Checkpoint Acquires Lakera
Checkpoint announced its acquisition of Lakera, a Swiss-based AI security startup, to deliver comprehensive protection across the AI lifecycle from development to deployment. Lakera’s platform is designed to safeguard AI models against emerging threats like prompt injection, data poisoning, and model exfiltration, making it a strategic addition to Checkpoint’s broader vision of end-to-end enterprise security.
This move reflects the growing demand for robust AI security solutions as organizations accelerate adoption of generative and predictive AI technologies.
Rain Capital is thrilled to be an early investor in Lakera and saw its journey from the game of Gandalf to a robust AI security platform.
For many CISOs, this acquisition signals a shift toward integrating AI-specific defenses into traditional security stacks, addressing risks that legacy tools often overlook. As AI becomes central to enterprise computing, the urgency and opportunity of building trust and resilience into the next generation of enterprise AI is paramount.
Congratulations to David Haber, Mateo Rohas-Carulla, and the rest of the Lakera team!
AI-Powered Successor to Cobalt Strike Raises Alarm
🧠 A newly discovered offensive AI tool automates exploit generation and lowers the barrier to entry for attackers
Straiker, one of Rain’s portfolio companies, has uncovered a powerful new AI-driven penetration testing tool called Villager, described as the “Cobalt Strike successor,” which has already been downloaded nearly 11,000 times. Developed by a China-based entity, Cyberspike, Villager integrates a suite of tools including Kali Linux, DeepSeek model, and a database of over 4,000 AI prompts to automate exploit generation and attack workflows. Its ease of use and automation capabilities make it accessible to attackers with minimal technical expertise, raising serious concerns about its potential for widespread abuse.
Straiker’s security researchers, Dan Regalado and Amanda Rousseau, uncovered Villager on Python Package Index. They discovered that Cyberspike repackaged established hacktools into a turnkey framework designed for penetration testing and probably malicious operations.”
Straiker is an innovative AI security platform that operates by detecting malicious prompt behavior and unauthorized model interactions in real time. Its deep visibility into AI workflows and ability to enforce trust boundaries across model inputs and outputs make it an essential layer of defense in today’s evolving threat landscape.
Dr. Wang To Speak At TechCrunch Disrupt
On October 29, Dr. Chenxi Wang will take the stage at TechCrunch Disrupt 2025 in San Francisco on the panel: “Being Heard in the Age of AI”
In a world where AI systems increasingly filter, generate, and amplify information, how do people, companies, and even entire industries ensure their voices are heard? This panel brings together leaders in AI, cybersecurity, and venture to explore what it means to stand out in a landscape dominated by algorithms and automation. From trust and authenticity to brand differentiation and governance, this panel will discuss the new rules of influence, the risks of being misrepresented by machines, and the strategies innovators are using to shape their narratives in the age of AI.
Check out the techCrunch Disrupt Agenda.
Madrona 2025 CIO Summit: Driving the Future of Secure Cloud Innovation
David Cross will share insights on aligning trust, resilience, and innovation in cloud-native enterprises.
On Wednesday, October 22nd, David Cross will be speaking at the Madrona 2025 CIO Summit, a premier gathering of technology leaders and innovators. His session will focus on the evolving role of security leadership in modern enterprises, offering insights into how CISOs can align trust, resilience, and innovation in increasingly distributed environments. With deep experience in enterprise security and cloud transformation, David brings a strategic perspective that’s highly relevant to today’s CIOs and CISOs navigating complex digital landscapes.
For CIOs and members of the cybersecurity community, David’s talk will highlight the growing convergence between executive leadership and security innovation. As enterprises prioritize secure cloud migration and AI adoption, the summit provides a valuable lens into the technologies and partnerships shaping the next wave of enterprise infrastructure. Attendees can expect actionable takeaways on building scalable, secure systems and identifying startups that are solving tomorrow’s security challenges today.
CISO Series Podcast Unpacks Vendor Outreach Failures
David Cross joins hosts David Spark and Mike Johnson to explore how CISOs can foster trust, composure, and meaningful engagement in a noisy cybersecurity landscape.
In the latest episode of the CISO Series Podcast, titled “No Email Has Ever Found You Well,” the speakers dive into the broken dynamics of vendor outreach in cybersecurity. CISOs are inundated with generic, impersonal emails that fail to reflect their actual needs or environments highlighting a systemic issue in how vendors approach engagement. The discussion emphasizes the importance of personalization, warm introductions, and understanding the real decision-makers within security organizations, rather than defaulting to volume-based tactics.
For many CISOs, the episode offers a candid look at how trust and relevance must be rebuilt in the vendor-CISO relationship. It also explores how emotional intelligence and composure especially during high-pressure incidents are becoming essential leadership traits. With insights on tabletop exercises, veteran hiring, and strategic humor, the conversation provides practical guidance for building resilient teams and fostering meaningful industry connections.






