VulnCheck

VulnCheck

Provides subscription-based cyber threat intelligence platform

Overview

VulnCheck provides an ongoing Cyber Threat Intelligence platform that helps organizations protect digital assets by predicting and mitigating cyber threats. They operate on a subscription model that delivers vulnerability and exploit intelligence directly into clients’ security workflows. The platform gives visibility into the vulnerability ecosystem and lets customers prioritize fixes based on the likelihood that a vulnerability will be exploited, which is crucial as exploits are weaponized more quickly than in the past. The service tiers include basic vulnerability intelligence, advanced exploit prediction, and custom integrations with existing security tools. Customers range from large enterprises to government agencies, all seeking to reduce cyberattack risk and protect their assets and reputation.

Significant Headcount Growth

About VulnCheck

Simplify's Rating
Why VulnCheck is rated
B
Rated B on Competitive Edge
Rated A on Growth Potential
Rated C on Differentiation

Industries

Data & Analytics

Enterprise Software

Cybersecurity

Company Size

51-200

Company Stage

Series B

Total Funding

$45M

Headquarters

Lexington, Massachusetts

Founded

2021

Get referred to VulnCheck

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • September 1, 2026: EMEA revenue tripled and customer count doubled.
  • August 11, 2026: Inc. 5000 ranked VulnCheck No. 478 with 717% growth.
  • February 17, 2026: Sorenson led $25 million Series B, lifting total funding to $45 million.

What critics are saying

  • Cobalt, Synack, and Nucleus Security can bundle exploit intelligence into broader platforms.
  • September 23, 2026 changelog shows constant product churn; buyers can commoditize feeds quickly.
  • Microsoft, CISA, and scanner vendors can absorb exploit signals, collapsing VulnCheck into a data supplier.

What makes VulnCheck unique

  • VulnCheck refreshes exploit intelligence multiple times daily from 500+ sources and first-party canaries.
  • Its 2026 report tracked 14,000+ exploits across 10,000+ CVE-2025 vulnerabilities.
  • Canary Intelligence exposes real attacker payloads, IPs, geolocation, and first-seen exploitation timestamps.

Help us improve and share your feedback! Did you find this helpful?

Funding

Total Funding

$45M

Below

Industry Average

Funded Over

4 Rounds

Series B funding is typically for startups that have proven their business model and need more funding to expand rapidly—often by entering new markets or adding more products. Investors are usually venture capital firms that specialize in later-stage investments.
Series B Funding Comparison
Below Average

Industry standards

$35M
$30M
Patreon
$45M
Linktree
$65M
Substack
$100M
ClickUp

Benefits

Unlimited Paid Time Off

401(k) Retirement Plan

401(k) Company Match

Health Insurance

Parental Leave

Remote Work Options

Flexible Work Hours

Phone/Internet Stipend

Professional Development Budget

Growth & Insights and Company News

Headcount

6 month growth

↑ 4%

1 year growth

↑ 6%

2 year growth

↑ 0%
Cobalt
Sep 16th, 2026
How Cobalt brings real-time exploit and threat intelligence to vulnerability findings.

How Cobalt brings real-time exploit and threat intelligence to vulnerability findings. Sep 16, 2026 Est Read Time: 4 min Common Vulnerabilities and Exposures (CVE) identify known vulnerabilities in specific components. They don't confirm whether you're exposed or whether attackers are actively exploiting a vulnerability. The additional context from adding reliable threat intelligence and known CVE information to your pentest findings can make the difference between wasting time on research and triage and quickly identifying pressing risks that your business needs to address. Cobalt integrated CVE intelligence from VulnCheck directly into the Cobalt Offensive Security Platform. This new real-time exploit and threat intelligence shows up on suggested findings (for pentesters) and on validated findings delivered to customers. Now, on any finding tied to a CVE, Cobalt automatically surface: * EPSS score: Probability of exploitation in the wild within 30 days * KEV status: Whether it's on CISA's Known Exploited Vulnerabilities list * MITRE ATT&CK techniques: How attackers actually use this vulnerability * Publicly available exploits: Sources, PoC links, and dates Threat intelligence gives you the macro view of what tools adversaries are building across the internet. Offensive security research and pentest finding validation from Cobalt give you the ground truth: whether that flaw is reachable in your stack, how it connects to your broader attack tree, and what an adversary can actually do with it once they get in. Not every finding has a CVE Not all pentest findings are tied to known CVEs. CVEs catalog publicly disclosed security flaws in third-party software and hardware, whereas penetration tests frequently expose custom application errors, operational misconfigurations, and business logic flaws that will never receive a CVE. Common non-CVE pentest findings: * Business logic flaws: Defects in how proprietary application code processes workflows, such as altering item prices during a checkout process or bypassing step-up authentication. * Access control weaknesses: Insecure Direct Object References (IDOR/BOLA) and broken authorization models where authenticated users can view or modify another user's private data. * Security misconfigurations: Weak password policies, default credentials, exposed cloud storage buckets, permissive CORS policies, or improper TLS/SSL configurations. * Zero-day vulnerabilities: Newly discovered flaws in third-party software identified by the tester before the vendor or public database has assigned an official CVE identifier. * Human and physical security gaps: Vulnerabilities uncovered through social engineering (phishing, pretexting), tailgating into secure facilities, or cleartext credentials stored on internal documentation sites. What if the finding does have an associated CVE? A finding tied to a known CVE (sometimes) comes with a severity rating or CVSS score. The Common Vulnerability Scoring System is the open industry standard used to calculate a vulnerability's technical severity on a scale from 0.0 to 10.0. But severity rating alone isn't enough to decide what to fix first. Additional context is needed, including: * Is there a working exploit in the wild? * Has this been weaponized by ransomware operators? * Is it on CISA's radar for tracking? Obtaining this information without a partner is no easy task. The data is scattered across the National Vulnerability Database (NVD), the CISA Known Exploited Vulnerabilities (KEV) catalog, exploit repositories, and threat reports that you may or may not have access to. Researching all the necessary information is manual and time-consuming, pulling pentesters and security teams out of the work that matters most: finding more of the critical vulnerabilities in your systems. Cobalt added CVE context for faster discovery and remediation Cobalt pentesters already validate whether a CVE represents real exposure in your environment. They manually verify that the issue is reachable and exploitable in the target scope. For its expert testers, having instant access to exploit payloads and telemetry speeds up their manual verification, helping them test attack paths faster and back up their findings with real-world threat data. What gets surfaced If there's a known CVE in your environment, Cobalt enrich the finding in the Cobalt Platform with: * EPSS score: The probability a vulnerability will be exploited in the wild within 30 days. Model-driven and updated daily, so it reflects current risk, not a static rating. * KEV status: Inclusion on CISA's Known Exploited Vulnerabilities list confirms active exploitation in the wild, which helps teams prioritize the fix and meet compliance deadlines. * MITRE ATT&CK techniques: The adversary techniques mapped to the vulnerability. This connects the flaw to how attackers actually use it in an intrusion, not just that it exists. * Exploited by: The categories of threat activity tied to the CVE: threat actors, ransomware, botnets, VulnCheck canaries, and honeypots. It shows not just that a vulnerability has been exploited, but what kind of adversary activity has been observed. * Publicly available exploits: References tied to the CVE, from GitHub repositories to blog posts, each tagged by publication date and classified as proof-of-concept or weaponized, so you can tell a known technique from ready-to-deploy tooling. Why it matters for customers Remediation capacity is finite. Every security team faces more findings than it can fix at once, especially with the uptick in AI-assisted and AI-generated findings, and severity alone is insufficient for deciding what goes to the top of the queue. If you're relying solely on severity rating for prioritization, a critical-rated CVE that no one is exploiting will outrank a moderate CVE that ransomware operators are actively using. Additionally, real attackers do not look at vulnerabilities in isolation. They look at attack chains: pairing a known CVE in an external component with custom application weaknesses, like an authorization flaw or a cloud misconfiguration, to pivot deeper into an environment. Translating a finding into a remediation decision usually means making the case twice: to engineering to prioritize the work, and to leadership to justify the urgency. Severity alone rarely settles either conversation. Exploit and threat intelligence does. When a validated finding arrives with a high EPSS score, a KEV listing, weaponized exploits, or confirmed exploitation activity, the priority is not a matter of interpretation. It is a vulnerability to fix now, with the evidence already attached. That gives your security team the language to move findings from backlog to remediation, and to show the business why it mattered. Why Cobalt chose VulnCheck VulnCheck provides the relevant data to make prioritization of your Cobalt findings easier, so you can remediate the most consequential vulnerabilities that threaten your business. Most vulnerability data is purely vulnerability-centric. It describes the flaw only, not the impact or if and how it's being used in the real world. VulnCheck pairs vulnerability intelligence with exploit intelligence, aggregated from hundreds of sources, including its own exploit developers and honeypot canaries, adding the necessary context to streamline remediation. Available now The enrichment is live across suggested findings for pentesters and validated findings delivered to customers. There is nothing to enable or configure. When a CVE is identified on a finding, the available exploit intelligence is populated automatically. Prioritizing vulnerabilities has always been hard. With exploit and threat intelligence built into the finding in the Cobalt Platform, its pentesters verify attack vectors faster, and its customers get the context they need to act with confidence. If you have any questions, please reach out to your Cobalt team. If you're interested in learning more about its products and services, request a demo today. About Molly Finn. Molly Finn is the Senior Product Manager at Cobalt. With over 12 years of product leadership experience, she helps bring to life the Cobalt mission to take Pentest as a Service (PtaaS) further with an Offensive Security Testing Platform. Molly partners closely with engineering, design, and its customers to deliver end-to-end security testing across your attack surface. More By Molly Finn Related readings. Never miss a story. Stay updated about Cobalt news as it happens

The Infotech
Sep 6th, 2026
VulnCheck Partners with Rilian to Expand in EMEA.

VulnCheck Partners with Rilian to Expand in EMEA. ET By Editorial Team September 6, 2026 VulnCheck, The Exploit Intelligence Company, announced a partnership with Rilian, a leading provider of AI-native cybersecurity and defense technology solutions for the U.S., allied sovereign nations and critical infrastructure operators. The partnership expands VulnCheck's presence in Europe, the Middle East and Africa (EMEA), where the company has experienced 319% year-over-year growth and doubled its customer count. VulnCheck's partnership with Rilian represents a collaboration with a trusted market leader serving sovereign defenders and leading enterprise organizations in the region. It also underscores VulnCheck's growing momentum and the rising demand for exploit intelligence solutions. Cyberattacks in EMEA carry outsized consequences. Recent research shows that 80% result in data breaches, many of which surface quickly on the dark web. By delivering timely insight into active exploits, VulnCheck enables regional organizations to prioritize defenses, remediate the right vulnerabilities within the critical window and prevent breaches stemming from exploitation. "Expanding in the Middle East allows us to deliver exploit intelligence directly to the organizations that protect critical infrastructure and sensitive operations," said Anthony Bettini, CEO and Founder of VulnCheck. "Exploit and threat intelligence are essential to national defense, giving leaders the foresight to anticipate attacks and proactively secure the systems that safeguard citizens and strategic assets." "Our partnership with VulnCheck is designed to respond to an overwhelming demand for vulnerability-related threat intelligence from our customers across the globe," said Nick Pompeo, Co-Founder and President of Rilian. "It's our commitment to our customers to help them outpace adversaries and protect national security interests through actionable vulnerability and threat intelligence from VulnCheck." Key benefits of VulnCheck for sovereign and sensitive environments. * Actionable Exploit Intelligence: Insights into vulnerabilities under active attack, including weaponization details, zero-day vulnerabilities and threat actor attribution. * Enhanced Defense for Critical Infrastructure: Prioritized vulnerability intelligence tailored for sovereign organizations and dual-use technology applications. * Accelerated Adoption and Automation: Streamlined workflows to operationalize security innovation faster and more safely than traditional approaches. Together, VulnCheck and Rilian are enabling customers to operationalize high-fidelity intelligence, reduce risk exposure and make faster, more informed security decisions.

Citybiz
Aug 11th, 2026
VulnCheck ranks No. 478 on 2026 Inc. 5000.

VulnCheck ranks No. 478 on 2026 Inc. 5000. August 11, 2026 VulnCheck, a Lexington, Massachusetts-based exploit intelligence company, has ranked No. 478 on the 2026 Inc. 5000 list of America's fastest-growing private companies. The cybersecurity company recorded 717% revenue growth over three years, placing it in the top 10% of Inc. 5000 honorees and among the list's 10 fastest-growing cybersecurity companies. "Our rapid growth reaffirms that the market is demanding better approaches to address the rapidly accelerating volume of software vulnerabilities," said Anthony Bettini, founder and CEO of VulnCheck. "Security teams need exploit intelligence that shows what is actively weaponized in the wild." VulnCheck has expanded its workforce more than ninefold over the past three years. In February 2026, the company also announced a $25 million Series B funding round to support growing demand for its exploit intelligence products. VulnCheck provides structured intelligence identifying software vulnerabilities and exploits that are actively being weaponized. Its technology is designed to integrate with data platforms, automation systems and AI and large language model workflows. The 2026 Inc. 5000 ranks private U.S. companies based on percentage revenue growth from 2022 through 2025. Companies on this year's list posted median three-year revenue growth of 130%.

Business Wire
Aug 11th, 2026
VulnCheck ranks No. 478 on Inc. 5000 with 717% three-year revenue growth

VulnCheck, a cybersecurity company based in Lexington, Massachusetts, has ranked No. 478 on the 2026 Inc. 5000 list of America's fastest-growing private companies. The firm achieved 717% three-year revenue growth, placing it in the top 10% overall and among the top 10 fastest-growing cybersecurity companies. The company announced a $25 million Series B funding round in February 2026. Over the past three years, VulnCheck has grown its team more than ninefold. VulnCheck provides exploit intelligence solutions that identify actively weaponised software vulnerabilities. The company's services are designed for integration with automated systems, AI models, and existing security workflows. The Inc. 5000 list recognises the fastest-growing independent private companies in the US based on percentage revenue growth from 2022 to 2025.

Operation: Technology Cyber Coalition
Feb 24th, 2026
VulnCheck Joins Operational Technology Cybersecurity Coalition to Advance Real-Time Exploit Intelligence

VulnCheck joins Operational Technology Cybersecurity Coalition to advance real-time exploit intelligence. Partnership expands collaboration to strengthen operational technology security and critical infrastructure protection WASHINGTON, D.C. and LEXINGTON, Mass - Feb. 24, 2026 - The Operational Technology Cybersecurity Coalition (OTCC) and VulnCheck today announced that VulnCheck has joined the coalition as its newest member, expanding efforts to strengthen the cybersecurity of operational technology (OT) environments and protect critical infrastructure as threats targeting industrial control systems and network-edge devices continue to increase. "There is growing urgency within the critical infrastructure segment to modernize how we prioritize and address potential software vulnerabilities," said Arun Chetty, Vice President at National Grid Partners. "It's clear that attackers are moving faster than defenders can triage flaws, and VulnCheck provides continuously updated intelligence at machine speed and with more precision than any other organization we've seen. VulnCheck's contribution to the OTCC's efforts in safeguarding critical infrastructure will enrich the global intelligence ecosystem." The OTCC focuses on improving OT security and advancing policies that strengthen critical infrastructure resilience. Representing the entire OT lifecycle, the OT Cyber Coalition believes that the strongest, most effective approach to securing its nation's critical infrastructure is one that is open, vendor-neutral, and allows for diverse solutions and information sharing without compromising cybersecurity defenses. VulnCheck delivers threat intelligence solutions that power cybersecurity products and critical response workflows used to protect the global economy, critical infrastructure, enterprises and governments. By joining OTCC, VulnCheck strengthens the group's ability to ground policy discussions and infrastructure defense strategies in current threat activity. "Network-edge devices, particularly in OT environments, are among the most highly targeted assets," Anthony Bettini, founder and CEO, VulnCheck. "Greater visibility into exploited flaws and active threats is essential to helping defenders reduce risk in critical infrastructure environments. Through OTCC membership, we can help ensure policymakers and operators have access to timely, actionable exploit intelligence that reflects real-world activity." VulnCheck provides machine-readable exploit intelligence to help organizations identify and prioritize vulnerabilities that pose an active risk. Its platform analyzes first-party evidence of exploitation and reviews more than 500 million records across all known CVEs from over 500 sources to surface actionable intelligence. Data sources are refreshed multiple times per day, providing updated context on threat actor activity, ransomware associations and publicly available exploit proof-of-concept code. Automating this analysis removes operational bottlenecks and enables security teams to respond more quickly to emerging threats. "Operational technology environments face increasingly sophisticated and persistent threats," Tatyana Bolton, Executive Director, OTCC. "Adding VulnCheck's exploit intelligence capabilities strengthens the coalition's collective ability to inform data-driven public policy discussions and support organizations responsible for securing critical infrastructure." VulnCheck will participate in S4x26, a conference focused on industrial control systems and operational technology security. VulnCheck representatives will be available onsite, including during the Premium Cabana Session on Wednesday, Feb. 25, from 1 p.m. to 4:30 p.m. ET. To learn more about OTCC and its members, visit https://www.otcybercoalition.org/. To learn more about VulnCheck and its exploit and vulnerability intelligence offerings, visit https://www.vulncheck.com/. About the Operational Technology Cybersecurity Coalition The OTCC is a diverse group of cybersecurity stakeholders dedicated to improving the cybersecurity of operational technology environments and strengthening public policy to secure critical infrastructure across the country. About VulnCheck VulnCheck closes the exploitation-timing gap by enabling security teams to operate on attacker timelines instead of disclosure timelines. By delivering machine-consumable, evidence-driven intelligence on when vulnerabilities become exploitable and how attackers actually use them, VulnCheck helps organizations prepare earlier, respond decisively, and verify exploitation without relying on scores or delayed consensus. Follow the company on LinkedIn or X.

Recently Posted Jobs

Sign up to get curated job recommendations

VulnCheck is Hiring for 13 Jobs on Simplify!

Find jobs on Simplify and start your career today

Don't see your dream role? Check out thousands of other roles on Simplify. Browse all jobs →