Cantina Raises $8 Million to Let AI Agents Hunt and Fix Security Flaws Automatically

A New York startup wants to replace slow, manual vulnerability management with software agents that find problems, investigate them, and patch them without waiting for a human to file a ticket.

ThreatVectr NewsdeskUpdated · Editor: Lee Brown· 3 min read
Photoreal news-editorial style, 16:9 framing, full-frame edge-to-edge composition
Share

Key points

  • Cantina raised $8 million in a new funding round led by Framework Ventures, bringing its total funding to $16.5 million.
  • The startup emerged from stealth mode today after operating quietly while building its product.
  • Cantina's platform uses autonomous AI agents, meaning software programs that act independently, to find and fix security weaknesses across a company's systems.
  • Customers can share agents they've built with other Cantina users, creating a community library of ready-made security tools.
  • The platform maintains a live digital twin, a constantly updated virtual map of a company's entire technology environment, to track risks in real time.

A New York cybersecurity startup called Cantina stepped out of stealth today, revealing itself publicly for the first time after raising money and building its product behind closed doors.

The company announced $8 million in new investment, led by venture firm Framework Ventures, bringing its total raised to $16.5 million. We've covered six startup funding rounds in the last 90 days, but this one lands differently: the problem Cantina is selling against, alert overload, was already broken before anyone bolted AI onto it.

What does Cantina actually do?

Cantina sells a platform that automates vulnerability management, the ongoing process of finding security weaknesses in a company's systems before criminals do. Software agents scan across cloud servers, identity systems (the tools controlling who can log in to what), code repositories, and databases. The platform maps what it finds, applies business context about each system's importance, and surfaces a ranked list of what needs fixing first.

This is the part of security operations that most teams quietly drown in. Alerts pile up faster than people can review them. The failure mode isn't that threats go undetected; it's that they go uninvestigated because nobody had four hours to dig in.

Cantina claims its platform learns from each investigation, getting sharper over time. It also verifies that a fix was actually applied correctly. That's the step most organisations skip and then regret at postmortem time.

What is the community angle?

Organisations using the platform can share agents they've built with other Cantina customers, and pick up agents others have published. One company solves a tricky detection problem, packages the solution as an agent, and the whole user base can deploy it immediately.

Cantina co-founder and CEO Hari Mulackal framed the problem bluntly, telling SecurityWeek: "Attackers can identify vulnerabilities, understand systems, and build exploits faster than ever before. Security teams cannot keep responding with workflows built for a pre-AI world."

He's not wrong. The tooling gap between attackers who've adopted AI and defenders still running ticket-driven processes is real and widening.

Should ordinary people care about this?

Directly, no. Cantina sells to businesses. But the companies protecting your medical records or bank accounts are exactly who this product targets. Better automated vulnerability management means fewer of the misconfigurations and unpatched flaws that end up as breach headlines six months later.

If Cantina's agents ever miss something big, the postmortem will say the platform ranked it low priority. Prioritisation logic is now your biggest single point of failure, and no amount of agent-sharing fixes a bad scoring model.

Operational takeaway: Automation surfaces more than humans can review. Your prioritisation logic is now your biggest single point of failure.

© 2026 Threat Vectr