Skip to content
Rush Commerce
Software & Dev3 min read

Empirical Security raised $25M to predict which CVEs get hit

Exploited vulnerabilities passed stolen credentials as the top breach vector. Empirical Security raised $25M on that shift — and the free version of its idea works for you.

For nineteen years, the Verizon Data Breach Investigations Report said attackers get in with stolen passwords. This year it doesn't. Exploited software vulnerabilities took the top spot, and on July 20 Empirical Security closed a $25M Series A to sell the thing that logically follows: predicting which CVEs are actually going to be used against you, instead of handing you a list of 400 and wishing you luck.

What actually happened

Per SecurityWeek, the round was led by Brightmind Partners with Costanoa Ventures and Hyde Park Angels participating, bringing the Chicago company's total to $37M since it was founded in 2024.

The founding team is the reason this is worth reading. CEO Ed Bellis co-founded Kenna Security. CTO Michael Roytman was Kenna's chief data scientist. Chief data scientist Jay Jacobs co-created EPSS — the Exploit Prediction Scoring System, the open standard that scores a CVE by how likely it is to be exploited in the wild. These are the people who built vulnerability prioritization the first time.

Two products: Foundation, a global model tracking over 18,000 exploited CVEs, and Radiant, a per-organization engine tuned to what's actually running in your environment.

The market backdrop is the whole story. The 2026 DBIR analyzed more than 22,000 breaches and found vulnerability exploitation accounted for 31% of initial access, up from 20% the prior year — passing credential abuse, which fell to 13%. Meanwhile only 26% of CISA KEV vulnerabilities were fully remediated in 2025, down from 38%. Attackers sped up. Patching slowed down.

Why exploit prediction matters for your business

You are not the customer here. Empirical sells to enterprise security teams, and that's fine — the useful part is free.

Most small businesses handle vulnerabilities one of two ways: ignore them entirely, or run a scanner that produces a 400-line report sorted by CVSS score, which is a severity rating, not a probability. CVSS tells you how bad it would be if someone exploited it. It says nothing about whether anyone ever has. That's why the reports don't get read — everything is red, so nothing is.

The prioritization method Empirical is commercializing is available to you at zero cost:

  • CISA KEV is a free, public catalog of vulnerabilities confirmed exploited in the wild. If something you run is on it, patch it this week. Not next quarter.
  • EPSS scores are free and published daily. They estimate exploitation probability in the next 30 days. Sort by that, not CVSS.
  • Know your inventory. You cannot prioritize a list of CVEs against software you can't name. WordPress plugins, that abandoned staging box, the CMS on the marketing site — the thing that gets exploited is almost always the thing nobody remembered was running.

That's the entire method. Inventory, cross-reference against what's confirmed exploited, patch that first. It is unglamorous and it is most of the value.

We run patch windows on the systems we maintain, and the CVE list has never been the hard part. Deciding which twelve of the four hundred matter this week is the work — and the answer is public.

Key takeaways

  • Empirical Security raised $25M Series A on July 20, led by Brightmind Partners — $37M total, founded by the Kenna Security and EPSS team
  • Verizon's 2026 DBIR: vulnerability exploitation hit 31% of initial access, up from 20%, passing credential abuse for the first time in 19 years
  • Only 26% of CISA KEV vulnerabilities were fully remediated in 2025, down from 38% — remediation is losing the race
  • You don't need to buy this: CISA KEV and EPSS are free. Patch by exploitation probability, not CVSS severity

No idea what software you're actually running? We inventory it, patch what's confirmed exploited, and keep it maintained instead of handing you a report. See how we handle maintenance.

Sources: SecurityWeek, Help Net Security, watchTowr.

  • #security
  • #vulnerability-management
  • #patching
  • #cve
  • #epss
TR

Tommy Rush — Founder, Rush Commerce

Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More

Get The Rush Report weekly — one email, zero fluff.