90+ zero days discovered by AI this year: humans now locked out of the defense loop
Armiden launches AI-powered black-box attacks against client networks, discovering 90+ zero days since early 2026; attack-defense cycles now compress to microseconds, erasing the window for human decision-making.
The video won't play here. Listen to the audio instead:
The argument · tap a timestamp to hear it
Second startup: can't afford to miss this AI shift
After 30 years in security, Kevin Mandia opted to start again—not from serial-founder ambition but after meeting founders Travis Lanham, David Slater, and Evan Pena. He says his three decades felt ‘nearly obsolete’ in the AI era, yet he judged he could help the team deliver what clients need right now, so he joined rather than remaining an investor.
— Kevin MandiaAI attack's advantage: sheer scale and speed
Human intruders hit bandwidth ceilings—they pick one path and dig deep. AI has no such constraint; it probes many paths in parallel. What takes AI one microsecond takes 70 people to match. Mandia notes AI still lacks stealth—it tends to repeat against breached points, creating detectable timing anomalies. But for structured work like vulnerability discovery and exploit writing, AI is already strong enough; no need to wait for smarter models.
— Kevin MandiaWithout strong attacks, there is no strong defense
Armiden's product logic: attack first, defense after. Armiden Red simulates top-tier attackers in AI-driven hyperattacks against client networks, mapping all services, routes, and assets into metadata. Then it polls for changes at low cost—‘heartbeat’ cadence. When new vulnerability intelligence or network changes appear, it immediately re-engages against the delta. The goal: judge whether a vulnerability is exploitable before CVE publication.
— Kevin MandiaNinety zero days found by external black-box attacks alone
Since January 2026, Armiden has found 90+ zero days in production at Fortune 500 clients—black-box external testing only. Clients are mostly grateful, because this differs fundamentally from ‘here's source-code scan noise.’ Armiden typically alerts the CISO within 48 hours: ‘You have remote code execution in your DMZ.’ The response is emergency mode, not standard pen-test workflow.
— Kevin MandiaTactical defense cannot have humans in the loop anymore
Mandia argues that speed requirements force AI into tactical defense—humans cannot stay in the loop. Once breached, agentic command-and-control spreads through the system at alarming velocity: humans type one lateral-movement command at a time; AI executes thousands in parallel. Armiden Blue's direction: EDR and firewall platforms auto-generate compensating controls, stanch the wound first, hand off to humans or mature agentic systems later.
— Kevin MandiaHugging Face incident: underestimating what models can really do
The Hugging Face incident, Mandia says, follows the pattern of every paradigm shift he has witnessed—people underestimate their adversary (this time, the model itself), then discover in postmortem that simple guardrails would have stopped it. The root problem: AI researchers and security veterans rarely pair. The former chase innovation velocity; the latter know how to cage a beast but not AI. At Armiden, red-team veterans passively review every attack-agent prompt. Most killed agents are wasteful—not unsafe.
— Kevin MandiaTwenty kill chains: open and closed models reach the same wall
Armiden benchmarked against 20 real kill chains attackers walked at customer sites. Neither open-source weights nor the most advanced closed-source models completed more than 8 full chains—both stopped at the same place. Difference: closed-source is faster, open-source catches up given more time and compute. In cybersecurity, the capability gap between open and closed is narrower than in other domains.
— Kevin MandiaThis startup's playbook is nothing like Mandiant's 2004 model
Mandiant launched in 2004 bootstrapped and profit-driven—few believed ‘breaches are inevitable,’ so competition barely existed. Armiden faces headwinds: massive tailwinds but dependent on fundraising and sales/international expansion to seize the window. Mandia cites Wiz: $100M ARR in 18 months from first product. Armiden's target: faster. The only durable moat today, he argues, is relentless execution—win, satisfy, repeat. Code advantages erode in six months.
— Kevin MandiaIn their own words · checked verbatim
What AI does in a microsecond would take 70 humans. They can't even do it. It's apples to oranges.
Kevin Mandia6:06
You don't have a defense unless you have a great offense to go up against.
Kevin Mandia11:12
Armiden since January this year, in 2026, we have found over 90 zero days at customer sites, all in production.
Kevin Mandia16:22
It's like the balloon popped. You know, so it gets in. It's just like, they're gone. The whole defense apparatus just popped.
Kevin Mandia23:45
we had no model go through the entire kill chains of more than eight.
Kevin Mandia29:57
Get customer, make customer happy, repeat.
Kevin Mandia46:19
Figures
| Zero days discovered (since early 2026) | 90+ | 16:22 |
| Kill chains completed (of 20 tested) | 8 | 29:57 |
| Fortune 100 firms covered in team's career | 99/100 | 35:14 |
| RSA main stage speakers who are Mandiant alumni | 43% | 39:17 |
| Wiz: time to $100M ARR from first product | 18 months | 40:18 |
Glossary
- zero day
- A vulnerability with no released patch; directly exploitable.
- CVE
- Standardized identification number used by public vulnerability databases.
- SOC
- Security operations center—team or system that monitors and responds to security incidents.
- EDR
- Endpoint detection and response—product that monitors endpoint anomalies and auto-responds to intrusion.
- kill chain
- The complete sequence of steps an attacker executes from breach to objective.
How to listen
Cybersecurity entrepreneurs, investors, enterprise CISOs, and security leads curious about how AI reshapes the attack-defense tempo.
After 35 minutes: the fundraising and sales tactics section leans toward generic startup methodology; pure-technical audiences can skip it.