Full-Time
Updated on 9/3/2026
Offensive security consulting, training, and STaaS
No salary listed
Remote in USA + 1 more
More locations: Remote in Canada
Remote
See people who can refer or advise you
Theori delivers offensive-security cybersecurity solutions for government and commercial clients, combining proactive testing, threat intelligence, and training. Its products include Xint for AI-powered application security testing, αprism for securing AI models, Dreamhack for realistic hacking simulations, and Fermium-252, PatchDay, and ChainLight for threat intelligence, bug bounty, and blockchain security. Its services cover penetration testing, source code audits, APT simulations, and Security Team as a Service (STaaS), which places experts inside a client’s operations for ongoing security guidance and incident response. Theori stands apart through its Carnegie Mellon hacker heritage and a proven track record in competitions, offering an integrated suite of tools and embedded security talent to help clients stay ahead of threats and reduce risk.
Company Size
51-200
Company Stage
Early VC
Total Funding
$11.5M
Headquarters
Austin, Texas
Founded
2016
See people who can refer or advise you
Help us improve and share your feedback! Did you find this helpful?
Health Insurance
Dental Insurance
Vision Insurance
Paid Vacation
Remote Work Options
Home Office Stipend
Company Equity
Linux Copy Fail bug actively exploited, urgent patch warning issued. Cybersecurity authorities have raised a serious alarm after a newly disclosed Linux vulnerability, known as "Copy Fail," is now being actively exploited in real-world attacks just a day after its public disclosure. Tracked as CVE-2026-31431, the flaw exists in the Linux kernel's algif_aead cryptographic interface. It allows unprivileged local users to gain full root access on affected systems. Attackers can exploit this bug by writing controlled data into the page cache of readable files, ultimately taking complete control of the system. Security researchers from Theori revealed the vulnerability and released a proof-of-concept exploit, describing it as fully reliable. The exploit has already been tested successfully on major distributions, including Ubuntu 24.04 LTS, Amazon Linux 2023, RHEL 10.1, and SUSE 16. According to researchers, the same exploit works across nearly all Linux distributions released since 2017 without modification, making the issue extremely widespread. Shortly after the disclosure, the Cybersecurity and Infrastructure Security Agency added the vulnerability to its Known Exploited Vulnerabilities catalog. The agency has instructed U.S. federal agencies to patch affected systems within two weeks, warning that such flaws are commonly used by attackers and pose significant risks. Although the directive officially applies to government systems, security experts are urging all organizations and Linux users to update their systems immediately. At the time of disclosure, some vendors had not yet released official patches, though updates are now beginning to roll out. This incident follows another recent Linux security issue, CVE-2026-41651, also known as Pack2TheRoot, which had remained undiscovered for years before being fixed. If this article helped you, please consider supporting its work. Every small contribution keeps Abijita.com independent and running. The rapid exploitation of the Copy Fail bug highlights how quickly attackers move once vulnerabilities become public, making timely patching critical for system security. Bijay Pokharel is the Founder and Editor-in-Chief of Abijita.com and a freelance technology writer covering the tech industry since 2017. He specializes in cybersecurity, digital privacy, malware, vulnerabilities, and online safety, with a strong interest in internet protection and women's online security. A dedicated tech enthusiast and continuous learner, Bijay approaches his professional work with clarity, rational thinking, and a calm, solution-oriented mindset.
Theori launches Xint Code AI platform to uncover hidden vulnerabilities in massive codebases. Offensive cybersecurity firm Theori Inc. today announced the commercial availability of Xint Code, a new large language model-native static application security testing or SAST tool capable of analyzing millions of lines of source code, configuration files and binaries in less than 12 hours. The new offering takes a unique approach to deep scanning and contextual analysis of massive codebases to help application security teams quickly identify, reproduce, validate and understand the real-world critical vulnerabilities in applications. Xint Code uses LLMs combined with a orchestration engine to scan and analyze each line of code from a context and business logic perspective to dramatically reduce false positives and help defenders quickly prioritize the vulnerabilities that matter. Attackers are increasingly using artificial intelligence to surface critical vulnerabilities, resulting in security teams strugglingly to stay one step ahead. Also, traditional SAST solutions may be able to find known software vulnerabilities but also produce a high rate of false positives and trivial findings. Human penetration testing, though able to find more subtle business context vulnerabilities, can't do so at large scale. Additionally, emerging AI coding assistants have context and attention window limits that prevent them from scanning entire codebases and prioritizing their results. Xint Code claims to solve these issues by offering human-level insight at machine-level speed and scale. "Critical vulnerabilities often stay hidden because traditional scanners miss business logic flaws and manual reviews can't scale across hundreds of millions of lines of code," said Chief Technology Officer Andrew Wesie. "But LLMs are changing this. What would take pentesters weeks or months to find - if they know what to look for - Xint Code surfaces in hours. And it doesn't just flag potential issues; it tells you exactly how an attacker would trigger the exploit and what the impact is." Key capabilities of Xint Code include human-level insight into business logic vulnerabilities, with support to orchestrate multiple AI models to analyze code with contextual understanding. To define signals over noise, a multistage analysis pipeline verifies the severity and exploitability of every vulnerability before reporting, dramatically reducing false positives that drain security teams. Every Xint Code discovery includes step-by-step reproduction instructions and real-world impact assessment, so teams can prioritize the vulnerabilities that actually matter and the offering offers zero-friction deployment with no formatting, packaging or harness configuration required. While only being released commercially today, Xint Code is already being used by popular project maintainers, governments and companies, including MongoDB Inc., Fortune 10 companies, manufacturing giants and global retailers, to analyze massive legacy codebases. Alongside the launch, Theori also released a new research paper that shows how Xint Code was used to identify a severe vulnerability. The problem had enabled data exfiltration and arbitrary code injection that had been undetected for over two decades in the popular PostgreSQL open-source project, which powers transactional and analytical workloads across software-as-a-service, finance, telecom and government deployments. The report explains why traditional SAST tools, human pentesters and even next-gen AI tools missed this vulnerability and explains how both attackers and defenders can now scan millions of lines of code in just a few hours to find critical vulnerabilities in massive, legacy code bases. Theori is a venture capital-backed startup that has raised $15.4 million over two rounds. Investors in the company include Naver Corp., Hana Bank and Dunamu & Partners Inc. Image: Theori. A message from John Furrier, co-founder of SiliconANGLE: Support its mission to keep content open and free by engaging with theCUBE community. Join theCUBE's Alumni Trust Network, where technology leaders connect, share intelligence and create opportunities. * 15M+ viewers of theCUBE videos, powering conversations across AI, cloud, cybersecurity and more * 11.4k+ theCUBE alumni - Connect with more than 11,400 tech and business leaders shaping the future through a unique trusted-based network. About SiliconANGLE Media SiliconANGLE Media is a recognized leader in digital media innovation, uniting breakthrough technology, strategic insights and real-time audience engagement. As the parent company of SiliconANGLE, theCUBE Network, theCUBE Research, CUBE365, theCUBE AI and theCUBE SuperStudios - with flagship locations in Silicon Valley and the New York Stock Exchange - SiliconANGLE Media operates at the intersection of media, technology and AI. Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a dynamic ecosystem of industry-leading digital media brands that reach 15+ million elite tech professionals. Its new proprietary theCUBE AI Video Cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.
Theori receives $1.5M prize at DARPA's AI Cyber Challenge
Theori is also introducing αprism, an LLM security and monitoring solution.
SAN FRANCISCO, April 30, 2025 /PRNewswire/ - Theori, a leading offensive security firm specializing in advanced threat simulation, today announced a new agreement with Okta, the leading independent Identity partner.