{"slug": "empirical-security-raised-25m-to-predict-which-flaws-hackers-will-actually", "title": "Empirical Security raised $25M to predict which flaws hackers will actually exploit", "summary": "Empirical Security raised $25 million in Series A funding led by Brightmind Partners to predict which software vulnerabilities hackers will actually exploit, CEO Ed Bellis told Axios. The Chicago startup, which brings total funding to $37 million, sells two predictive models — Foundation, which tracks over 18,000 CVEs globally, and Radiant, which trains on a single organization's assets — to help security teams prioritize flaws as AI accelerates the pace of attacks.", "body_md": "Most security teams face the same problem. There are far more flaws than anyone can fix, and no clear way to know which ones matter. Empirical Security wants to predict the answer.\n\nThe Chicago startup’s Series A was led by Brightmind Partners, chief executive Ed Bellis told [Axios](https://www.axios.com/pro/enterprise-software-deals/2026/07/20/cybersecurity-empirical-security-ai-25-million), which first reported the round. It takes total funding to $37 million. Earlier backers Costanoa Ventures and Hyde Park Angels returned for the round.\n\n## Unfinished business\n\nThe pitch has history. Bellis and his chief technology officer, Michael Roytman, built Kenna Security, the firm that helped popularise risk-based vulnerability management. The idea was simple: stop treating every flaw the same, and focus on the ones most likely to be exploited.\n\nIt helped, but the job was never done. The backlog kept growing as cloud, SaaS, APIs, and third-party code piled on new exposure. Bellis calls Empirical his [“unfinished business.”](https://research.empiricalsecurity.com/research/empirical-series-a) He has brought in Jay Jacobs, co-creator of the widely used EPSS exploit-scoring system.\n\n## Two models\n\nEmpirical sells two predictive models. Foundation is the global one. It watches more than 18,000 CVEs with real exploitation activity, tracking what attackers are actually using across the internet.\n\nRadiant is the local one. It trains on a single organisation’s own assets, telemetry, and cloud setup, then predicts the threats most relevant to that environment. Foundation tells you what is happening globally, Bellis says, and Radiant tells you what is likely to matter to you.\n\n## Why now\n\nThe timing is not an accident. [AI is speeding up](https://thenextweb.com/news/gpt-red-openai-ai-hacker) the pace at which attackers find and exploit weaknesses, and the window to respond keeps shrinking. It can even [run breaches on its own](https://thenextweb.com/news/hugging-face-ai-agent-breach-glm-forensics).\n\nAttackers now turn newly disclosed flaws into [working exploits](https://thenextweb.com/news/gravity-smtp-wordpress-plugin-vulnerability-cve-2026-4020-api-keys-exploit) faster than ever. Bellis argues the defence has only just caught up. Three years ago the data was too fragmented and the modelling too immature to try this properly.\n\nThat has changed. Security data lakes now pool telemetry that once sat in separate systems. Better AI can mine and reason over huge volumes of signal, and models can be trained against real-world exploitation rather than static severity scores.\n\n## A crowded field\n\nEmpirical is not alone in selling AI-driven defence. A steady run of [security startups](https://thenextweb.com/news/neuraltrust-20-million-seed-ai-agent-security) has raised on the promise of taming AI-era risk, part of a wider scramble to secure the [AI-agent era](https://thenextweb.com/news/ai-agent-security-four-attacks-one-flaw). Exposure management is a crowded market, and $25 million is modest by its standards.\n\nThe performance claims, for now, are the company’s own. One customer says its engineers are “addicted” to checking the tool daily, a nice line that still needs independent proof. The bet is that prediction, tuned to each organisation, beats another generic risk score.\n\nPrediction, Bellis argues, has become a requirement for modern defence, not a luxury.\n\n## Get the TNW newsletter\n\nGet the most important tech news in your inbox each week.", "url": "https://wpnews.pro/news/empirical-security-raised-25m-to-predict-which-flaws-hackers-will-actually", "canonical_source": "https://thenextweb.com/news/empirical-security-series-a-exploit-prediction", "published_at": "2026-07-21 14:01:57+00:00", "updated_at": "2026-07-21 14:50:28.463705+00:00", "lang": "en", "topics": ["artificial-intelligence", "ai-startups", "ai-products", "machine-learning"], "entities": ["Empirical Security", "Brightmind Partners", "Ed Bellis", "Michael Roytman", "Kenna Security", "Costanoa Ventures", "Hyde Park Angels", "Jay Jacobs"], "alternates": {"html": "https://wpnews.pro/news/empirical-security-raised-25m-to-predict-which-flaws-hackers-will-actually", "markdown": "https://wpnews.pro/news/empirical-security-raised-25m-to-predict-which-flaws-hackers-will-actually.md", "text": "https://wpnews.pro/news/empirical-security-raised-25m-to-predict-which-flaws-hackers-will-actually.txt", "jsonld": "https://wpnews.pro/news/empirical-security-raised-25m-to-predict-which-flaws-hackers-will-actually.jsonld"}}