Upwind buys Aegis to staff a lab for AI-made attacks
Upwind acquired nine-month-old Aegis on September 23 and launched AI Security Labs. AI-generated attacks now have a dedicated research team pointed at them.
When a defender buys a nine-month-old company to staff a lab, the thing they are worried about is moving faster than their roadmap. On September 23, cloud security firm Upwind acquired Israeli startup Aegis in a stock deal Calcalist reported at tens of millions of dollars, and stood up Upwind AI Security Labs around the team. The target of that lab is AI-generated attacks — and the economics of those attacks are what should interest anyone running a small company.
What actually happened
Aegis was founded roughly nine months ago by Omri Limor and Saar Ankonina, both alumni of Unit 8200, Israel's signals intelligence outfit. The company built defenses against attacks that are themselves machine-generated: autonomous exploitation pipelines and credential harvesting run at scale.
Both founders now lead Upwind AI Security Labs, which Upwind says will work on scanning, attack detection and defenses for AI-driven workflows. The team is 12 developers and researchers today, with plans to reach about 25 within three months.
The deal follows Upwind's $300 million raise at roughly a $3.8 billion valuation — more than double the $1.5 billion it carried in January after a $250 million round. Axios also reported the acquisition on September 23.
Why AI-generated attacks matter for your business
Here is the uncomfortable part, and we will say it plainly because most security vendors will not.
For twenty years, small businesses were protected by not being worth the trouble. A human attacker picking targets by hand went after the payoff, and a 12-person shop in Phoenix was not it. That protection was never a control. It was an accident of attacker labor cost, and automated exploitation pipelines are the thing that removes it. When reconnaissance, exploit selection and credential stuffing all run without a person in the loop, being small stops being cover. You get scanned because everything gets scanned.
So the defenses that matter are the unglamorous ones that do not depend on being overlooked.
Credentials first. Large-scale credential harvesting works because reused passwords work. Phishing-resistant MFA on email, banking, your domain registrar and your payment processor closes the door that most automated campaigns are actually trying.
Then ask what your agents can reach. Every AI integration you have authorized holds a token, and most of those tokens were scoped to "everything this app can do" rather than to the one job. An automated attacker that lands on an over-scoped agent credential inherits whatever you granted it. Inventory the connections, cut the scopes to the task, rotate on a schedule.
Then patch on exploitation, not severity. Automated pipelines go after what is known to work. Whatever is on the CISA KEV catalog and touching your stack goes first, regardless of its CVSS number.
None of that requires a security team. It requires an afternoon and a list.
Key takeaways
- Upwind acquired nine-month-old Aegis on September 23 in a stock deal valued at tens of millions
- Aegis founders Omri Limor and Saar Ankonina, both Unit 8200 alumni, now lead Upwind AI Security Labs
- The lab starts at 12 researchers and targets roughly 25 within three months
- Aegis built defenses against autonomous exploitation pipelines and large-scale credential harvesting
- Being small stopped being protection the moment target selection stopped needing a human
- Phishing-resistant MFA on email, banking, registrar and payments closes the door most campaigns use
- Audit what every AI integration's token can reach and cut the scope down to the actual job
- Patch by known exploitation — the CISA KEV catalog — before you patch by CVSS score
Most AI integrations are over-scoped on day one and never revisited. Rush Commerce builds automation with least-privilege credentials, rotation baked in, and an audit log of what each agent touched. See how we scope it or have us review what your current integrations can reach.
- #ai-security
- #credential-hygiene
- #threat-research
- #acquisition
- #small-business
Tommy Rush — Founder, Rush Commerce
Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More
Get The Rush Report weekly — one email, zero fluff.
Keep reading
Verda raises $189M: another place to run inference
Helsinki's Verda hit unicorn status with a $189M Series B and a $165M revenue run rate. The neocloud tier is now real enough to quote against your hyperscaler bill.
Read itAI CEOs brief the UN Security Council: what changes for you
France convened the Security Council's first session on AI safety risks on Sept 23, with Altman, Amodei, Bengio and Delangue briefing. Here's the operator read.
Read it