<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Bloom Security on Sherman - Israeli Startups</title><link>https://sherm4n.com/tags/bloom-security/</link><description>Recent content in Bloom Security on Sherman - Israeli Startups</description><generator>Hugo -- gohugo.io</generator><language>en-us</language><lastBuildDate>Sun, 16 Aug 2026 08:59:00 +0100</lastBuildDate><atom:link href="https://sherm4n.com/tags/bloom-security/index.xml" rel="self" type="application/rss+xml"/><item><title>Love at First Sight From the First Week: How Bloom's Founders Chose the Team Before the Problem, and the Research Before the Pitch</title><link>https://sherm4n.com/bloom-security-israel-ai-endpoint-itay-keren/</link><pubDate>Sun, 16 Aug 2026 08:59:00 +0100</pubDate><guid>https://sherm4n.com/bloom-security-israel-ai-endpoint-itay-keren/</guid><description>&lt;img src="https://sherm4n.com/bloom-security-israel-ai-endpoint-itay-keren/cover.webp" alt="Featured image of post Love at First Sight From the First Week: How Bloom's Founders Chose the Team Before the Problem, and the Research Before the Pitch" /&gt;&lt;script type="application/ld+json"&gt;
{
"@context": "https://schema.org",
"@type": "NewsArticle",
"headline": "Love at First Sight From the First Week: How Bloom's Founders Chose the Team Before the Problem, and the Research Before the Pitch",
"description": "Three Dig Security alumni committed to each other after a $255M exit, then went looking for a problem. Along the way they published eleven pieces of original vulnerability research under a company name nobody could look up — and told Anthropic its security boundary doesn't fire.",
"image": "https://sherm4n.com/bloom-security-israel-ai-endpoint-itay-keren/cover.webp",
"author": {
"@type": "Person",
"name": "Alex Sherman",
"url": "https://sherm4n.com/authors/alex-sherman"
},
"publisher": {
"@type": "Organization",
"name": "Sherman",
"logo": {
"@type": "ImageObject",
"url": "https://sherm4n.com/images/logo-black.png"
}
},
"datePublished": "2026-08-16T08:59:00+01:00",
"dateModified": "2026-08-16T08:59:00+01:00",
"mainEntityOfPage": {
"@type": "WebPage",
"@id": "https://sherm4n.com/bloom-security-israel-ai-endpoint-itay-keren/"
}
}
&lt;/script&gt;
&lt;p&gt;Itay Keren played handball in the Israeli national league, and he&amp;rsquo;ll tell you that&amp;rsquo;s the reason he knew inside a week that Bloom was going to exist — about five years before it did.⁵&lt;/p&gt;
&lt;p&gt;The week in question was his first at Dig Security, sometime around 2021. He, Ofir Balassiano and Itay Frishman joined as the core team. Keren&amp;rsquo;s description of what happened next is not a sentence you expect from a man who now sells endpoint security to CISOs:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;&amp;ldquo;Honestly it was love at first sight from the first week. We just clicked, the way a great team does on the court. The pace, the trust, the way we challenged each other.&amp;rdquo;&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Two and a half years later Palo Alto Networks bought Dig. All three went inside. And then, in late 2025, all three left within weeks of each other to start something together — without knowing what it was.&lt;/p&gt;
&lt;p&gt;On 30 July 2026 that something came out of stealth as &lt;a class="link" href="https://bloom.security/" target="_blank" rel="noopener"
&gt;Bloom Security&lt;/a&gt; with a &lt;strong&gt;$20M seed&lt;/strong&gt;, co-led by &lt;strong&gt;Glilot Capital Partners&lt;/strong&gt; and &lt;strong&gt;Ten Eleven Ventures&lt;/strong&gt;, with &lt;strong&gt;Okta Ventures&lt;/strong&gt; and &lt;strong&gt;Runtime Ventures&lt;/strong&gt; participating. Axios Pro broke it. CTech followed. Roughly a dozen outlets ran variations of the same release, and the number was the story in all of them.&lt;/p&gt;
&lt;p&gt;The number is the least interesting fact here.&lt;/p&gt;
&lt;p&gt;Two things happened before it, and neither made the coverage. They picked each other before they picked a problem — deliberately, as doctrine, and Keren will explain the mechanics of it on the record. And then, for six months, they published original vulnerability research under a company name nobody could look up.&lt;/p&gt;
&lt;p&gt;This piece is built on a Q&amp;amp;A with Frishman and Balassiano conducted in August 2026, on the record, plus Bloom&amp;rsquo;s published corpus and the founders&amp;rsquo; own posts. Where&amp;rsquo;s no answer, we say so.&lt;/p&gt;
&lt;h2 id="same-faces-same-scars"&gt;Same Faces, Same Scars
&lt;/h2&gt;&lt;p&gt;Keren has written about his selection criteria for co-founders and framed the whole thing through sport. &lt;em&gt;&amp;ldquo;You need people who&amp;rsquo;ve been in the fire with you. People who were there at 2am because a deal mattered. People who know what your silence means.&amp;rdquo;&lt;/em&gt; His line about the roster that won things: same faces, same scars.&lt;/p&gt;
&lt;p&gt;The sport was never public until now. Handball, professionally, in the Israeli national league.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;&amp;ldquo;Team sports at that level teach you something you can&amp;rsquo;t learn anywhere else: you win or lose based on who&amp;rsquo;s standing next to you. Talent matters, but chemistry matters more.&amp;rdquo;&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;You can file that under founder poetry if you want. Hold the thought until the last section, where it turns into an operational answer about how thirty people shipped an enterprise platform in nine months.&lt;/p&gt;
&lt;p&gt;The three biographies are worth laying out, because none of them is the origin story the category usually runs on. &lt;strong&gt;Keren&lt;/strong&gt; was a submarine officer in the Israeli Navy before Demisto around 2015, then Dig, then Palo Alto — an engineering and sales-engineering career that has now survived two acquisitions. &lt;strong&gt;Balassiano&lt;/strong&gt; came out of &lt;strong&gt;Mamram&lt;/strong&gt;, the IDF&amp;rsquo;s central computing and software unit, through Cognyte and XM Cyber, then Dig from day zero, then roughly two years leading cloud and AI security research inside Palo Alto. &lt;strong&gt;Frishman&lt;/strong&gt; came out of &lt;strong&gt;Unit 81&lt;/strong&gt;, the IDF&amp;rsquo;s classified technology R&amp;amp;D unit, and spent four years across Dig and PANW building the core of their data and AI posture management products.&lt;/p&gt;
&lt;p&gt;No 8200. A submariner, a software-corps researcher, and a classified-hardware R&amp;amp;D lead.&lt;/p&gt;
&lt;p&gt;One correction while we&amp;rsquo;re here, since it keeps getting repeated. Dig&amp;rsquo;s acquisition was widely reported in the Israeli press at $300–400M. Palo Alto&amp;rsquo;s own FY2024 10-K puts total consideration at &lt;strong&gt;$255.4M&lt;/strong&gt; — $247.6M cash plus $7.8M in replacement awards.⁶&lt;/p&gt;
&lt;p&gt;Keren&amp;rsquo;s account of what happened after it:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;&amp;ldquo;After Dig was acquired by Palo Alto Networks, there was never really a question of &amp;lsquo;if&amp;rsquo; we&amp;rsquo;d start a company together. It was only a matter of &amp;lsquo;when&amp;rsquo; and &amp;lsquo;what.&amp;rsquo;&amp;rdquo;&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h2 id="nine-names"&gt;Nine Names
&lt;/h2&gt;&lt;p&gt;Every piece of launch coverage carried the same line about Bloom&amp;rsquo;s angel investors: founders of Dig Security, Demisto, Snyk and Talon. Nobody printed who they actually are. Bloom named them for us:&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Dig&lt;/strong&gt; — Dan Benjamin, Gad Akuka, Ido Azran.
&lt;strong&gt;Demisto&lt;/strong&gt; — Slavik Markovich, Rishi Bhargava, Dan Sarel, Guy Rinat.
&lt;strong&gt;Snyk&lt;/strong&gt; — Guy Podjarny.
&lt;strong&gt;Talon&lt;/strong&gt; — Ofer Ben Noon, Ohad Bobrov.&lt;/p&gt;
&lt;p&gt;Ten people, four companies. Keren has separately named Benjamin, Azran and Akuka as his mentors, alongside the Demisto four. Which means it&amp;rsquo;s the people who watched these three work at close range, for years, writing personal checks on that basis.&lt;/p&gt;
&lt;p&gt;For context on the round itself: per YL Ventures&amp;rsquo; &lt;em&gt;State of the Cyber Nation&lt;/em&gt;, Israeli cyber raised &lt;strong&gt;$4.4B across 130 rounds in 2025&lt;/strong&gt;, up 9% in dollars and 46% in round count, with an average seed of &lt;strong&gt;$9.6M&lt;/strong&gt;. Bloom raised roughly double that average. More telling than the dollars — &lt;strong&gt;endpoint security went from one seed round in 2024 to eleven in 2025&lt;/strong&gt;. Bloom is the leading edge of a wave that was already forming.&lt;/p&gt;
&lt;h2 id="there-was-no-aha"&gt;There Was No Aha
&lt;/h2&gt;&lt;p&gt;Keren&amp;rsquo;s launch essay contains the sentence every founder profile is built around: &lt;em&gt;&amp;ldquo;The day we understood that gap was the day Bloom started.&amp;rdquo;&lt;/em&gt; I asked which conversation that was and what the person said.&lt;/p&gt;
&lt;p&gt;He pushed back on the question, and the pushback is better than an answer would have been.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;&amp;ldquo;Honestly, I&amp;rsquo;ll push back on the premise a little: it wasn&amp;rsquo;t one conversation. That&amp;rsquo;s the thing people get wrong about ideation. It&amp;rsquo;s rarely a single aha moment.&amp;rdquo;&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;What he describes instead is hundreds of conversations with CISOs, and three composites that are worth reading slowly because they are the entire product thesis in plain language:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;&amp;ldquo;One CISO tells you employees are running desktop AI agents that can read files, click buttons and take actions on the endpoint, and he has zero visibility into any of it. Another tells you developers are connecting MCP servers to their tools faster than security can even catalog them, each one a new door into the environment. A third tells you about agent skills, capabilities their agents are picking up and executing, and admits nobody in the company can answer a simple question: what can these agents actually do right now?&amp;rdquo;&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;And then the part that explains why the team-first sequence works:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;&amp;ldquo;No single one of those conversations is the idea. But when you analyze all of them together, you reach a point where you understand the problem better than anyone. You become a subject matter expert in the gap itself.&amp;rdquo;&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Keren has published his test for whether a problem is real, and it&amp;rsquo;s usable by anyone: leadership and the people on the ground describe the exact same pain; they&amp;rsquo;ve already burned time or budget trying to patch it themselves; and something changed recently enough to make the old workaround impossible. His tell for finding it is the mess built around it — &lt;em&gt;&amp;ldquo;the workaround someone rigged up months ago and still babysits, the spreadsheet quietly holding a broken process together, the vendor everyone pays for and no one trusts.&amp;rdquo;&lt;/em&gt;&lt;/p&gt;
&lt;h2 id="before-they-had-a-name"&gt;Before They Had a Name
&lt;/h2&gt;&lt;p&gt;On &lt;strong&gt;1 February 2026&lt;/strong&gt;, a company that did not publicly exist published a threat-intelligence post.&lt;/p&gt;
&lt;p&gt;It kept doing that. By the time Bloom launched on 30 July, &lt;strong&gt;eleven research posts&lt;/strong&gt; were live under a name nobody could look up, on a blog organised like a research lab rather than a marketing site — categories for threat intelligence, security research and tooling, named campaign tags (Hades, Mini Shai-Hulud, OpenClaw, Moltbot), and four credited authors: Keren, Balassiano, and researchers Moriel Harush and Golan Myers.&lt;/p&gt;
&lt;p&gt;The obvious read is content marketing with a long runway. Balassiano&amp;rsquo;s answer says something more interesting than that.&lt;/p&gt;
&lt;p&gt;The engine existed before the company did.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;&amp;ldquo;We&amp;rsquo;d already started building our agentic software analysis engine back then, and when the marketplace for OpenClaw plugins surfaced, we pointed the engine at them. What we found was dozens of malicious plugins.&amp;rdquo;&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;So the research posts weren&amp;rsquo;t produced to generate demand. They were the product&amp;rsquo;s exhaust — output from a system that was already running, pointed at whatever marketplace happened to open that month. Which reframes the whole stealth period: Bloom wasn&amp;rsquo;t quietly building toward a launch and doing some content on the side. It was operating the core of the product in public, under an alias, against live campaigns, and publishing what fell out.&lt;/p&gt;
&lt;p&gt;His reasoning for shipping it with nothing to sell:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;&amp;ldquo;Even in stealth, that&amp;rsquo;s not something we could keep to ourselves. We wanted people to see the actual exposure and make their own decisions about it. For a security company, that&amp;rsquo;s also how you earn the right to be heard — we were claiming there&amp;rsquo;s a whole layer of the endpoint no one else was looking at, and the research was the proof, before there was ever a pitch.&amp;rdquo;&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;The output over those six months: &lt;strong&gt;37 malicious AI agent skills&lt;/strong&gt; caught across three active campaigns, live under a week — 33 with hidden command-and-control backdoors, two with Python reverse shells, two exfiltrating &lt;code&gt;.env&lt;/code&gt; files to webhook.site. An active campaign against the VS Code Marketplace. The TeamPCP attack chain, from a compromised VS Code extension into GitHub&amp;rsquo;s source code. And &lt;em&gt;License to Skill&lt;/em&gt;, which tested &lt;code&gt;SKILL.md&lt;/code&gt; across &lt;strong&gt;31 agentic clients&lt;/strong&gt; and found that the instructions travel perfectly while the safety frontmatter does not — the fields meant to constrain which tools a skill can run are honoured by a handful of clients and silently ignored by the rest. As Bloom put it: your allowlist might gate execution, limit scope, get rewritten into nothing, or simply vanish, and nothing tells you which one happened.&lt;/p&gt;
&lt;p&gt;A rule that parses cleanly looks like a safeguard. Reviewers count on it. In most runtimes it was never enforced.&lt;/p&gt;
&lt;h2 id="the-dialog-that-never-fires"&gt;The Dialog That Never Fires
&lt;/h2&gt;&lt;p&gt;The sharpest thing Bloom published in stealth was a Claude Code finding, credited to researcher Golan Myers.&lt;/p&gt;
&lt;p&gt;Take an ordinary GitHub repository. Add one innocuous configuration file. Open it the way you open anything.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;&amp;ldquo;Within seconds — no click, no approval, often not even a warning — we were running commands on the machine and watching secrets leave it. And it doesn&amp;rsquo;t stop when you do: it survives closing the repo and rides along in every session after.&amp;rdquo;&lt;/em&gt; — Balassiano&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;&lt;em&gt;&amp;ldquo;Nothing was &amp;lsquo;hacked.&amp;rsquo; Every piece we chained together is an approved, working-as-intended feature.&amp;rdquo;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;Bloom reported it to Anthropic. Then said publicly that they don&amp;rsquo;t fully agree with where Anthropic drew the line. I asked Balassiano to be specific about where each side sits.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;&amp;ldquo;Anthropic&amp;rsquo;s position is that the workspace trust dialog is the security boundary for project-level config — because you have to accept trust before that shell-executing setting runs, they consider the attack mitigated. I think that architecture is correct.&amp;rdquo;&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Then the objection, which is one gap wide and hard to argue with:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;&amp;ldquo;My disagreement is with one gap in it: trust is inherited recursively. If you&amp;rsquo;ve ever trusted &lt;code&gt;~/projects&lt;/code&gt; — a completely normal thing to do — you&amp;rsquo;ve pre-approved every repository you&amp;rsquo;ll ever clone into it, including ones that don&amp;rsquo;t exist yet, including the attacker&amp;rsquo;s. So for most developers in most real scenarios, the dialog never fires at all. A boundary that&amp;rsquo;s bypassed by design for the majority of your users isn&amp;rsquo;t doing the work it&amp;rsquo;s supposed to do.&amp;rdquo;&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;He&amp;rsquo;s holding that position from inside Anthropic&amp;rsquo;s own security integrations programme — Bloom says it was selected for the programme around Claude&amp;rsquo;s Compliance API.⁴&lt;/p&gt;
&lt;p&gt;We didn&amp;rsquo;t ask Anthropic for its side. That&amp;rsquo;s a gap in this piece. But the disagreement itself is the useful artifact: a seed-stage vendor publicly telling a frontier lab that its security boundary doesn&amp;rsquo;t fire for most of its users, while sitting in that lab&amp;rsquo;s partner programme, is not standard behaviour in a category where everyone would rather have the logo than the argument.&lt;/p&gt;
&lt;h2 id="what-it-actually-does"&gt;What It Actually Does
&lt;/h2&gt;&lt;p&gt;Frishman has the best explanatory frame in Bloom&amp;rsquo;s corpus, and it isn&amp;rsquo;t about AI at all.&lt;/p&gt;
&lt;p&gt;Supply-chain attacks don&amp;rsquo;t pick the lock. They walk in behind a real badge. &lt;em&gt;&amp;ldquo;Shai-Hulud doesn&amp;rsquo;t break in. It tailgates the update. Same publisher, same verified badge, same install you&amp;rsquo;ve run a hundred times.&amp;rdquo;&lt;/em&gt; And once inside: &lt;em&gt;&amp;ldquo;It doesn&amp;rsquo;t bring its own burglar tools. It finds yours, already on the workbench.&amp;rdquo;&lt;/em&gt; It runs TruffleHog to hunt secrets. It republishes itself using the developer&amp;rsquo;s own GitHub and npm credentials. In the related Nx attack it recruited the AI CLI tools already installed on the machine to go looking for credentials.&lt;/p&gt;
&lt;p&gt;The Nx Console extension had &lt;strong&gt;2.2 million installs and a verified badge&lt;/strong&gt;. A poisoned AsyncAPI extension exfiltrated for nearly a month — just because no alarm pointed at that door. And GitHub itself disclosed that a poisoned VS Code extension on an employee device led to roughly &lt;strong&gt;3,800 internal repositories&lt;/strong&gt; being exfiltrated.¹&lt;/p&gt;
&lt;p&gt;Keren&amp;rsquo;s version of the same argument is aimed squarely at every AI-discovery dashboard on the market: a list of 400 AI tools answers the old question, what exists. &lt;em&gt;&amp;ldquo;Until you can judge each one by how it runs and what surrounds it — and act on it — you don&amp;rsquo;t have a handle on the surface. You have a spreadsheet.&amp;rdquo;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;Bloom ships five modules against that:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Live inventory&lt;/strong&gt; — everything running on an endpoint, including who built it, what it can reach and where it came from.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Contextual risk analysis&lt;/strong&gt; — marketplace intelligence, static analysis and behavioural sandboxing, scored per endpoint.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Granular remediation&lt;/strong&gt; — previews what breaks and who&amp;rsquo;s affected before it acts, then notifies them.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Supply-chain prevention&lt;/strong&gt; — blocks packages and skills at the source across npm, the Chrome Web Store and Open VSX.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;AI guardrails&lt;/strong&gt; — scales over-permissioned MCP servers back to safe defaults.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Three product answers from the Q&amp;amp;A that aren&amp;rsquo;t in any launch coverage, and that a CISO would ask in this order.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;On &amp;ldquo;agentic, contextual, per endpoint.&amp;rdquo;&lt;/strong&gt; Frishman says the phrase describes granularity of judgment, not a process running on every machine.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;&amp;ldquo;The same extension can be perfectly fine on a developer&amp;rsquo;s machine and a real risk on a finance laptop, so there are no global verdicts.&amp;rdquo;&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;The agent revisits its conclusion whenever the software or the endpoint changes — which is the actual supply-chain case: a trusted extension changes ownership, a new version requests permissions it never needed, a package quietly adds behaviour unrelated to its stated purpose. Yesterday&amp;rsquo;s safe verdict doesn&amp;rsquo;t carry into today&amp;rsquo;s compromised version. It also lets policy be written as intent rather than as an allow list: AI agents are fine for engineering, not on machines that touch customer data.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;On where detonation happens.&lt;/strong&gt; In Bloom&amp;rsquo;s cloud, not on the device. They sandbox marketplace software at the source, before it reaches anyone&amp;rsquo;s fleet. What leaves the laptop is inventory and metadata about how software is used — &lt;em&gt;&amp;ldquo;no file contents, no documents, no browsing data, no code. The endpoint receives verdicts; it doesn&amp;rsquo;t ship your data out to earn them.&amp;rdquo;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;On onboarding taking minutes.&lt;/strong&gt; There are two modes, and the light one is agentless: Bloom rides the EDR or MDM the organisation already runs — CrowdStrike, Intune, Jamf — and dispatches an ephemeral sensor across the fleet that runs, collects software-posture metadata, and terminates. No persistent agent, no admin rights on user machines. The heavier mode is a full agent for continuous coverage, pushed through the existing MDM in one automated process.&lt;/p&gt;
&lt;h2 id="thirty-people-nine-months"&gt;Thirty People, Nine Months
&lt;/h2&gt;&lt;p&gt;Bloom was founded in late 2025. It launched in July 2026 with thirty people, all in Israel, SOC 2, five shipped modules and what it describes as dozens of enterprise deployments.² That&amp;rsquo;s roughly nine months.&lt;/p&gt;
&lt;p&gt;Frishman has written that every engineer at Bloom effectively runs a team of agents, and that work which took four months five years ago now fits inside a two-week sprint. I asked what broke the first time they ran R&amp;amp;D that way.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;&amp;ldquo;The honest answer is that less broke than you&amp;rsquo;d expect, and the reason is boring: most of this team has worked together for years, across previous companies. We already knew how to run together, so when the ground shifted we adjusted in stride rather than in crisis.&amp;rdquo;&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;What did change was planning.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;&amp;ldquo;Our old planning assumed the unit of work was an engineer writing code. Once a 4-month project fits in two weeks, that model stops describing reality: things we expected to be hard shipped in a day, and things that looked trivial stalled because the agents lacked the context to do them well.&amp;rdquo;&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;So the sprint changed shape. Engineers&amp;rsquo; primary job became building the infrastructure, the skills and the encoded organisational knowledge that let agents work properly in Bloom&amp;rsquo;s environment — and sprints now budget explicitly for that layer, because an hour spent there pays out across every project that follows, while an hour spent brute-forcing a feature pays out once.&lt;/p&gt;
&lt;p&gt;I asked whether anyone good couldn&amp;rsquo;t work that way. He says they didn&amp;rsquo;t hit it, and again credits the history: experienced engineers who already think in leverage rather than lines of code, and who trust each other enough to change how they work without feeling threatened by it.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;&amp;ldquo;When execution is nearly free, the thinking is where engineers earn their keep.&amp;rdquo;&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;So the handball answer wasn&amp;rsquo;t decoration. Thirty people changed how they build software in the middle of a build, and nobody fought about it.&lt;/p&gt;
&lt;p&gt;It&amp;rsquo;s the inverse of the problem Sherman keeps running into. &lt;a class="link" href="https://sherm4n.com/questil-no-code-game-engine-israel/" target="_blank" rel="noopener"
&gt;Ziv Mizrahi&lt;/a&gt; building a game engine alone, &lt;a class="link" href="https://sherm4n.com/not-your-dads-media-jordan-winston-street-interview-ads/" target="_blank" rel="noopener"
&gt;Jordan Winston&lt;/a&gt; as the host and the salesman and the face, &lt;a class="link" href="https://sherm4n.com/nyc-relocation-israeli-founders-pinpointe-rachel-fiegler/" target="_blank" rel="noopener"
&gt;Rachel Fiegler&lt;/a&gt; with the operating knowledge living in two people&amp;rsquo;s heads — all of them stuck on the same wall, where the thing that makes you good is the thing you can&amp;rsquo;t hand off. Bloom&amp;rsquo;s founders solved that before they had a product, by refusing to build without people they&amp;rsquo;d already been in the fire with.&lt;/p&gt;
&lt;h2 id="golda"&gt;Golda
&lt;/h2&gt;&lt;p&gt;Bloom has a Chief Dog Officer. Her name is Golda, she&amp;rsquo;s been there since day one, she comes to the office on Harav Ashi every day, and per Frishman she &lt;em&gt;&amp;ldquo;personally interviews every new dog who wants to join the team.&amp;rdquo;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;It&amp;rsquo;s a joke. It&amp;rsquo;s also the tell. In the same nine months this company hired a dog, published eleven pieces of research nobody asked for, argued with Anthropic in public, and built a prediction market for Black Hat gossip because, in Keren&amp;rsquo;s words, the cyber industry runs on threat intel and gossip, mostly gossip.&lt;/p&gt;
&lt;p&gt;None of that is what a seed-stage company does to close a round. All of it is what a group of people do when they&amp;rsquo;ve already decided they&amp;rsquo;re working together for the next several years and are figuring out the rest as they go.&lt;/p&gt;
&lt;p&gt;You win or lose based on who&amp;rsquo;s standing next to you. 💜&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id="fast-facts-bloom-security"&gt;Fast facts: Bloom Security
&lt;/h2&gt;&lt;p&gt;&lt;strong&gt;What is Bloom Security?&lt;/strong&gt; An Israeli endpoint-security company securing what it calls non-binary software — browser extensions, IDE plugins, packages, MCP servers, agent skills and AI agents — through live inventory, per-endpoint contextual risk scoring, remediation with blast-radius preview, and install-time blocking across npm, the Chrome Web Store and Open VSX.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Who founded it?&lt;/strong&gt; Itay Keren (CEO), Ofir Balassiano (CPO) and Itay Frishman (CTO), all three from Dig Security and then Palo Alto Networks. Founded late 2025. Around 30 people, all in Israel. Offices at 6 Harav Ashi St., Tel Aviv.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;What did it raise?&lt;/strong&gt; $20M seed, announced 30 July 2026, co-led by Glilot Capital Partners and Ten Eleven Ventures, with Okta Ventures and Runtime Ventures participating. Angels: the founders of Dig, Demisto, Snyk and Talon — ten named individuals. Valuation undisclosed.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;How is it deployed?&lt;/strong&gt; Agentless via existing EDR/MDM (CrowdStrike, Intune, Jamf) using an ephemeral sensor, or as a full agent pushed through MDM. Sandboxing runs in Bloom&amp;rsquo;s cloud against marketplace software, not on employee devices.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;What&amp;rsquo;s verified and what isn&amp;rsquo;t?&lt;/strong&gt; Funding, headcount, launch date, founder backgrounds and the research corpus are verified. Customer count, ARR, pricing, OS coverage and the Anthropic partnership are not.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Contact:&lt;/strong&gt; &lt;a class="link" href="https://bloom.security/" target="_blank" rel="noopener"
&gt;bloom.security&lt;/a&gt; · &lt;a class="link" href="mailto:info@bloom.security" &gt;info@bloom.security&lt;/a&gt; · all three founders respond to LinkedIn DMs and openly solicit them.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id="notes-on-the-numbers"&gt;Notes on the numbers
&lt;/h2&gt;&lt;p&gt;We publish what we can verify and label what we can&amp;rsquo;t. Here&amp;rsquo;s the honest ledger for this piece:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;The ~3,800 internal repositories exfiltrated via a poisoned VS Code extension traces to GitHub&amp;rsquo;s own public statement, which was itself based on the attackers&amp;rsquo; claims. Bloom pointed us to the source. Treat it as GitHub relaying an attacker&amp;rsquo;s number, not as an audited count.&lt;/li&gt;
&lt;li&gt;&amp;ldquo;Dozens of large enterprises&amp;rdquo; is self-reported and unnamed. No ARR, no ACV, no pricing. The only named public reference is Paychex&amp;rsquo;s CISO, who also sits in lead investor Glilot&amp;rsquo;s CISO advisory network.&lt;/li&gt;
&lt;li&gt;Glilot&amp;rsquo;s Kobi Samboursky called Bloom&amp;rsquo;s early traction &amp;ldquo;unprecedented for a company at this stage.&amp;rdquo; That is an investor describing his own portfolio company, which is why it doesn&amp;rsquo;t appear in the body of this piece.&lt;/li&gt;
&lt;li&gt;The Anthropic security integrations partnership is sourced only to Balassiano&amp;rsquo;s own post and has not been independently confirmed. Anthropic was not asked for comment on the disclosure disagreement described above; if it responds, we&amp;rsquo;ll update this piece.&lt;/li&gt;
&lt;li&gt;The handball career, the mentor names and the account of Dig&amp;rsquo;s first week come from Keren&amp;rsquo;s own statements and are not independently verifiable.&lt;/li&gt;
&lt;li&gt;Dig&amp;rsquo;s acquisition price is $255.4M total consideration per Palo Alto Networks&amp;rsquo; FY2024 10-K, against the $300–400M widely reported in the Israeli press at the time.&lt;/li&gt;
&lt;/ol&gt;</description></item><item><title>Lazy Digest #3: Six Startups Raised to Babysit Robots. One Sold for $1B.</title><link>https://sherm4n.com/lazy-digest-israeli-tech-july-26-august-1-2026/</link><pubDate>Tue, 04 Aug 2026 09:00:00 +0100</pubDate><guid>https://sherm4n.com/lazy-digest-israeli-tech-july-26-august-1-2026/</guid><description>&lt;img src="https://sherm4n.com/lazy-digest-israeli-tech-july-26-august-1-2026/cover.webp" alt="Featured image of post Lazy Digest #3: Six Startups Raised to Babysit Robots. One Sold for $1B." /&gt;&lt;script type="application/ld+json"&gt;
{
"@context": "https://schema.org",
"@type": "NewsArticle",
"headline": "Lazy Digest #3: Six Startups Raised to Babysit Robots. One Sold for $1B.",
"description": "Cyera agreed to pay ~$1B for Oasis Security, and six more Israeli startups raised $278M in the same week to solve versions of the same problem: what AI agents are allowed to touch. Plus Xsight Labs at $2.8B, Hailo's sad ending, and a NIS 1B government lifeline.",
"image": "https://sherm4n.com/lazy-digest-israeli-tech-july-26-august-1-2026/cover.webp",
"author": {
"@type": "Person",
"name": "Alex Sherman",
"url": "https://sherm4n.com/authors/alex-sherman"
},
"publisher": {
"@type": "Organization",
"name": "Sherman",
"logo": {
"@type": "ImageObject",
"url": "https://sherm4n.com/images/logo-black.png"
}
},
"datePublished": "2026-08-04T09:00:00+01:00",
"dateModified": "2026-08-04T09:00:00+01:00",
"mainEntityOfPage": {
"@type": "WebPage",
"@id": "https://sherm4n.com/lazy-digest-israeli-tech-july-26-august-1-2026/"
}
}
&lt;/script&gt;
&lt;h1 id="lazy-digest-3-six-startups-raised-to-babysit-robots-one-sold-for-1b"&gt;Lazy Digest #3: Six Startups Raised to Babysit Robots. One Sold for $1B.
&lt;/h1&gt;&lt;p&gt;Seven Israeli companies made news this week for solving the same problem: deciding what a piece of software is allowed to touch when no human is watching.&lt;/p&gt;
&lt;p&gt;One of them — &lt;a class="link" href="https://www.calcalistech.com/ctechnews/article/8115vtsb5" target="_blank" rel="noopener"
&gt;Oasis Security&lt;/a&gt; — got a $1 billion offer. The other six raised $278 million between them. All in five days.&lt;/p&gt;
&lt;p&gt;That&amp;rsquo;s the week. Everything else is context, and the context is good, so stay.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Lazy Digest #3&lt;/strong&gt; — Israeli tech, one week, researched with AI and filtered by a human who reads the primary sources. Estimates are labeled as estimates. Let&amp;rsquo;s go.&lt;/p&gt;
&lt;h2 id="the-billion"&gt;The Billion
&lt;/h2&gt;&lt;p&gt;Cyera signed a letter of intent on Tuesday to buy Oasis Security for approximately $1 billion — roughly $700 million in cash, the rest in Cyera shares, expected to close later this year.&lt;/p&gt;
&lt;p&gt;The numbers around it are more interesting than the number itself.&lt;/p&gt;
&lt;p&gt;Oasis was founded in &lt;strong&gt;2022&lt;/strong&gt;. It raised about $195 million and was valued at $700 million in a March Series B led by Craft Ventures. Four months later it&amp;rsquo;s selling for a billion. The company&amp;rsquo;s own claim is that it&amp;rsquo;s the fastest cybersecurity company ever to go from launch to a $1B sale, and nobody&amp;rsquo;s rushed to correct them. Founders Danny Brickman and Amit Zimerman met in Unit 81 — Brickman did 11 years there through the Talpiot program. Roughly 170 employees are set to share &lt;a class="link" href="https://www.calcalistech.com/ctechnews/article/s1ymqfpbzx" target="_blank" rel="noopener"
&gt;more than $100 million&lt;/a&gt; in option exercises, and the founders are looking at a $200M+ payday.&lt;/p&gt;
&lt;p&gt;The buyer&amp;rsquo;s math is worth its own paragraph. Cyera — founded 2021 by Yotam Segev and Tamar Bar-Ilan, also Talpiot and 8200 — raised $600 million at a $12 billion valuation last month and is estimated to run north of $200M ARR across 1,500+ employees in 18 countries. This is not their first purchase. It&amp;rsquo;s their sixth: Trail Security ($162M), Ryft (est. $100–130M), Genie Security (~$50M), plus Otterize and Shape AI. Oasis brings their total acquisition spend to roughly $1.35–1.4 billion.&lt;/p&gt;
&lt;p&gt;Cyera isn&amp;rsquo;t building a product line anymore. It&amp;rsquo;s assembling one, with a chequebook, at a pace most companies reserve for hiring.&lt;/p&gt;
&lt;p&gt;The multiple deserves a flag. Virtru&amp;rsquo;s analysis puts Oasis at $10–20M ARR, which prices this at 50–100x revenue — above Google/Wiz (46x) and Okta/Auth0 (43x). That&amp;rsquo;s an estimate on an undisclosed number, so hold it loosely. But even loosely held, it tells you what the market thinks it&amp;rsquo;s buying: not a business, a position. Cyera knows what your sensitive data is. Oasis knows which non-human account just asked for it. Segev&amp;rsquo;s framing in the announcement blog is the cleanest version — knowing your data isn&amp;rsquo;t much use if you can&amp;rsquo;t govern what touches it.&lt;/p&gt;
&lt;p&gt;The stat both companies keep repeating: non-human identities inside Fortune 500 organizations grew nearly 500% in six months. Company-sourced, unaudited, and directionally impossible to argue with.&lt;/p&gt;
&lt;h2 id="the-six-behind-it"&gt;The Six Behind It
&lt;/h2&gt;&lt;p&gt;Here&amp;rsquo;s what makes this week different from an ordinary big-exit week. Within days of Cyera–Oasis, six more Israeli startups raised for variants of the same question:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;&lt;a class="link" href="https://www.calcalistech.com/ctechnews/article/b1fsjydszg" target="_blank" rel="noopener"
&gt;Onyx Security&lt;/a&gt; — $113M Series B&lt;/strong&gt; at roughly $640M, led by Bessemer. Four months after coming out of stealth with $40M. Founders Maxim Bar Kogan and Gil Elbaz. Manages what enterprise AI agents are permitted to do and watches what they actually do.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Act Security — $60M out of stealth.&lt;/strong&gt; A $20M seed (Team8, Bessemer, Hetz, Claltech) plus a $40M Series A (Notable Capital, Startpoint, SVCI), announced together. This is the Medigate team — Jonathan Langer, Itay Kirshenbaum, Stephen Goldberg, Ilai Fallach — who sold to Claroty for $400M in 2022. Their claim: about 97% of cloud access sits dormant.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Mate Security — $35M Series A&lt;/strong&gt;, led by Canaan with Insight, Team8 and Microsoft&amp;rsquo;s M12. Eight months after a $15.5M seed. Wiz and Microsoft alumni, building an agentic SOC, reporting 500%+ growth since Q3 2025.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a class="link" href="https://www.prnewswire.com/il/news-releases/hush-security-raises-30m-to-close-the-ai-agent-governance-gap-with-akamai-joining-as-strategic-investor-302836307.html" target="_blank" rel="noopener"
&gt;Hush Security&lt;/a&gt; — $30M Series A&lt;/strong&gt;, Akamai joining as strategic investor alongside Battery and YL. Meta Networks alumni. 31 people. Kills standing credentials for agents in favor of just-in-time permissions and one central kill switch.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a class="link" href="https://www.calcalistech.com/ctechnews/article/b1exptvszl" target="_blank" rel="noopener"
&gt;Way Security&lt;/a&gt; — $20M seed&lt;/strong&gt;, co-led by Insight and Glilot. Ex-Sygnia founders. An execution layer that automates running IAM systems rather than replacing Okta.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a class="link" href="https://www.ynetnews.com/business/article/byi71r00sze" target="_blank" rel="noopener"
&gt;Bloom Security&lt;/a&gt; — $20M seed&lt;/strong&gt;, led by Glilot and Ten Eleven, with Okta Ventures and Runtime. Palo Alto and Dig Security alumni securing agents, MCP servers and browser extensions on employee devices.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Six companies. Six founding teams with real pedigree. One problem, sliced six ways.&lt;/p&gt;
&lt;p&gt;Now the caveat, and it&amp;rsquo;s the same one as last week because it keeps being true: &lt;strong&gt;these rounds closed months ago.&lt;/strong&gt; What you&amp;rsquo;re watching is announcement calendars converging on a hot category, not $278 million arriving in July. Anyone building a thesis on &amp;ldquo;the week agent security exploded&amp;rdquo; is reading a PR schedule.&lt;/p&gt;
&lt;p&gt;Still — six comparable rounds landing in one week is its own signal, just not the one it looks like. It means six sets of investors independently reached the same conclusion in the spring, and now every one of those companies has to differentiate in a market where the thesis is common property. Onyx and Mate are already competing on velocity numbers rather than ideas. That&amp;rsquo;s what a crowded category sounds like early.&lt;/p&gt;
&lt;p&gt;Also in the AI-application layer, less crowded and worth naming:&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Harmony — $34M seed&lt;/strong&gt; led by Lightspeed, founded by the Epsagon team (sold to Cisco for ~$500M), dropping 100+ prebuilt agents inside Slack and Teams. Customers include n8n and eToro.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Encore AI — $30M Series A&lt;/strong&gt; led by Team8, with Harel and Bank Leumi converting from customers to investors — always the strongest signal on a cap table. Founded by Dr. Dvir Ginzburg. Trains agents on recordings of a company&amp;rsquo;s top performers, which is either brilliant or a management consultant&amp;rsquo;s fever dream, and 40+ enterprises are paying for it.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Modus — $10M seed&lt;/strong&gt; led by Insight. Founded this year by ex-Lusha and ex-Cyera people. A &amp;ldquo;context warehouse&amp;rdquo; that feeds agents only relevant context to stop them burning tokens on noise. Twelve employees.&lt;/p&gt;
&lt;h2 id="two-chip-stories-opposite-directions"&gt;Two Chip Stories, Opposite Directions
&lt;/h2&gt;&lt;p&gt;&lt;strong&gt;Xsight Labs raised $300M+ at a $2.8 billion valuation&lt;/strong&gt; on Thursday, led by Fidelity with a long list including Intel Capital, T. Rowe Price, Battery, Valor, Maverick and Aliya. Run from Kiryat Gat, chaired by Avigdor Willenz, competing directly with Nvidia-Mellanox.&lt;/p&gt;
&lt;p&gt;The valuation is more than 5x its 2021 mark of roughly $500M, and the timing isn&amp;rsquo;t subtle: the raise landed a week after Xsight&amp;rsquo;s X2 programmable Ethernet switch was validated aboard &lt;strong&gt;SpaceX&amp;rsquo;s Starlink V3 satellites&lt;/strong&gt;. The pitch is power, not peak performance — 12.8 Tbps under 200W, sub-700ns latency, around 40% lower power than legacy switches at that speed, per the company&amp;rsquo;s own release. In a year where every AI conversation ends at the electricity bill, that&amp;rsquo;s the right thing to be selling.&lt;/p&gt;
&lt;p&gt;An Israeli-designed switch shipping on satellites in orbit is also just a good week for the ecosystem, and nobody outside the industry will hear about it.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Hailo sold to Microchip.&lt;/strong&gt; Terms undisclosed, deal signed July 24, expected to close by September 30.&lt;/p&gt;
&lt;p&gt;Founded 2017 by Orr Danon and Avi Baum. Raised roughly $344 million from the Zisapel family, OurCrowd, Idan Ofer, Gil Agmon, Poalim Equity, Maniv and others. Peaked above a $1 billion valuation. Then: liquidity crisis, emergency loans, layoffs, a SPAC merger that collapsed as the valuation sank below $500M. Now an undisclosed price that everyone reporting on it describes as a fraction of what came before.&lt;/p&gt;
&lt;p&gt;The most brutal line in the whole story is in &lt;a class="link" href="https://ir.microchip.com/news-events/press-releases/detail/1406/microchip-technology-signs-definitive-agreement-to-acquire-hailo" target="_blank" rel="noopener"
&gt;Microchip&amp;rsquo;s own filing&lt;/a&gt;: the transaction &amp;ldquo;is not expected to have a material impact on Microchip&amp;rsquo;s financial results.&amp;rdquo; A company that raised $344 million and once cleared a billion in valuation is, to its acquirer, a rounding error worth mentioning for legal completeness.&lt;/p&gt;
&lt;p&gt;Two mitigating notes, because this isn&amp;rsquo;t a morality tale. Industry sources expect Danon to stay on and most of Hailo&amp;rsquo;s roughly 110 employees to move over, with Microchip opening a second Israeli development center. And Hailo&amp;rsquo;s technology was never the problem — 100+ customers, HP shipping Hailo-based cards in point-of-sale systems, real silicon in real products. The company built the thing. It just couldn&amp;rsquo;t build the revenue fast enough to outrun the capital it had taken.&lt;/p&gt;
&lt;p&gt;Put Xsight and Hailo in the same paragraph and you get the honest version of hardware: same country, same category, same decade, and the gap between $2.8 billion and &amp;ldquo;not material&amp;rdquo; is mostly about who timed the market.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Razer bought StreamElements&lt;/strong&gt; on Friday — substantially all assets of the Israeli-founded livestreaming tools platform, 2.6 million creators, from holding company Live Momentum. Undisclosed, believed well below the ~$111M raised. Part of the price is earmarked for outstanding creator payments, and the SEPay tipping product is being sunset with balances withdrawable through the end of 2026. A rescue, handled decently. Those two things can coexist.&lt;/p&gt;
&lt;h2 id="the-government-wrote-a-check"&gt;The Government Wrote a Check
&lt;/h2&gt;&lt;p&gt;The Israel Innovation Authority launched a &lt;strong&gt;NIS 1 billion (~$328M) fast-track program&lt;/strong&gt; on Sunday, jointly with the Finance Ministry, aimed squarely at one problem: the shekel.&lt;/p&gt;
&lt;p&gt;The mechanics matter if you&amp;rsquo;re raising, and the &lt;a class="link" href="https://innovationisrael.org.il/en/programs/fast-track/#about_route" target="_blank" rel="noopener"
&gt;official program page&lt;/a&gt; is more precise than the press coverage, so use it rather than us. There are two tracks. Companies founded within the last three years, with expenses under NIS 4M during the extension period, can get up to &lt;strong&gt;NIS 2 million&lt;/strong&gt;. Everyone else — older than three years, or spending more than NIS 4M — up to &lt;strong&gt;NIS 15 million&lt;/strong&gt;. Either way the grant covers 33% or 50% of the approved R&amp;amp;D budget, with an advance mechanism of up to 35% once you show matching finance. The goal is six additional months of runway.&lt;/p&gt;
&lt;p&gt;Eligibility, from the source: Israeli-registered, incorporated no more than 15 years ago, runway of 12 months or less on your latest trial balance, expenses exceeding revenues, worldwide expenses over the past 12 months between NIS 1.5M and NIS 100M, at least 40% of last year&amp;rsquo;s expenses on R&amp;amp;D, and at least 50% incurred in Israel. If you haven&amp;rsquo;t raised in three years, you also need to show that half your sales are in foreign currency. Press coverage widely reported a &amp;ldquo;50% on R&amp;amp;D&amp;rdquo; threshold — the Authority&amp;rsquo;s own criteria say 40% R&amp;amp;D and 50% spent in Israel. Two different tests, and the distinction could decide whether you bother applying.&lt;/p&gt;
&lt;p&gt;The timeline is the part most reports got wrong in the other direction. This isn&amp;rsquo;t a four-week window — &lt;strong&gt;applications run through November 19, 2026&lt;/strong&gt;, with investment committees meeting weekly and decisions in roughly 20–30 business days. Fast decisions, long runway to apply. With required matching finance, the effective injection across the program lands somewhere around NIS 2–3 billion.&lt;/p&gt;
&lt;p&gt;Strip the press release and it&amp;rsquo;s this: your costs are in shekels, your revenue and your raise are in dollars, the shekel got strong, and the state has decided that&amp;rsquo;s a market failure worth subsidizing rather than a founder problem worth ignoring. It&amp;rsquo;s also the same force that drove last week&amp;rsquo;s layoff wave. Wix cited it in May. monday.com&amp;rsquo;s cuts sat on top of it.&lt;/p&gt;
&lt;p&gt;Whether it works is a Q4 question. The number to watch is whether Israeli hi-tech layoffs — roughly 9,500 in H1 2026, per career consultant Hayut Yogev&amp;rsquo;s analysis in the Jerusalem Post — actually slow.&lt;/p&gt;
&lt;p&gt;If your burn is shekel-denominated and your runway is under a year, go read the criteria properly. NIS 15M is real money and the committee sits every week.&lt;/p&gt;
&lt;h2 id="everything-else-worth-your-time"&gt;Everything Else Worth Your Time
&lt;/h2&gt;&lt;p&gt;&lt;strong&gt;Enigma — $71M seed&lt;/strong&gt;, out of stealth Monday, co-led by Index and Ribbit with Sarah Guo&amp;rsquo;s Conviction and angels from OpenAI, Anthropic, DeepMind, xAI, Cognition and Wiz. Founded less than a year ago by Jonathan Jacobi — Microsoft&amp;rsquo;s youngest-ever employee, later recruited by Assaf Rappaport — and Gal Niv, who met in hacking competitions and served together in 8200. San Francisco-based, Israeli-founded, building robot-agnostic foundation models. They also shipped &amp;ldquo;Robots Online,&amp;rdquo; which lets anyone drive an AI-powered robot over the internet in real time. A $71M seed is absurd on paper; it landed days after Travis Kalanick&amp;rsquo;s Atoms raised $1.7B in the same category, which tells you what the paper is worth right now.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;groundcover — $100M Series C&lt;/strong&gt;, led by One Peak with Morgan Stanley Expansion Capital. Total $160M. Bring-your-own-cloud observability built on eBPF and OpenTelemetry, 250+ paying customers, 3x YoY ARR. Boring category, real revenue, no agent narrative required.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Aleph launched a $150M Fund V.&lt;/strong&gt; Michael Eisenberg, Eden Shochat and team, ~$850M under management since 2013, and the stated thesis is &amp;ldquo;more of the same&amp;rdquo; — early-stage Israeli founders, global companies. In a year of pivots, a fund announcing it isn&amp;rsquo;t changing anything is a position.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Maor Shlomo started a small self-funded fund for cancer research.&lt;/strong&gt; The Base44 founder — who sold to Wix in 2025 — put his own proceeds into seven companies over four months, after losing his mother to cancer. His thesis is that AI-driven in-silico discovery has moved the bottleneck to clinical validation, and that&amp;rsquo;s where the money should go. Not a business story. Include it anyway.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Traysar Industries — $25M Series A&lt;/strong&gt;, founder Yadin Soffer, building autonomous systems for military operations underground. Israel has an obvious reason to care about what&amp;rsquo;s beneath the surface, and this is now the second Israeli company in three weeks funded to see through dirt — Exodigo bought a California engineering firm in &lt;a class="link" href="https://sherm4n.com/lazy-digest-israeli-tech-july-12-17-2026/" target="_blank" rel="noopener"
&gt;issue #1&lt;/a&gt;. Worth flagging that the $25M was first reported earlier in July; only the Series A framing surfaced this week.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Tomer is heading toward the capital markets.&lt;/strong&gt; The state-owned rocket-propulsion maker behind Arrow engines — ~900 employees, ~NIS 550M in 2024 sales — is starting with institutional bonds via TASE UP. A full IPO is unlikely before 2027 and has to follow IAI. Classification is the obstacle, same as Rafael. The defense-IPO queue is now three deep and moving at the speed of government.&lt;/p&gt;
&lt;h2 id="what-id-do-with-this-week"&gt;What I&amp;rsquo;d Do With This Week
&lt;/h2&gt;&lt;p&gt;&lt;strong&gt;If you&amp;rsquo;re raising in agent/identity security:&lt;/strong&gt; the thesis is no longer yours. Six teams pitched it to six sets of investors and all six got funded. What&amp;rsquo;s left to differentiate on is distribution — named design partners, ARR trajectory, deployment velocity. Onyx got a Series B four months after stealth; Mate raised eight months after seed. That cadence is the new benchmark, and if you can&amp;rsquo;t show it, expect harder terms than the founders you&amp;rsquo;re reading about got.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;If your burn is in shekels:&lt;/strong&gt; the &lt;a class="link" href="https://innovationisrael.org.il/en/programs/fast-track/#about_route" target="_blank" rel="noopener"
&gt;IIA fast-track&lt;/a&gt; is open through November 19, committees sit weekly, decisions land in 20–30 business days, and the ceiling is NIS 15M for established companies or NIS 2M if you&amp;rsquo;re under three years old. The bar is 12 months of runway or less, 40% of last year&amp;rsquo;s spend on R&amp;amp;D, half of it in Israel. This is the single most actionable item in the digest.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;If you&amp;rsquo;re deciding where to work:&lt;/strong&gt; the barbell is obvious now. Infrastructure and security are hiring on fresh capital — Xsight, groundcover, Onyx, Act. Distressed acquirers are not; Microchip and Razer bought assets, and asset buyers rarely expand local headcount. Weight offers toward dollar revenue and a round closed in the last six months.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;If you&amp;rsquo;re an investor anchoring to Cyera–Oasis:&lt;/strong&gt; every founder in non-human identity will quote 50–100x at you for the next year. It&amp;rsquo;s an estimate on an undisclosed ARR, for a category leader, in a signed-but-unclosed LOI. Three qualifiers. Price accordingly.&lt;/p&gt;
&lt;p&gt;See you next week. Same lazy hands, same working head.&lt;/p&gt;
&lt;p&gt;With 💜,
Alex Sherman&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Research assisted by AI, every claim read and filtered by a human. Primary sources: &lt;a class="link" href="https://www.calcalistech.com/ctechnews" target="_blank" rel="noopener"
&gt;CTech / Calcalist&lt;/a&gt;, &lt;a class="link" href="https://en.globes.co.il" target="_blank" rel="noopener"
&gt;Globes&lt;/a&gt;, &lt;a class="link" href="https://www.ynetnews.com/business" target="_blank" rel="noopener"
&gt;Ynetnews&lt;/a&gt;, the &lt;a class="link" href="https://innovationisrael.org.il/en/programs/fast-track/#about_route" target="_blank" rel="noopener"
&gt;Israel Innovation Authority&lt;/a&gt;, and official company releases including &lt;a class="link" href="https://ir.microchip.com/news-events/press-releases/detail/1406/microchip-technology-signs-definitive-agreement-to-acquire-hailo" target="_blank" rel="noopener"
&gt;Microchip&lt;/a&gt; and &lt;a class="link" href="https://www.prnewswire.com/il/news-releases/hush-security-raises-30m-to-close-the-ai-agent-governance-gap-with-akamai-joining-as-strategic-investor-302836307.html" target="_blank" rel="noopener"
&gt;Hush Security&lt;/a&gt;. Fast-track program figures come from the Authority&amp;rsquo;s own program page, which differs from several press summaries on the R&amp;amp;D threshold and the application window. Cyera–Oasis is a signed letter of intent, not a closed deal; the ~$1B value, the $700M cash split and the 50–100x revenue multiple (Virtru&amp;rsquo;s analysis) are estimates. Hailo and StreamElements prices are undisclosed and characterized via press estimates. Growth figures from Mate, groundcover, Encore and Cyera are company-provided and unaudited. Microchip–Hailo was signed July 24, just outside this window, and is included because it was the week&amp;rsquo;s dominant exit story. Previous issues: &lt;a class="link" href="https://sherm4n.com/lazy-digest-israeli-tech-july-12-17-2026/" target="_blank" rel="noopener"
&gt;#1&lt;/a&gt;, &lt;a class="link" href="https://sherm4n.com/lazy-digest-israeli-tech-july-19-25-2026/" target="_blank" rel="noopener"
&gt;#2&lt;/a&gt;.&lt;/em&gt;&lt;/p&gt;</description></item></channel></rss>