# A Security Emerges From Stealth With $37M to Automate Offensive Security and AI-Powered Vulnerability Remediation


Funding Round Led by Lightspeed and Cyberstarts as Enterprise Defense Shifts Toward Autonomous Threat Simulation


A Security, a startup focused on autonomous offensive security and remediation, announced its emergence from stealth mode on Monday after securing $37 million in Series A funding. The company, founded by former security leaders from Sygnia and Hunters, has built a platform designed to counteract the rapidly evolving threat of AI-driven cyberattacks by using its own autonomous agents to identify, simulate, and remediate vulnerabilities before attackers can exploit them.


The funding round was led by Lightspeed Venture Partners and Cyberstarts, with participation from high-profile industry figures including Assaf Rapaport (CEO of Wiz), Yotam Segev (CEO of Cyera), and Cerca Partners. The company plans to use the capital to expand its platform and grow its team.


## The Founding Team and Background


A Security was founded by three security professionals with deep experience in enterprise defense:


  • Yossi Torati (CEO) — Previously served as Director of Enterprise Security at Sygnia, bringing expertise in incident response and enterprise security operations
  • Omer Gull (Chief Product Officer) — Formerly held a leadership role at Hunters, a platform specializing in security threat detection
  • Yuval Itzchakov (Chief Technology Officer) — Also from Hunters, bringing technical depth in security platform development

  • The founding team's background reflects a clear focus on both offensive and defensive security disciplines—a combination that informs the company's core platform architecture.


    ## The Problem: AI-Driven Threats and Traditional Vulnerability Management


    Enterprise security teams face a fundamental challenge: vulnerability management has become exponentially more complex. Organizations typically operate across multiple domains, cloud environments, on-premises infrastructure, and hybrid ecosystems. Traditional vulnerability scanners identify isolated weaknesses, but they fail to answer a critical question: How would an actual attacker connect these vulnerabilities into an exploitable path?


    The emergence of AI-driven attack tools has accelerated this challenge. Automated, AI-powered threat actors can:


  • Rapidly enumerate vulnerabilities across domains
  • Identify chaining opportunities faster than human analysts
  • Launch sophisticated multi-stage attacks with minimal manual intervention
  • Adapt and evolve tactics in real time

  • Traditional patch management and vulnerability remediation processes, often measured in weeks or months, cannot keep pace with this threat evolution. A Security's platform aims to bridge that gap by automating both the identification of exploit paths *and* the remediation process itself.


    ## How A Security's Platform Works


    The platform operates on a principle of proactive offensive security through continuous autonomous simulation. Here's how it functions:


    ### Continuous Vulnerability Discovery and Linking


    A Security's system uses a combination of offensive and defensive AI agents that operate autonomously across the enterprise environment. Rather than simply identifying individual vulnerabilities, the platform performs contextual analysis to connect vulnerabilities across multiple domains and systems.


    For example, a platform might identify:

  • Weak credentials in a cloud environment
  • An unpatched application on a domain-joined server
  • Lateral movement paths through network segmentation gaps

  • The platform links these together to map the complete, end-to-end exploit path that an attacker would follow to breach a critical asset.


    ### Proof-of-Exploitability Through Scoped Execution


    Once exploit paths are identified, A Security's agents perform what the company calls "stress testing" of different enterprise domains. Critically, this is done through scoped execution with full audit trails—meaning the platform:


  • Validates that each identified exploit path is actually exploitable
  • Operates within defined boundaries to avoid causing damage
  • Maintains comprehensive logs of all simulated attack activities
  • Provides proof of exploitability rather than theoretical vulnerability chains

  • This approach converts abstract vulnerability reports into concrete evidence of actual risk.


    ### Automated Remediation and Containment


    Once vulnerabilities and their exploit paths are validated, the platform moves beyond identification into active remediation:


  • Direct corrective actions — The platform can initiate fixes directly at the source of vulnerabilities
  • Compensating controls — Where direct patches cannot be applied immediately, the platform adjusts secondary controls to prevent exploitation
  • Automated containment — Potential attack routes are neutralized automatically before external threats have an opportunity to exploit them

  • This full-lifecycle approach eliminates the traditional gap between vulnerability identification and remediation—a window that attackers often exploit.


    ## Market Context and Investor Rationale


    The $37 million funding round reflects growing enterprise appetite for autonomous security solutions. The investor syndicate is particularly notable:


    | Investor | Significance |

    |----------|--------------|

    | Lightspeed Venture Partners | Early-stage investor in enterprise security; recognized pattern of AI-driven security adoption |

    | Cyberstarts | Venture firm focused exclusively on cybersecurity startups |

    | Assaf Rapaport (Wiz CEO) | Founder of one of the fastest-growing cloud security platforms; validates market demand |

    | Yotam Segev (Cyera CEO) | Leader in data security and governance; signals crossover appeal |

    | Cerca Partners | Emerging venture fund focused on security infrastructure |


    The participation of active CEOs from Wiz and Cyera is particularly significant—it suggests these leaders view A Security's approach as complementary to their own platforms rather than competitive.


    ## Competitive Landscape and Positioning


    A Security enters a crowded but rapidly consolidating market of vulnerability and remediation platforms. Recent related funding announcements include:


  • Emphere — $2.1 million for AI-powered vulnerability remediation
  • Opal Security — $23 million for AI-native identity governance
  • Offroad Security — $7 million for enterprise identity risk

  • A Security's distinct positioning centers on the autonomous offensive simulation component—the ability to not just identify vulnerabilities, but to validate them as exploitable and automatically remediate them without human intervention.


    ## Implications for Enterprise Security Teams


    The emergence of platforms like A Security signals a fundamental shift in how enterprises approach vulnerability management:


    1. From reactive to proactive — Organizations are moving beyond identifying vulnerabilities to actively simulating how attackers would exploit them

    2. From manual to automated — Security teams, already stretched thin, will increasingly rely on autonomous agents for both vulnerability assessment and remediation

    3. From isolated to contextual — Enterprise security tools are converging on a model that understands cross-domain attack paths, not just individual weaknesses

    4. From compliance-driven to risk-driven — Rather than simply checking boxes for patch management, organizations are moving toward proving that actual exploit paths have been eliminated


    ---


    ## HackWire Analysis


    The funding of A Security reflects a critical inflection point in enterprise cybersecurity: the industry is now racing to automate defense against automated attacks. This is no longer theoretical. AI-driven attack tools are already in use by both sophisticated threat actors and commodity malware operators, and traditional vulnerability management—built for a slower threat landscape—is breaking down.


    What makes A Security's approach significant is not just that it uses AI for defense (many vendors now claim to do this), but that it closes the exploit-path gap. Most vulnerability management tools identify isolated weaknesses; A Security's platform answers the question security teams really need answered: *Can an attacker actually chain these vulnerabilities together to compromise my critical assets?*


    The investor syndicate is equally telling. Assaf Rapaport and Yotam Segev are not investing out of idle capital—they're signaling that autonomous offensive security is becoming a core capability that security platforms need. Wiz, which has dominated cloud security investment in recent years, is essentially saying: "This problem is real enough that we want to be close to how it gets solved."


    However, there's a critical unresolved question the industry hasn't fully grappled with: Who audits the auditors? When autonomous agents are performing offensive operations—even scoped ones—against production environments, the attack surface shifts. A compromised A Security instance could become a beachhead for attackers. The company's emphasis on "full audit trails" is important, but enterprises will need to demand SOC 2 Type II attestations, third-party pentesting of the platform itself, and clear liability frameworks before deploying autonomous offensive agents in sensitive environments.


    This funding also highlights a consolidation pattern: the largest security problems are increasingly being solved by specialized platforms with venture backing, not by traditional vendors. Organizations will need to evaluate not just whether A Security's technology works, but whether this company can execute on the mission before it gets acquired or pivots.


    — HackWire Editorial


    ---


    ## Related Coverage


  • Read more in our [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)