Bugcrowd Acquires AI Security Startup Mayhem to Merge Human Hackers with Machine Intelligence

2 Sources

Share

Crowdsourced cybersecurity platform Bugcrowd has acquired AI-powered offensive security company Mayhem Security to create an adaptive security platform that combines human hacker expertise with autonomous AI testing capabilities for faster, more comprehensive vulnerability detection.

Strategic Acquisition Combines Human and AI Security Testing

Bugcrowd Inc., a leading crowdsourced cybersecurity platform, has announced its acquisition of Mayhem Security, an artificial intelligence-powered offensive security company, marking a significant step toward creating what the company calls the "industry's first truly adaptive security platform."

1

The deal, whose financial terms were not disclosed, brings together Bugcrowd's global community of ethical hackers with Mayhem's autonomous AI testing capabilities.

2

Source: CRN

Source: CRN

Mayhem Security's AI-Driven Technology Foundation

Founded in 2012 and originally known as ForAllSecure, Mayhem Security emerged from research conducted at Carnegie Mellon University by cybersecurity researchers including David Brumley and Thanassis Avgerinos.

1

The company's platform leverages advanced AI techniques such as symbolic execution and fuzzing to perform offensive security testing that mimics attacker behavior across code, applications, and runtime environments. These methods generate sophisticated test cases that explore deep code paths and trigger exploitable conditions that traditional testing might miss.

Source: SiliconANGLE

Source: SiliconANGLE

Mayhem's technology emphasizes continuous testing integration into development lifecycles, supporting application programming interfaces, full applications, and software bills of materials. A standout feature is the company's "Dynamic SBOM" capability, which examines actual runtime behavior rather than relying solely on static dependency lists. This approach helps organizations identify and remove unused or risky code and third-party dependencies that could expose them to supply-chain threats. [1](https://siliconangle.com/2025/11/04/bugcrowd-acq uires-ai-security-startup-mayhem-fuse-hacker-ingenuity-machine-intelligence/)

Enterprise Customer Base and Government Contracts

Mayhem Security has established itself as a trusted provider for enterprise-grade customers across multiple sectors, including aerospace, automotive, technology, and federal agencies. The company's autonomous test suite has been deployed to defend complex systems, including weapon systems and high-stakes infrastructure under government contracts. Notable customers include major technology companies such as Cloudflare Inc., Deloitte Touche Tohmatsu Ltd., Roblox Corp., F. Hoffmann-La Roche AG, and Rivian Automotive Inc.

1

Integration Strategy and Future Vision

The acquisition brings all 11 Mayhem Security employees into Bugcrowd's organization, combining their AI-driven automation capabilities with Bugcrowd's human-powered security testing approach.

2

Bugcrowd customers will benefit from automated, proactive protection during development through continuous vulnerability discovery, prioritization, and validation, complemented by human-driven adversarial testing of deployed software by skilled ethical hackers.

"By integrating Mayhem's capabilities into the Bugcrowd Platform, we're building the industry's first truly adaptive security platform, enabling customers to anticipate, test and defend at unprecedented scale," said Bugcrowd CEO Dave Gerry. The integration represents a strategic step toward realizing Bugcrowd's vision of an intelligent, self-learning platform that unites human creativity with machine intelligence while reducing customers' attack surfaces.

1

Financial Background and Market Context

Prior to the acquisition, Mayhem Security had raised $38 million across three funding rounds, including a $21 million Series B round in March 2022 led by New Enterprise Associates and Koch Disruptive Technologies.

1

This acquisition follows Bugcrowd's previous strategic moves, including the 2024 acquisition of Informer, a provider of external attack surface management capabilities, and the August launch of AI Connect, designed to enable secure integration of AI systems with real-time vulnerability data feeds.

2

TheOutpost.ai

Your Daily Dose of Curated AI News

Don’t drown in AI news. We cut through the noise - filtering, ranking and summarizing the most important AI news, breakthroughs and research daily. Spend less time searching for the latest in AI and get straight to action.

© 2025 Triveous Technologies Private Limited
Instagram logo
LinkedIn logo