Friday, 02 October 2026 PDT | 04:48 AM
The 1 News Alt Logo Text Smart News for Global Indians

Offensive Security Startup Armadin Raises $255.5M Series B at $2.5B+ Valuation

Business October 02, 2026 11:00 AM
Offensive Security Startup Armadin Raises $255.5M Series B at $2.5B+ Valuation

Offensive Security Startup Armadin Raises $255.5M Series B at $2.5B+ Valuation

There used to be time to patch a vulnerability after it was disclosed. Not anymore. Google Cloud’s Mandiant M-Trends 2026 report found that 28.3% of CVEs disclosed this year were exploited within 24 hours, and the average time-to-exploit has gone negative — attacks now routinely start before a patch even exists. CrowdStrike’s 2026 Global Threat Report tells a similar story: average breakout time, the time it takes an attacker to move laterally after initial compromise, fell to 29 minutes, with the fastest observed case at just 27 seconds. As AI accelerates the offense, periodic pentests and scanners that score vulnerabilities in isolation can no longer keep pace, by the industry’s own account.

Armadin, an offensive-security startup built to close that gap, said it has raised $255.5 million in a Series B. The round was co-led by Andreessen Horowitz (a16z) and Accel, pushing the company’s valuation above $2.5 billion. Bain Capital Ventures (BCV) and Redpoint joined as new investors, while existing backers 8VC, Ballistic Ventures, Google Ventures, In-Q-Tel, Kleiner Perkins, and Menlo Ventures all returned. That brings Armadin’s total funding to $445 million — just seven months after it exited stealth with a combined $189.9 million seed and Series A, itself the largest combined seed-and-Series-A round in cybersecurity history at the time.

AI Attack Squads Do the Breaking-In, Not Humans

Armadin runs a swarm of autonomous AI agents that reason across an organization’s full attack surface the way a human adversary would. Individually low-severity flaws get chained together into validated “kill chains” — paths running from unauthenticated remote code execution at the perimeter, through lateral movement, to full cloud compromise. Instead of a theoretical risk score, security teams see the exact attack path an adversary could use today, along with its blast radius, and can sever it before it’s exploited. The company says it’s already running these campaigns in production for Fortune 500 enterprises and government customers, seven months after leaving stealth.

The Founder Is “the Mandiant Guy”

CEO Kevin Mandia is already a near-mythical figure in security circles. He founded a forensics and incident-response firm in 2004 that became Mandiant in 2006, then joined FireEye as CEO when it acquired Mandiant for $1 billion in 2013. When FireEye sold off its product business in 2021, Mandiant re-emerged as a standalone threat-intelligence and response company — which Google then acquired for $5.4 billion in 2022. Mandia stayed on as CEO of Mandiant under Google Cloud until stepping down in May 2024.

He didn’t leave security behind. He joined cybersecurity-focused venture firm Ballistic Ventures as a general partner, and in October 2024 joined the board of security startup Expel. Then, in March 2026, he bet 30 years of credibility on a new company and launched Armadin out of stealth. Just before this Series B, in September, he was elected to Amazon’s board, also joining its Audit and Security committees. Explaining why he started Armadin, Mandia has said: “When attacks move at machine speed, defense must become autonomous. It will not be feasible to have a human in the loop for every defensive decision and expect to win.”

On this round, Mandia said: “Offense is uniquely advantaged right now. AI lets an attacker find and chain weaknesses faster than any human team can respond. The only way to build a defense that keeps pace is to train it against the best offense available, every day. That is what we built. With a16z and Accel co-leading and the support of every investor in this round, we are going to put that offense to work for the enterprises and government agencies defending the world’s most critical systems.”

Accel partner Ping Li said: “Against agentic adversaries, the best defense is a great offense powered by AI. That was our conviction when we led Armadin’s Series A, and it’s even more pressing today. In less than a year, Armadin has set the standard for AI-powered offensive security and remediation across enterprises and governments.” Andreessen Horowitz general partner David George added: “Every major platform shift creates a new generation of security leaders, and AI is the biggest shift we’ve seen. Kevin has been on the front lines of the most consequential breaches in history, and he has built a team that pairs elite red teamers with world-class AI engineers. We invested because we believe Armadin will become the defining security company of the AI era.”

Competitors: A Three-Way Race in AI Offensive Security

Armadin is entering a market that already has several serious players in autonomous, agentic pentesting. The most established is Horizon3.ai, which has run its agentless autonomous pentest product, NodeZero, since 2019 — the longest track record in the category, spanning internal, external, cloud, Kubernetes, and identity environments, with automated re-verification after a fix is applied. Horizon3 closed a $250 million Series E in August at a valuation above $2 billion, as wowtale covered at the time, bringing its total funding to $428.5 million; it counts more than 6,500 organizations as customers, including the NSA and CISA.

XBOW has focused its large-scale parallel agents specifically on web applications. It drew attention after topping HackerOne’s US leaderboard for vulnerability submissions in the second quarter of 2025, and has since raised multiple additional rounds to cross a $1 billion valuation. Its customers include Moderna and Samsung Data Systems.

Pentera, the more established incumbent, has built its business around “automated security validation” — continuous, productized pentesting rather than agent-driven discovery of novel attack paths. It raised a $60 million Series D last year at a valuation above $1 billion and counts more than 1,000 customers across 60 countries. Where Armadin, Horizon3, and XBOW all lead with AI agents finding new attack paths on their own, Pentera has leaned more into repeatable validation for regulatory and compliance needs — a different emphasis within the same broader category.