Connect with us

Tech

Reco raises $55M as AI agent security startups crowd the market

Published

on

Terms like “AI sprawl” have become common fare on tech social media and in thought leadership as enterprises start deploying AI agents en masse. But CISOs worried about securing swarms of agents suddenly operating across networks are likely finding themselves dealing with a new kind of sprawl: vendors offering to help.

Just a quick glance at public Crunchbase and PitchBook profiles turns up at least two dozen companies selling some form of AI agent security. Some vendors vet the tools agents use, while others try to help companies control what data their agents can reach. Some others, like CrowdStrike, are building detection and response controls on the devices agents run, and still others are focused on finding and resolving unapproved AI usage.

The products differ, of course, but their promises to discover and govern agents sound quite similar, involving knowledge graphs, continuous monitoring, runtime security, tool access, MCP vetting, and the like.

Some are even updating their products to join the bandwagon. Until last year, AI security startup Reco was mostly selling software to map and secure SaaS and AI platforms. Now, it’s repositioned around a broader solution that uses a context graph to connect agents to apps, people, accounts, and permissions, giving security teams a way to see what an agent can reach and cut off access it doesn’t need.

According to Reco’s co-founder and CEO Ofer Klein, the biggest change over the past year that spurred the startup to broaden its scope was that companies are building and deploying AI agents faster than they can keep track of. At one of the startup’s Fortune 100 customers, he said, Reco’s platform found 21,000 agents the company didn’t know about. And at a large financial services customer, the startup claims it identified an agent set up by an ex-employee that could access Salesforce and share that data with a domain the company couldn’t see.

“The market demand right now for agent security is not only about the agent itself; it’s about the entire ecosystem end-to-end,” Klein told TechCrunch in an exclusive interview.

Image Credits:Reco /

Klein’s not alone in stressing the urgency for companies to secure this sprawl. Security startup HiddenLayer‘s co-founder and CEO, Chris Sestito, earlier this month told me that when agents reach production, the scale of their costs and risk goes from theoretical to “full scale really quickly,” and that over 50 of his customers have AI agents in production touching critical systems and sensitive assets.

Cymphony, another AI startup, said at one U.S. public company, it found about 85,000 files that had become accessible to AI tools and agents.

There’s no doubt a ton of investors are interested in companies that can make a mint out of helping companies find and secure all these agents, and Reco has capitalized on that demand: The startup on Tuesday said it raised $55 million, building on a $30 million Series B in February. AT&T, a customer, invested in the extension via its venture arm, as did Forestay and Quadrille Capital.

Klein said the company’s valuation has “more than doubled” since the Series B was first announced in February, and vaguely estimated it in the “high hundreds of millions” though he wouldn’t share specifics. Annual recurring revenue right now is in the “double-digit millions of dollars,” he said, and he expects it to triple this year. The startup has more than 100 customers, and financial services companies account for about 40% of the business.

Reco’s bet, it appears, is that its existing coverage of SaaS apps, and the AI agents they are increasingly offering, will help it stand out from the crowd. The company currently integrates with more than 280 apps, and Klein says new integrations can be added within days. Klein said the platform uses browser and network signals to find agents outside apps it connects to directly within companies, and it has controls to inspect prompts and tool calls.

The startup will use the new funding for hiring, sales, partnerships, and customer support. The new funding brings Reco’s total capital raised to $140 million.

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

>

Continue Reading

Tech

Still running iOS 26? Update your iPhones, iPads and Macs for this urgent security fix

Published

on

Apple has fixed a security vulnerability in its iOS 26, iPadOS 26 and macOS 26 operating systems that the company says “may have been exploited” by hackers. The tech giant said the now-fixed bug could be used to launch “an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27.”

According to a listing on Apple’s security pages, the bug was found in the main graphics engine that powers the user interface and visuals on iPhones, iPads and Macs. 

Meta’s product security team was credited with the discovery.

Details of the bug, officially classed as CVE-2026-86950, were not released, but a device’s graphics engine typically has broad access to the rest of the device’s operating system. A successful exploit could potentially allow a hacker to steal a broad range of personal data from an affected device.

When reached by TechCrunch, spokespeople for Apple and Meta did not provide comment about how the bug was discovered, or how many people had their devices hacked due to this vulnerability, if any. It’s also unclear who may be exploiting the bug, such as government spyware makers or cybercriminals.

While the bug affects Apple’s previous generation of operating systems, it remains in wide usage. Almost four-in-five of Apple’s iPhone owners are still running iOS 26, according to the company’s own statistics. Devices running the latest version, iOS 27, iPadOS 27, and macOS 27, released earlier this month, also received a software update on Tuesday, but are unaffected by the bug under attack.

A separate ‘zero-click’ bug now fixed

News of the security patch comes soon after Apple fixed another critical security bug, known as CVE-2026-86869, which could have allowed hackers to silently steal data from affected iPhones, iPads, or Macs. 

Belgian cybersecurity research firm ironPeak published a detailed writeup last week explaining that the bug was a “zero-click” vulnerability that could be invisibly triggered via a maliciously crafted iMessage, without the user’s knowledge. Such bugs require no interaction from the victim, such as clicking a link, and are highly sought-after by surveillance vendors and spyware makers. 

Per ironPeak’s post, the bug is capable of bypassing BlastDoor, a security feature that Apple implemented to prevent malicious code, like spyware, from escaping iMessage’s sandbox and hacking the user’s device.

Apple fixed the bug in September with the release of iOS 27, iPadOS 27, and macOS 27, and credited ironPeak’s Niels Hofmans with the discovery, alongside security researchers at Meta who confirmed their findings in a post on X.

It’s not yet known if this bug had been used in cyberattacks before it was fixed.

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

>

Continue Reading

Tech

Fireflies adds dictation to its desktop notetaking apps

Published

on

Voice AI has gained particular traction for a few consumer use cases: The biggest category is meeting note-taking, and the other is AI-powered dictation, in which filter words are removed and the text is formatted neatly. Fireflies.ai, having gained a solid foothold in the meeting note-taking space, is now venturing into dictation by way of a new feature on its Mac and Windows apps.

Called Fireflies Talk, the dictation feature works just like any of the others on the market like Wispr Flow, Willow or SuperWhisper. Users can press the Fn key on Mac or Ctrl + Win on Windows to start speaking, no matter which app is open, and Fireflies will record their voice and transcribe it neatly in the text field of the app.

“People speak roughly 3x faster than they type, and voice is a much more natural way to get work done. Meetings were just the starting point; the bigger vision has always been Fred as your AI teammate throughout the day. Talk takes Fireflies beyond meetings into email, Slack, docs, prompts, and wherever else you work,” Fireflies CEO Krish Ramineni told TechCrunch over email.

The company has bundled the dictation into its existing subscription plans rather than charging for it separately. This is not entirely a new strategy. Wispr took the opposite route, releasing its meeting notetaker for free for its existing dictation app users. Speechify has also introduced dictation capabilities across different apps.

Fireflies said that the company doesn’t keep any recordings and stores dictation transcripts locally.

Like other meeting notetakers and productivity suites, Fireflies is aiming to automate workflows based on meeting transcriptions and the context it builds on its users, and has plans to build an assistant that taps that context.

Last year, the company introduced “mini-apps” to extract insights in different ways from meetings, and last month, it launched a feature to manage your inbox and draft emails on your behalf.

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

>

Continue Reading

Tech

OpenAI apologizes to Australia after its AI agents breached government sites

Published

on

OpenAI on Monday apologized to the Australian government for not immediately notifying the country’s administration that its agents had breached some public services websites. The company also detailed how some of those breaches happened, and outlined additional measures it is taking to assess the impact of the events.

“In June, during internal training and evaluation our models accessed Australian government websites in ways they were not authorised to. We also should have handled our response better. We are sorry and working to do better in the future,” OpenAI wrote in a blog post.

The apology comes roughly a week after the Australian government launched an investigation into how OpenAI’s models accessed a Services Australia system containing Medicare spending information and other health statistics.  

The data breach occurred in June, but Australian authorities weren’t notified until September 10.

OpenAI also detailed the breach. An experimental model it was testing in June was assigned a task to research government spending on medicines for skin conditions in Victoria. Unable to find the information in public datasets, the model found a way to access Services Australia’s internal system, ran commands, retrieved files and credentials, and even wrote files.

The company said it also found that one of its models had accessed the New South Wales Bureau of Crime Statistics and Research’s public Crime Mapping Tool to find crime statistics. And, the lab found that its agents gained access to Victoria’s Agency for Health Information via an exposed access key to exfiltrate “reporting configuration and aggregate survey statistics.” OpenAI said its agents also retrieved aggregate statistics from the Australian Institute of Health and Welfare website.

The company said it had found no evidence that its models had accessed individuals’ medical or criminal records.

In its apology, the AI lab said it would provide the affected Australian agencies with technical findings and connect them with its response teams to assess the impact of the breaches. The company will also provide credits from its $1 billion Daybreak for Frontline Defenders program, and set up a task force with independent Australian experts to review the incident and its response.

“The taskforce, which is expected to complete its work by the end of the year, will also recommend practical steps AI companies can take to reduce the risk of similar incidents,” OpenAI wrote.

OpenAI did not immediately return a request for comment.

Australian Prime Minister Anthony Albanese described the breach as “unacceptable” during a news briefing last week, saying the government was weighing potential legal measures aimed at preventing similar incidents in the future.

The breach is the latest in a growing list of security incidents involving AI agents doing things outside of their intended boundaries. The tinder on this particular bonfire was lit after OpenAI agents hacked into Hugging Face, and since then, Anthropic, Meta and Google have separately disclosed similar incidents where their models gained access to third parties’ systems during evaluations.

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

>

Continue Reading

Trending

Copyright © 2017 Zox News Theme. Theme by MVP Themes, powered by WordPress.