
- Milan’s Bynario raised €2.1 million in pre-seed funding led by 360 Capital Companions.
- Its AI-assisted Apple bug practically went unreported amid a bug bounty backlog.
- Vulnerability exploits now trigger 31% of breaches, edging out stolen credentials.
In August, the Monetary Instances reported that Apple had began capping what number of vulnerability stories particular person researchers may undergo its bug bounty program, after a wave of fabricated findings — what safety researchers now name “AI slop” — overwhelmed Apple’s evaluation workforce.
Caught in that backlog was a seven-person Milan startup that had been utilizing AI fashions to hunt for macOS bugs of its personal. Bynario’s chief government, Alfredo Pesoli, informed the FT the flaw his workforce had present in Apple’s Display screen Sharing expertise may fetch as much as $200,000 on the black market. Apple finally reviewed the submission and patched it.
Bynario has now turned that scrutiny into cash: the corporate has raised €2.1 million in pre-seed funding, led by 360 Capital Companions, with participation from PranaVentures.
Constructing the repair no one else presents
Bynario, based in 2025 by Alfredo Pesoli, Giancarlo Russo and Lorenzo Cavallaro, builds an autonomous software safety platform known as Atlas that scans code, cloud infrastructure and software program provide chains for exploitable flaws.
Relatively than flagging each potential difficulty the best way most scanners do, Atlas is constructed to substantiate which vulnerabilities are literally reachable in a buyer’s particular surroundings, then prioritise and assist repair them. A scanner would possibly flag tons of of theoretical weaknesses in an organization’s cloud setup. Briefly, Bynario’s pitch is to inform a safety workforce which handful an attacker may exploit that week.
The pre-seed spherical will go towards increasing Bynario’s engineering workforce and constructing out the platform for enterprise prospects, although the corporate has not disclosed particular hiring targets.
It comes from 360 Capital Companions, a Paris- and Milan-based enterprise agency with greater than €700 million underneath administration and a portfolio of over 80 corporations, together with robotics unicorn Exotec and fellow Italian cybersecurity startup Equixly. PranaVentures, the spherical’s different backer, merged with fund supervisor P101 SGR earlier this yr to kind a platform overseeing greater than €600 million.
“Defence at scale wants the identical depth as offense. Attackers are basically incentive-driven. As AI continues to scale back the price of vulnerability analysis and exploitation, extra exploitable vulnerabilities grow to be engaging targets. The problem for defenders is barely changing into extra acute,” mentioned Pesoli.
AI is altering the cybersecurity arms race
Bynario is coming into a safety market the place practically each latest funding spherical has an AI angle, even when the targets differ.
Escape raised $18 million in March to run AI brokers in opposition to dwell manufacturing methods, looking for logic flaws that solely present up as soon as code is deployed. Qevlar AI raised $30 million the identical month to automate the alert investigations that swamp company safety operations centres. Mindgard raised $30 million in August to red-team AI fashions and brokers themselves, turning up flaws in instruments like Cursor and ChatGPT.
Not one of the three covers what Bynario is making an attempt to personal: the total loop from discovering a vulnerability, to proving it’s exploitable, to truly closing it.
“Bynario’s method of autonomous vulnerability discovery, validation, prioritisation, and remediation is what is required in trendy cybersecurity,” mentioned Cesare Maifredi, companion at 360 Capital.
Giancarlo Russo, Bynario’s co-founder and chief working officer, pointed to the workforce’s blended background as the corporate’s edge: “We’ve assembled a workforce of safety researchers, engineers, entrepreneurs, and teachers who perceive each the speculation and apply of cybersecurity. That mixture permits us to bridge the hole between cutting-edge safety analysis and sensible options that organisations can deploy at scale,” he added.
Bynario needs enterprises to belief AI to search out and repair their vulnerabilities sooner than attackers can exploit the. Whether or not autonomous validation is the repair, or whether or not the business finally ends up needing people to referee the AI referees, is the open query.
