The world is too loud. Read what matters.

The a16z Show

90+ zero days discovered by AI this year: humans now locked out of the defense loop

Armiden launches AI-powered black-box attacks against client networks, discovering 90+ zero days since early 2026; attack-defense cycles now compress to microseconds, erasing the window for human decision-making.

CybersecurityAI red teamZero-day vulnerabilitiesAutonomous defenseSecurity startup

The video won't play here. Listen to the audio instead:

For entrepreneurs and investors seeking to understand how AI rewrites security product logic and where the next wave of security startups emerges, this episode delivers concrete tactics and numbers.

The argument · tap a timestamp to hear it

2:01

Second startup: can't afford to miss this AI shift

After 30 years in security, Kevin Mandia opted to start again—not from serial-founder ambition but after meeting founders Travis Lanham, David Slater, and Evan Pena. He says his three decades felt ‘nearly obsolete’ in the AI era, yet he judged he could help the team deliver what clients need right now, so he joined rather than remaining an investor.

— Kevin Mandia
6:06

AI attack's advantage: sheer scale and speed

Human intruders hit bandwidth ceilings—they pick one path and dig deep. AI has no such constraint; it probes many paths in parallel. What takes AI one microsecond takes 70 people to match. Mandia notes AI still lacks stealth—it tends to repeat against breached points, creating detectable timing anomalies. But for structured work like vulnerability discovery and exploit writing, AI is already strong enough; no need to wait for smarter models.

— Kevin Mandia
11:12

Without strong attacks, there is no strong defense

Armiden's product logic: attack first, defense after. Armiden Red simulates top-tier attackers in AI-driven hyperattacks against client networks, mapping all services, routes, and assets into metadata. Then it polls for changes at low cost—‘heartbeat’ cadence. When new vulnerability intelligence or network changes appear, it immediately re-engages against the delta. The goal: judge whether a vulnerability is exploitable before CVE publication.

— Kevin Mandia
16:22

Ninety zero days found by external black-box attacks alone

Since January 2026, Armiden has found 90+ zero days in production at Fortune 500 clients—black-box external testing only. Clients are mostly grateful, because this differs fundamentally from ‘here's source-code scan noise.’ Armiden typically alerts the CISO within 48 hours: ‘You have remote code execution in your DMZ.’ The response is emergency mode, not standard pen-test workflow.

— Kevin Mandia
23:45

Tactical defense cannot have humans in the loop anymore

Mandia argues that speed requirements force AI into tactical defense—humans cannot stay in the loop. Once breached, agentic command-and-control spreads through the system at alarming velocity: humans type one lateral-movement command at a time; AI executes thousands in parallel. Armiden Blue's direction: EDR and firewall platforms auto-generate compensating controls, stanch the wound first, hand off to humans or mature agentic systems later.

— Kevin Mandia
27:52

Hugging Face incident: underestimating what models can really do

The Hugging Face incident, Mandia says, follows the pattern of every paradigm shift he has witnessed—people underestimate their adversary (this time, the model itself), then discover in postmortem that simple guardrails would have stopped it. The root problem: AI researchers and security veterans rarely pair. The former chase innovation velocity; the latter know how to cage a beast but not AI. At Armiden, red-team veterans passively review every attack-agent prompt. Most killed agents are wasteful—not unsafe.

— Kevin Mandia
29:57

Twenty kill chains: open and closed models reach the same wall

Armiden benchmarked against 20 real kill chains attackers walked at customer sites. Neither open-source weights nor the most advanced closed-source models completed more than 8 full chains—both stopped at the same place. Difference: closed-source is faster, open-source catches up given more time and compute. In cybersecurity, the capability gap between open and closed is narrower than in other domains.

— Kevin Mandia
39:17

This startup's playbook is nothing like Mandiant's 2004 model

Mandiant launched in 2004 bootstrapped and profit-driven—few believed ‘breaches are inevitable,’ so competition barely existed. Armiden faces headwinds: massive tailwinds but dependent on fundraising and sales/international expansion to seize the window. Mandia cites Wiz: $100M ARR in 18 months from first product. Armiden's target: faster. The only durable moat today, he argues, is relentless execution—win, satisfy, repeat. Code advantages erode in six months.

— Kevin Mandia

In their own words · checked verbatim

What AI does in a microsecond would take 70 humans. They can't even do it. It's apples to oranges.

Kevin Mandia6:06

You don't have a defense unless you have a great offense to go up against.

Kevin Mandia11:12

Armiden since January this year, in 2026, we have found over 90 zero days at customer sites, all in production.

Kevin Mandia16:22

It's like the balloon popped. You know, so it gets in. It's just like, they're gone. The whole defense apparatus just popped.

Kevin Mandia23:45

we had no model go through the entire kill chains of more than eight.

Kevin Mandia29:57

Get customer, make customer happy, repeat.

Kevin Mandia46:19

Figures

Zero days discovered (since early 2026)90+16:22
Kill chains completed (of 20 tested)829:57
Fortune 100 firms covered in team's career99/10035:14
RSA main stage speakers who are Mandiant alumni43%39:17
Wiz: time to $100M ARR from first product18 months40:18

Glossary

zero day
A vulnerability with no released patch; directly exploitable.
CVE
Standardized identification number used by public vulnerability databases.
SOC
Security operations center—team or system that monitors and responds to security incidents.
EDR
Endpoint detection and response—product that monitors endpoint anomalies and auto-responds to intrusion.
kill chain
The complete sequence of steps an attacker executes from breach to objective.

How to listen

Who it's for

Cybersecurity entrepreneurs, investors, enterprise CISOs, and security leads curious about how AI reshapes the attack-defense tempo.

Skip

After 35 minutes: the fundraising and sales tactics section leans toward generic startup methodology; pure-technical audiences can skip it.