Interview with Snehal Antani
Snehal Antani, CEO and co-founder of Horizon3 joins us to talk about how automated validation can help with exposure management. As vulnerability counts spike, security teams are looking for a way to prioritize. Automated penetration testing offers a way to quickly separate exploitable vulnerabilities from the rest.This segment is sponsored by Horizon3. Visit https://securityweekly.com/horizon3 to learn more about them!Topic Segment - SmartTVs and Privacy
For this week's topic segment, we explore privacy and TVs. LG has been in the news for allegedly collecting data from its customers, but the facts are unclear.We share our recent experiences and dive into some of the primary concerns and theories about what's going on here.If you want to opt out of some of your TV's data collection, Consumer Reports has a collection of instructions for a variety of TV platforms.Weekly Enterprise News
Finally, in the enterprise security news,- We check the vibes
- We check finding and acquisitions
- Nightmare Eclipse or Good Night of Sleep Eclipse?
- Update on Anthropic’s Glasswing project
- How long would it take for a mobile phone worm to spread?
- Don’t expose SSH to the public Internet
- Massive amounts of cryptocurrency continue to get stolen
- Did you actually read your third party’s SOC 2?
- Your boss may be reading your AI chat history
Snehal Antani is the Co-Founder and CEO of Horizon3.ai, where he leads the company’s mission to empower organizations to proactively defend their infrastructure through autonomous security solutions. With a unique blend of entrepreneurial, public sector, and enterprise leadership experience, Snehal previously served as CTO of JSOC, CTO at Splunk, and CIO at GE Capital. An industry-recognized technologist and innovation advocate, Snehal holds 18 U.S. patents in data processing, cloud computing, and virtualization. He is a sought-after keynote speaker and a prolific writer on topics including leadership, digital transformation, cybersecurity, and cloud architecture.
- Security leaders, you can’t secure what you can’t see. Between cloud sprawl, SaaS, and shadow IT, most organizations don’t have a complete picture of their attack surface.So how do you measure and reduce exposure?At the Attack Surface Management Virtual Cybersecurity Summit on September 16th, learn how leading teams are gaining continuous visibility and turning unknown assets into managed risk.Security Weekly listeners can register for free at https://securityweekly.com/ASM using the promo code: CSS26-SW
- Unlock the full InfoSec World experience with the All Access Pass, featuring premium workshops, exclusive content, VIP experiences, and expanded opportunities to connect with cybersecurity leaders across industries. Join us in Orlando, October 12–14. Listeners save 30% on their pass with code ISW26-SWSAVINGS at securityweekly.com/infosecworld2026.
Adrian Sanabria
- FUNDING/M&A courtesy of the Security, Funded newsletter, issue #260 – Model Behavior
VIBE CHECK
Five years out, who owns security for the mid-market?
- 46% - MSSPs / MDRs
- 23% - Platform Giants
- 23% - AI Agents
- 8% - Nobody, still DIY
**FUNDING **
- Upwind Security, an Israel-based cloud native application protection platform, raised a $300.0M Venture Round from Bessemer Venture Partners and TCV.
- HiddenLayer, a United States-based platform protecting against adversarial machine learning (AML) attacks, raised a $100.0M Series B from Delta-v Capital.
- AIR Security, a United States-based AI agent supply chain security platform, raised a $40.0M Seed from Greenoaks.
- Guardio, an Israel-based remote browser isolation platform, raised a $40.0M Venture Round from Assaf Rappaport, Cerca Partners, Emerge Ventures, ION Crossover Partners, Union Tech Ventures, and Vintage Investment Partners. -> Unicorn Alert ????
- Lasso Security, an Israel-based platform focused on secure Large Language Model (LLM) usage in enterprises, raised a $30.0M Seed from ClearSky.
- Huskeys, an Israel-based AI-driven network edge security management platform, raised a $27.0M Series A from Blackstone Innovations Investments.
ACQUISITIONS
- Console, a United States-based agentic AI service and asset management platform, was acquired by Palo Alto Networks for $500.0M.
- DoControl, a United States-based SaaS security posture management (SSPM) and data access control platform, was acquired by Spin.AI for an undisclosed amount. DoControl had previously raised $43.4M in funding.
- VULNERABILITIES: Zero Day Clock
After getting called out by Root Evidence's latest report for bad math, the Zero Day Clock website has a fresh look. Is it any better?
- VULNERABILITIES: Serial Microsoft 0-day hunter drops yet another Defender exploit
Nightmare Eclipse? More like GoodNight's Sleep... Eclipse! Or something. Got 'em.
- VULNERABILITIES: The Anthropic Glasswing Receipts Are Starting to Trickle In
The big takeaway here? Human bottlenecks are EVERYWHERE and prevent AI from 10x/100x/1000x most processes. The truth is that most of our businesses and processes can't instantly scale even 5x, so what good does it do you if AI can go far beyond that?
It's like giving someone a car that can go Mach 2. There are speed limits, so you might as well get good fuel economy, save money, and drive something economical. What's the AI equivalent of that?
- VULNERABILITIES: WeWorm
Boy, am I glad they coordinated disclosure and a fix before releasing this.
Naturally, I had to do some analysis here. I watched the video and noticed it took 20 seconds for the infection to complete and call the next phone. Doing some quick math, I discovered it would take only 10 minutes for the worm to reach 1 billion devices. Of course, I suspect the WeChat servers would give up the ghost long before that happened. Around 6:40, 1 million devices would be calling 1 million other devices simultaneously, 2 million 20 seconds after that...
commence servers melting
- INTERNET ASBESTOS: MikroTik routers hijacked, Russian data center threats, UK cybercrime losses surge
- AUDITS: Customs and Border Control got cyber-audited and got an F on their security posture
- BREACHES: Bitcoin-based Liquid Network says $320 million withdrawn in hack
Totally wasn't cybercrime. They swear they were white hat hackers, because they gave most of the bitcoin back. They only held back $47M, no biggie.
- ESSAYS: The changing security risk calculus in the age of AI
Some interesting thoughts here, though I worry we're making WAY too many assumptions about what AI can and can't do.
For example: assuming coding patches is a solved problem now. Or that AI coding is unproblematic. There are entirely new classes of problems emerging from AI use.
- THREAT INTEL: BengalSEO Part 1: Anatomy of the Operation – The DFIR Report
- GRC: The Assurance Gap
Man, if you can't get your controls on your SOC 2 right, how bad is your actual security???
- BIG YIKES: Your boss, tech companies and police can read your chatbot conversations
I've worked a LOT of internal incidents. This is going to get interesting and DFIR folks are going to need some brain bleach.
- SQUIRREL: Violoop – Screen-Aware AI Hardware for Any PC
Would you use this?
