a16z|Oct 06, 2026 16:52
Kevin Mandia on finding 90+ security holes at Fortune 500 companies that nobody knew existed:
"When you have an AI-based attack, it'll find logic flaws rather than code flaws in custom applications. It'll exhaust all routes all the time."
"Armadin, since January of this year, we have found over 90 zero-days at customer sites, all in production."
"We've post-trained all our models with real red teamers, real folks that actually can develop exploits."
"When we're scanning networks, we don't have source code to review. We're not finding these zero-days with source code. We're not finding these zero-days because we can log into an app and now we have access, and we can get to other things. We are black box coming from the internet."
"Over 90 zero-days in major software companies, and they're thankful. We're coming from the outside, and then we're calling a CISO, usually within 48 hours, 'Hey, we've got remote code execution in your DMZ.' And usually from there we're getting in, and they agree with us."
"That's not a pen test. That is like a real adversary coming at you."
@ArmadinSecurity @DavidGeorge83
Share To
Timeline
HotFlash
APP
X
Telegram
CopyLink