Pre-Vegas week:
the announcements, the money, and your homework.
Next week is Black Hat, so naturally this issue covers BlackHat-related themes. Most security companies use the weeks leading to RSA and BlackHat to make product and business announcements, and this week was no exception. Lots of product launches, but also several key funding and transaction news. Some thought leaders used this opportunity to take stock of where the industry is going. And my humble suggestions for how to approach the hacker summer camp week. Let’s dig in.

Las Vegas, Freemont Street - Circa 1940 (Credit: Freemont Street History)
This Week's Signals
$1.7B says agents are the next endpoint
Security companies time their biggest announcements for the run-up to Vegas, and this year nearly every dollar pointed at the same problem: securing AI agents and the identities they run on. The past two weeks:
Glow: $180M all-equity Series A at a $1.2B valuation (Sequoia, Cyberstarts, Greenoaks, Redpoint) to rebuild endpoint security for the AI era.
Neo: $100M total ($75M Series A led by a16z and Bessemer), founded by three SentinelOne veterans including Nick Warner, pitching agentic software control.
Oak: $60M seed co-led by Accel, Greylock, and CRV for an AI-native identity OS, from Ermetic founder Shai Morag.
Act Security: $60M across seed and Series A to secure cloud environments and the AI agents inside them.
AegisAI: $36M Series A led by Battery Ventures to stop AI-generated spear phishing, from ex-Google security execs.
Twenty: $30M add-on from Khosla Ventures at a $1.2B valuation for offensive cyber, on top of its Accel-led $100M Series B.
Empirical Security: $25M Series A led by Brightmind Partners; the Kenna founding trio, now predicting exploitability per customer environment.
Cyera acquired Oasis Security: roughly $1B (about $700M cash), the second-largest security deal of 2026, weeks after Cyera raised $600M at a $12B valuation.
Okta acquired Permiso: just under $200M per TechCrunch, Okta's biggest identity security move since Auth0.
Keyfactor announced intent to acquire Cofide: verified identity for AI agents and cloud workloads.
June was the warm-up act with the same theme: SailPoint bought Entro (roughly $200M per Calcalist) for non-human identity and secrets security, and Cisco announced its intent to acquire WideField to feed identity and session telemetry into Splunk's agentic SOC. Everyone cites the same Gartner projection: enterprise apps with agentic capabilities going from about 5% in 2025 to 40% by end of 2026.
The numbers in context: Roughly $490M in fresh funding and $1.2B in disclosed M&A in two weeks, nearly all of it betting that agents operating with legitimate permissions are the next endpoint and identity is the control point.
Pre-Vegas Case: Arm Your Defenders or Gift the Advantage to Adversaries
Frank Wang's last Frankly Speaking before Hacker Summer Camp argues that security teams blocking internal AI adoption are creating an asymmetric advantage for attackers, who already run frontier models and uncensored open weights with zero governance overhead. This argument is worth noting: blocking Cursor doesn't slow adversaries down, it forces your developers into shadow AI while your analysts operate at human speed. He borrows the framing from Dario Amodei's open-weights essay: focus on the adversary, not the technology. And he wants security to flip from corporate brake pedal to the loudest internal advocate for unrestricted defender AI tooling.
Here's what I think: He's right, and the recent events are the proof. If a model can build a fuzzing lab in a day, your defense needs the same leverage.

Balance and Asymmetry by Victor Castanera
Your Vegas Homework: Darwin's Summer Camp Field Guide
Darwin Salazar published his 2026 Hacker Summer Camp Field Guide this week, and with 30 to 40 thousand of us descending on Vegas, it's the prep doc worth reading first. It's his eighth Summer Camp, so I was glad to see DevArmor's CISO Roast make his shortlist. Other events Darwin noted: the Black Hat Startup Spotlight (Deception Check, Mallory, Opnova, and Perpetual Systems competing at the Innovators and Investors Summit), and Decibel GameDay with Kevin Mandia and Rob Joyce.
One takeaway: Given everything above (sandbox escapes, SDLC collapsing, machine-speed discovery), walk the floor with one filter: does this help my team triage faster and make my devs self-sufficient? Darwin's guide is the map; that question is the compass.

CISO Roast - Wednesday August 5th
My Take:
Every Assumption Behind Your AppSec Program Broke This Year
For twenty years, AppSec was organized around one constraint: finding vulnerabilities is hard. That assumption funded the scanner industry, shaped how we hire, and defined what "coverage" means. This year it broke. FIRST's mid-year forecast now projects roughly 66,000 CVEs for 2026, and the exploit window is measured in hours.
What becomes scarce is everything after discovery: deciding what's real, what's reachable, what actually matters in your environment, and fixing it without breaking the business. The advantage is no longer in finding bugs but in confirming, severity-rating, patching, and coordinating. That's judgment work, and it lives at the design level, in the context a vuln-finding tool never sees.
The other assumption that was debunked this year: that security teams will have time to review every single code change and prevent bad code from being checked into prod. With AI now writing the overwhelming majority of code on some teams (Anthropic and Google have both said AI writes most of their new code), the traditional SDLC has completely collapsed into "ticket + prompt”, requiring a new paradigm to secure.
If your 2027 AppSec plan still measures success in findings or reviews per quarter, I'd push back on it. Where does this land in your org? Reply and tell me, I read every one.
Until Next Time
Next week is Black Hat, DEF CON, and BSidesLV, which means half of you are reading this from an airport lounge. If you're in Vegas and want to talk about any of this, especially the triage problem, come find me. I'll be at booth 5808, wandering the conference halls, or in the coffee line grabbing my next caffeine fix.

What am I getting wrong here? Tell me.
- Amir

Thanks for reading The AppSec Signal, DevArmor’s newsletter for security professionals.
Have feedback or ideas for what we should cover next?
Feel free to reach out - [email protected]


