📊 Key Data
  • $25M Series A Funding: Nebulock secures $25 million in funding led by FirstMark.
  • 40% Customer Impact: Platform detected 50,000+ events related to OpenClaw across 40% of its customer base.
  • 750 Source Code Files: Prevented insider threat from copying nearly 750 source code files.
🎯 Expert Consensus

Experts would likely conclude that Nebulock's funding and technology represent a critical shift in cybersecurity, emphasizing autonomous, context-aware defense against AI-driven threats.

25 days ago
Nebulock's $25M War Chest Signals New Front in AI Cyber Arms Race

Nebulock's $25M War Chest Signals New Front in AI Cyber Arms Race

BOSTON, MA – June 25, 2026 – In a move that underscores a critical inflection point for the cybersecurity industry, AI-native security firm Nebulock has secured a $25 million Series A funding round. The investment, led by FirstMark with significant participation from existing backers like Bain Capital Ventures and Decibel, is more than just a financial milestone; it's a strategic bet on a new philosophy for defending the enterprise in an era where attackers are increasingly weaponizing artificial intelligence to disappear into the noise of normal network activity.

Less than a year after emerging from stealth, Nebulock’s rapid capital injection highlights the urgent market need for a different approach. As attackers trade brute-force intrusions for sophisticated, AI-assisted campaigns using valid credentials, the traditional security playbook of chasing alerts is proving dangerously inadequate. Nebulock’s thesis is that the future of defense lies not in building a better alarm system, but in creating a persistent, autonomous hunter that understands context and behavior.

The New Calculus of Cyber Warfare

The central challenge for modern security teams is no longer just finding the obvious red flags. It is, as Nebulock posits, about identifying the “green flags that should look fine, but are not.” According to the 2026 Verizon Data Breach Investigations Report, threat actors are already leveraging AI in dozens of attack vectors, allowing them to mimic legitimate user workflows and operate undetected for months. When a malicious actor uses valid credentials, they don't trip the obvious wires. For legacy systems, they look like just another employee.

This is the problem Nebulock was built to solve. Instead of relying on static rules and siloed data, the platform correlates telemetry across an organization's entire digital footprint—endpoint, identity, cloud, and SaaS applications—to build a behavioral context graph. It’s a shift from asking “Is this suspicious?” to “Is this normal, for this user, on this device, at this time, with this intent?”

This “hunt-first” methodology is already demonstrating its value. “Security teams need to understand not just what looks suspicious, but what looks ordinary for the wrong reasons. Bringing on Nebulock changed the math on how quickly we can detect and act,” said Myke Lyons, CISO of Cribl, a Nebulock customer. “That shift from assumption to evidence is what a proactive posture actually looks like.” His experience points to a crucial operational advantage: having the hunt pre-run, allowing teams to move directly to remediation before a traditional alert is even generated.

From Stealth to Scale on Investor Conviction

Nebulock’s impressive trajectory—from a stealth launch to a $25 million Series A backed by a consortium of top-tier VCs in under a year—is a story of both market timing and investor alignment. The syndicate of investors, including FirstMark, Bain Capital Ventures, Decibel, Zetta Venture Partners, and Step Function, represents a deep bench of expertise in AI-native and enterprise infrastructure platforms. Their collective bet is a powerful signal of where the market is headed.

Firms like FirstMark and Bain Capital Ventures have built theses around the idea that AI is a dual-use technology, creating new vulnerabilities while also empowering a new generation of defenders. Similarly, Zetta Venture Partners’ exclusive focus on AI-first companies and Decibel’s interest in “agentic solutions” perfectly align with Nebulock’s core product philosophy. These are not just financial backers; they are strategic partners who see a fundamental platform shift on the horizon.

“The entire security market is at an inflection point,” noted David Waltcher, Partner at FirstMark. “As attacks become faster, more credentialed, and more autonomous, enterprises need a new security layer built around context, behavior, and continuous reasoning.” His confidence in the company is rooted in a belief that its founding team, composed of veterans from security giants like CrowdStrike and Palo Alto Networks, possesses the rare combination of deep domain expertise and product vision required to execute on such an ambitious goal.

Taming the 'Agentic' Threat and Shadow AI

Perhaps the most compelling evidence of Nebulock's relevance is its real-world performance against novel threats that legacy systems are blind to. The company has been on the front lines of combating “agentic” insider threats, a new category of risk driven by the explosion of generative AI tools in the workplace.

When the open-source AI agent framework OpenClaw went viral earlier this year, employees across dozens of organizations began downloading it, often bypassing corporate IT controls in a rush to experiment. This seemingly benign “shadow AI” adoption quickly created a massive, unforeseen attack surface. Nebulock’s platform observed attackers exploiting OpenClaw to bypass authentication and gain control of local machines. Within a single week, the company tracked over 50,000 related events across 40% of its customer base and deployed proactive detections, preventing incidents before they could escalate. This rapid response to an emergent, zero-day style risk illustrates the power of a behavioral, context-aware model.

This is just one example. The platform has also been credited with uncovering a malicious remote actor who had been operating undetected for months within a digital retailer and stopping an insider at a Fortune 1000 company who was copying nearly 750 source code files to a USB drive—subtle, high-impact events that are often missed until it is too late.

The Vision Beyond the Hunt: Redefining Security Operations

While the immediate focus is on autonomous threat hunting, Nebulock’s long-term vision is far more disruptive. “Our vision is much bigger than agentic threat hunting alone—we want to do for SIEM what EDR did for endpoint,” stated Damien Lewke, Nebulock’s founder and CEO. This is a bold declaration to challenge the established order of the Security Information and Event Management (SIEM) market, a space long criticized for its complexity, high cost, and tendency to generate overwhelming alert fatigue for Security Operations Centers (SOCs).

The comparison to Endpoint Detection and Response (EDR) is apt. EDR platforms fundamentally changed endpoint security by moving beyond signature-based antivirus to provide deep visibility and behavioral analysis. Lewke and his team aim to bring that same revolution to the core of the SOC, collapsing complexity and delivering actionable, high-confidence findings out of the box. The new capital will be used to expand these capabilities, deepening the platform's context graph and scaling its engineering and go-to-market teams to meet enterprise demand.

For organizations struggling to keep pace with an evolving threat landscape, this shift represents a move away from a reactive, alert-driven model and toward a state of continuous, proactive protection. By providing security teams with the context to see what their existing stack cannot, Nebulock is not just selling a product; it is advocating for a fundamental change in how security is operationalized.

Topics & Related

Sector:
AI & Machine Learning
Cybersecurity
Theme:
Agentic AI
Threat Landscape
Event:
Series A
UAID: 39691