Featured image of post Love at First Sight From the First Week: How Bloom's Founders Chose the Team Before the Problem, and the Research Before the Pitch

Love at First Sight From the First Week: How Bloom's Founders Chose the Team Before the Problem, and the Research Before the Pitch

Three Dig Security alumni committed to each other after a $255M exit, then went looking for a problem. Along the way they published eleven pieces of original vulnerability research under a company name nobody could look up — and told Anthropic its security boundary doesn't fire.

Itay Keren played handball in the Israeli national league, and he’ll tell you that’s the reason he knew inside a week that Bloom was going to exist — about five years before it did.⁵

The week in question was his first at Dig Security, sometime around 2021. He, Ofir Balassiano and Itay Frishman joined as the core team. Keren’s description of what happened next is not a sentence you expect from a man who now sells endpoint security to CISOs:

“Honestly it was love at first sight from the first week. We just clicked, the way a great team does on the court. The pace, the trust, the way we challenged each other.”

Two and a half years later Palo Alto Networks bought Dig. All three went inside. And then, in late 2025, all three left within weeks of each other to start something together — without knowing what it was.

On 30 July 2026 that something came out of stealth as Bloom Security with a $20M seed, co-led by Glilot Capital Partners and Ten Eleven Ventures, with Okta Ventures and Runtime Ventures participating. Axios Pro broke it. CTech followed. Roughly a dozen outlets ran variations of the same release, and the number was the story in all of them.

The number is the least interesting fact here.

Two things happened before it, and neither made the coverage. They picked each other before they picked a problem — deliberately, as doctrine, and Keren will explain the mechanics of it on the record. And then, for six months, they published original vulnerability research under a company name nobody could look up.

This piece is built on a Q&A with Frishman and Balassiano conducted in August 2026, on the record, plus Bloom’s published corpus and the founders’ own posts. Where’s no answer, we say so.

Same Faces, Same Scars

Keren has written about his selection criteria for co-founders and framed the whole thing through sport. “You need people who’ve been in the fire with you. People who were there at 2am because a deal mattered. People who know what your silence means.” His line about the roster that won things: same faces, same scars.

The sport was never public until now. Handball, professionally, in the Israeli national league.

“Team sports at that level teach you something you can’t learn anywhere else: you win or lose based on who’s standing next to you. Talent matters, but chemistry matters more.”

You can file that under founder poetry if you want. Hold the thought until the last section, where it turns into an operational answer about how thirty people shipped an enterprise platform in nine months.

The three biographies are worth laying out, because none of them is the origin story the category usually runs on. Keren was a submarine officer in the Israeli Navy before Demisto around 2015, then Dig, then Palo Alto — an engineering and sales-engineering career that has now survived two acquisitions. Balassiano came out of Mamram, the IDF’s central computing and software unit, through Cognyte and XM Cyber, then Dig from day zero, then roughly two years leading cloud and AI security research inside Palo Alto. Frishman came out of Unit 81, the IDF’s classified technology R&D unit, and spent four years across Dig and PANW building the core of their data and AI posture management products.

No 8200. A submariner, a software-corps researcher, and a classified-hardware R&D lead.

One correction while we’re here, since it keeps getting repeated. Dig’s acquisition was widely reported in the Israeli press at $300–400M. Palo Alto’s own FY2024 10-K puts total consideration at $255.4M — $247.6M cash plus $7.8M in replacement awards.⁶

Keren’s account of what happened after it:

“After Dig was acquired by Palo Alto Networks, there was never really a question of ‘if’ we’d start a company together. It was only a matter of ‘when’ and ‘what.’”

Nine Names

Every piece of launch coverage carried the same line about Bloom’s angel investors: founders of Dig Security, Demisto, Snyk and Talon. Nobody printed who they actually are. Bloom named them for us:

Dig — Dan Benjamin, Gad Akuka, Ido Azran. Demisto — Slavik Markovich, Rishi Bhargava, Dan Sarel, Guy Rinat. Snyk — Guy Podjarny. Talon — Ofer Ben Noon, Ohad Bobrov.

Ten people, four companies. Keren has separately named Benjamin, Azran and Akuka as his mentors, alongside the Demisto four. Which means it’s the people who watched these three work at close range, for years, writing personal checks on that basis.

For context on the round itself: per YL Ventures’ State of the Cyber Nation, Israeli cyber raised $4.4B across 130 rounds in 2025, up 9% in dollars and 46% in round count, with an average seed of $9.6M. Bloom raised roughly double that average. More telling than the dollars — endpoint security went from one seed round in 2024 to eleven in 2025. Bloom is the leading edge of a wave that was already forming.

There Was No Aha

Keren’s launch essay contains the sentence every founder profile is built around: “The day we understood that gap was the day Bloom started.” I asked which conversation that was and what the person said.

He pushed back on the question, and the pushback is better than an answer would have been.

“Honestly, I’ll push back on the premise a little: it wasn’t one conversation. That’s the thing people get wrong about ideation. It’s rarely a single aha moment.”

What he describes instead is hundreds of conversations with CISOs, and three composites that are worth reading slowly because they are the entire product thesis in plain language:

“One CISO tells you employees are running desktop AI agents that can read files, click buttons and take actions on the endpoint, and he has zero visibility into any of it. Another tells you developers are connecting MCP servers to their tools faster than security can even catalog them, each one a new door into the environment. A third tells you about agent skills, capabilities their agents are picking up and executing, and admits nobody in the company can answer a simple question: what can these agents actually do right now?”

And then the part that explains why the team-first sequence works:

“No single one of those conversations is the idea. But when you analyze all of them together, you reach a point where you understand the problem better than anyone. You become a subject matter expert in the gap itself.”

Keren has published his test for whether a problem is real, and it’s usable by anyone: leadership and the people on the ground describe the exact same pain; they’ve already burned time or budget trying to patch it themselves; and something changed recently enough to make the old workaround impossible. His tell for finding it is the mess built around it — “the workaround someone rigged up months ago and still babysits, the spreadsheet quietly holding a broken process together, the vendor everyone pays for and no one trusts.”

Before They Had a Name

On 1 February 2026, a company that did not publicly exist published a threat-intelligence post.

It kept doing that. By the time Bloom launched on 30 July, eleven research posts were live under a name nobody could look up, on a blog organised like a research lab rather than a marketing site — categories for threat intelligence, security research and tooling, named campaign tags (Hades, Mini Shai-Hulud, OpenClaw, Moltbot), and four credited authors: Keren, Balassiano, and researchers Moriel Harush and Golan Myers.

The obvious read is content marketing with a long runway. Balassiano’s answer says something more interesting than that.

The engine existed before the company did.

“We’d already started building our agentic software analysis engine back then, and when the marketplace for OpenClaw plugins surfaced, we pointed the engine at them. What we found was dozens of malicious plugins.”

So the research posts weren’t produced to generate demand. They were the product’s exhaust — output from a system that was already running, pointed at whatever marketplace happened to open that month. Which reframes the whole stealth period: Bloom wasn’t quietly building toward a launch and doing some content on the side. It was operating the core of the product in public, under an alias, against live campaigns, and publishing what fell out.

His reasoning for shipping it with nothing to sell:

“Even in stealth, that’s not something we could keep to ourselves. We wanted people to see the actual exposure and make their own decisions about it. For a security company, that’s also how you earn the right to be heard — we were claiming there’s a whole layer of the endpoint no one else was looking at, and the research was the proof, before there was ever a pitch.”

The output over those six months: 37 malicious AI agent skills caught across three active campaigns, live under a week — 33 with hidden command-and-control backdoors, two with Python reverse shells, two exfiltrating .env files to webhook.site. An active campaign against the VS Code Marketplace. The TeamPCP attack chain, from a compromised VS Code extension into GitHub’s source code. And License to Skill, which tested SKILL.md across 31 agentic clients and found that the instructions travel perfectly while the safety frontmatter does not — the fields meant to constrain which tools a skill can run are honoured by a handful of clients and silently ignored by the rest. As Bloom put it: your allowlist might gate execution, limit scope, get rewritten into nothing, or simply vanish, and nothing tells you which one happened.

A rule that parses cleanly looks like a safeguard. Reviewers count on it. In most runtimes it was never enforced.

The Dialog That Never Fires

The sharpest thing Bloom published in stealth was a Claude Code finding, credited to researcher Golan Myers.

Take an ordinary GitHub repository. Add one innocuous configuration file. Open it the way you open anything.

“Within seconds — no click, no approval, often not even a warning — we were running commands on the machine and watching secrets leave it. And it doesn’t stop when you do: it survives closing the repo and rides along in every session after.” — Balassiano

“Nothing was ‘hacked.’ Every piece we chained together is an approved, working-as-intended feature.”

Bloom reported it to Anthropic. Then said publicly that they don’t fully agree with where Anthropic drew the line. I asked Balassiano to be specific about where each side sits.

“Anthropic’s position is that the workspace trust dialog is the security boundary for project-level config — because you have to accept trust before that shell-executing setting runs, they consider the attack mitigated. I think that architecture is correct.”

Then the objection, which is one gap wide and hard to argue with:

“My disagreement is with one gap in it: trust is inherited recursively. If you’ve ever trusted ~/projects — a completely normal thing to do — you’ve pre-approved every repository you’ll ever clone into it, including ones that don’t exist yet, including the attacker’s. So for most developers in most real scenarios, the dialog never fires at all. A boundary that’s bypassed by design for the majority of your users isn’t doing the work it’s supposed to do.”

He’s holding that position from inside Anthropic’s own security integrations programme — Bloom says it was selected for the programme around Claude’s Compliance API.⁴

We didn’t ask Anthropic for its side. That’s a gap in this piece. But the disagreement itself is the useful artifact: a seed-stage vendor publicly telling a frontier lab that its security boundary doesn’t fire for most of its users, while sitting in that lab’s partner programme, is not standard behaviour in a category where everyone would rather have the logo than the argument.

What It Actually Does

Frishman has the best explanatory frame in Bloom’s corpus, and it isn’t about AI at all.

Supply-chain attacks don’t pick the lock. They walk in behind a real badge. “Shai-Hulud doesn’t break in. It tailgates the update. Same publisher, same verified badge, same install you’ve run a hundred times.” And once inside: “It doesn’t bring its own burglar tools. It finds yours, already on the workbench.” It runs TruffleHog to hunt secrets. It republishes itself using the developer’s own GitHub and npm credentials. In the related Nx attack it recruited the AI CLI tools already installed on the machine to go looking for credentials.

The Nx Console extension had 2.2 million installs and a verified badge. A poisoned AsyncAPI extension exfiltrated for nearly a month — just because no alarm pointed at that door. And GitHub itself disclosed that a poisoned VS Code extension on an employee device led to roughly 3,800 internal repositories being exfiltrated.¹

Keren’s version of the same argument is aimed squarely at every AI-discovery dashboard on the market: a list of 400 AI tools answers the old question, what exists. “Until you can judge each one by how it runs and what surrounds it — and act on it — you don’t have a handle on the surface. You have a spreadsheet.”

Bloom ships five modules against that:

  • Live inventory — everything running on an endpoint, including who built it, what it can reach and where it came from.
  • Contextual risk analysis — marketplace intelligence, static analysis and behavioural sandboxing, scored per endpoint.
  • Granular remediation — previews what breaks and who’s affected before it acts, then notifies them.
  • Supply-chain prevention — blocks packages and skills at the source across npm, the Chrome Web Store and Open VSX.
  • AI guardrails — scales over-permissioned MCP servers back to safe defaults.

Three product answers from the Q&A that aren’t in any launch coverage, and that a CISO would ask in this order.

On “agentic, contextual, per endpoint.” Frishman says the phrase describes granularity of judgment, not a process running on every machine.

“The same extension can be perfectly fine on a developer’s machine and a real risk on a finance laptop, so there are no global verdicts.”

The agent revisits its conclusion whenever the software or the endpoint changes — which is the actual supply-chain case: a trusted extension changes ownership, a new version requests permissions it never needed, a package quietly adds behaviour unrelated to its stated purpose. Yesterday’s safe verdict doesn’t carry into today’s compromised version. It also lets policy be written as intent rather than as an allow list: AI agents are fine for engineering, not on machines that touch customer data.

On where detonation happens. In Bloom’s cloud, not on the device. They sandbox marketplace software at the source, before it reaches anyone’s fleet. What leaves the laptop is inventory and metadata about how software is used — “no file contents, no documents, no browsing data, no code. The endpoint receives verdicts; it doesn’t ship your data out to earn them.”

On onboarding taking minutes. There are two modes, and the light one is agentless: Bloom rides the EDR or MDM the organisation already runs — CrowdStrike, Intune, Jamf — and dispatches an ephemeral sensor across the fleet that runs, collects software-posture metadata, and terminates. No persistent agent, no admin rights on user machines. The heavier mode is a full agent for continuous coverage, pushed through the existing MDM in one automated process.

Thirty People, Nine Months

Bloom was founded in late 2025. It launched in July 2026 with thirty people, all in Israel, SOC 2, five shipped modules and what it describes as dozens of enterprise deployments.² That’s roughly nine months.

Frishman has written that every engineer at Bloom effectively runs a team of agents, and that work which took four months five years ago now fits inside a two-week sprint. I asked what broke the first time they ran R&D that way.

“The honest answer is that less broke than you’d expect, and the reason is boring: most of this team has worked together for years, across previous companies. We already knew how to run together, so when the ground shifted we adjusted in stride rather than in crisis.”

What did change was planning.

“Our old planning assumed the unit of work was an engineer writing code. Once a 4-month project fits in two weeks, that model stops describing reality: things we expected to be hard shipped in a day, and things that looked trivial stalled because the agents lacked the context to do them well.”

So the sprint changed shape. Engineers’ primary job became building the infrastructure, the skills and the encoded organisational knowledge that let agents work properly in Bloom’s environment — and sprints now budget explicitly for that layer, because an hour spent there pays out across every project that follows, while an hour spent brute-forcing a feature pays out once.

I asked whether anyone good couldn’t work that way. He says they didn’t hit it, and again credits the history: experienced engineers who already think in leverage rather than lines of code, and who trust each other enough to change how they work without feeling threatened by it.

“When execution is nearly free, the thinking is where engineers earn their keep.”

So the handball answer wasn’t decoration. Thirty people changed how they build software in the middle of a build, and nobody fought about it.

It’s the inverse of the problem Sherman keeps running into. Ziv Mizrahi building a game engine alone, Jordan Winston as the host and the salesman and the face, Rachel Fiegler with the operating knowledge living in two people’s heads — all of them stuck on the same wall, where the thing that makes you good is the thing you can’t hand off. Bloom’s founders solved that before they had a product, by refusing to build without people they’d already been in the fire with.

Golda

Bloom has a Chief Dog Officer. Her name is Golda, she’s been there since day one, she comes to the office on Harav Ashi every day, and per Frishman she “personally interviews every new dog who wants to join the team.”

It’s a joke. It’s also the tell. In the same nine months this company hired a dog, published eleven pieces of research nobody asked for, argued with Anthropic in public, and built a prediction market for Black Hat gossip because, in Keren’s words, the cyber industry runs on threat intel and gossip, mostly gossip.

None of that is what a seed-stage company does to close a round. All of it is what a group of people do when they’ve already decided they’re working together for the next several years and are figuring out the rest as they go.

You win or lose based on who’s standing next to you. 💜


Fast facts: Bloom Security

What is Bloom Security? An Israeli endpoint-security company securing what it calls non-binary software — browser extensions, IDE plugins, packages, MCP servers, agent skills and AI agents — through live inventory, per-endpoint contextual risk scoring, remediation with blast-radius preview, and install-time blocking across npm, the Chrome Web Store and Open VSX.

Who founded it? Itay Keren (CEO), Ofir Balassiano (CPO) and Itay Frishman (CTO), all three from Dig Security and then Palo Alto Networks. Founded late 2025. Around 30 people, all in Israel. Offices at 6 Harav Ashi St., Tel Aviv.

What did it raise? $20M seed, announced 30 July 2026, co-led by Glilot Capital Partners and Ten Eleven Ventures, with Okta Ventures and Runtime Ventures participating. Angels: the founders of Dig, Demisto, Snyk and Talon — ten named individuals. Valuation undisclosed.

How is it deployed? Agentless via existing EDR/MDM (CrowdStrike, Intune, Jamf) using an ephemeral sensor, or as a full agent pushed through MDM. Sandboxing runs in Bloom’s cloud against marketplace software, not on employee devices.

What’s verified and what isn’t? Funding, headcount, launch date, founder backgrounds and the research corpus are verified. Customer count, ARR, pricing, OS coverage and the Anthropic partnership are not.

Contact: bloom.security · info@bloom.security · all three founders respond to LinkedIn DMs and openly solicit them.


Notes on the numbers

We publish what we can verify and label what we can’t. Here’s the honest ledger for this piece:

  1. The ~3,800 internal repositories exfiltrated via a poisoned VS Code extension traces to GitHub’s own public statement, which was itself based on the attackers’ claims. Bloom pointed us to the source. Treat it as GitHub relaying an attacker’s number, not as an audited count.
  2. “Dozens of large enterprises” is self-reported and unnamed. No ARR, no ACV, no pricing. The only named public reference is Paychex’s CISO, who also sits in lead investor Glilot’s CISO advisory network.
  3. Glilot’s Kobi Samboursky called Bloom’s early traction “unprecedented for a company at this stage.” That is an investor describing his own portfolio company, which is why it doesn’t appear in the body of this piece.
  4. The Anthropic security integrations partnership is sourced only to Balassiano’s own post and has not been independently confirmed. Anthropic was not asked for comment on the disclosure disagreement described above; if it responds, we’ll update this piece.
  5. The handball career, the mentor names and the account of Dig’s first week come from Keren’s own statements and are not independently verifiable.
  6. Dig’s acquisition price is $255.4M total consideration per Palo Alto Networks’ FY2024 10-K, against the $300–400M widely reported in the Israeli press at the time.
💜️️️️️️
Built with Hugo
Theme Stack designed by Jimmy