Full-Time

Commercial Sales Manager

Updated on 9/9/2026

Horizon3.ai

Horizon3.ai

501-1,000 employees

Autonomous pentesting SaaS for vulnerabilities

Compensation Overview

$230k - $260k/yr

Chicago, IL, USA + 1 more

More locations: United States

Hybrid

Three days on-site per week required in the Chicago office.

Category
Sales & Account Management (1)
Required Skills
Forecasting
Cybersecurity
Salesforce
Penetration Testing
DevOps

Get referred to Horizon3.ai

See people who can refer or advise you

Requirements
  • 7–10 years of total experience in B2B SaaS or technology sales.
  • 2–4 years of frontline sales management experience leading Commercial Account Executives or similar high-velocity teams.
  • Direct exposure to cybersecurity or security tooling through a security-focused vendor or sustained selling into security, DevOps, or IT buyers.
  • Demonstrated quota over-achievement as both an individual contributor and a manager, with clear examples of targets and outcomes.
  • Strong coaching and people-development skills, including addressing performance issues directly, fairly, and with an outcomes focus.
  • Clear, confident communication and presentation skills with the ability to engage technical stakeholders and executive leadership.
  • A data-informed approach to pipeline management, forecasting, and productivity.
  • High initiative and follow-through, including the ability to make progress without a fully built playbook and close the loop on commitments.
  • Experience designing or refining outbound programs and campaign-based motions that drive net-new pipeline.
  • Ability to work closely with the Director, Commercial Sales and reinforce shared standards and expectations within the Commercial pod.
  • Genuine interest in cybersecurity and offensive security, with the ability to explain technical concepts in straightforward language.
Responsibilities
  • Lead and develop a Commercial sales team, including hiring, onboarding, coaching, and day-to-day management.
  • Own pipeline and revenue targets for the Commercial segment and guide the team toward meeting or exceeding them.
  • Build and refine inbound and outbound motions for small business customers, including campaigns, sequences, and industry-specific plays that can be tested and scaled.
  • Partner with Marketing, Sales Operations, Product, Solutions Engineering, and Alliances to design and execute integrated programs that drive quality pipeline and predictable progression.
  • Establish and run a regular operating rhythm with clear goals and expectations, ongoing coaching and feedback, data and dashboards, and timely performance follow-up with support plans and next steps.
  • Provide forecasting and reporting on team performance, pipeline health, and key productivity metrics to sales leadership.
  • Build and maintain career paths and development plans for team members, preparing them for promotion into Account Executive and other sales roles.
  • Create a supportive, accountable team culture balancing encouragement and recognition with clear expectations and follow-through.
  • Stay current on Horizon3.ai’s cybersecurity and offensive security offerings, the broader security landscape, and buyer needs, then translate that knowledge into talk tracks, discovery questions, and plays.
  • Champion process and tooling improvements in Salesforce, Salesloft or Outreach, LinkedIn Navigator, and other systems.
  • Help shape the Commercial segment as the company scales, including refining existing processes and creating new ones.
Desired Qualifications
  • Formal coaching or leadership training or certifications.
  • Experience at a high-growth SaaS or cloud provider, especially in commercial segments.
  • Experience building or significantly reshaping a sales function, including processes, playbooks, hiring profiles, or metrics.
  • Deeper exposure to offensive security, penetration testing platforms, red teaming, purple teaming, or security automation.

Horizon3.ai specializes in cybersecurity by offering NodeZero, a SaaS platform for autonomous penetration testing. It lets enterprises simulate cyber-attacks on their own systems in a self-service way, without installing persistent agents, and without ongoing human intervention. The platform works by running security-focused attack simulations in production environments to uncover exploitable vulnerabilities and weak controls, delivering vulnerability assessments, threat simulations, and compliance-oriented testing through tiered subscription plans. This approach differentiates Horizon3.ai from traditional pentesting by being self-service, agentless, and safe to run in live environments, while targeting enterprise customers that must meet standards such as PCI DSS. The company aims to help organizations improve their security posture, prioritize remediation, and maintain regulatory compliance by continuously identifying and fixing weaknesses.

Company Size

501-1,000

Company Stage

Series E

Total Funding

$437M

Headquarters

San Francisco, California

Founded

2019

Get referred to Horizon3.ai

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • Horizon3 raised $250 million on August 3, 2026, valuing it above $2 billion.
  • Deloitte alliance on August 25, 2026 broadens channel reach across Australia and New Zealand.
  • Sydney sovereign instance on August 31, 2026 unlocks Australian government and critical infrastructure demand.

What critics are saying

  • Pentera and XBOW pressure pricing in autonomous pentesting through 2026-2027.
  • Federal expansion depends on Chad Keefer executing against entrenched incumbents like Tenable.
  • Any production mishap would shatter Horizon3's trust moat and stall enterprise renewals.

What makes Horizon3.ai unique

  • NodeZero tests production systems safely without persistent agents or credentials.
  • Horizon3 completed 310,000 production tests with zero disruptions by August 2026.
  • Sydney sovereign instance and FedRAMP High support regulated buyers needing data residency.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Health Insurance

Vision Insurance

Dental Insurance

Unlimited Paid Time Off

Remote Work Options

Stock Options

Growth & Insights and Company News

Headcount

6 month growth

-3%

1 year growth

-2%

2 year growth

-6%
iTWire
Aug 30th, 2026
Horizon3 launches sovereign Sydney instance, bringing the World's Best AI Hacker onshore for Australian organisations.

Horizon3 launches sovereign Sydney instance, bringing the World's Best AI Hacker onshore for Australian organisations. Horizon3 | Published 31 Aug 2026 COMPANY NEWS: New in-country sovereign instance delivers production-safe autonomous security validation with full Australian data residency, enabling government, critical infrastructure, and enterprise customers to continuously prove resilience in the AI vs. AI era. Horizon3, the AI-Native Proactive Security Company behind NodeZero(R), the World's Best AI Hacker(TM), today announced the general availability of its first Asia-Pacific Sovereign Instance, hosted in Sydney. The new Australian point of presence keeps all customer data resident in-country and enables Australian organisations to run continuous, production-safe autonomous penetration testing under full data sovereignty. As adversaries increasingly weaponise AI to discover and exploit vulnerabilities at machine speed, organisations can no longer rely on theoretical findings or periodic assessments. NodeZero continuously validates real, exploitable attack paths across Internal, External, Cloud, Identity, and Web Application surfaces - then drives a disciplined hack-fix-verify loop so customers can prove their defences actually hold. The Sydney Sovereign Instance makes this capability available onshore for the first time in the region, giving Australian organisations a practical way to operationalise Continuous Threat Exposure Management (CTEM) with continuous, attacker-validated evidence. The instance is purpose-built for the highest-trust Australian environments, including government agencies, critical infrastructure operators, Defence Industrial Base organisations, major banks, and other regulated entities. By keeping data resident in Australia and operating under local control, it helps organisations meet key requirements under the SOCI Act, APRA CPS 234, the ASD Essential Eight, and related frameworks, while reducing operational and data sovereignty risk. "Australian organisations face the same AI-accelerated threat landscape as the rest of the world, but they rightly demand that the tools they use to defend themselves meet the highest standards of data residency and national control," said Gareth Cox, Vice President of Sales, Asia Pacific and Japan, Horizon3. "With the Sydney Sovereign Instance, customers can now run the World's Best AI Hacker continuously and safely, knowing their data never leaves Australia. This enables them to move beyond assumptions and continuously prove which exposures actually matter - and that remediation works." "Data sovereignty is no longer a compliance checkbox, it is a strategic requirement for any platform trusted with critical infrastructure and national security workloads," said Snehal Antani, Co-Founder and CEO of Horizon3. "As AI-powered attacks accelerate, countries will only allow continuous, autonomous security validation on their most sensitive networks if they know the data remains under their control and is accessed by cleared nationals. The Sydney Sovereign Instance is the first step in making NodeZero available as a true national-scale capability for Australia." The Sydney instance complements Horizon3's existing points of presence in the United States and Germany and marks the company's first Sovereign Instance in Asia Pacific. It follows Horizon3's recent US$250 million Series E at a valuation exceeding US$2 billion, which is funding accelerated international expansion, including deeper investment across Australia, New Zealand, and the wider Asia-Pacific region. Horizon3's NodeZero platform has already executed more than 310,000 production-safe autonomous security tests for more than 7,500 organisations worldwide, including multinational banks, major healthcare networks, four Fortune 10 enterprises, and national security agencies. The company is FedRAMP High authorised and helps customers meet demanding regulatory regimes globally. With the Sydney Sovereign Instance now generally available, Australian organisations can continuously find, prioritise, and verify the risks that actually matter, while keeping their most sensitive security data under Australian sovereign control.

Horizon3.ai
Aug 25th, 2026
Horizon3 names Chad Keefer Vice President of Federal Sales.

Horizon3 names Chad Keefer Vice President of Federal Sales. August 25, 2026 Former Marine Corps special operator and 24-year federal go-to-market leader will build Horizon3's federal sales organization and drive adoption of continuous security validation across civilian, defense and national security agencies. SAN FRANCISCO - August 25, 2026 - Horizon3, the AI-native proactive security leader, today announced the appointment of Chad Keefer as Vice President of Federal Sales. In this role, Keefer will lead Horizon3's go-to-market strategy across the federal civilian, defense and intelligence community markets, building out the sales organization, processes and partner relationships needed to scale adoption of the company's NodeZero autonomous pentesting platform across government. A 24-year veteran of federal go-to-market leadership, Keefer joins Horizon3 after most recently serving as Head of U.S. Federal at Infoblox. He previously held Vice President roles at Appian, leading both the company's Federal Civilian and Enterprise Financial Markets go-to-market strategies, and spent a decade at Forescout Technologies, rising from Sales Director to Vice President of the Federal Civilian Business Unit and ultimately leading multi-segment sales across Public Sector, Financial Services, Healthcare, Energy and Strategic Enterprise accounts. Earlier in his career, he led federal security sales teams at IBM (BigFix) and ArcSight, spanning both Department of Defense and civilian agency programs. Over the past 15 years, Keefer has built and led federal go-to-market teams through reorganizations, technology transformations and ground-up builds. Before his technology career, Keefer served as a Platoon Leader in the United States Marine Corps, where he led small-unit teams in high-stakes environments - experience he credits with shaping his approach to discipline, mission focus and team-building. "Chad has spent nearly a quarter century building and scaling federal go-to-market organizations, and he brings the operator's instinct to match our technology to the government's mission," said Matt Hartley, Chief Revenue Officer at Horizon3. "As agencies move to operationalize continuous monitoring and cyber readiness mandates, Chad will help us prove those investments actually hold up against a real attacker. He's exactly the leader we need to scale Horizon3's federal business and build the team to support it." "Government agencies have invested significantly in cyber readiness," said Chad Keefer, Vice President of Federal Sales at Horizon3. "Our job is to prove those investments work against a real attacker. Can they get through the controls? Can they move through the environment? Can they reach something that matters? And when we fix the problem, can we prove the attack path is actually gone? I want to establish continuous security validation as an operational standard across civilian, defense and national security environments, and make Horizon3 a trusted part of how those organizations protect their missions. Ultimately, success means changing the standard from 'we believe our controls are working' to 'we can prove they're working.'" Keefer's appointment builds on Horizon3's continued momentum in the federal market, where the company already counts the NSA, CISA and other federal agencies among its more than 7,000 customers worldwide. As Horizon3 stands up a mature, full-scale federal go-to-market organization, Keefer will lead the buildout of dedicated sales, technical and marketing resources to support civilian, defense and intelligence community customers. About Horizon3. Horizon3, the AI-Native Proactive Security Company behind NodeZero(R), shifts the advantage from attackers to defenders by giving organizations the power to fight AI with AI. NodeZero, the World's Best AI Hacker(TM), autonomously tests defenses at machine speed, safely uncovers and prioritizes exploitable attack paths, instantly verifies fixes, and drives a continuous hack, fix, verify loop. More than 7,000 organizations, including global defense agencies, Fortune 10 enterprises, multinational banks, and major healthcare providers, trust Horizon3 for security they can prove. Horizon3 was recently named the Fastest Growing Cybersecurity Company in North America by the Deloitte Technology Fast 500 and named one of the Most Innovative companies by Fast Company in 2026. Follow Horizon3 on LinkedIn and X.

TechDay
Aug 24th, 2026
Horizon3 & Deloitte forge cyber resilience alliance.

Horizon3 & Deloitte forge cyber resilience alliance. Tue, 25th Aug 2026 (Today) Horizon3 has formed an alliance with Deloitte in Australia focused on cyber resilience for organisations across Australia and New Zealand. The partnership combines Horizon3's NodeZero security platform with Deloitte's cyber advisory, transformation, resilience and managed services. Together, they will work with enterprises seeking more frequent testing of cyber defences and clearer evidence of which weaknesses attackers can exploit. Boards, regulators, customers and insurers are putting more pressure on companies to show they can withstand cyber incidents. At the same time, many organisations still rely on periodic assessments and fragmented security tools, leaving gaps between tests. Horizon3 and Deloitte said their approach is designed to help clients move beyond theoretical risk scoring and broad lists of findings. Instead, it focuses on identifying exploitable attack paths, ranking the most significant exposures and checking whether remediation has reduced risk. NodeZero is designed to validate attack paths across internal systems, internet-facing assets, cloud environments, identities, web applications and hybrid estates. Deloitte will add strategic and operational support to help clients interpret findings and act on them across security and IT teams. Shift in testing The alliance reflects a broader shift in cyber security from point-in-time reviews to continuous validation. Companies face growing scrutiny not just to report risks, but to show that controls work in practice. The need has become more urgent as security teams contend with faster-moving threats, vulnerabilities linked to artificial intelligence tools and increasingly automated attack methods. The companies said their work together is intended to help executive teams understand cyber exposure in business terms rather than through technical scores alone. For Deloitte, the arrangement adds an attacker-perspective testing platform to its cyber consulting and managed services work in Australia. For Horizon3, it opens access to a large advisory and delivery network in a market where companies are seeking more measurable ways to assess resilience. Gareth Cox, Vice President, Sales, APJ, Horizon3, said the alliance responds to demand for clearer evidence of risk. "Organisations across Australia and New Zealand do not need more cyber noise. They need proof," said Gareth Cox, Vice President, Sales, APJ, Horizon3. "By combining Deloitte's strategic advisory and delivery strength with Horizon3's ability to safely discover exposure, prioritise based on impact and remediate with clarity, we can help executive leaders make faster, better-informed security decisions, reduce risk and demonstrate measurable resilience over time." Client focus The two companies will target organisations seeking stronger assurance over the effectiveness of cyber controls across broad, complex technology estates. That includes businesses running a mix of on-premise systems, cloud services and externally exposed applications. The alliance is also intended to help security and IT teams improve prioritisation. Rather than treating all findings as equal, the goal is to highlight the exposures that create material business risk and verify that fixes have worked. Liz Douglass, Partner and Cyber Lead, Deloitte Australia, said the need for continuous evidence is growing as the threat environment changes. "In an increasingly dynamic threat environment, organisations need more than periodic assurance exercises. They need continuous, evidence-based insight into where they are exposed and how to strengthen resilience. Our partnership with Horizon3 expands our ability to help clients translate attacker-perspective validation into practical action across strategy, operations and transformation," said Liz Douglass, Partner and Cyber Lead, Deloitte Australia. Horizon3 said more than 7,000 organisations use its technology, including defence agencies, large enterprises, banks and healthcare providers. The company positions NodeZero as a platform that can test defences, uncover exploitable paths and verify fixes in an ongoing cycle. Cox said the relationship pairs Horizon3's exposure validation with Deloitte's ability to help clients turn that evidence into action. "Horizon3 provides evidence of real exposure through attacker-perspective validation, and Deloitte helps clients translate that evidence into action, operating change, and sustained cyber resilience," said Cox. "That is what makes this alliance meaningful for executive leaders."

Rescana
Aug 23rd, 2026
Active exploitation alert: critical GitLab CVE-2026-19478 code injection vulnerability targets unpatched instances.

Active exploitation alert: critical GitLab CVE-2026-19478 code injection vulnerability targets unpatched instances. Executive summary. CVE-2026-19478 is a critical code injection vulnerability impacting GitLab Community Edition (CE) and Enterprise Edition (EE). Publicly disclosed in August 2026, this vulnerability has been weaponized by threat actors within days, resulting in active exploitation campaigns targeting unpatched, internet-facing GitLab instances. The flaw, which scores 9.4 on the CVSS v3.1 scale, enables unauthenticated attackers to manipulate, delete, or forge records in public projects via a maliciously crafted GraphQL directive. The rapid exploitation underscores the urgent need for immediate remediation and highlights the evolving threat landscape where adversaries leverage newly disclosed vulnerabilities at unprecedented speed. Threat actor profile. Current intelligence indicates that exploitation of CVE-2026-19478 is being conducted by a mix of opportunistic cybercriminals and potentially more sophisticated actors. The initial wave of attacks has been characterized by broad, automated scanning and exploitation, as observed by security research organizations such as watchTowr and Horizon3.ai. These actors are leveraging public proof-of-concept (PoC) code and automated tools to identify and compromise vulnerable GitLab instances. While no specific advanced persistent threat (APT) group attribution has been made, the scale and automation of attacks suggest involvement from both financially motivated cybercriminals and actors seeking to disrupt software supply chains. The use of AI-assisted reconnaissance and exploitation tools has further accelerated the weaponization timeline, reducing the window between disclosure and exploitation to mere hours. Technical analysis of malware/ttps. The core of CVE-2026-19478 lies in improper input validation within the GitLab GraphQL API endpoint (/api/graphql). Attackers exploit this by injecting a specially crafted GraphQL directive, such as @gl_introduced, which bypasses authentication and authorization controls. This enables remote, unauthenticated manipulation of project metadata and repository contents. Upon successful exploitation, attackers can perform destructive actions including deletion of public projects, removal of entire repositories, and the forging of merge records - making it appear as though code changes or security fixes have been applied when they have not. Additionally, attackers can ban legitimate project maintainers, effectively locking out authorized users and facilitating further malicious activity. Technical indicators of compromise (IOCs) include anomalous requests to the /api/graphql endpoint containing the @gl_introduced string, unexpected project deletions or modifications, and the presence of merge records that do not correspond to actual code changes. Attackers are leveraging automated scripts and exploitation frameworks, some of which have been publicly released by security researchers and subsequently weaponized by malicious actors. The exploitation chain does not require any user interaction or credentials, making it highly attractive for mass exploitation. The attack vector is purely network-based, and the vulnerability affects all unpatched versions of GitLab CE/EE prior to 18.11.11, 19.0.8, 19.1.6, and 19.2.4. Exploitation in the wild. Within hours of public disclosure, exploitation of CVE-2026-19478 was observed in the wild. watchTowr reported successful exploitation attempts against their honeypot infrastructure almost immediately after the vulnerability details were published. Horizon3.ai released a rapid response test for their NodeZero platform, confirming that active exploitation was underway. Security professionals have reported widespread scanning and exploitation attempts on platforms such as Reddit and LinkedIn, with attackers targeting internet-facing GitLab instances globally. Indicators of compromise include web server logs with requests to /api/graphql containing the @gl_introduced directive, sudden and unexplained project deletions, and the appearance of forged merge records. The exploitation activity is not limited to a specific sector or geography; rather, it is opportunistic and automated, targeting any vulnerable GitLab instance accessible over the internet. The rapid proliferation of PoC code and automated exploitation tools has contributed to the scale and speed of these attacks. Victimology and targeting. Victims of CVE-2026-19478 exploitation are organizations running self-managed, unpatched versions of GitLab CE or EE. The attacks have been indiscriminate, affecting a wide range of sectors including technology, finance, education, and government. Any organization with a public-facing GitLab instance that has not applied the latest security patches is at risk. The primary targets are public projects and repositories, as the vulnerability allows unauthenticated access and manipulation. However, the potential for lateral movement and further compromise exists if attackers are able to escalate privileges or pivot within the victim's environment. The impact includes loss of intellectual property, disruption of software development workflows, and potential supply chain compromise if malicious code is injected into widely used open-source projects. Mitigation and countermeasures. Immediate action is required to mitigate the risk posed by CVE-2026-19478. Organizations should upgrade their GitLab CE/EE instances to the latest patched versions: 18.11.11, 19.0.8, 19.1.6, or 19.2.4. GitLab.com and GitLab Dedicated are already running patched versions and are not affected. If immediate patching is not feasible, organizations should restrict unauthenticated access to the /api/graphql endpoint, either by implementing network-level access controls or by temporarily disabling public repository access. Monitoring and reviewing web server logs for requests containing the @gl_introduced directive and other anomalous activity on the GraphQL endpoint is critical for early detection of exploitation attempts. Incident response teams should audit all recent project deletions, modifications, and merge records to identify potential unauthorized actions. Restoring from known-good backups and resetting credentials for affected maintainers may be necessary in the event of compromise. Long-term, organizations should implement a robust vulnerability management program, ensure timely application of security patches, and leverage threat intelligence feeds to stay informed of emerging threats. Integrating runtime application self-protection (RASP) and web application firewalls (WAFs) can provide additional layers of defense against similar exploitation techniques. References. The following sources provide additional technical details and ongoing updates regarding CVE-2026-19478: About Rescana. Rescana is a leader in third-party risk management (TPRM) and cyber threat intelligence. Its platform empowers organizations to proactively identify, assess, and mitigate cyber risks across their digital supply chain. By leveraging advanced analytics and real-time threat intelligence, Rescana enables security teams to make informed decisions and strengthen their overall security posture. For more information about its solutions or to discuss your organization's cybersecurity needs, Rescana is happy to answer questions at [email protected].

Brainrot Creations
Aug 8th, 2026
Hadrian lands $1.4B to mass-produce submarine parts, Whatnot hits $20B, and the week mega-rounds became a defense and hard-tech arms race.

Hadrian lands $1.4B to mass-produce submarine parts, Whatnot hits $20B, and the week mega-rounds became a defense and hard-tech arms race. Hadrian raises $1.37B to automate defense manufacturing, Whatnot doubles to $20B valuation, and August's mega-rounds show funding flowing to factories, nuclear, and batteries - not just chatbots. Published August 8, 2026 This week's funding tracker reads like a pivot away from the AI model wars and straight into the physical world. Hadrian raised $1.37 billion in a Series D at an $8 billion valuation to build automated factories that mass-produce defense components - think submarine parts, not software subscriptions. It is one of the largest rounds in recent memory that isn't tied to training clusters or model APIs. The thesis is simple: the U.S. needs to manufacture critical defense hardware faster, and Hadrian's betting that robotics and automation can scale production without the lead times that currently plague DoD suppliers. The round signals that venture dollars are moving downstream from pure software into the capital-intensive, regulation-heavy world of making things. When a defense-tech startup commands an $8B valuation in 2026, it means LPs are pricing in geopolitical risk and reshoring demand as core investment drivers. Nuclear, batteries, and energy infrastructure take half the mega-round list. Valar Atomics closed $1 billion in Series B at a $6 billion valuation, making it the second nuclear startup to cross ten-figure funding this quarter. The company had already signed a development deal with Nvidia in June, which probably helped close the round. When GPU vendors are co-investing in reactor startups, it is a safe bet that data center power consumption is the real product roadmap. Base Power secured $1 billion in Series D at a $13 billion post-money valuation for residential battery storage. That is a higher valuation than most enterprise SaaS companies will ever see, and it reflects the fact that distributed energy storage is now a VC category with exit multiples that rival software. Residential batteries solve grid reliability, peak shaving, and EV charging - all problems that scale with housing density and vehicle electrification. The funding proves that hard-tech infrastructure can command software-like valuations when the TAM is measured in every house with a garage. Whatnot doubles its valuation in ten months by staying weird. Whatnot raised $545 million in Series G, nearly doubling its valuation from $11.5 billion in October 2025 to around $20 billion. The round was led by ICONIQ, Lightspeed, and Avra. For context, Whatnot is a live-streaming commerce app where people auction Pokémon cards, sneakers, and vintage toys in real time. It is not an AI play, not a vertical SaaS, not a fintech rails company - it is a niche social commerce platform that found product-market fit by letting obsessive collectors haggle over webcams. The valuation jump shows that consumer apps can still 10x in a downturn if they own a category no one else is serving. Whatnot's moat is community and format: live video auctions create urgency and parasocial trust in a way that static product pages cannot. When a live-commerce app is worth $20B, it means investors believe the format will expand beyond collectibles into broader retail. If you are building a consumer product in 2026, the takeaway is clear: own a behavior, not a feature set. Cybersecurity and stablecoins get funding, but at smaller checks. Horizon3 announced a $250 million Series E at a more than $2 billion valuation, led by NightDragon and NEA. That was roughly triple its Series D valuation from last year. The company does pentesting and attack surface management - basically automated red-teaming for enterprises that do not want to hire consultants every quarter. Yellow Card raised $40 million for stablecoin payments infrastructure, with backers including SC Ventures by Standard Chartered, Sony Innovation Fund, Polychain Capital, and Blockchain Capital. Stablecoin rails are now being priced as fintech plumbing - boring, regulated, but necessary if cross-border payments are going to route through USDC instead of correspondent banks. When a traditional bank like Standard Chartered is co-investing, it means the infrastructure layer is no longer speculative. Khosla led eight deals in July; Y Combinator led in volume. Khosla Ventures led eight deals of $5 million or more in July, including a $300 million Series A for Oratomic and a $120 million Series C for Norm AI. That makes Khosla the most active lead investor by reported dollars in the month. Coatue backed a $10 billion financing for Blue Origin, which probably skews the leaderboard but also shows that space infrastructure is now a VC asset class. Nvidia backed a $5 billion financing for Safe Superintelligence, continuing its pattern of writing massive checks into AI labs and anything adjacent to GPU demand. Y Combinator was the most prolific investor by deal count, which tracks with its batch model - high volume, smaller checks, spray-and-pray at the seed stage. The funding landscape in August 2026 is split: billion-dollar rounds are clustering in defense, energy, and physical infrastructure, while software and fintech are raising smaller growth rounds. If you are pitching a deck right now, the meta-strategy is obvious - either go after a hard problem that requires factories and reactors, or own a niche consumer behavior no one else is monetizing. The middle is getting squeezed.