Welcome back to the Trident Radar
A slightly bumper edition this week. The short catch-up issue for the first week of June did not make it out, so we have rolled the first two weeks of the month into one and covered everything from 1 to 14 June, plus a couple of deals from the 15th and 16th that were simply too big to hold over, Ent's seed among them.
Two things defined the fortnight. The first was money pouring into the layer that secures AI: Cyera raised $600 million, Ent came out of stealth with a $100 million seed, and NewCore added another $66 million, all of it aimed at securing how humans and AI agents actually behave. The second was consolidation rolling on in identity, with SailPoint taking Entro and 1Password taking Apono, exactly the pattern our Bold Call is built on.
Let's dive in.
TL;DR
Cyera raises $600M at a $12B valuation. The data security platform's Series G, one of the year's largest cyber rounds.
Ent emerges from stealth with a $100M seed. Intent-aware security for human and AI-agent activity, from the RiskIQ founders, and one of the biggest seeds in cybersecurity history.
NewCore raises a $66M seed. Identity security for human and AI-agent identities, out of Tel Aviv at a $300M valuation.
SailPoint acquires Entro, 1Password acquires Apono. Non-human identity and privileged access keep folding into the identity platforms.
Optiv goes private in a Vobis Ventures buyout. The cyber advisory giant repositions around securing enterprise AI.
Four more cybersecurity companies ceased operations. The mid-market squeeze has not eased.
Anthropic's Fable 5 and Mythos 5 launched and were pulled within a week after a US government export-control order. Our Insider Insight digs in.
THE TRIDENT VIEW

The Jobs Are American
Here is something our own numbers throw up that still surprises people: we are a London firm, and yet roughly three in four of the placements we have made this year, 74% of them, were US roles. The UK accounts for under one in five, and the whole of Europe for less than one in ten.
That is not an accident of who we happen to know. It is where the cyber go-to-market money is. The companies we work with, wherever they are founded, put their senior commercial hires where the enterprise security budgets sit, and those budgets are overwhelmingly American. A Tel Aviv or French startup raising a Series A will very often make its first expensive sales and marketing hires in New York or the Bay Area before it hires a second person at home, simply because that is where the pipeline is.
What the headline number does not show is the part we care about most. US roles are not just the bulk of our book, they are the ones we fill fastest and the ones that last longest once filled. A US cyber go-to-market search closes much faster for us than the equivalent role in the UK or Europe, and the people we place into those seats stay materially longer. That combination, speed to hire and staying power afterwards, is the real tell: it is what a market looks like when demand is deep, the candidate pool is mature, and the fit between role and person is right rather than forced.
This fortnight's deal flow says the same thing from the funding side. The biggest rounds we are writing about landed in New York and San Francisco, Cyera's $600 million and Ent's $100 million among them, and the centre of gravity for cyber capital and commercial spend keeps pulling west across the Atlantic.
So here is the point, plainly. If you are building a cyber go-to-market team in the US, this is the part of the market we know better than any other, the one we move fastest in, and the one where our placements stay. We work across all three regions and we are glad to see the UK and Europe growing, but US commercial hiring in cyber is the brief we are built for, and the numbers behind us say so.
Funding Spotlight
$50M and above
Cyera
Series G, $600M (Evolution Equity Partners)
Data security platform that automatically discovers, classifies and protects sensitive data across an organisation, now valued at around $12 billion. One of the largest cyber rounds of the year. Other investors: Accel, Coatue Management, Blackstone, Sequoia Capital, Lightspeed Venture Partners and Temasek.
Category: Data Security
HQ: New York, NY
Ent
Seed, $100M (Decibel Partners)
Intent-aware workspace security that reads what users and AI agents are trying to do and intervenes before risky actions complete, rather than alerting after the fact. Built by the founders of RiskIQ, later acquired by Microsoft, and one of the largest seed rounds in the industry's history. Other investors: Sequoia Capital, Crosspoint Capital, Craft Ventures, Shield Capital, Felicis and In-Q-Tel.
Category: AI Security / Endpoint
HQ: San Francisco, CA
NewCore
Seed, $66M (CyberStarts, Evolution Equity Partners, Index Ventures)
Identity security platform that secures and governs both human and AI-agent identities, using a split-key architecture, hardware-bound credentials and identity tooling for coding agents. Emerged from stealth at a $234 million pre-money valuation.
Category: Identity Security
HQ: Tel Aviv, Israel
$20M to $50M
Aryon Security
Series A, $29M (Viola Ventures, Blumberg Capital)
Cloud security enforcement platform that stops risky configurations from ever reaching production, using AI-powered, cloud-agnostic guardrails and automated drift detection. The round drew a notable cast of operator-angels. Other investors: Datadog, George Kurtz, Nadir Izrael, Shlomo Kramer, Robert Herjavec and Yevgeny Dibrov.
Category: Cloud Security
HQ: Tel Aviv, Israel
Opal Security
Venture Funding, $23M (Battery Ventures, Greylock)
Identity and access governance built for enterprise scale, automating access reviews and enforcing just-in-time permissions across human, machine and AI identities. Other investors: Cambium Capital.
Category: Identity / Access Management
HQ: New York, NY
$5M to $20M
Arpio
Series A, $15M (S3 Ventures, Paladin Capital Group)
Cyber resilience and automated recovery platform that protects and restores entire AWS environments, with Azure support live and Google Cloud on the roadmap. Other investors: CreativeCo Capital, Draper Associates, Lookout Ventures, Valor Ventures, Uncorrelated Ventures and NC Tweener Fund.
Category: Cyber Resilience / Recovery
HQ: Durham, NC
Magnitude
Seed, $10M (Ballistic Ventures)
Third-party risk management platform that deploys seven specialised AI agents across vendor intake, assessment, continuous monitoring and supply-chain mapping, with source-cited reasoning inside isolated tenant environments.
Category: Third-Party Risk
HQ: San Francisco, CA
Incalmo
Seed, $9.65M (undisclosed investors)
Autonomous cybersecurity platform for threat detection, monitoring and adaptive response that runs with minimal human oversight, raised at a $40 million pre-money valuation.
Category: Autonomous Security
HQ: Menlo Park, CA
Oplane
Seed, $5.25M (SEED Capital)
Threat-modelling platform that helps developers identify and mitigate security threats early, now adding integrations with AI coding tools including Claude Code, Cursor and GitHub Copilot. Other investors: Icebreaker.vc and Neo4j founder Emil Eifrem.
Category: Application Security
HQ: Malmö, Sweden
$1M to $5M
InfoHawk
Seed, $2.25M (Moonshots Capital)
AI platform that detects, analyses and neutralises online deception at scale, monitoring URLs, ads and accounts with multimodal fraud detection and explainable scoring APIs. Other investors: former FTC chairman Jon Leibowitz and AppNexus founder Brian O'Kelley, among others.
Category: Anti-Fraud / Deception Detection
HQ: Austin, TX
Emphere
Seed, $2.1M (Outsiders Fund, AI2 Incubator)
Remediation platform for security teams that secures Dockerfiles and CVEs, mapping dependencies and supply-chain integrity before code is promoted to production.
Category: Supply Chain Security
HQ: Seattle, WA
Undisclosed amount
Candor Security
Venture Funding, Undisclosed (Transpose Platform Management)
AI-powered insider-threat platform that surfaces the riskiest employee behaviours, integrates with existing enterprise tools and contains threats automatically.
Category: Insider Threat / AI Security
HQ: San Francisco, CA
Imperum
Seed, Undisclosed (Curiosity VC)
Autonomous SOC platform that automates alert triage, investigation and resolution, with governance and auditability built in.
Category: Autonomous SOC
HQ: Amsterdam, Netherlands
Exponential Security Labs
Pre-Seed, Undisclosed (Mätch VC)
AI security for agentic systems, using self-improving red-teaming and adaptive guardrails across the agent stack, from coding agents to memory-driven, multi-step workflows.
Category: AI Security / Agentic
HQ: Tübingen, Germany
Aeglos
Venture Funding, Undisclosed (Scout Ventures, Mana Ventures)
Security and governance for enterprise LLM pipelines, monitoring the AI lifecycle in real time to detect hallucinations, data leaks and anomalous model behaviour for regulated industries.
Category: AI Security / LLM Governance
HQ: Austin, TX
Zealot
Seed, Undisclosed (Khosla Ventures)
AI-based cyber-operations systems for defence and military missions, engineered for rapid deployment in contested environments. Other investors: DCVC, Vine Ventures, Garry Tan, Jack Altman and Shyam Sankar.
Category: Defence / Cyber Operations
HQ: Washington, DC
M&A Intelligence
SailPoint Acquires Entro
Entro → Acquired by SailPoint Technologies (NASDAQ: SAIL)
Deal Type: Acquisition
Deal Date: June 15, 2026
Deal Size: Undisclosed
SailPoint, the enterprise identity giant, buys its way deeper into the fastest-consolidating corner of the market. Entro discovers and secures the secrets and non-human identities, the API keys, tokens and service accounts, that now run quietly across every enterprise. Folding that into SailPoint's governance platform is the same move Cisco made with Astrix and Snowflake made with Natoma last month, and it is precisely the trend our Bold Call is tracking.
1Password Acquires Apono
Apono → Acquired by 1Password
Deal Type: Acquisition
Deal Date: June 15, 2026
Deal Size: Undisclosed
1Password extends from credential storage into live access control. Apono delivers context-based, just-in-time privileged access across users and workloads, letting 1Password govern not just where secrets live but who and what can use them, and when. Another identity platform buying its way up the stack.
Companies That Ceased Operations
Four cybersecurity companies went out of business across the fortnight:
DFend - AI-powered digital safety agent for consumer cyber protection (New York, NY)
CRFQ- Cyber risk quantification and financial impact assessment (Minneapolis, MN)CRFQ are in fact still in business and thriving. A number of platforms have inaccurately reported this.
SpyderWatch - Child online safety and real-time threat monitoring (Meridian, ID)
Loni - AI network management and security operations (Wilmington, DE)
Insider Insight

The Model That Lasted a Week
On 9 June, Anthropic launched its most capable models yet: Fable 5 for everyone, and Mythos 5, the same model with its cybersecurity guardrails removed, for a small group of vetted cyber defenders. The company described Mythos as having the strongest cybersecurity capabilities of any model in the world. Three days later, on the evening of 12 June, the US government ordered it pulled. A directive from the Commerce Department, citing national security, barred access to both models by any foreign national anywhere, including Anthropic's own foreign-born staff. Unable to separate those users from everyone else in real time, Anthropic disabled both models for the entire world. The most powerful AI on the commercial market lasted, in effect, about seventy-two hours.
The official trigger, as reported by Axios and CNBC, was a jailbreak. A rival, Amazon, reportedly called administration officials with a demonstration that researchers had bypassed Mythos's safeguards. Anthropic's account is that the technique amounted to asking the model to read a codebase and find flaws, surfacing a handful of minor, already-known vulnerabilities that other public models can find too, and it has called the episode a misunderstanding it is working to reverse. Whatever the merits, the mechanism is what should make every operator sit up: a competitor's report moved a government to pull a frontier product inside three days.
There are two ways to read this, and they are not mutually exclusive. The cynical reading is that this is the safety-as-marketing flywheel running at full speed. A model so dangerous the government yanks it within a week is a story no budget could buy, and it burnishes exactly the narrative the frontier labs have leaned on for two years, that their technology is powerful enough to be a matter of national security. Anthropic raised $65 billion in May. Being the lab whose models are treated like munitions does no harm to the next round, and "too capable to sell abroad" is the most flattering complaint a vendor can field.
The more serious reading is that the precedent matters far more than this one model. For the first time, a commercial AI model has been pulled from the market by government order rather than by its maker. AI cyber capability is now being handled like a controlled good, much as strong encryption was in the 1990s, and the machinery of export control has formally reached the model layer. That is a genuinely new condition for this industry, and it will not be the last time it is invoked. The dual-use problem underneath it is real: the same model that helps a defender find a flaw helps an attacker find the same flaw, which is the entire reason this category is so valuable and so fraught.
The irony at the centre of the week is hard to miss. Anthropic spent the launch explaining why a model this capable needed broad safeguards, making the case for restriction as a tool of safety. Then a broader, blunter restriction arrived than the one it had in mind, and it objected. Calling for limits on powerful technology is straightforward right up until the limits land on you, and that tension is going to shape a great deal of the next few years.
For our corner of the market, the signal is what counts. AI cyber capability has crossed from product feature to strategic asset: regulated, geopolitically contested, and valuable enough that an investor in one breath and a competitor in the next will pick up the phone to Washington over it. That repricing flows straight downstream. The people who build, secure and defend these models have just become more valuable again, the M&A logic behind our Bold Call gets stronger rather than weaker, and any founder building at the frontier now has to assume that the export and national-security rules governing defence technology apply to them too.
The Trident Take: we do not know which reading is the true one, and our honest guess is that it is both. The PR upside is real and the security and precedent questions are real at the same time. What is not in doubt is the direction. The frontier of AI is now national-security infrastructure, and everything that sits downstream of it, talent, deals and budgets included, will be priced accordingly.
Company Spotlight: Ent

Website - ent.ai
The biggest seed round cybersecurity has seen in a long time went to a company that came out of stealth the same week this newsletter went out, built by two people who have done it before.
The Founders. Ent was founded by Elias Manousos and Brandon Dixon, the pair behind RiskIQ, the attack-surface company Microsoft acquired in 2021 for a reported $500 million and more. After the sale, both stayed on to help launch Microsoft Security Copilot. Their new company is, pointedly, a bet against the detection-first model that Microsoft and most of the industry still run on.
The Thesis. Traditional endpoint detection and response logs and reacts to malicious activity after it has happened. Ent's argument is that this no longer holds, because the riskiest activity now looks exactly like legitimate work, especially as autonomous AI agents begin executing real workflows across corporate systems with real credentials. To stop something rather than clean up after it, you have to understand intent at the moment of action.
The Product. Ent calls it intent-aware workspace security. It runs specialised AI models directly on the endpoint to read what a user or an AI agent is trying to do, and why, then intervenes before a risky action completes rather than flagging it afterwards. It sits deliberately between the EDR market and the newer push to govern how employees and agents use enterprise AI, covering insider risk, AI usage and data loss in a single layer.
The Funding Journey. This was Ent's first public round, and at $100 million it is one of the largest seeds the industry has seen. Decibel led, with Sequoia, Crosspoint Capital, Craft Ventures, Shield Capital, Felicis and In-Q-Tel, the venture arm tied to the US intelligence community, all participating. The money is earmarked for engineering, go-to-market hiring and extending the platform.
The Traction. Unusually for a company leaving stealth, Ent says it is already deployed inside Global 2000 customers across hospitality, financial services and defence, used for insider-risk detection, AI governance and data-loss prevention. Its advisory board reads like a buyer-side who's who, including former CISOs from Google, Aetna and MassMutual, a former director of the NSA, and a former head of Azure cloud security. A seed round this size is paying for production traction that already exists, not the promise of it.
The Takeaway. Ent captures two of the year's biggest themes at once: the shift from detection to prevention, and the scramble to secure a workplace where humans and AI agents now work side by side. The risk the founders are taking is the very one their pitch identifies, because a system that acts on inferred intent has to be right often enough that it does not block real work and train people to ignore it. But with this team, this backing and this much usage on day one, Ent starts as one of the most credible new names in the AI-security layer, and a textbook example of the kind of business the platforms in our Bold Call will eventually want to own.
Hot Jobs
Role | Base | Location | Description | Contact |
|---|---|---|---|---|
VP Sales - North America | $250K | US | Threat intelligence and adversary simulation platform, strong open-source community. Leading the North America build. | |
Channel Director - East | $225K | US | Same threat intelligence platform. Standing up the East Coast channel function. | |
Channel Leader | $200K | US | AI-powered security operations platform. Building the channel from scratch. | |
Sales Director - East | $200K | US | Threat intelligence platform. East Coast enterprise sales. | |
Enterprise AE - West | $175K | US | AI-driven continuous penetration testing platform. West Coast enterprise. | |
Software Engineer | $175K | US | Real-time threat intelligence and situational awareness platform. Core engineering hire, retained. | |
Enterprise AE | $160K | US | Early-stage AI security platform. Enterprise sales. | |
Sales Director - UK | £130K | UK | Autonomous AI SOC platform automating alert investigation. UK sales lead. | |
Account Executive - East Coast | $130K | US (NYC) | Offensive security and attack surface management platform. NYC enterprise. |
Ready to make your next move? These roles won't stay open long.
THE BOLD CALL
One prediction per month.
June 2026 Prediction: Microsoft makes a major AI-security acquisition before the end of 2026.
The Logic: Every platform of its size has already bought its way into the layer that secures AI: Google took Wiz for $32 billion, Palo Alto took CyberArk for $25 billion, and last month Cisco took Astrix and Snowflake took Natoma. Microsoft is the holdout. It owns the biggest enterprise identity platform in Entra and ships the most-used enterprise AI in Copilot, yet it keeps building its AI-security stack in-house rather than buying one. That is getting harder to justify when machine identities now outnumber humans by roughly 82 to 1 and the pool of independent targets is thinning fast, with Astrix and Natoma gone last month and SailPoint taking Entro this fortnight. If Microsoft wants the best team rather than the leftovers, it has to move while the likes of Oasis Security and Token Security are still standing. What could prove us wrong is Microsoft's real preference for organic builds, which is exactly what makes this a bold call.
Prediction Tracker
Month | Call | Status |
|---|---|---|
May 2026 | Torq acquires again before end of 2026 | 🔵 In Progress |
June 2026 | Microsoft makes a major AI-security acquisition before end of 2026 | 🔵 In Progress |
📥 INBOX INTEL
Have market intelligence to share? Our network sees deals before they're announced, hiring freezes before they're public, and technology shifts before they hit the headlines.
Send us your tips:
Funding rounds in stealth mode
Executive movements and reorganizations
Customer wins/losses that signal market shifts
Technology partnerships before they're announced
Hiring sprees or freezes at specific companies
Email: [email protected]
All sources protected. We verify before we publish.
The Trident Radar - Intelligence that moves faster than your competition
Delivered by Trident Search Research Desk
Editor: Ryan Keeley | London

