For nearly two decades, cybersecurity optimized for the wrong problem. The question was always the same: Can we find the vulnerabilities we already know about? Traditional scanners got remarkably good at it. Compare code against known libraries. Find the vulnerability. Prevent the attack. Then Mythos changed everything. AI could discover vulnerabilities that traditional scanners never would. It learned to reason about software itself. It discovered vulnerabilities that no scanner had ever seen before. Zero-days. Real ones. And suddenly we realized - the real question is : How do you defend against AI that discovers vulnerabilities nobody knows exist? You can't fight AI-speed discovery with human-speed defense. That's why the future of cybersecurity isn't periodic vulnerability management. It's Continuous Threat Exposure Management! At Black Hat USA (August 4-6, Booths #4422 & #5506), we're unveiling what that looks like in action. Come witness the future :)
Safe Security
Computer and Network Security
Palo Alto, California 77,212 followers
SAFE has reinvented cyber risk management with Agentic AI across enterprise, third-party, and AI-related risks.
About us
SAFE has reinvented cyber risk management with Agentic AI. The company helps CISOs, TPRM, and GRC leaders become strategic business partners by automating the understanding, prioritization and management of cyber risk—accelerating AI adoption and digital transformation. SAFE is the #1 platform to unify the management of all cyber risks—enterprise, third-party, and AI-related—and deliver autonomous cyber risk management through a fleet of specialized AI agents. Its platform replaces manual effort with agentic automation, backed by the world’s most trusted risk standards. Trusted by hundreds of global organizations, SAFE has more than doubled revenue three years in a row and raised $100M+ to fuel the future of cyber risk automation.
- Website
-
https://safe.security
External link for Safe Security
- Industry
- Computer and Network Security
- Company size
- 51-200 employees
- Headquarters
- Palo Alto, California
- Type
- Privately Held
- Founded
- 2012
- Specialties
- Cyber Risk Quantification, Cybersecurity, CRQ, Cyber Risk Management, Vulnerability Management, Cloud Security Posture Management, Cybersecurity Maturity Index, Cyber Risk Scoring, Cyber Scorecard, IT Risk Management, IT Vendor Risk Management, ITVRM, Cyber Risk Assessment, Cyber Risk Posture Management, Breach Likelihood, Safe Score, Cyber Risk Quantification and Management, Cyber Insurance, Third Party Risk Management, TPRM, and Third Party Cyber Risk Management
Locations
Employees at Safe Security
Updates
-
AI just found a way around the fence! During an internal cybersecurity evaluation, OpenAI models escaped a highly isolated test environment, exploited a previously unknown vulnerability, reached the open internet, and compromised parts of Hugging Face’s production infrastructure - all in pursuit of one narrow objective: finding the answers to a benchmark. There was no malicious intent, the models simply found the most effective way to achieve their goal. This is cybersecurity’s Jurassic Park moment! You build intelligence. You surround it with rules, guardrails, and containment. Then the intelligence encounters the fence - and treats it as another problem to solve. Better sandboxes matter. Stronger guardrails matter. But fences alone will not be enough. Because you cannot defend against machine-speed attacks with quarterly reviews, static vulnerability lists, and human-only workflows. We need to fight AI with AI. That is the shift Continuous Threat Exposure Management must enable. At Black Hat USA, we are introducing CTEM AI Co-Worker - powered by 100+ AI agents that continuously discover exposures, determine what is actually exploitable, prioritize what matters most, and orchestrate remediation across your enterprise and third-party ecosystem. Not another dashboard. An autonomous AI workforce that reasons, decides, and acts at machine speed. See it live at Black Hat USA 2026. 📍Business Hall - Booth 4422 📍 AI Zone - Booth 5506 📅 August 4–6 | Mandalay Bay, Las Vegas The age of agent-versus-agent cybersecurity is here. Is your defense ready? Come say hi. Reserve a seat or book a 1:1 - link in comments :)
-
-
The gap between vulnerability disclosure and active exploitation is collapsing. This week, 12 CVEs showed confirmed exploitation signals - and 8 of them were newly published. WordPress wp2shell moved from disclosure to public exploits and real-world attacks within hours. SonicWall SMA1000 appliances were compromised through zero-days before patches were available. The recently disclosed ServiceNow AI Platform RCE is also being targeted in the wild. Meanwhile, 2,654 CVEs were published this week. But more vulnerabilities do not automatically mean better security. The real challenge is identifying where active exploitation, public exploit availability, external exposure, and business-critical systems intersect - and acting before attackers do. That is exactly why SAFE CTEM is Mythos-ready. Powered by 100+ AI agents, SAFE’s CTEM AI Co-Worker autonomously turns threat and exposure insights into prioritized action at machine speed. See it in action at Black Hat USA 2026. 📍 Business Hall - Booth 4422 📍 AI Zone - Booth 5506 📅 August 4–6 | Mandalay Bay, Las Vegas
-
100 trillion. That's how many security signals Microsoft alone processes every single day. Gartner says by 2030, over half of exposure management will run autonomously. Today, it's less than 10%. Then Mythos happened. One AI model found more vulnerabilities in weeks than humanity found in decades. Machines now attack at machine speed while most defenses still run at human speed. You can't throw more people at a machine-speed problem. If machines are finding the holes, machines have to close them too. We need to fight AI with AI. Cybersecurity spent decades building software. We're building AI Coworkers! One for your vulnerability team. One for your third-party risk team. Working like your best security engineers - discovering, validating, fixing. Around the clock. Without falling behind. We're bringing them to Black Hat - can't wait to show you what we've built. See you in Vegas! 📍 Booth #4422, AI Zone 5506, Mandalay Bay | Aug 4-6
-
-
This room is why SAFE CTEM is Mythos-ready. This week, Microsoft released its July Patch Tuesday. 570 flaws patched in a single day - an all-time record, the biggest Patch Tuesday ever. Post-Mythos, over 10,000 critical vulnerabilities surfaced in one month. AI is discovering exposures faster than any human team can triage them. Our answer is being built right here, on the SAFE One platform: - Unified exposure visibility across your entire attack surface - 150+ native integrations - Exposure validation that proves what's actually exploitable in YOUR environment - Agentic Risk Reduction that neutralizes it - powered by 100+ agentic workflows It's why 10% of the Fortune 500 already put AI to work with SAFE. What ships on August 4th takes all of this somewhere the industry hasn't seen. Last year at Black Hat, we told the industry where vulnerability management needed to go. This year, we're taking it there - our biggest leap yet, built in this very room. Come say hi at Booth #4422 - we'll show you what we've been up to! Want the full reveal before the crowd? Sneak into our calendar - link in comments. ps - this is just the half of the team that could step away from their screens long enough for a photo :)
-
-
Somewhere in a university physics department, a researcher opened an email that looked routine. No attachment or suspicious link. Just a message that quietly ran JavaScript inside their webmail. That's how the China-aligned group UNK_MassTraction has been breaking into physics and engineering departments across the US and Canada, using two Roundcube flaws (CVE-2024-42009, CVE-2025-49113) to steal credentials and plant webshells. And that's just one of 29 CVEs our Threat Research team flagged with real exploitation signals this week. Only 2 of them are new. The other 27 are older vulnerabilities attackers keep returning to, because they sit on exposed webmail servers, CMS platforms, and plugins that are hard to patch quickly. Also on our radar this week: - WP-SHELLSTORM: 1.4M websites on a single attacker's target list, thousands of confirmed compromises across WordPress and Joomla - Four Joomla extensions added to CISA KEV in one week, every one an unauthenticated file upload leading to RCE The pattern is consistent. Attackers aren't chasing the newest CVE. They're reaching for whatever is exposed, unpatched, and close to credentials. Your patch queue should follow the same logic: exploitability, exposure, and business impact first. Read full analysis - link in the comments!
-
What do avocados have to do with cyber risk? More than you'd think :) We recently gathered our CXO Advisory Board for an evening of radical transparency and it started with a guacamole-making competition. The metaphor wrote itself: security leaders spend their days mashing together siloed ingredients - infrastructure data, application vulnerability logs, third-party questionnaires trying to blend disparate elements into a seamless solution. Then came the uncomfortably honest part. Security leaders from Shelter Insurance, BECU, Blackbaud and more shared what's actually broken: - Stop chasing a fictional level of precision. The board doesn't need decimal-point precision; they need realistic financial ranges. Prove that a $6M investment can reduce a catastrophic risk range from $100M to $20M, and budget approvals shift from an uphill battle to an objective business decision. - "Patch everything" is fundamentally broken. With vulnerability counts projected to grow up to 50X, teams must prioritize ruthlessly on real-world exposure context - not raw counts. - AI adoption is outpacing governance. Organizations are increasingly forced to deny AI access by default and allow it only through explicit exceptions. Our engineering philosophy is to build solutions that are 10 times better, not 10% better. When our customers tell us where the industry is broken, we don't just listen - we ship the code. Thank you to our CXO Advisory Board for their raw honesty. And congratulations to our guacamole champions, Travis Nichols and Tushar Bansal. Full recap in the comments!
-
-
SAFE CTEM is Mythos-ready. Is your security program? (No judgment if the honest answer is "we're working on it." That's most of the industry right now) Vulnerability discovery now moves at machine speed. Remediation still moves at human speed. That gap is the defining exposure problem of 2026 - and closing it is what Black Hat USA will be about this year. At Booth 4422 (Business Hall) and 5506 (AI Zone), see the Autonomous CTEM Platform live: 100+ specialized AI agents running the full exposure lifecycle - so your team can stop chasing 50,000 findings and start making the 5 decisions that matter. And when your feet give up (they will, it's Black Hat), the SAFE Theater has a seat with your name on it. 15-minute sessions, every hour, zero pitch. We promise. Come say hi. Reserve a seat or book a 1:1 - link in comments!
-
-
Somewhere right now, an AI model is finding a vulnerability faster than your team can even open the ticket. That's not a scare line. That's just what happened when Mythos started hunting for bugs on its own - thousands of high and critical-severity flaws, surfaced in weeks, across software the whole internet runs on. Here's the thing about vulnerability management: for 25 years, the instinct never changed. Scan more. Score more. List more. We built an entire industry around getting better at finding things. Mythos just proved that was never the hard part. Discovery - the thing we've optimized for since the late 90s basically stopped being the bottleneck overnight. The bottleneck now is us. Human teams trying to verify, prioritize, and fix a flood that AI can generate far faster than any org can absorb. And the tools most teams still lean on weren't built for this. A critical CVE on a forgotten test server is not the same as a medium-severity exposure sitting one hop away from a crown-jewel system. CVSS does not always know the difference. Attackers do. That is the shift CTEM was built for. Not another dashboard or a longer backlog. But a continuous program that starts with what the business cannot afford to lose, validates real attack paths, quantifies business impact, and drives remediation all the way to closure. In Part 1 of our CTEM series, Ramesh Ramachandran, Director, Product Management at SAFE, breaks down how vulnerability management evolved over the last 25 years, where it broke, and why the next era has to be different. And this is also why we are especially excited for Black Hat this year ( More on that soon) :) Finding more was never the finish line. Knowing what matters, mobilizing the right teams, and proving the risk actually went down - that is the future of exposure management. Read the full blog - link in comments!
-
We spent the last month making TPRM disappear - in the best way possible. 🚀 Here's what's new in SAFE TPRM: 1. Agentic Workflows - built by you - Design and automate your entire third-party lifecycle with a no-code, drag-and-drop workflow builder. Leverage pre-built templates, AI-powered actions, and customizable automations for onboarding, assessments, approvals, notifications, and more - with version control and complete run history built in. 2. Smarter onboarding with AI-powered Intake Forms - SAFE AI reviews uploaded intake forms, extracts vendor information, and automatically populates third-party records - accelerating onboarding while improving data quality. 3. Smarter Outside-In Intelligence - Sharper asset attribution with transparent discovery reasoning, plus expanded fourth-party intelligence for deeper supply chain visibility. 4. Understand every Exposure Score change - See exactly what changed - and why. Track Exposure Score trends over time with AI-generated summaries and detailed change history across findings, questionnaires, assets, and breach events. 5. AI Review, on your terms - Define review guidelines once, and SAFE AI applies them to every vendor response automatically. Reduce assessment cycle time by catching missing evidence, incomplete responses, and weak justifications before analysts ever need to step in. Plus: - Redesigned Global Settings - Complete Activity Timeline for audit visibility - 50+ new AI-powered document categories - 100+ AI agents. One platform. Zero manual toil. If you're heading to Black Hat USA 2026, stop by and see the SAFE team in action! Until then, explore what's new: https://lnkd.in/eA7xz8kv