
Work Here?
runZero provides network discovery and asset inventory tools that help organizations map all devices and assets across IT, OT, and cloud environments. The product works as a subscription-based software platform that continuously scans networks to identify devices, both managed and unmanaged, and inventories them with context for security and IT operations. Clients access different tiers of service, including basic asset discovery, advanced reporting, and integrations with other security tools, with pricing based on network size and asset count. runZero differentiates itself by delivering accurate, up-to-date asset data across diverse environments and by targeting a wide range of customers—large enterprises, MSPs, and government—while focusing on incident response and rapid decision-making. Its goal is to provide complete visibility of every asset in a network to improve cybersecurity and operational efficiency.
Industries
Data & Analytics
Enterprise Software
Cybersecurity
Company Size
51-200
Company Stage
Series A
Total Funding
$20M
Headquarters
Austin, Texas
Founded
2018
See people who can refer or advise you
Help us improve and share your feedback! Did you find this helpful?
Total Funding
$20M
Meets
Industry Average
Funded Over
2 Rounds
Industry standards
Health Insurance
Dental Insurance
Vision Insurance
Life Insurance
Disability Insurance
401(k) Company Match
Unlimited Paid Time Off
Stock Options
Dragos completed acquisitions of NetRise and runZero to strengthen exposure and firmware security for extended operational technology, while keeping vendor-neutral independence.
Desert heat, dragons & cyber quests: How the runZero Yetis took over Las Vegas. Updated August 14, 2026, 8:00am EDT Another Hacker Summer Camp is officially in the books! The runZero Yetis have safely returned from Las Vegas, and after catching up on some much-needed sleep, runZero, Inc. is still buzzing from the incredible energy of the community, the people runZero, Inc. met, and the fantastic research presented. From August 3-9, runZero, Inc. took on BSides Las Vegas, Black Hat USA, and DEF CON 34. With all the recent big news from runZero, including three product launches and an intent to join forces with Dragos and NetRise (backed by a $4B Accenture investment), the excitement at its booths was off the charts, not to mention roaming Yetis and flying dragons. From rolling the dice in epic interactive quests to dropping new research and open-source tools, this year's Summer Camp was truly one for the history books. Here is a quick look back at its week in the desert. BSides Las Vegas: Caesar Ciphers, segmentation challenges, and CVE program insights. runZero, Inc. kicked off the week at BSides Las Vegas, where its Caesar Cipher challenge put attendees' cryptography puzzle skills to the test in exchange for some fantastic swag. Of course, Zeti the Yeti was there to spread some cheer and help attendees capture some of the coolest selfies during the conference. Its founder and CEO, HD Moore, took the stage to present Mind the Gap: Bridges, Backplanes, and BloodHound. He provided a deep dive into some of the most dangerous network segmentation failures and showed defenders how to analyze them at scale. The next day, Tod Beardsley joined a powerhouse group of experts from across industry and the government for the panel, I am CVE, AMA! They navigated tough questions and explored what the future of the CVE program looks like in the age of AI. And wow, this panel did not disappoint! Black Hat USA: Epic quests and broken BMCs. By Tuesday afternoon, the Yetis had taken over the Bayside Foyer at Mandalay Bay for Black Hat USA. runZero, Inc. gave out tons of swag, and as usual, attendees were lined up to see demos, to solve its Caesar Cipher challenges, and to snap countless pics with Zeti the Yeti. Its interactive game, Prism of Truth: Zeti's Odyssey - The Quest to Restore the Shattered Network, was a huge hit. It was amazing to see so many of you channel your inner fantasy tabletop RPG skills to solve high-stakes cybersecurity challenges and claim some legendary swag, along with bragging rights on the leaderboard for the fastest play times! The coveted grand prize, "One Hacker Bundle to Rule Them All", found its new home with CAPTAIN_ORCHESTRATOR. Packed inside a ultra-sleek SLNT Faraday Dry Bag, its winner walked away with an incredible cyber hardware haul featuring a Wi-Fi Pineapple, Key Croc, Hacker Pager, and a TBeam. Its second and third place prize bundles went to SAGENECROMANCER and 9889_ORCHESTRATOR_OPAL, each winning a set of SLNT Phone and Laptop Sleeves to keep their gear shielded in style. But the defining moment of Black Hat was HD Moore's highly anticipated briefing: Lights Out: BMCs Are Still Broken and Now runZero, Inc. has the Receipts. Featured in the official Black Hat press release, HD detailed his latest research on Baseboard Management Controllers (BMCs) and released OOBscan - a brand-new open-source tool designed to help you audit IPMI-exposed devices. (If you missed it, you can grab OOBscan from its open-source repository today!) DEF CON 34: Out-of-band and out of control. runZero, Inc. closed out the week at the Las Vegas Convention Center for DEF CON 34. The energy on the floor was exactly what runZero, Inc. has come to love about this community. runZero, Inc. handed out tons of gear, and had great conversations about securing the total attack surface across IT, OT, IoT, cloud, and mobile. And yes, runZero, Inc. may have done a bit of soldering while runZero, Inc. were exploring the villages. HD Moore wrapped up its 2026 Hacker Summer Camp speaking sessions with his final talk, Lights Out: Out-of-Band, Out of Mind, Out of Control, where he expanded upon his BMC research, providing a deep, technical dive into everything he discovered. Until next time! To everyone who stopped by the booths, attended its sessions, and played its games, thank you! Hacker Summer Camp is all about the community, and you made this year unforgettable. If you didn't get a chance to meet with runZero, Inc. 1:1, or if you're ready to see how runZero can help your security team win by default, even against AI: * Book a Demo: See its Exposure Management platform in action. * Try runZero today: Sign up for a free trial now. * runZero Hour: Catch next week's runZero Hour where HD, Tod, and the rest of the research team will provide their hot takes on Hacker Summer Camp, and HD will also provide followups on all the BMC research he presented last week in Vegas. See you all next year! Great research and development is a team effort! Multiple runZero team members collaborated on this post. Go team!
IPMI vulnerabilities expose enterprise networks at DEF CON 34. Wide Area Network August 10, 2026 Highlights. * At DEF CON 34, security researcher HD Moore disclosed 123 confirmed vulnerabilities across multiple baseboard management controller systems. * The research found that IPMI access can expose server hardware through management interfaces, with many devices responding without authentication or with crackable password hashes. * runZero released OOBscan, an open-source tool that scans for vulnerable BMCs and other out-of-band management devices. Security researcher HD Moore disclosed a set of largely unpatched vulnerabilities at DEF CON 34 involving baseboard management controllers, or BMCs, and the IPMI protocol used to reach them. The disclosure covered HPE iLO, Supermicro IPMI, Dell iDRAC 10, and the open source OpenBMC project. Moore said the presentation included 123 confirmed vulnerabilities, consolidated into 35 draft advisories across eight vendors. Moore said the exposure has worsened since earlier BMC research in 2013. He described BMCs as hardware embedded in server motherboards that provide remote power control, console access, and firmware updates independent of the host operating system. In his session, Moore said these devices are effectively a sanctioned backdoor to the real hardware. Some affected systems were described as carrying $1 million of GPU hardware and reachable through a web login with no password at all. The research also showed how management ports can end up exposed. Many servers ship with a single physical network port shared between the host and the BMC. If a device resets or a checksum error occurs, the BMC can obtain its own address through DHCP on the subnet where the port is connected. An internet-wide scan found roughly 51,000 devices responding to IPMI, with about 23,000 to 25,000 handing over a crackable password hash without authentication. Moore said the flaws can lead to code execution on the host server, not just the BMC. The research grouped the issues into several classes, including RAKP state-transition bugs, type confusion, vendor-specific backdoor modes, session relabeling, and integrity and encryption bypass. Moore also called out OpenBMC, saying a bug in the shared codebase can affect every product built on it. Alongside the disclosure, runZero released OOBscan, an open-source tool that scans for vulnerable BMCs and other out-of-band management devices. Moore said network teams can reduce risk by segmenting management traffic, using a dedicated management NIC, disabling KCS where it is not needed, setting unique credentials on every device, and favoring Redfish over IPMI where possible. company spotlight Vercara. Networking secure the online experience so you can focus on growing your business. Vercara offers a purpose-built, global cloud security platform that provides layers of protection to safeguard businesses' online presence, no matter where an attack comes from or where it is aimed. A single attack can have a crushing effect on both revenue and reputation, which means organizations must employ security solutions that are flexible enough to adapt to their unique needs, easily scalable, and can evolve with their business. Vercara's massively scaled cloud platform protects networks and applications against threats and downtime to create peace of mind for businesses, ensuring that they and their customers experience exceptional interactions all day, every day.
Buggy microcontrollers making up some of the world's most important servers can be easily backdoored. Published 2 hours ago Researchers found more than a dozen new flaws * runZero disclosed 12+ new flaws in BMCs from HPE, Supermicro, Dell, Lenovo, Huawei, and others at Black Hat * Scans found 86k internet-exposed BMCs and 120k internal devices * Researchers warn BMCs form a widespread, under-patched parallel attack surface Security researchers have discovered more than a dozen new vulnerabilities in Baseboard management controllers (BMC), hardware components found in thousands of the world's most popular enterprise servers. BMCs are specialized chips built into servers that allow administrators to remotely monitor and manage hardware regardless of the operating system, and even when the hardware is turned off. They provide out-of-band management capabilities such as remote console access, firmware updates, hardware health monitoring, and power control, and have been a pivotal component since their introduction in the late 1990s. Earlier this week, during the Black Hat security conference in Las Vegas, security expert HD Moore of runZero disclosed finding more than a dozen flaws in BMCs sold by HPE, Supermicro, Avocent, Huawei, Lenovo, Dell, and others - and to make matters worse, some of the flaws disclosed in the past remain active even today. Latest Videos FromTechRadar Parallel attack surface. "The end result is a pervasive, under-monitored, under-patched parallel attack surface that is both Internet-exposed and widespread inside corporate networks, and is much more exploitable than many folks realize," Moore told the publication. To assess the associated risks, Moore ran two scans - one looking at internet-connected BMCs in general, and another internally surveying devices in corporate networks. The first one found 86,000 exposed BMCs, more than half of which (54%) carried at least one of the flaws he found. The internal scan, counting more than 120,000 BMCs, found almost a third (29%) carrying at least one critical vulnerability. Details about the flaws will remain under lock and key until the manufacturers address them, Moore explained, saying that many of them cannot be exploited without prior authentication. However, for many (well-equipped) threat actors, that often isn't a problem, since a number of smaller pre-authentication flaws exist as well, which could be abused.
runZero 5.0: exposure management built for the ai-attack era. New release accelerates the journey from initial discovery to verified remediation, empowering defenders to 'Win by Default,' even against AI Network Monitoring & Management AUSTIN, Texas, June 25, 2026 (GLOBE NEWSWIRE) - runZero, a leader in exposure management, today announced runZero 5.0, a major platform evolution designed to help organizations defend their expanding attack surfaces against high-velocity, AI-fueled threats. The new release unifies the exposure management lifecycle into an automated workflow that enables security teams to seamlessly discover assets and network connections, identify and prioritize critical risks, and initiate and validate remediation to proactively reduce exposure and achieve operational resilience. For years, defenders have been overwhelmed by siloed asset and vulnerability data, leaving gaps that modern threat actors exploit with unprecedented speed. runZero 5.0 gives defenders the upper hand, transforming in-depth asset and exposure data into actionable, outcome-driven intelligence, making it easy to isolate truly critical risks, track environmental changes in near real time, and instantaneously operationalize guidance to remediate exposures. runZero 5.0 empowers security teams to map complex IT, OT, IoT, cloud and mobile environments without agents or credentials, returning unmatched asset and exposure intelligence that is analyzed and summarized to focus attention where it matters most. New dashboards and views alert defenders to high-risk and emerging exposures, delivering each with environmental context to accelerate response and substantially compress the time from detection to verified remediation. Security teams can act quickly and decisively on the most critical exposures and then verify that these risks are fully mitigated. "AI is essentially automating the attacker's recon, so threat actors can find and exploit weaknesses in minutes instead of days," said HD Moore, founder and CEO of runZero. "runZero 5.0 levels the playing field, giving defenders the immediate intelligence needed to find and prioritize the exposures that are most likely to be exploited, spot segmentation issues, verify remediation, and shut down threats quickly." A unified program for continuous exposure management By seamlessly connecting comprehensive asset and exposure discovery, automated risk prioritization, coordinated remediation, and shareable reporting into a streamlined workflow, runZero 5.0 delivers actionable intelligence that empowers security teams to go from passive asset inventory to proactive risk reduction. New capabilities in runZero 5.0 include: Management Discover more Machine Learning & Artificial Intelligence * Focused exposure intelligence: A new default dashboard prioritizes exposures that are most likely to lead to an incident and instantly surfaces critical operational issues - such as emerging threats, newly identified exposures and attack surface insights, multi-homed devices, and recent changes in the environment. By automatically highlighting high-risk exposures and segmentation gaps, teams can focus attention on the assets and connections that pose the greatest operational risk. * Enhanced vulnerability impact insights and risk prioritization: Version 5.0 broadens vulnerability detection, including expanded end-of-life coverage for network devices and out-of-band testing that identifies blind vulnerability classes without requiring customer infrastructure. runZero 5.0 also correlates asset-specific hardware and software data with known advisories; the results are consolidated into streamlined "Missing Patches" entries that offer impact intelligence and remediation recommendations, reducing noise and accelerating fixes. * Faster, verified vulnerability remediation: With 5.0, runZero serves as the definitive system of record for risk reduction, managing the remediation lifecycle from initial exposure identification to verified closure. Security teams can now easily and quickly open issues with runZero and then drive execution in Jira, including tracking ownership, enforcing closure comments for audit readiness, and mapping status transitions in Jira. Most importantly, defenders can confirm fixes against live state, ensuring that gaps are truly closed. * Interactive exposure reporting: New capabilities transform real-time dashboards and asset inventories into automated, interactive reports. Delivered via email, these reports enable stakeholders to filter and analyze risk data without platform access. Recipients can search, export to CSV/JSON, or download layouts as graphics - all without a login - easing the burden of compliance and executive reporting. runZero 5.0 builds on new capabilities recently released in Version 4.9, including powerful new 2D/3D topology maps, interactive attack path mapping, multi-homed device detection, and expanded OT discovery capabilities. The combined feature sets advance complete attack surface intelligence across converged IT, OT, IoT, cloud, and mobile environments, offering the agility and insights to successfully defend infrastructure against a new wave of AI-driven attacks. Machine Learning & Artificial Intelligence Availability The new 5.0 capabilities are immediately available to all runZero customers and Community Edition users. New users can test the features by starting a free 21-day trial: https://www.runzero.com/try/ About runZero runZero provides a single source of truth for exposure management across your total attack surface. Without requiring agents, authentication, or appliances, runZero delivers the most complete and accurate visibility into every asset and exposure across internal, external, IT, OT, IoT, mobile, and cloud environments. Founded in 2018 by HD Moore, runZero is trusted by more than 500 companies and 30,000 users worldwide to mitigate risks faster, meet compliance requirements, and improve overall security. Hacking & Cracking Contact Jennifer Wood, [email protected]
Find jobs on Simplify and start your career today
Industries
Data & Analytics
Enterprise Software
Cybersecurity
Company Size
51-200
Company Stage
Series A
Total Funding
$20M
Headquarters
Austin, Texas
Founded
2018
Find jobs on Simplify and start your career today