← News

Hackuity raises $19M for AI vulnerability operations

Hackuity, an AI-powered Vulnerability Operations Center (VOC) based in Lyon, France, announced a $19 million funding round led by Forgepoint Capital International, with existing investors Bright Pixel, Bpifrance, and Seventure Partners participating. The company says the raise brings total funding to $38 million and will fund product and AI work plus expansion across Europe and Asia. Hackuity’s platform aggregates findings from more than 130 security tools and prioritizes remediation using severity, exploitability, threat intel, asset criticality, and business impact.

SAFETY desk — same-day primary that an AI vulnerability-ops platform closed a disclosed multimillion-dollar round as AI-driven discovery floods security teams with findings.

The round was led by Forgepoint Capital International, with participation from existing investors Bright Pixel, Bpifrance, and Seventure Partners. The company says the raise brings total funding to $38 million. File the $19 million figure, the unlabeled funding-round wording, the Forgepoint Capital International lead, those named existing participants, and the $38 million cumulative line as Hackuity’s. This desk is not inventing a Series letter, a valuation, an ownership split, or a check size. None was printed.

Use of proceeds, as the same wire has it: product innovation, AI capabilities, and international expansion across Europe and Asia. The company also says the investment will accelerate its mission to help security teams prioritize and remediate cyber risk at machine speed. File that product / AI / Europe-and-Asia spend plan as Hackuity’s. This desk did not sit in a board meeting and is not inventing a dollar split.

Product, as the same wire has it: an AI-powered Vulnerability Operations Center, or VOC. A VOC here means a control room that gathers vulnerability findings — reports of software weaknesses — and decides what to fix first. Hackuity says it aggregates data from more than 130 security tools, enriches every finding with business and threat context, and orchestrates remediation across security, IT, and engineering teams. Powered by a proprietary risk-scoring engine, the company says it continuously analyzes vulnerability severity, exploitability, threat intelligence, asset criticality, and business impact to determine what to fix first. File that VOC / 130-plus-tools / five-factor scoring picture as Hackuity’s. This desk did not open the console or rank a finding. Extra “leading” / “category-defining” wording is company positioning — not a desk ranking.

Customers named on the same wire, company-attributed — do not independently certify: Fortune 500 enterprises such as ENGIE and BPCE, and managed security service providers, or MSSPs, including Orange Cyberdefense. An MSSP is a company that runs security operations for other companies. The wire also says Hackuity works with a growing ecosystem of systems integrators, resellers, and MSSPs. File those ENGIE / BPCE / Orange Cyberdefense names and the Fortune 500 label as Hackuity’s. This desk did not review a customer contract. “Leading MSSPs” is company wording — not a desk ranking.

Outcome claims, still company — not an independent audit: customers see significant gains, the wire says — reducing critical-vulnerabilities noise to 0.01%; improving mean time to remediate, or MTTR, by x3; automating up to 70% of full exposure-management activities; and delivering $100Ks to $1 million in savings. MTTR here means how long it takes to fix a finding once it is known. Noise here means alerts that do not need a fix right now. File the 0.01% / x3 / up-to-70% / $100Ks-to-$1M lines as Hackuity’s. This desk did not meter a queue or sit on the books.

Context cited in the same wire, still company/wire framing — not independent Bad Signal verification of those secondary stats: AI-powered discovery is fueling a “vulnerability tsunami”; Anthropic’s Claude Mythos Preview alone identified 10,000-plus high or critical severity flaws in under two months, 99% still unpatched, with a footnote to Anthropic’s Project Glasswing news post; there are now 350,000 known Common Vulnerabilities and Exposures, or CVEs, up 20% year-on-year, with a footnote to a 2025 CVE data-review post. A CVE is a public catalog entry for a known software bug attackers can use. File that Mythos / 10,000-plus / 99% / 350,000-CVE / 20% picture as the company’s wire framing. This desk did not rerun Mythos or recount the CVE catalog.

Named voices on the release: Patrick Ragaru, CEO and co-founder of Hackuity; Damien Henault, managing director and partner at Forgepoint Capital International; Omar Abdelmoumen, head of cyber defence at ENGIE; and Cyril Demonceaux, head of Defense Center at Orange Cyberdefense. File the names and titles as theirs, via Hackuity. Their other quotes are color only and stay in Sources. This is not investment advice.

About-box context, still company-attributed: as of 2026, Hackuity says it powers vulnerability operations for more than 6,000 users, helping them protect over 2 million assets and manage 1 billion findings. The same box repeats the more-than-130-tools line and says the platform combines AI-powered exposure prioritization, validation, remediation orchestration, and cross-functional collaboration. Headquartered in Lyon, France, with operations across Europe, Singapore, and the Middle East. File those 6,000-plus / 2 million / 1 billion / Lyon / Europe-Singapore-Middle-East lines as Hackuity’s about-box. Extra “leading” / “next generation of cyber defense” wording is company positioning — not a desk ranking.

Plain English for the rest of the card: funding round = a venture raise; this wire does not print a Series letter. VOC = Vulnerability Operations Center, a control room that gathers vulnerability findings and decides what to fix first. CVE = Common Vulnerabilities and Exposures, the public catalog of known software bugs attackers can use. MSSP = managed security service provider, a company that runs security operations for other companies. MTTR = mean time to remediate, how long it takes to fix a finding once it is known. exploitability = how easy a weakness is to attack. threat intelligence = information about who is attacking what right now. asset criticality = how important a machine or system is to the business. business impact = what would break if that system were hit. exposure management = the work of finding, ranking, and fixing weaknesses across a company. noise = alerts that do not need a fix right now.

PRIMARY here: Hackuity’s 16 Sep 2026 Business Wire company release — Tier A PRIMARY company source, the original record, wire id 20260916319331. The Wedbush FinancialContent page is a full-text redistributor of that same originating wire, not a second newsroom. The hackuity.io company home is product-home context, not a third originating announce. The $19 million funding round, the Forgepoint Capital International lead, Bright Pixel / Bpifrance / Seventure Partners, the $38 million total-funding line, the product-innovation / AI / Europe-and-Asia spend plan, the VOC / 130-plus-tools / five-factor scoring product, the ENGIE / BPCE / Orange Cyberdefense names, the 0.01% / MTTR-x3 / up-to-70% / $100Ks-to-$1M outcome lines, the Mythos / 350,000-CVE wire framing, the Ragaru / Henault / Abdelmoumen / Demonceaux titles, the 6,000-plus users / 2 million assets / 1 billion findings about-box, and the Lyon headquarters are company-attributed. Customer logos, savings claims, CVE counts, and Mythos context stay company/wire-attributed — not independently audited here. NOT claimed: a Series letter, a valuation, ARR, independently verified noise or MTTR or savings figures, independently verified Mythos or CVE secondary stats, that this desk tested the VOC or saw a term sheet, a stock tip, or investment advice. Distinct from the already-filed ox-cloud-ga, cloneguard-private-ai, stackhawk-wingman, esentire-atlas-aidr, pindrop-botstopper, digicert-ai-trust-manager, lawzero-300m-canada-germany, and loora-22m-series-b.

RELATED

ONLINE

article thread

guidelines

warming…

warming…

On 16 Sep 2026 Hackuity announced a $19 million funding round. The wire says “funding round” and does not print a Series letter. The company PRIMARY is Hackuity’s Business Wire release “Hackuity Raises $19 Million to Help Enterprises Prepare for the AI-Driven Vulnerability Explosion,” dated September 16, 2026, 03:00 ET, SOURCE Hackuity, wire id 20260916319331. The same-day Wedbush FinancialContent reprint carries that originating Business Wire text. That company wire is the filing event. These are company claims. This desk did not see the term sheet or run the product.

Sources