Full-Time
Machine-readable threat intelligence with VAR partnerships
$152k - $228.5k/yr
Remote in USA
Remote
See people who can refer or advise you
Recorded Future provides machine-readable threat intelligence to help organizations lower the risk of cyber attacks. Its data can be integrated with customers' existing security tools and workflows used by SOCs, IR teams, and vulnerability programs. The company grows via a partner-led model with VARs, offering training, certifications, and marketing support to help partners sell and implement the technology. Revenue comes from direct sales and VAR partnerships with recurring revenue and margins, and its goal is to help organizations detect, understand, and respond to threats more effectively.
Company Size
1,001-5,000
Company Stage
Acquired
Total Funding
$58.7M
Headquarters
Somerville, Massachusetts
Founded
2009
See people who can refer or advise you
Help us improve and share your feedback! Did you find this helpful?
Professional development and career advancement
Flexible work environment, be yourself
Generous vacation policy
Wellness programs
Company outings
Competitive compensation and benefits
Free snacks, drinks, and coffee in the office
Parental leave program
Environmentally conscious
Recorded Future's automated signatures combat AI exploits. This article was written by a language model from the source above and was not reviewed by a human before publication. Verify anything operational against the original. Editorial policy Key points * " Immediate impact: AI-accelerated exploits shorten vulnerability exploitation windows, increasing enterprise risk. * " Affected systems: Organizations relying on manual vulnerability detection processes face significant defense challenges. * " Remediation: Automated Signature Creation rapidly generates detection logic, improving real-time vulnerability prioritization. Overview: accelerating vulnerability prioritization with automated signatures. Recorded Future has introduced Automated Signature Creation, a new capability within its Attack Surface Intelligence (ASI) platform designed to combat the escalating speed of AI-generated exploits. This enhancement aims to accelerate vulnerability detection and prioritization, allowing organizations to remediate exposures before adversaries can act. The new function automates the generation of detection logic, enabling the platform to identify specific vulnerable or exposed conditions across an organization's assets in near real-time, significantly shortening the window between vulnerability disclosure and potential exploitation, according to Recorded Future. The challenge: defending against ai-accelerated exploits. The landscape of cybersecurity threats is continuously evolving, with artificial intelligence now playing a significant role in accelerating the discovery and exploitation of vulnerabilities. Historically, the time from vulnerability discovery to exploitation has drastically decreased, from an average of 45 days in 2010 to 15 days in 2020, and currently, this window is often measured in hours. Advanced AI models are demonstrating the ability to automatically find zero-day vulnerabilities in critical software, a task once exclusive to highly specialized government units and research labs. This rapid weaponization of vulnerabilities renders traditional, manual security processes increasingly insufficient. For instance, Recorded Future previously detailed how manual signature creation for issues like CVE-2025-0994 in Trimble Cityworks, while effective, operated at a human pace. The urgency of this challenge is underscored by recent incidents, such as OpenAI's agents exploiting a zero-day vulnerability in Artifactory during the Hugging Face incident, illustrating the real-world implications of machine-speed exploitation. Technical deep dive: Automated Signature Creation vulnerability prioritization. Automated Signature Creation addresses the speed gap by generating production-ready detection signatures autonomously, often within as little as 31 minutes of a new vulnerability surfacing. This capability operationalizes detection logic by defining specific questions to ask an asset; a particular answer indicates a vulnerable state. This transforms general asset discovery into actionable intelligence on exploitable weaknesses. The system functions as a three-step early warning system, greatly increasing the number of in-platform signatures produced - a tenfold increase - and subsequently boosting detection events across customer assets. How Automated Signature Creation works. At its core, a 'signature' in this context is a piece of detection logic that queries an asset for a specific condition. If the asset's response matches a predefined pattern, it's identified as vulnerable. This is crucial for defending against AI-accelerated exploits because it shifts from reactive, human-paced analysis to proactive, machine-speed detection. For example, during one week in August 2026, automated signatures accounted for nearly 20% of all critical-severity events and over 25% of all high-severity events detected within ASI, demonstrating its impact on threat visibility and prioritization. Alignment with CISA directive vulnerability mitigation. The compressed time to exploitation has also prompted new policy directives for federal agencies, such as the CISA directive issued on June 10, 2026, which aims to improve how federal agencies prioritize vulnerability mitigation. This directive outlines specific criteria for prioritization, which directly map to Recorded Future's capabilities. Automated Signature Creation effectively operationalizes this risk-based prioritization approach, making it an invaluable tool not only for federal agencies but for any organization seeking to adopt a more proactive and risk-aligned security posture. Recommendations for defenders. Given the accelerating pace of vulnerability exploitation, security teams must evolve their defensive strategies beyond traditional, manual processes. To effectively counter AI-accelerated threats and improve automated signature creation vulnerability prioritization, consider the following: * Embrace Automated Detection: Invest in platforms that offer automated signature generation and real-time vulnerability detection to reduce the window of exposure. * Prioritize Based on Risk: Implement frameworks that align with directives like the CISA guidance, focusing on vulnerabilities with known exploitation, high impact, and broad applicability. * Maintain Comprehensive Asset Visibility: Ensure a continuous and accurate mapping of your external attack surface to identify all internet-facing assets that could be exposed. * Integrate Threat Intelligence: Leverage current threat intelligence to understand which vulnerabilities are being actively exploited in the wild and prioritize patching efforts accordingly. By adopting these strategies, organizations can better position themselves to defend against the rapid and sophisticated threats emerging from AI-driven exploitation.
Recorded Future Launches AI Alert Filtering PUBLISHED ON 26 AUG 2026 Jess Pagonis, Product Marketing
Recorded Future adds native risk ratings to Third-Party Risk: what defenders should do with it. Security Arsenal Team August 20, 2026 Recorded Future has launched native risk ratings capabilities inside its Third-Party Risk product, uniting external threat intelligence and point-in-time vendor risk ratings in a single workflow. For security teams drowning in questionnaire-driven vendor assessments and disconnected scoring tools, this is a meaningful architectural shift - not just a feature checkbox. Third-party compromise remains one of the most reliable initial access vectors Security Arsenal see in incident response engagements. MoveIT, the 3CX supply-chain compromise, and the steady drumbeat of managed service provider intrusions all share the same pattern: the attacker's path of least resistance ran through a vendor the victim had assessed once, on paper, and never monitored again. The 2025-2026 threat landscape has only sharpened this reality, with ransomware groups and nation-state operators alike deliberately targeting downstream dependencies to multiply their access. The defensive question this launch addresses is simple: are you scoring your vendors continuously based on real-world exposure, or are you scoring them based on what they told you in a spreadsheet 14 months ago? What Recorded Future actually shipped. Based on the announcement, the key changes to the Third-Party Risk product are: * Native risk ratings inside the Third-Party Risk workflow. Risk ratings are no longer a separate tool or data feed you pivot between - they are embedded directly where analysts perform vendor assessments and monitoring. This eliminates the swivel-chair problem between a ratings platform and an intelligence platform. * Unification of threat intelligence and ratings. Recorded Future's core strength is its intelligence graph - dark web chatter, exposed credentials, vulnerability references, infrastructure signals, and geopolitical context. Folding that intelligence directly into vendor risk ratings means a vendor's score reflects observable, current external exposure rather than static self-attestation. * A single workflow for assess-and-monitor. Practically, this means a third-party risk analyst can onboard a vendor, see its continuously updated rating, understand why the rating moved (e.g., newly observed leaked credentials, an exposed service, a mention in ransomware leak site activity), and trigger action - without leaving the product. This is not a vulnerability, CVE, or exploit - there is no patch to deploy. This is a capability launch, and the defensive value depends entirely on how your organization operationalizes it. Why this matters to defenders in 2026. Three trends make continuous, intelligence-driven third-party risk scoring operationally relevant right now: * Regulatory and contractual pressure is continuous-monitoring-shaped. NIST CSF 2.0's Govern function explicitly calls out supply chain risk management as an organizational responsibility. PCI DSS 4.0 requirements around third-party service providers (12.8.x) demand ongoing oversight, not annual attestation. Cyber insurers increasingly ask for evidence of continuous vendor monitoring during underwriting and claims. * Questionnaires don't catch compromise. A vendor can pass your SIG Lite assessment in January and be listed on a ransomware leak site in March. If your risk posture for that vendor only updates at renewal, you have an 11-month blind window - during which that vendor may still hold network access, API credentials, or your data. * Alert fatigue from disjointed tooling. Teams that bolt a security ratings service onto a separate TIP onto a separate GRC platform end up with three scores per vendor and no authoritative workflow. Consolidation into a single workflow - ratings plus the intelligence explaining the rating - is how you get analysts to actually act on score changes instead of ignoring them. Executive takeaways. Since this is a product capability announcement rather than a technical threat, the appropriate response is organizational, not signature-based. Here is what Security Arsenal recommend to clients evaluating or deploying this capability: * Inventory your third-party tiering before you buy anything. Risk ratings deliver value proportional to how well you've tiered your vendor population. Identify your critical vendors (those with network connectivity, data access, or operational dependency) and make them the mandatory scope for continuous monitoring. A rating on a vendor you can't act against is trivia. * Define response playbooks for rating changes before deployment. The most common failure mode Security Arsenal see with security ratings is alerting into a void. Decide now: what happens when a critical vendor's rating drops two grades? Who gets paged? Is there a contractual right-to-audit trigger? Can you suspend API keys or network peering while you investigate? A rating drop on a payroll provider, an MSP, or a SaaS platform holding customer data should kick off a defined workflow - vendor outreach, internal exposure assessment (what data/access does this vendor touch?), and documented risk acceptance or mitigation. * Use the intelligence behind the score, not the score itself. A letter grade is an executive communication device. The operational value sits in the drivers - leaked credentials attributed to the vendor's domain, exposed RDP or unpatched internet-facing services, mentions in criminal forums, ransomware victim listings. Train your analysts to drill into evidence and translate it into concrete questions for the vendor: "We observed credentials for yourdomain.com in a stealer log corpus on this date - confirm your remediation." * Integrate ratings into procurement and renewal gates. Third-party risk delivers the most leverage at contract time. Make the current rating and its trend line a required input for vendor onboarding and renewal decisions. Vendors respond to commercial pressure; a deteriorating score that threatens renewal gets remediation budgets approved faster than any security questionnaire. * Map coverage against your compliance obligations. If you're operating under NIST CSF 2.0, PCI DSS 4.0, HIPAA, or contractual flow-downs from customers, document exactly which third-party oversight controls this capability satisfies - and which it doesn't. Continuous external monitoring complements, but does not replace, contractual security requirements, right-to-audit clauses, and breach notification SLAs. * Plan for the fourth-party problem. A rating on your direct vendor doesn't automatically cover their subcontractors. Use the intelligence layer to identify concentration risk - multiple critical vendors dependent on the same upstream cloud, MSP, or software component - because that's where correlated failure lives. Bottom line. Recorded Future folding native risk ratings into Third-Party Risk is a sensible consolidation move that reflects where the discipline is heading: continuous, evidence-driven vendor assessment instead of point-in-time self-attestation. The tooling is the easy part. The organizations that extract real defensive value will be the ones that pair it with tiered vendor inventories, pre-built response playbooks for score degradation, and contractual teeth at procurement time. If your third-party risk program still runs on annual questionnaires and good intentions, this is the right moment to close that gap - before a vendor's incident becomes yours. Related resources. Is your security operations ready? Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.
Pentera and Recorded Future to deliver threat-led exposure validation. On: July 28, 2026 Pentera announces a strategic partnership with Recorded Future, allowing Recorded Future customers to identify and validate whether emerging threats are exploitable in their own environments and act on the exposures that matter most. Recorded Future and Pentera will demonstrate the integration at Black Hat 2026. Today, security teams consume threat intelligence and run security testing as parallel efforts, often across disconnected tools and processes. This new integration unifies threat signals and security controls testing into a single autonomous operational flow in alignment with Continuous Threat Exposure Management (CTEM). Recorded Future provides the most comprehensive view of relevant threats as they emerge, while Pentera validates which of those threats represent exploitable exposure inside the organization and moves them to remediation. By operationalizing live threat intelligence directly into security validation, enterprises can assess their preparedness against specific attack groups, techniques and campaigns actively observed in the wild, tailored to their industry, geography, and specific environment, enabling faster and more accurate exposure reduction. "This partnership connects threat intelligence and security validation in a way the market has been missing," said Amitai Ratzon, CEO of Pentera. "Recorded Future customers already understand which threats are relevant to them. Pentera turns that intelligence into proactive security validation testing, including a fast cycle of surgical remediation steps, leading to measurable risk reduction." "With Autonomous Threat Operations, Recorded Future is already pushing the boundaries of what's possible with threat intelligence," said Jamie Zajac, Chief Product Officer at Recorded Future. "This integration with Pentera unlocks the next level. Automated validation helps determine whether those threats are exploitable in a given environment. That's the future of operationalized intelligence." The integration aligns with a growing set of global cybersecurity regulations and resilience frameworks that prioritize threat-informed testing, including the EU's Digital Operational Resilience Act (DORA) and TIBER-EU. These frameworks emphasize validating defenses against real adversary behavior, not abstract vulnerability lists. Together, Pentera and Recorded Future bring these principles into continuous operation rather than limiting them to point-in-time red team exercises. Pentera and Recorded Future will showcase the integration during a joint speaking session titled "Threat Intel Just Got Teeth: TLPT Goes Live" on August 6, at Black Hat 2026 in Las Vegas. The companies will demonstrate how integrating live threat intelligence with automated validation helps organizations continuously test their defenses against the latest attacker activity. 2026-07-28
Pentera and Recorded Future have partnered to integrate threat intelligence with security validation testing. The collaboration allows Recorded Future customers to identify whether emerging threats are exploitable in their environments and prioritise remediation accordingly. The integration combines Recorded Future's threat intelligence with Pentera's AI-powered security validation platform, creating an autonomous operational flow aligned with Continuous Threat Exposure Management principles. Previously, security teams handled threat intelligence and security testing as separate processes using disconnected tools. The partnership addresses requirements in global cybersecurity frameworks including the EU's Digital Operational Resilience Act and TIBER-EU, which emphasise validating defences against real adversary behaviour. Recorded Future serves over 1,900 businesses and government organisations across 80 countries, whilst Pentera is used by thousands of security professionals globally. The companies will demonstrate the integration at Black Hat 2026 in Las Vegas on 6 August.