Skip to content
Rush Commerce
Field Notes3 min read

Exein raises $270M: 5,000 new device attacks a week

Exein raised $270M at a $1.7B valuation for kernel-level device security, citing 5,000 new attacks weekly. What it means for the hardware on your shop network.

Count the computers in your shop. Not the laptops — the router, the card readers, the label printer, the cameras, the kiosk, the thermostat. Most of them run Linux, none of them have been patched since install, and on September 15 a Rome company raised $270 million on the argument that this is now the soft edge of every network.

What actually happened

Per Exein's announcement, the round values the company at $1.7 billion and is led by Headline, with Sofina, Goldman Sachs, the EIB Group through the European Tech Champions Initiative, KfW Capital's Wachstumsfonds Deutschland and Deutsche Telekom's T.Capital joining. Existing backers Balderton, HV, Lakestar and 33N followed on.

The number to sit with is in the same post: Exein sees around 5,000 new, non-repetitive attacks a week against connected devices, a fivefold increase year over year. Its footprint covers more than two billion devices across industrial automation, automotive, energy, healthcare, semiconductors, aerospace and robotics.

The product, Photon, is a runtime security layer that sits at the kernel level and blocks malicious execution rather than reporting it afterward. Exein plans an agentic security architecture by the end of 2026 and foundation models trained on device telemetry in Q1 2027. Founder and CEO Gianni Cuozzo frames it plainly: AI is moving out of the cloud and into the physical world, and attacks now happen at machine speed. TechCrunch reports roughly 400% year-over-year growth, with Asia Pacific driving about half of revenue.

Why device security matters for your business

You are not a customer for this. Exein sells to manufacturers who embed it before the box ships. But the thesis is a free diagnosis of your own network, and the fix is unglamorous.

Inventory first. Walk the shop with the DHCP lease table open and write down every device with an IP. You will find two you forgot. Then check each one for a firmware update — the 2019 camera firmware is not fine. Then segment: your payment terminals and your guest Wi-Fi and your back-office machines do not belong on one flat network, and a VLAN on a $200 switch costs an hour. Finally, kill the defaults. An admin password printed on the underside of a device is a published credential.

None of that needs a kernel module. It closes the path that actually gets used, which is a 2021 vulnerability on a box nobody owns because nobody ever assigned it to anyone. Pick a person. Put it on the calendar quarterly.

Key takeaways

  • Exein raised $270M at a $1.7B valuation, led by Headline, with Goldman Sachs and the EIB Group participating
  • The company reports around 5,000 new non-repetitive device attacks per week — 5x year over year
  • Photon runs at the kernel level to block execution, not to alert after the fact; it ships embedded by manufacturers
  • Exein plans an agentic security architecture by end of 2026 and telemetry-trained foundation models in Q1 2027
  • Your practical move is inventory, firmware updates, VLAN segmentation, and killing default credentials
  • Assign one named owner for device patching and put it on a quarterly calendar

Every device on your network is a computer someone else configured. We map what you actually run, segment it, and write down who owns the patching — before it becomes an incident. Ask us for a device and network review, or see what we've shipped.

Sources: Exein, TechCrunch, Tech.eu.

  • #iot-security
  • #device-security
  • #firmware
  • #network-security
  • #funding
TR

Tommy Rush — Founder, Rush Commerce

Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More

Get The Rush Report weekly — one email, zero fluff.