2 Sources
2 Sources
[1]
Bugcrowd acquires AI security startup Mayhem to fuse hacker ingenuity with machine intelligence - SiliconANGLE
Bugcrowd acquires AI security startup Mayhem to fuse hacker ingenuity with machine intelligence Crowdsourced cybersecurity platform company Bugcrowd Inc. today announced that it has acquired Mayhem Security, an artificial intelligence offensive security company, to advance the next generation of humans-in-the-loop, AI-powered security testing. Founded in 2012, Mayhem Security emerged from research at Carnegie Mellon University to automate the discovery and remediation of software vulnerabilities. The company was founded by cybersecurity researchers includingDavid Brumley and Thanassis Avgerinos, who built capabilities originally to contend in research competitions before commercializing their technology. Mayhem's platform leverages AI and autonomous execution to perform offensive security testing that effectively thinks like an attacker across code, applications and runtime environments. The underlying technology uses methods such as symbolic execution and fuzzing to generate test cases that explore deep code paths and trigger exploitable conditions. The company emphasizes continuous testing and integration into development lifecycles, with support for application programming interfaces, full applications and their runtimes and software bills of materials. For example, Mayhem's "Dynamic SBOM" capability examines actual runtime behavior rather than only static dependency lists to help organizations remove unused or risky code and third-party dependencies that might expose them to supply-chain threat vectors. Mayhem serves enterprise-grade customers across sectors including aerospace, automotive, technology and federal agencies, with its autonomous test suite being used for defending complex systems, including weapon systems and high-stakes infrastructure, under contract to government agencies. Notable Mayhem customers include Cloudflare Inc., Deloitte Touche Tohmatsu Ltd., Roblox Corp., F. Hoffmann-La Roche AG and Rivian Automotive Inc. With the acquisition, Bugcrowd plans to combine its global hacker community with Mayhem's AI platform to help organizations ship safer software faster, at lower cost and with greater confidence, while shrinking their attack surface. Bugcrowd customers will gain automated, proactive protection during development through noise-free testing that continuously finds, prioritizes and validates the remediation of vulnerabilities, complemented by Bugcrowd's human-driven adversarial testing of deployed software by trusted, highly skilled hackers. "By integrating Mayhem's capabilities into the Bugcrowd Platform, we're building the industry's first truly adaptive security platform, enabling customers to anticipate, test and defend at unprecedented scale," said Bugcrowd Chief Executive Dave Gerry. "This is a strategic step toward realizing our vision of an intelligent, self-learning platform that unites human creativity with machine intelligence while shrinking customers' attack surface." Coming into its acquisition, Mayhem Security, formerly known as ForAllSecure Inc., had raised $38 million over three rounds, including $21 million in March 2022. Investors in the company include New Enterprise Associates Inc. and Koch Disruptive Technologies.
[2]
Bugcrowd Acquires Mayhem Security To Boost Autonomous App Testing
Key capabilities from Mayhem Security include continuous penetration testing for discovering and fixing vulnerabilities in APIs as well as application code, Bugcrowd says. Bugcrowd announced the acquisition Tuesday of Mayhem Security, a longtime provider of autonomous application security testing, in a bid to help accelerate vulnerability remediation. Terms of the acquisition deal weren't disclosed. Mayhem Security has 11 employees, all of whom are joining crowdsourced security provider Bugcrowd, the vendor told CRN. [Related: 10 Cool New Security Products Announced At Black Hat 2025] Formerly known as ForAllSecure, Mayhem Security was founded in 2012 and has been working to enable faster identification of software vulnerabilities through automation, Co-Founder and CEO David Brumley said in a previous interview. Key capabilities from Mayhem Security include continuous, automated penetration testing for discovering and fixing vulnerabilities in APIs as well as application code, Bugcrowd said in a news release. For Bugcrowd, the addition of Mayhem Security's "AI-driven automation" will enable the crowdsourced cybersecurity platform to deliver the industry's "first truly adaptive security platform," Bugcrowd CEO Dave Gerry said in a quote included in the release. Mayhem Security had raised at least $36 million in funding, with the company -- under the former name ForAllSecure -- last raising a $21 million Series B round in 2022 led by New Enterprise Associates and Koch Disruptive Technologies. Prior M&A by Bugcrowd has included the 2024 acquisition of Informer, a veteran provider of external attack surface management capabilities. In August, Bugcrowd unveiled a new offering, AI Connect, aimed at enabling secure integration of AI systems with the company's real-time feeds of vulnerability data. Bugcrowd also debuted its new Asset View capability that brings together asset discovery and management with scanning and offensive testing.
Share
Share
Copy Link
Crowdsourced cybersecurity platform Bugcrowd has acquired AI-powered offensive security company Mayhem Security to create an adaptive security platform that combines human hacker expertise with autonomous AI testing capabilities for faster, more comprehensive vulnerability detection.
Bugcrowd Inc., a leading crowdsourced cybersecurity platform, has announced its acquisition of Mayhem Security, an artificial intelligence-powered offensive security company, marking a significant step toward creating what the company calls the "industry's first truly adaptive security platform."
1
The deal, whose financial terms were not disclosed, brings together Bugcrowd's global community of ethical hackers with Mayhem's autonomous AI testing capabilities.2

Source: CRN
Founded in 2012 and originally known as ForAllSecure, Mayhem Security emerged from research conducted at Carnegie Mellon University by cybersecurity researchers including David Brumley and Thanassis Avgerinos.
1
The company's platform leverages advanced AI techniques such as symbolic execution and fuzzing to perform offensive security testing that mimics attacker behavior across code, applications, and runtime environments. These methods generate sophisticated test cases that explore deep code paths and trigger exploitable conditions that traditional testing might miss.
Source: SiliconANGLE
Mayhem's technology emphasizes continuous testing integration into development lifecycles, supporting application programming interfaces, full applications, and software bills of materials. A standout feature is the company's "Dynamic SBOM" capability, which examines actual runtime behavior rather than relying solely on static dependency lists. This approach helps organizations identify and remove unused or risky code and third-party dependencies that could expose them to supply-chain threats. [1](https://siliconangle.com/2025/11/04/bugcrowd-acq uires-ai-security-startup-mayhem-fuse-hacker-ingenuity-machine-intelligence/)
Mayhem Security has established itself as a trusted provider for enterprise-grade customers across multiple sectors, including aerospace, automotive, technology, and federal agencies. The company's autonomous test suite has been deployed to defend complex systems, including weapon systems and high-stakes infrastructure under government contracts. Notable customers include major technology companies such as Cloudflare Inc., Deloitte Touche Tohmatsu Ltd., Roblox Corp., F. Hoffmann-La Roche AG, and Rivian Automotive Inc.
1
Related Stories
The acquisition brings all 11 Mayhem Security employees into Bugcrowd's organization, combining their AI-driven automation capabilities with Bugcrowd's human-powered security testing approach.
2
Bugcrowd customers will benefit from automated, proactive protection during development through continuous vulnerability discovery, prioritization, and validation, complemented by human-driven adversarial testing of deployed software by skilled ethical hackers."By integrating Mayhem's capabilities into the Bugcrowd Platform, we're building the industry's first truly adaptive security platform, enabling customers to anticipate, test and defend at unprecedented scale," said Bugcrowd CEO Dave Gerry. The integration represents a strategic step toward realizing Bugcrowd's vision of an intelligent, self-learning platform that unites human creativity with machine intelligence while reducing customers' attack surfaces.
1
Prior to the acquisition, Mayhem Security had raised $38 million across three funding rounds, including a $21 million Series B round in March 2022 led by New Enterprise Associates and Koch Disruptive Technologies.
1
This acquisition follows Bugcrowd's previous strategic moves, including the 2024 acquisition of Informer, a provider of external attack surface management capabilities, and the August launch of AI Connect, designed to enable secure integration of AI systems with real-time vulnerability data feeds.2
Summarized by
Navi
[1]
1
Business and Economy

2
Technology

3
Policy and Regulation
