Bynario
Milan-based startup whose AI validates which software vulnerabilities are actually exploitable, cutting through CVE noise.
Visit Website ↗ + Add to Compare Claim This CompanyOverview
Bynario builds an AI-powered application security platform that discovers, validates, prioritizes, and helps remediate software vulnerabilities across code, cloud infrastructure, and the software supply chain. Rather than flagging every possible CVE match, its Atlas product confirms which findings are actually exploitable in a customer’s specific environment, including code, packages, containers, firmware, and vendor binaries with or without source access.
The company, founded in 2025 by Alfredo Pesoli, Giancarlo Russo, and academic security researcher Lorenzo Cavallaro, combines offensive security research with product engineering. It drew attention in August 2026 when its AI-driven research uncovered serious vulnerabilities in Apple’s macOS Screen Sharing technology, which Apple subsequently patched.
Bynario closed a €2.1 million pre-seed round in September 2026 led by 360 Capital Partners with participation from PranaVentures, to build out its engineering team and platform.
Innovation Matrix Assessment
Founded in 2025 and already running real offensive-security research that found a disclosed, vendor-patched Apple vulnerability within roughly a year.
Exploitability-confirmation approach addresses genuine alert-fatigue pain for vuln management teams, though the platform is still unproven at scale.
Pre-seed stage with a €2.1M round and a small team; independently verified traction is limited to the Apple disclosure, not customer adoption data.
Exploitability-first vulnerability validation is a real shift from CVE-list triage, but several funded competitors (Tonic Security, Nucleus Security, others) pursue a similar thesis.
The Apple macOS Screen Sharing finding is an independently verifiable, vendor-confirmed result, which is stronger evidence than most pre-seed vendors can show.
AI-assisted vulnerability research is a growing need, but the category is increasingly crowded.
Why CISOs Should Care
Gives security teams a way to cut through CVE noise and focus remediation effort only on vulnerabilities proven exploitable in their own environment.
What Makes It Different
Confirms exploitability directly rather than relying on CVSS scores or static matching, spanning code, containers, firmware and vendor binaries.
The Matrix Verdict
55/100 — INCREMENTAL INNOVATOR
An Incremental Innovator: credible technical proof point (a real Apple disclosure) but still pre-seed with no disclosed customer base, in an increasingly contested exploitability-validation niche.
Editorial Note: Claims vs. Verified Findings
The Apple vulnerability disclosure is independently reported and vendor-confirmed; broader efficacy and customer-adoption claims have not yet been independently verified.
Sources
Alternatives to Bynario
Unknown Cyber Inc.
CISO ReviewedMalware genomics platform using automated deep static analysis and code-lineage comparison to identify unseen malware, variants, and supply-chain…
Synack Inc
A penetration-testing-as-a-service platform pairing a vetted researcher community with AI-driven attack surface discovery for continuous security validation.
Horizon3.ai
Autonomous penetration testing company whose NodeZero platform self-attacks networks without persistent agents, aiming to replace annual manual pentests…
Cogent Security
Agentic AI platform that autonomously triages, investigates, and remediates vulnerabilities as a force multiplier for security teams.
Airlock Digital
Application allowlisting (deny-by-default) platform that blocks unapproved executables, scripts, and processes to prevent ransomware and malware execution.
Pentera
Automated security validation platform that safely runs real attack techniques against production environments to prove which exposures are…