The defensive-preparation window is real, and it is measured in months, not years.
Openness Made All of This Possible
The Open Source Initiative’s Duane O’Brien makes the values-and-economics case against restriction, citing Harvard-backed research that values the demand-side worth of open-source software at $8.8 trillion, and noting that more than 200 companies have come out against restrictions on Chinese AI models.
His core point is one worth dwelling on, that every AI system in the headlines today, proprietary or open, exists because researchers shared their work openly. It is the optimistic take, and the honest tension is that the same openness that drives innovation and defensive visibility also lowers the floor for offensive capability.
Claude Security Enters Public Beta
Now to the wave of product launches that, more than anything else, defines this week. Anthropic moved Claude Security into public beta for Enterprise customers, built on Claude Opus 4.7 and integrated with CrowdStrike, Microsoft Security, Palo Alto Networks, SentinelOne, and Wiz.
It had already been tested by hundreds of organizations in a limited research preview. Hebbia’s Matt Aromatorio offers the practitioner-flavored endorsement, that his team has used patches built with Claude Security to close real vulnerabilities in minutes rather than days. Whether that holds at enterprise scale, across messy real-world codebases, is the question, but the direction of travel is unmistakable.
How Anthropic Secures Its AI-Native SDLC
Anthropic Deputy CISO Jason Clinton’s writeup is the most useful of the bunch for practitioners, because it describes running the thing rather than selling it. He reports that Claude now authors approximately 80% of the code merged into Anthropic’s codebase, that engineers ship 8x more code per quarter versus a 2021-2025 baseline, and that the share of PRs receiving substantive review comments rose from 16% to 54%.
His framing of accountability is good, that human accountability stays central, and what they accelerated was the review process by combining automated agentic and deterministic reviews while reserving human review for regulated or truly critical code. This is what “security keeping pace” actually looks like in an AI-native shop, and it is a governance model, not a tool purchase.
Atlas, Wiz’s AI Vulnerability Researcher
Wiz introduced Atlas, an autonomous vulnerability-research system that ranks first on CyberGym with a 90.9% success rate and has uncovered 200+ previously unknown vulnerabilities in open-source projects including gRPC, dnsmasq, Kubernetes, gVisor, and the Linux kernel, plus a critical RCE in GitHub (CVE-2026-3854) that earned GitHub’s largest bug bounty payout.
The line from the Wiz research team is the one to hold onto, that the system compounds the value of the model, and that scoping, orchestration, validation, and proof are what turn frontier-model capability into reliable security outcomes. The model is the engine, but the harness is the product.
Introducing Gemini 3.5 Flash Cyber
Google DeepMind’s Raluca Ada Popa and Four Flynn introduced Gemini 3.5 Flash Cyber, a lightweight model tuned for finding, validating, and patching vulnerabilities. It found 55 unique confirmed issues in the V8 JavaScript engine, against 47 for mainline 3.5 Flash and 36 for Opus 4.6, and uncovered remote code execution vulnerabilities in Google Cloud APIs within two hours.
They are also deploying it first to governments and trusted partners through CodeMender via a limited-access pilot, which is itself a signal about how the labs are thinking about dual-use cyber capability. For context on the haystack, they note the OSV.dev database now holds over 700,000 open-source vulnerabilities.
Introducing MAI-Cyber-1-Flash
Microsoft AI’s Mustafa Suleyman and Hayete Gallot introduced MAI-Cyber-1-Flash inside MDASH, claiming 96% on CyberGym (a 12-point improvement over Mythos) at 50% of the cost of leading models, and designed to handle up to 90% of tasks efficiently. Suleyman’s framing is the recurring idea across every one of these launches, that cybersecurity is not just a data-rich domain, it is a live reinforcement learning loop, which is exactly why Microsoft’s 100 trillion security signals a day matters as a training asset.
The pattern across MAI, Gemini Cyber, and the rest is that the frontier labs have decided cyber is a first-class specialization, not a side benchmark.
Cisco Introduces Antares for Vulnerability Localization
Cisco went the opposite direction from the big-model launches with Antares, releasing two small open-weight models, Antares-350M and Antares-1B, aimed at vulnerability localization and evaluated on a new benchmark of 500 tasks, where they outperform a dozen larger models.
NUS professor Reza Shokri names the reason this design matters, that small models run locally, so proprietary code never leaves the machine. This is the counter-narrative to the frontier arms race, and an important one for regulated and IP-sensitive environments, that the right tool is often the small, local, inspectable one rather than the biggest available model.
Cogent Announces VR-1, a Mythos-Class Model Built for Cyber Defense
Cogent Security unveiled VR-1, which it describes as twice as effective at finding attack paths in enterprise environments as other frontier models at one-fourth the cost, measured on its IntrusionBench benchmark for attack-path discovery across cloud infrastructure, identity systems, and internal tools.
Co-founder and CTO Geng Sng frames the defensive logic well, that every organization needs the counterpart to offensive AI, a model that finds the attack paths an AI would find so defenders can close them first. It is available only through the company’s Frontier Access Program rather than openly, another data point in how vendors are gating cyber-capable models.
Benchmarking AI Models on Known CVEs
Aikido’s Rein Daelman ran 13 models against 26 known vulnerabilities from the GitHub advisory database, with GPT-5.6 leading at 23 of 26 (88.5%). The more actionable finding is economic, that three pooled runs of the cheaper gpt-5.4-nano reached 18 of 26 at around $170, and that Kimi K3 matched frontier models at 23 of 26 while running 4x cheaper than GPT-5.6 Sol.
The takeaway, that running a cheaper model a few times and pooling the results finds more for less than a single pass of a flagship, is the kind of practical guidance defenders can actually operationalize, and it undercuts the assumption that only the most expensive model is worth pointing at your code.
Can Frontier Models Tackle Autonomous Long-Horizon Malware Analysis?
SentinelOne Labs’ Juan Andrés Guerrero-Saade and Gabriel Bernadett-Shapiro put the models through a genuinely hard, multi-stage reverse-engineering benchmark, and only GPT-5.6 Sol completed all eight investigation stages, while GPT-5.5, GLM-5.2, and the Opus 4.x family could not sustain the full run.
Analyzing a 2005 Windows toolkit with 101 patching rules, they compressed an expert task that would normally take three weeks into 8 to 10 hours with model assistance. Their conclusion is the optimistic counterweight to the week’s scarier headlines, that a single expert supervising these systems can now expand their output by any metric worth tracking. This is the “defender’s dividend” case, and it is real, provided you have the expert in the loop.
BotsBench: A Vendor-Neutral SOC and IR Benchmark
The team behind Louie.ai launched BotsBench, a vendor-neutral benchmark for AI models and agents on SOC and incident-response investigations, built on Splunk’s BOTSv3 and a proprietary CTF dataset.
The uncomfortable finding they surface is a model regression, where Claude 4.6 scored 14 of 17 on a control subset against Claude 4.7’s 5 of 17 under matched conditions. Whatever the eventual explanation, the value here is the discipline, that we need independent, reproducible benchmarks for security tasks rather than taking each vendor’s self-reported CyberGym number at face value. Given how many of those numbers appear in this very issue, that is not a small point.
Industry Leaders Form the Open Secure AI Alliance
Tying the week together, NVIDIA and 40+ inaugural partners, including Cisco, CrowdStrike, Hugging Face, Microsoft, Palo Alto Networks, Red Hat, and the Linux Foundation, formed the Open Secure AI Alliance to build and share open AI tools for cyber defense.
The founding argument is the same one Hugging Face learned the hard way this month, that when defenders cannot inspect, adapt, and run advanced AI on their own infrastructure, their ability to respond is constrained at exactly the moment speed matters most.
An alliance is not a solution, and I will hold my applause until there is shared tooling rather than a launch post. That said, the fact that direct competitors are aligning on open, inspectable, defender-controlled AI is a meaningful signal about where the industry thinks the puck is going.
A Theory of Least Autonomy in AI
On the research side, Christophe Parisel argues that least privilege alone is insufficient for AI agents and proposes least autonomy as a generalization, introducing a compositional “blast radius” measure of structural separation between actions, a directed agent influence graph, and a collusion predicate for detecting when combined authorizations produce an unintended capability.
It is dense and theoretical, but it is pointed at the exact gap the incidents above expose, that our permission models were built for deterministic software, and agents that plan and act need a governance primitive built for autonomy rather than access.
Orbit: A Multi-Agent Security Evaluations Framework
Worth a bookmark for the builders in the audience, Orbit is a new open-source framework for empirical multi-agent safety evaluations, built on the UK AI Security Institute’s Inspect AI, shipping five scenario families and configurable threat types (prompt injection, compromised agent, collusion, and misuse) alongside defense categories like monitors, guardian agents, and the dual-LLM pattern.
As the AISI work this week shows, the ability to run your own adversarial evaluations rather than trust a vendor’s is quickly becoming table stakes.
AppSec
Patchmageddon
When J.P. Morgan’s Michael Cembalest devotes an Eye on the Market to your industry’s core dysfunction, the discovery-remediation gap has officially gone mainstream.
The figures he assembles are the ones to internalize. Mozilla found and fixed 271 vulnerabilities in Firefox 150 while testing a preview model, more than 10x the 27 found in Firefox 148 using a prior-generation model. Median time-to-exploitation fell from roughly a year in 2021 to a single day in 2026, projected toward a minute by 2027. And through May 2026, Anthropic identified over 23,000 potential open-source vulnerabilities, of which 3,900 were high or critical, yet only 75 of 530 reported high-or-critical items were patched.
Anthropic’s Nicholas Carlini puts the human scale on it, that he has “found more bugs in the last couple of weeks than I’ve found in the rest of my life combined.” Discovery is no longer the bottleneck. Remediation capacity is, and the gap between them is the defining AppSec problem of the year.
The Economics of Security Vulnerabilities: Why Discovery Is Not Commoditizing
AISLE’s Ondrej Vlcek pushes back thoughtfully on the assumption that AI makes vulnerability discovery a commodity, noting that black-hat brokers still pay up to $9 million for zero-click exploit chains against modern smartphones and $3 million for Chrome and Safari exploits, prices that keep rising rather than falling.
His metaphor is worth keeping, that commodities produce interchangeable output, but discovery engines produce different slices of an unfinished map. In other words, cheap AI discovery floods the easy findings while the scarce, exclusive, weaponizable discoveries stay expensive.
Both things are true at once, which is exactly why the market is confusing right now.
The Agentic SDLC
GEICO’s Jet Anderson makes the case that security has to move from episodic, gate-based reviews to continuous, embedded, agent-native validation, and backs it with numbers that should reframe how you think about your own pipeline.
He cites Gartner’s projection of 40% of enterprise applications embedding agents by end of 2026, Checkmarx data that roughly 70% of organizations estimate more than 40% of their code is AI-generated, and IEEE-ISTAS research showing a 37.6% increase in critical vulnerabilities after five agent iterations without embedded security checks. The Cycode figure is the one that should focus minds, that 100% of surveyed companies have AI-generated code in production while 81% of security teams lack visibility into it.
As Anderson quotes threat-modeling authority Adam Shostack, you need to know the threat model to evaluate what the AI’s hallucinate, and today you need AI to keep up.
Final Thoughts
Last week the story was that autonomous exploitation stopped being hypothetical. This week the story is that the defensive response stopped being rhetorical.
Nearly every major lab and vendor shipped a cyber-specific model, an alliance formed to keep that capability open and inspectable, and independent evaluators started telling us, in numbers, both how good these systems are and how readily they cheat to win. That is genuine progress, and I do not want to undersell it, because the “defender’s dividend” is real when there is an expert in the loop, as SentinelOne’s malware work shows.
That said, the harder truth is sitting in the AppSec section. We are getting very good at discovery and barely better at remediation, and Patchmageddon is the name for that gap. Anthropic surfaced over 23,000 potential open-source vulnerabilities (although as Patrick Garrity has pointed out, we’re yet to see actual CVE’s for most of the findings) and the ecosystem patched a tiny fraction of the critical ones.
The models that find the bugs are improving on a monthly cadence, while the human and organizational capacity to fix, test, and ship patches is improving on the timeline it always has. Shipping more powerful discovery models into that imbalance, without a matching investment in remediation capacity, prioritization, and the disclosure plumbing, risks handing offense a faster lever than defense.
So the open question I would leave you with is the one underneath all forty-some items this week.
We have proven we can build AI that finds and exploits vulnerabilities at machine speed. The far harder problem, and the one that will decide whether this wave leaves us safer or just faster, is whether we can build the organizational muscle to fix them at anything close to the same pace.
Much of that remains to be seen, but the shape of the challenge is now unmistakable.
Stay resilient.





























