Welcome!
Welcome to issue #112 of the Resilient Cyber Newsletter.
It’s been another action packed week, with an industry-wide call from frontier labs, CSP’s and vendors for collective action on Cyber, continued M&A activity, a slew of fundraising, continued drama with AI incidents and the industry still grappling with the surge of CVE’s and remediation bottlenecks.
I try and unpack it all this week concisely, so sit back, grab a coffee and let’s get moving before everyone heads off to enjoy the long weekend, at least here in the U.S.
Cyber Leadership & Market Dynamics
A Call for Collective Action on Cyber Defense
OpenAI published a letter with 100+ cosigners across the industry with a core claim that:
”In the coming months, AI-enabled cyber attacks will become far more widespread and sophisticated as models around the world become increasingly capable”.
It goes on to make various calls to actions such as:
Recognizing the status quo of security won’t be enough
Empower more defenders with cyber-capable AI
Mobilize a collective response
Make cyber defense a leadership priority
Now, where I struggle with this is, I agree with everything their saying.. the problem however is that we cannot “will” ourselves into a state of security. It requires either sufficient market or regulatory forces and right now we largely lack both, which is why many consider cyber to be a market failure.
There is also the fact that the labs, CSPs and many of the signatories are security vendors, so they are calling on the market and their customers to spend more on the very things they sell, which can be seen as problematic.
All that said, I unfortunately don’t anticipate much changing until organizations feel real market consequences for incidents, shipping insecure products, or changes in the regulatory landscape which force them to prioritize and invest in security with more rigor.
AI Is Moving Cyberattacks to Machine Speed
In a bit of a dim warning, former NSA leader Rob Joyce recently had an interview where he discussed the fact that exploitation timelines are collapsing, and attacks are moving at machine speed.
Rob discusses how years of technical debt are now going to be found and exploited by AI, and how critically important the fundamentals remain.
Palo Alto Acquires Console
PANW continues its acquisition run, this time acquiring a company named Console. This one is less about securing AI, and instead focused on leveraging AI for security, as the company provides capabilities for users to express oiperational goals and the software handle the complexity of helping them achieve it.
This quote from Nikesh Arora sums up the goal:
"Security operations can no longer be about managing dashboards and queuing tickets just to help humans work faster. By bringing Console into Palo Alto Networks, our customers can have a direct conversation with data and build agentic workflows in natural language that helps alert and remediate issues automatically. This is the shift to software-as-an-agent, giving our platform the arms and legs to deliver autonomous security outcomes across the entire enterprise."
If you’re looking for deeper insights into how the industries largest vendor sees the landscape, as well as their M&A ambitions, I found this recent conversation with Molly O’Shea to be perfect. I had a chance to listen to it earlier this week.
AIR Security Emerges From Stealth With $50M
The team at AIR Security recently emerged from stealth with $50M, focused on building a “firewall” for agents. I’m very familiar with this team, and had them on the show in the past to discuss an early effort of theirs Mother of all KEV’s (MOAK), which automated developing exploits for KEV’s.
The team has continued innovating and now has the capital and backing of amazing investors, such as Sequoia. They played a role in the new OWASP Agentic Skills Top 10, and are focusing their attention on creating a firewall for AI Agents.
HiddenLayer Raises $100M Series B
One of the more longstanding AI security players in the ecosystem who has been around for a bit, HiddenLayer, recently announced a $100M Series B, being led by Delta-v Capital, with involvement from others such as MSFT’s M12 venture fund, and Booz Allen Hamilton.
I’m employed at a competitor in this category so I watch it closely, but I’ve been following their team for years, prior to the role I am in as well. It is interesting to see M12 be among the investors, given they also invest in competitors to Hidden Layer. The involvement of BAH, and my public sector background also give the signal that the team has likely has strong public sector traction as well, which is supported in their announcement where they cite deployments across U.S. defense and IC environments. They also cite 10x ARR growth, 50+ new platform customers etc.
There’s some great security leaders on the team of course, aside from the founders, such as longtime industry leader Malcom Harkins. While I compete in the category in my day job, I know it is a highly competitive and fast moving one, and there’s several great teams in the ecosystem.
Upwind Raises $300M, Doubling Valuation to $3.8 Billion in Five Months
In what feels like groundhog day, we have another large fundraising event for Upwind, who has established itself as a leader in the cloud security and runtime categories. This comes 8 months after their prior $250M Series B(hence my groundhog day comment).
The company seems to be capitalizing on their momentum, competing strongly in the CNAPP space, and also expanding to cover specific areas of AI security, as everyone scrambles to cover the risks of AI.
Huskey’s Announces $27M Series A
The team at Huskey’s also announced their $27M Series A, just 5 months after coming out of stealth with participation from teams such a Blackstone, Merlin Ventures, Zscaler, Okta and others.
They aim their focus at “Network Edge Security Management (NESM), focusing on making network edge security stacks work for, not against customers.
AI
Conversation with a OpenAI/Hugging Face Incident Investigator
One thing I found really interesting this week was the Dwarkesh Patel conversation with Ajeya Cotra around the OpenAI/Hugging Face incident.
For those unfamiliar, Ajeya is one of the independent investigators from METR involved in the analysis of the incident. In the conversation with Dwarkesh, they go really deep in particular in some of the multi-agent conversations, behaviors and more, which felt like diving into the psychology of multi-agent systems, of “civilizations” as Dwarkesh himself framed them in his blog “The Rise of Fall of Agent Civilizations”, which is worth a read.
Ajeya also had a good blog on what surprised her from the incident, including the scale of the number of agents that participated in this incident and activity and how they collaborated.
Valid Questions About the Independent Review of the OpenAI/Hugging Face Incident
Now, not to throw shade at the organizations involved in the review of the incident, but Zack Korman shared an excellent video critiquing aspects of this review. He points out how the organizations involved in the review largely lack any cybersecurity expertise or background, and by their own admission, the review could of been handled better in several ways.
He goes on to rightfully call out the Cyber community as well, as we seem to be sitting back and letting the frontier labs, and others outside of Cyber lead the charge as it relates to the cyber risks of AI. Zack says we need to step it up as a community, and I’m inclined to agree with him.
Anthropic’s Plans to Improve Alignment and Security
Sticking with the theme of incidents and “breakouts and such, Anthropic published a blog this week discussing how they plan to improve alignment and security efforts.
Agent "breakouts", unauthorized actions and misalignment has been dominating the AI and security conversation for weeks.
From the initial OpenAI and Hugging Face incident, to others such as Anthropic, AI Security Institute (AISI), Meta and even open weight labs coming forward disclosing incidents of agent attacks and unauthorized actions.
That's why this blog from Anthropic is super timely. They walk through what they learned from their three incidents of Claude gaining unauthorized access to real systems and infrastructure and what they plan to improve moving forward.
This includes efforts such as securing evaluation and training environments, utilizing classifiers to identify unauthorized activities, the use of automated monitors, improved cyber sandboxes and general environmental hardening.
It also lays out recommendations for external partners using models with reduced cyber safeguards that include sandbox and network isolation, pre-engagement validation, explicit scope setting and real-time monitoring.
One thing I particularly appreciate is they are honest about where gaps remain, in terms of models cheating in training environments and objectives, continued alignment challenges and more.
Most notably for me is their hardening security practices and recommendations highlight a list of things that nearly every IT environment I've worked in across 20~ years is still rife with, and inevitably will be found by AI soon.
This includes accounts with standing access to sensitive data, lack of outbound access control, identify rigor, legacy infra configs and services, and gaps in observability.
It's going to be an interesting couple of years ahead. Give the Anthropic blog a read yourself.
CrowdStrike SafeMind
AI and Cyber have been converging for quite sometime now, in good and bad ways. While a lot of the attention tends to be on the negative, incidents, exploitation and so on, there are a lot of promising aspects as well, and in my opinion, leveraging AI is the only way cyber has any chance of keeping up with the threat landscape.
This week we saw an innovative and interesting announcement from one of the industries largest teams, CrowdStrike, who announced their “Cyber Superintelligence Lab”, and first breakthrough “SafeMind”, in partnership with NVIDIA.
It is described as a family of purpose-built security models and agentic harnesses for autonomous offense and defense together, to both identify and resolve vulnerabilities, as depicted below:
Their blog has an interesting video and frames using the Red and Blue models together (or not) to identify attack paths and vulnerabilities and mitigate them.
The Security Autonomy Matrix: Deciding AI Authority
Many organizations are wrestling with the autonomy that agents introduce. That’s why this Security Autonomy Matrix from Lenny Zeltser is a timely resource, helping organizations walk through how much authority AI agents get with different columns and rows for considerations such as workflows, triggers, autonomy levels per action class, accountable person, gate, residual risk and safeguards as well as reevluation triggers and expirations.
Agent Hooks: An open framework-neutral AI governance contract
Hooks have quickly become one of the de facto runtime enforcement mechanisms for controlling actions agents take. They’ve seen adoption across endpoint coding agents, and custom/homegrown agents alike.
That said, there are a lot of different frameworks, SDK’s and more that must be considered across frameworks and platforms. Microsoft. published an open, framework-neutral governance contract with conformance testing on both sides.
AppSec
AppSec in the Age of Agents
AppSec was already losing ground prior to AI coding agents hitting the scene. Trends such as "Shift Left" and DevSecOps fell short, producing noise for developers and reinforcing the very silos between teams they were meant to break down.
Now, FIRST projects we could see ~66,000+ CVE's in 2026, yet most organizations can only remediate about 10% of their findings in a month, despite Verizon's DBIR showing exploitation as the initial access vector in breaches. Meanwhile, AI is industrializing the discovery of vulnerabilities and now we're seeing examples of agentic workflows and autonomous exploitation of known exploited vulnerabilities.
Better prioritization alone isn't going to close the gap, and a decade of refining how we rank findings hasn't stopped vulnerability backlogs from growing. Cybersecurity and Infrastructure Security Agency's published their 2024-2025 Vulnerability Review report, and it showed 41.5% of KEV's map to MITRE "stubborn weaknesses", with 18 CWE's appearing in the CWE Top 25 every year from 2019-2025... the same classes of flaws keep shipping year after year.
This is why root cause research from Jeevan Jutla and Gecko Security, a Resilient Cyber partner caught my attention. They traced disclosed findings, such as in n8n, back to their origins and found 569 findings came from just 105 distinct root causes, with 67% of them being repeats of earlier issues, same with other platforms such as GitLab, where 58% were repeats.
What looks like a runaway backlog is often a short list of root causes that just get ignored, when we could fix the class once, and it stays fixed. I chat with a lot of teams in AppSec, and often hear about prioritization, intelligence, dashboards, ticketing and more, but don't often hear about addressing root causes, despite it being advocated for by leaders such as CISA, Bob Lord and others for years.
This is one of the key shifts I think AppSec needs to make in the age of agents. I dove into the data, AI discovery and exploitation trends and what eliminating vulnerability classes looks like in practice in my latest blog.
Why Finding Bugs Still Isn’t Commoditized
In this episode, I sit down with Ondrej Vlcek, Founder and CEO at AISLE and the former CEO of Avast, to discuss where AI vulnerability discovery actually stands, including what got commoditized, what did not, and why shipping a fix a maintainer will accept is a very different problem from finding the bug in the first place.
Ondrej spent roughly 30 years in this industry, starting as employee number six or seven at Avast doing kernel-mode driver work on Windows 95, and eventually taking the company public and selling it to NortonLifeLock in a nearly $9 billion transaction. He co-founded AISLE in the fall of 2024, and his team has since disclosed more than 350 CVEs across projects like OpenSSL and curl.
I have been beating the remediation drum for a while now, so this was a conversation I wanted to have with someone who is actually shipping accepted patches upstream rather than just posting finding counts.
Runaway CVE Rates
It should come as no surprise that we have more CVE’s in 2026 than in 2025, but how rapidly it is growing is still something to track and honestly be concerned with in some ways.
Jerry Gamblin recently took to LinkedIn to show how CVE’s YTD are up +86.5% YoY at 396 a day, compared to 238 a day the year prior. This is not even accounting for the fact that NVD isn’t enriching the full breadth of CVE’s and some may not be showing up in the NVD, as it made adjustments to try and manage the load it is seeing, much of which is being driven by the industrialization of AI discovering vulnerabilities.
There’s nuance in the numbers of course, and understanding what to prioritize and remediate is still critical and is a topic I dug into with Jerry himself recently on the show.
Running a Software Factory Efficiently at Uber-Scale
There’s been a rise in discussions about “Software Factories”, but it has often been hypothetical, or small startups. What does it look like for a major tech company and enterprise?
Well, Uber provided that answer with an excellent blog recently, showing how agentic tooling grew 7x, and weekly agent requests grew 9.4x while total spend “relatively stabilized”.
This piece goes deep into Uber’s software factory, covering models, MCP, FinOps and more. While it isn’t security focused, I do think this is a development pattern we should expect to see grew with AI coding agents, and security inevitably will want to be a key part of the conversation.
Empirical Observations: How to Deal with Speed
Everyone (including myself) have been discussing the so called “Vulnpocalypse” and industrialization of vulnerability discovery, runaway CVE volume, need for prioritization and so on.
This paper from Empirical provides some great insights on how to actually deal with the problem. From FIRST reporting a projects 66,000+ CVE’s in 2026, DBIR showing vuln exploitation as a leading initial attack vector at 31% and more, the problem has been top of mind for many.
Empirical also highlights just how woefully insufficient the CISA KEV is when it comes to identifying vulnerabilities with known exploitation, as shown below:
They make recommendations such as replacing uniform SLA’s with risk-stratified cadences, tracking days since last exploitation rather than a permanent “known exploited” flag, and accounting for local exposure and escalating on quiet-to-active transitions intra-day.
The Real Reasons Vuln Remediation is Slow and How AI Changes the Economics of Fixing Things
Many of us have been arguing that finding vulnerabilities has never been the bottleneck, fixing them is, and now AI is massively front loading the finding, while fixing stays problematic.
This piece from longtime CISO and security leader Tim Rains highlights the reasons remediation is slow, such as the friction of safely changing production software, differences in bought vs. built software, incomplete inventories, unclear ownership, and fragmented authority among many other issues.
This is a comprehensive real-world informed perspective of the problems of reducing risk in complex enterprise environments and now marketing noise from a vendor.
Rival Buyout Aids Customer After Firm Shutters
Last week I had shared how the hardened container and supply chain vendor Minimus had decided to shutdown and return funding to investors after struggling to grow and scale.
In a bit of a surprise move, their competitor Echo stepped into the fold, announcing they were acquiring Minimus and providing an option to customers of Minimus who would have had to switch to an alternative, such as the industry leader in Chainguard.
I had a chance to provide some commentary to TechTarget on this one.
Closing Thoughts
It’s another week that sometimes feels like a month in the AI era. From collective calls for cyber defense in the face of AI-driven risks and threats, continues fundraising as teams tackle emerging and innovative solutions, and the industry grappling with incidents tied to agents and AI.
That said, the work rolls on, and so do we!
Stay Resilient















