The most interesting thing in Oligo Security’s funding announcement this week is not the $60 million. It is a four-word phrase buried in a supporting quote.
“In the post-Mythos era,” said Brad Arkin, a cybersecurity advisor and Salesforce’s former chief trust officer, “runtime simply has to be the source of truth for modern cybersecurity programs.” No definition follows. None is offered, because by August 2026 none is needed. Somewhere in the last three months, post-Mythos stopped being a description of a model release and became a period marker that security vendors can drop into a press release and expect buyers to parse without help.
That is a remarkably fast piece of category construction, and Oligo is one of the companies that built it.
How the phrase got its currency
Cisco published a piece under the heading “Security in the Post-Mythos Era” the same week the model shipped, arguing that AI does not change the principles of security but does add speed as a third term in the risk equation. Illumio produced a fact sheet arguing that Mythos breaks the timing assumptions security programs are built on, and that zero trust drops from best practice to minimum viable architecture. A cottage industry of explainers now defines “post-Mythos remediation” as an operational category rather than a product.
Oligo has been running its own version of the argument through sponsored placement in the trade press, making the case that execution-based observation is the only approach that survives when the same system that finds a flaw can write a working exploit against it. The claim is that watching what code actually does at runtime solves both halves of the problem at once: it catches the unknown without waiting for a CVE, and it drains the known flood by separating the vulnerabilities that genuinely execute from the thousands that only exist on paper.
So when a former Salesforce trust officer says runtime has to be the source of truth in the post-Mythos era, that is not a third party stumbling into agreement. It is the closing beat of a campaign, landing in the release that monetizes it.
The round itself
Oligo raised $60 million, bringing total funding to $140 million since its 2022 founding. Participants include Ballistic Ventures, Canon Capital, Greenfield Partners, Lightspeed Venture Partners, Red Dot Capital Partners, and TLV Partners, plus angels including Mellanox co-founder Eyal Waldman.
Read the structure rather than the total. No lead investor is named. Greenfield led the company’s $50 million Series B in January 2025, and the other firms were already on the cap table. Ballistic’s Jake Seid describes the decision as one to increase an existing investment. The release calls the money “additional funding” rather than a Series C, which is the kind of word choice that gets made deliberately.
The growth figures are real but unfalsifiable as presented. Annual recurring revenue up 300% year over year, on a base the company does not disclose. Valuation more than doubled since the Series B, with no dollar figure given for either point. That is an insider extension at a negotiated markup, and there is nothing wrong with one. It is just a different signal from a new lead paying up in a contested process.
What Oligo actually built
The technology holds up better than the narrative around it. Oligo’s sensor is built on eBPF, the Linux kernel instrumentation layer, and it tracks which library functions a running workload actually calls. Most flagged vulnerabilities are never reached in execution, and those are the ones Oligo tells customers to leave alone. The ones that do get called can be blocked mid-exploit at the application layer without killing the container or the process behind it.
That blocking capability shipped in April as Runtime Exploit Blocking, and it defends against classes of technique rather than individual CVEs, so one rule can cover zero-day and n-day exploits sharing a pattern. The company also sells the approach as virtual patching, buying time between patch cycles.
Commercially, the year brought two placements that matter more than most funding announcements. AWS named Oligo the exclusive AI runtime security partner for the extended plan of Security Hub in February. In June the company joined Palantir’s FedStart program to shorten its path to FedRAMP High and Defense Department Impact Level 5, which is the gate for selling into federal and defense customers at all.
The claim that has to hold
Every runtime vendor raising money right now needs one proposition to be broadly true: that AI has changed the economics of exploitation for everyone. The strongest counterargument says it has changed them for a narrow set of actors instead.
Reporting on the frontier vulnerability hunting that produced the post-Mythos anxiety describes costs on the order of tens of thousands of dollars in compute for a single significant bug, running the model repeatedly across individual source files, inside a program with a budget in the hundreds of millions. That is a capability for organizations that could already field elite offensive research teams. It is not a new weapon in the hands of the median attacker.
If that reading is right, the runtime thesis is still sound for large enterprises and defense customers with nation-state exposure, and considerably softer in the mid-market where most security budgets live. Oligo’s federal and hyperscaler positioning suggests the company understands exactly which half of that market it is selling to.
The phrase will keep working either way. Categories priced into funding rounds usually outlive the arguments that created them.
Leave a Reply