221 episodes
- What happens to security investing when vulnerability discovery becomes continuous and exploitation windows shrink from weeks to hours? I sit down with Chenxi Wang of Rain Capital to dig into it.
Chenxi is the Founder and Managing General Partner at Rain Capital, a venture fund focused on early-stage cybersecurity companies. She's been a Carnegie Mellon professor, a Forrester VP, and a strategy leader at Intel Security and Twistlock, and her portfolio includes companies like Claroty, ProjectDiscovery, Ox Security, runZero, and Straiker. She closes out my July run of conversations with security investors.
In this episode:
The AI Exploit Age and why vulnerability discovery is becoming continuous
Guardian Agents and the case that it takes an AI to govern an AI
Separating AI agent identity from traditional machine identity
The signals that predict enterprise adoption for early-stage security startups
The barbell funding market and the squeeze on Series B and C
What security leaders should do differently over the next twelve months
Connect with Chenxi:
LinkedIn: https://www.linkedin.com/in/chenxiwang88/
Rain Capital: https://raincap.vc/
Rain Capital Insights: https://raincapital.substack.com
Subscribe to Resilient Cyber for more conversations with security practitioners and leaders: https://www.resilientcyber.io - Bugcrowd founder Casey Ellis joins me to dig into what AI is actually doing to bug bounties, vulnerability discovery, and open source security. We get into his "slopdemic" framing, the curl bug bounty saga, VDP readiness, the pentest market correction, and where security research policy heads next.
Casey Ellis is the founder of Bugcrowd, co-founder of disclose.io, and a board member of the Security Research Legal Defense Fund. These days he advises and invests through Tall Poppy Group and works at the intersection of security, AI, and policy. His argument is that the vulnpocalypse was already here, and AI has made the cost of both finding and reporting vulnerabilities collapse at the same time.
In this episode:
Casey's path from building Bugcrowd to advising, investing, and policy work
Why more practitioners need to get involved in policy, and why law is just code
The slopdemic vs. the vulnpocalypse, and what actually changed in submissions
AI lowering the bar for a broader, less predictable pool of threat actors
Daniel Stenberg, curl, and maintainers below the security poverty line
The lightning rod vs. rockets distinction between VDPs and bug bounties
The pentest market correction underway from AI pricing pressure
Collapsing OODA loops, hack-back, CFAA reform, SRLDF, and disclose.io
Chapters:
0:00 Intro and Casey's background
2:56 Why practitioners belong in policy
6:22 The slopdemic vs. the vulnpocalypse
9:40 AI lowering the bar for threat actors
11:47 Open source, curl, and the security poverty line
15:37 VDP vs. bug bounty readiness
19:20 The pentest market correction
24:20 What breaks first in vulnerability management
27:20 Hack-back and non-cooperative defense
28:43 A near-term playbook for security leaders
31:40 CFAA, SRLDF, and disclose.io
Connect with Casey:
LinkedIn: https://www.linkedin.com/in/caseyjohnellis
Blog: https://cje.io
disclose.io: https://disclose.io
Bugcrowd: https://www.bugcrowd.com
Resilient Cyber: https://www.resilientcyber.io
Subscribe for more conversations with security practitioners and leaders. - Jon Sakoda of Decibel joins me to break down AI's impact on cybersecurity startups, venture funding, and why endpoint is the Super Bowl of cyber.
Jon is the Founding Partner at Decibel, an early-stage firm backing technical founders in security and infrastructure. He started his career founding IMlogic, an IM security company acquired by Symantec, then spent over a decade at NEA working with companies like Cloudflare, MongoDB, and HackerOne before launching Decibel. We got into why he thinks AI is only magical if you have a magic power, why Decibel led a $100M seed into Ent, and where the firm is placing its next bets.
In this episode:
Why Decibel operates like the Navy SEALs next to the big platform funds
The founder community model and finding the early believers among CISOs
What separates the founders who finish now that AI lets everyone start
Ent's $100M seed and the self-driving moment for endpoint security
Telling genuinely AI-native companies apart from AI washing
AI eating venture capital and why cyber's best years are ahead
Open models, frontier labs, and why the cat is out of the bag
The agentic SOC, Dropzone AI, and driver assistance vs. self-driving
Startup consolidation cycles and being an N of one
How buyers and job seekers should evaluate early-stage vendors
Decibel's next bets, from novel AI models to resilience and cyber insurance
Chapters:
0:00 Intro
0:32 Jon's background and founding Decibel
2:25 Big platform funds vs. specialized firms
3:56 Founders helping founders and early believers
6:22 Scaling beyond the early adopters
7:40 Who finishes the marathon in the AI era
10:19 Founders from outside cyber
12:21 Ent's $100M seed and the endpoint bet
14:53 AI-native vs. AI washing
17:04 AI is eating venture capital
18:55 Open models vs. frontier labs
22:41 The agentic SOC and Dropzone AI
26:03 Consolidation and the startup cycle
29:22 How buyers should evaluate young vendors
31:43 Decibel's next bets and cyber resilience
34:11 Game Day at Black Hat
Connect with Jon:
LinkedIn: https://www.linkedin.com/in/jonsakoda/
Decibel: https://www.decibel.vc
Subscribe for more conversations with security practitioners and leaders, and find my writing at https://www.resilientcyber.io - In this episode I sit down with Ed Sim, founder and managing partner of Boldstart Ventures, to dig into where AI security, agentic infrastructure, and the venture market are actually heading.
Ed has been an inception-stage investor for nearly 30 years and has run Boldstart since 2010, backing hardcore technology companies across AI infrastructure, cybersecurity, and physical AI. He was the first investor in Protect AI, which sold to Palo Alto Networks in a reported ~$700M exit roughly a year before ChatGPT launched. He is also early in companies like Keycard, Surf AI, and June. About a third of Boldstart's investments are in cyber, so Ed sees this market from the founder and investor side in a way most security conversations do not.
We get into why the era of building raw intelligence is giving way to an era of controlling it, what that means for on-prem models and private evals, and why Ed thinks nearly everything in security is going to get rebuilt from scratch.
In this episode:
- Why a day-one partnership looks different now that anyone can vibe code an MVP
- The Protect AI acquisition and what the first exit in AI security signaled to the market
- Competing as an inception fund against mega-funds writing giant seed rounds
- What founders should actually look for in a venture partner beyond the check
- The shift from building intelligence to controlling it, including routing, post-training, and on-prem deployment
- Why enterprise data, workflows, and private evals are becoming the crown jewels
- Vulnerability chaining, attack path reasoning, and how tools like Mythos are reshaping the security budget conversation
- Agentic identity and why Keycard treats agents as short-lived problem solvers rather than digital twins
- The Surf AI thesis on automated security hygiene and tying every asset back to an owner
- The real bottleneck slowing agent adoption in the enterprise
Chapters:
0:00 Intro
0:35 Ed's background and inception investing
1:57 Day-one partnerships in the vibe-coding era
3:53 The Protect AI exit to Palo Alto
6:14 Competing as an inception fund against mega-funds
9:17 What founders should look for in a VC partner
11:48 From building intelligence to controlling it
15:52 Boldstart's domain-specific model portfolio
16:16 Private evals, context, and memory as crown jewels
17:18 Mythos, vulnerability chaining, and attack path reasoning
20:59 How much access should you give the model
22:07 On-prem context and the autonomous workforce
24:49 Agentic identity and Keycard
28:11 Building brand and community with Insecure Agents
31:30 The Surf AI thesis and automated security hygiene
34:13 The real bottleneck to agent adoption
37:09 The easy button, Palantir, and a multi-model world
38:24 Two types of people in this new era
Connect with Ed:
LinkedIn: https://www.linkedin.com/in/edsim/
Boldstart Ventures: https://boldstart.vc
Ed's newsletter, What's Hot in Enterprise IT/VC: https://www.whatshotit.vc
More from Resilient Cyber:
Substack: https://www.resilientcyber.io
Subscribe for more conversations with security practitioners and leaders.
#aisecurity #agenticai #cybersecurity #venturecapital #appsec - Does restricting frontier AI in the name of safety actually make us less secure? Joshua Saxe joins me to make the case that it does, and that AI cybersecurity will be won through defender adoption, not restriction.
Josh has spent 15 years at the intersection of AI and security. He built and ran the machine learning program at Sophos, then led security for Llama at Meta, covering security post training, evals, agent guardrails, and prompt injection prevention. He recently left to co-found a startup reimagining vulnerability and exposure management agentically. He also writes one of the most cited blogs on AI and cyber policy.
In this episode:
- Why restricting frontier model access harms defenders more than attackers
- How monitored closed models put threat actors at a structural disadvantage
- The jagged frontier, and why attackers don't need frontier models for most of their tradecraft
- The national security and supply chain risks of pushing the world onto Chinese open weights models
- Why exploits don't cause cyberattacks, and which attacker constituencies AI actually unblocks
- The dual use ceiling on guardrails and classifiers
- Where defenders should be adopting AI right now, from access management to SOC automation
- Using agents to burn down the mountain of security technical debt
Chapters:
0:00 Intro
0:42 Josh's background, from blackhat teen to Llama security lead
3:07 The case for diffusion over restriction
6:14 Why restriction hurts defenders more than attackers
10:19 The jagged frontier and what attackers actually use models for
12:49 National security and the supply chain risk of Chinese open weights
16:08 Exploits don't cause cyberattacks
20:20 Where defenders should adopt AI right now
24:20 Guardrails, classifiers, and the dual use problem
27:34 Reimagining vulnerability management with agents
32:17 The structural advantage defenders hold
35:15 Policy wishes and the attacker's Claude Code moment
Follow Josh:
LinkedIn: https://www.linkedin.com/in/joshua-saxe-01845a1
Substack: https://joshuasaxe181906.substack.com
Follow Resilient Cyber:
Substack: https://www.resilientcyber.io
Subscribe for more conversations with security practitioners and leaders.
#aisecurity #cybersecurity #vulnerabilitymanagement #aipolicy #opensourceai
More Technology podcasts
Trending Technology podcasts
About Resilient Cyber
Resilient Cyber brings listeners discussions from a variety of Cybersecurity and Information Technology (IT) Subject Matter Experts (SME) across the Public and Private domains from a variety of industries. As we watch the increased digitalization of our society, striving for a secure and resilient ecosystem is paramount.
Podcast websiteListen to Resilient Cyber, AI Daily Briefing and many other podcasts from around the world with the radio.net app

Get the free radio.net app
- Stations and podcasts to bookmark
- Stream via Wi-Fi or Bluetooth
- Supports Carplay & Android Auto
- Many other app features
Get the free radio.net app
- Stations and podcasts to bookmark
- Stream via Wi-Fi or Bluetooth
- Supports Carplay & Android Auto
- Many other app features


Resilient Cyber
Scan code,
download the app,
start listening.
download the app,
start listening.
Resilient Cyber: Podcasts in Family

























