# $60 Million Says Patching Is Broken — Runtime Security Is the Bet


The average time between a critical vulnerability disclosure and its first exploit in the wild has collapsed from weeks to days. In some cases, researchers are now measuring it in hours. Oligo Security's $60 million Series B — announced today, bringing the Tel Aviv company's total raised to $140 million — is a direct wager that defenders can't patch their way out of that math anymore.


The round pulled in Ballistic Ventures, Lightspeed, Greenfield Partners, Canon Capital, Red Dot Capital, TLV Partners, and angels. Ballistic, which led and increased its position, framed the thesis plainly: "Runtime is where the business lives."


That's not marketing language. It's an acknowledgment that the security industry has been solving the wrong problem.


## Scanning for Ghosts


For years, the dominant model in application security was static: scan the code before it ships, generate a list of CVEs, hand that list to developers, and wait for patches. This model had one fatal assumption baked in — that you'd know which vulnerabilities actually mattered before attackers figured it out.


Log4Shell destroyed that assumption in December 2021. A zero-day in a library used by thousands of applications, exploited globally within 12 hours of proof-of-concept publication. SCA tools could tell you which software had the vulnerable Log4j dependency. What they couldn't tell you was which of those applications were actually calling the vulnerable code path at runtime — which meant security teams were triaging thousands of findings with no reliable way to sort existential risk from noise.


XZ Utils in 2024 was a different flavor of the same problem. The backdoor wasn't in a known-vulnerable library. It was deliberate, signed, and merged. No static CVE database in existence would have flagged it.


These aren't edge cases anymore. They're the dominant failure mode.


## What Runtime Visibility Actually Buys You


Oligo's platform operates on a principle called code execution observability — instrumentation at the application layer that watches what actually runs in production. The logic is straightforward: if you can see which functions execute, which libraries are actually invoked under real traffic, and what behavior those calls produce, you can filter out the 80% of CVEs that exist in your dependency graph but are never reached during execution.


That changes the economics of vulnerability management completely. Instead of triaging a scanner output of 4,000 findings, defenders work with a much shorter list of things that are actually reachable and actually running. The rest can be deprioritized until the next patch cycle.


The supply chain protection angle is where it gets more interesting. Oligo claims the platform can catch attacks that originate from compromised dependencies — the kind where the code itself has been tampered with upstream before it reaches your environment. Runtime behavioral analysis can detect when a library starts doing something it wasn't doing last week: reaching out to unexpected IPs, spawning shells, accessing credential stores. A static scanner has no visibility into this class of attack; it trusted the dependency before it was compromised.


Virtual patching — blocking exploit attempts at the application layer without requiring an emergency patch deployment — buys organizations something genuinely valuable: time. Patching production systems at emergency speed, under incident pressure, causes outages. Having a compensating control that blocks the specific exploit chain while a proper fix is tested and staged is operationally meaningful, not just theoretically nice.


## The AI Era Wrinkle


Oligo's pitch leans into AI-era threats, which is either prescient or convenient depending on your cynicism level. The specific claim is that the exploitation window has shrunk in the AI era — and there's real evidence for this. AI-assisted exploit development is reducing the expertise barrier for weaponizing disclosed vulnerabilities. What once required a skilled exploit developer to work through for days can now be rough-drafted in hours with LLM assistance, cleaned up, and deployed.


If that trend continues — and there's no reason to expect it reverses — the premise of "disclose, scan, patch in the next sprint" becomes untenable. You need something running at runtime that can interrupt the exploit before the patch is ready.


The company also covers AI workloads specifically, which in 2026 means protecting model inference endpoints, agentic pipelines, and the tooling chaos that most organizations have deployed faster than their security teams could audit it. This is the new attack surface, and static analysis is even less equipped to handle it than it is for traditional apps.


## HackWire Analysis


$140 million into a four-year-old company that hasn't yet reached the scale of incumbents like Contrast Security, Dynatrace's security layer, or Datadog's application security product tells you something about where the investment community thinks the market is heading. Ballistic Ventures doesn't make these bets casually — they backed some of the formative modern security companies and they're increasing their position here, which matters.


But there's a question worth asking that none of the announcement coverage is engaging with: runtime security has been tried before. The previous generation — RASP, or Runtime Application Self-Protection — emerged around 2014-2015, had a moment, and largely faded into a niche. It was criticized for performance overhead, high false positive rates, and the operational headache of injecting agents into production workloads. Vendors like Imperva, Sqreen (acquired by Datadog), and Signal Sciences (acquired by Fastly) all took runs at various corners of this problem.


What Oligo is betting is that the category failed before because the tooling wasn't mature enough, not because the concept was wrong. Observability technology has advanced significantly. eBPF-based instrumentation, which operates at the kernel level without heavy application agents, has changed what's possible for low-overhead runtime visibility. The AI-assisted exploit development threat is genuinely new pressure.


The real test isn't whether the technology works in a demo environment — it's whether security teams can operationalize it without adding friction to engineering velocity. Every runtime security product that came before eventually died on that altar. If Oligo has cracked the deployment and noise problem, $60 million is early-stage money for a large market. If they haven't, it's a well-funded repeat of history.


Defenders evaluating this category should ask hard questions about eBPF agent overhead in their specific stack, false positive rates in high-traffic production environments, and what the integration story looks like with existing SIEM and SOAR tooling. The pitch is compelling. The track record of the category warrants skepticism.


— HackWire Editorial


---


## Related Coverage


  • Read more in our [Breaches](https://www.hackwire.news/category/breaches) coverage
  • Cross-reference with [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)