>samit_hota
Back to security news

Security News · SN-2026-397

INFORMATIONALRESOLVED

Mindgard Secures $30M Series A to Expand Automated AI Red-Teaming Platform

Affected: Enterprise AI Systems · Autonomous AI Agents · LLM Integrations

Samit Hota·
#news#vulnerability-disclosure#mindgard

London and Boston-headquartered cybersecurity startup Mindgard has closed a $30 million Series A funding round, bringing its total capital raised to nearly $42 million. Led by Album VC with participation from Karma Ventures and existing backers including .406 Ventures, Atlantic Bridge, IQ Capital, and Lakestar, the investment will fund the expansion of Mindgard’s product, engineering, sales, and marketing teams to meet growing enterprise demand for automated AI security solutions.

Spun out of Lancaster University in 2022, Mindgard has focused its engineering efforts on building an automated AI security and red-teaming platform designed to test, assess, and defend artificial intelligence models, autonomous agents, and AI-enabled applications. The funding announcement comes as enterprise adoption of Generative AI (GenAI) and agentic workflows reaches a tipping point, exposing corporate networks to attack vectors that conventional application security tools were never designed to handle.

The Expanding AI Attack Surface and Red-Teaming Needs

Traditional cybersecurity solutions rely heavily on deterministic rules, static code analysis (SAST), dynamic application security testing (DAST), and signature-based detection. While these frameworks excel at identifying classic software flaws like SQL injection, buffer overflows, or cross-site scripting, they struggle when applied to probabilistic machine learning systems and Large Language Models (LLMs).

Mindgard’s platform addresses what the company terms the “psycho-technical attack surface”—the unique threat surface where natural language processing, context windows, model weights, and application logic intersect. As enterprises move beyond standalone internal chatbots to complex agentic workflows that grant LLMs direct access to corporate databases, API connectors, document repositories, and system terminals, the operational risk profile escalates rapidly.

Offensive AI security testing requires continuous probing for vulnerabilities across several unique threat vectors:

  • Direct and Indirect Prompt Injection: Attackers craft malicious prompts directly or embed hidden instructions inside untrusted external data (such as web pages, PDF uploads, or support tickets) that an AI agent parses, coercing the underlying LLM into bypassing safety policies or executing unauthorized actions.
  • Insecure Output Handling: Foundation models generating dynamic code, database queries, or system shell commands that downstream software executes without proper validation or sanitization, creating pathways for remote code execution (RCE) or data exfiltration.
  • Agentic Privilege Escalation: Manipulating an AI agent’s tool-use capabilities—such as automated script runners, file readers, or enterprise API extensions—to pivot across internal network segments or perform actions beyond the authorization level of the interacting user.
  • Model Poisoning and Information Extraction: Exploiting fine-tuning datasets, extracting proprietary system prompts, or forcing models to leak sensitive context stored within context windows or training weights.

Mindgard operates as an automated offensive red-teamer, simulating complex multi-step attacks against enterprise AI components during development and in live environments. In addition to identifying vulnerabilities prior to deployment, the platform delivers runtime protection designed to analyze inputs and model responses in real time, stopping malicious payloads before they result in system compromise.

Real-World Impact: Flaws in Cursor IDE, ChatGPT, and Google Antigravity

The necessity of automated offensive testing across AI infrastructure is illustrated by Mindgard’s vulnerability research team, which has uncovered over 150 security flaws across popular enterprise and developer AI platforms.

Among these discoveries was a zero-day code execution vulnerability in Cursor IDE, a widely adopted AI-powered code editor built on VS Code. In AI-assisted development platforms, autonomous agents continuously index repository context, generate code edits, and execute commands within terminal environments. By manipulating the context parsed by Cursor’s AI agent—such as inserting hidden prompt payloads into a repository file or external dependency—an attacker could trick the developer’s local AI assistant into executing arbitrary code on their local workstation, turning a developer tool into an initial access vector for corporate network penetration.

Mindgard researchers also identified notable security defects in consumer and enterprise foundation model ecosystems, including Google Antigravity and OpenAI’s ChatGPT. These defects involved prompt boundary breakouts, alignment jailbreaks, and function-calling exploits where fine-tuned models were manipulated into issuing privileged API requests.

Enterprise Adoption and Sector Focus

Mindgard plans to leverage its fresh funding to accelerate deployments across highly regulated and technology-dependent sectors, including financial services, digital services, healthcare, pharmaceuticals, gaming, and semiconductor manufacturing.

As organizations across these industries integrate foundation models into core operations—ranging from automated financial decisioning and drug discovery pipelines to customer support agents and automated software development—security leadership faces growing scrutiny from regulatory bodies, compliance auditors, and corporate boards to prove robust AI governance and risk management.

By combining continuous automated red-teaming with runtime defense, platforms like Mindgard aim to operationalize specialized offensive AI security expertise. Rather than relying on point-in-time manual penetration tests—which quickly become obsolete as prompt templates are adjusted, models are fine-tuned, or new agent tools are connected—automated security platforms provide ongoing visibility into the security posture of an organization’s evolving AI landscape.

Guidance for Enterprise AI Security Teams

For security teams tasked with securing internal LLM integrations, fine-tuned models, and autonomous AI agent workflows, traditional application security threat models must be updated:

  • Audit AI Agent Tooling: Map every internal application where an LLM or AI agent has execution capabilities over local shells, file systems, databases, or third-party APIs, enforcing strict least-privilege boundaries.
  • Implement Input and Output Guardrails: Deploy dedicated AI guardrail and semantic inspection layers to scan prompt inputs for injection techniques and validate structured LLM outputs before passing data to backend application logic.
  • Integrate Continuous Automated Probing: Incorporate automated AI vulnerability testing directly into development pipelines to continuously test custom system prompts, context windows, and tool integrations prior to production deployment.

Found something similar in your stack?

Let's find out before it becomes an incident.

Book an advisory call