Mitiga’s cover photo
Mitiga

Mitiga

Computer and Network Security

New York, New York 13,578 followers

EDR protects the endpoint. Mitiga protects everything else. Secure cloud, SaaS, identity, third-party services, and AI.

About us

EDR protects Endpoints. Mitiga protects Everything Else. Mitiga provides - The AI Security Layer. Enabling & Securing the Agentic World. We proactively detect and stop attacks in real-time before damage is done. Our AI-native platform gives SecOps teams panoramic visibility across your entire cloud—all SaaS, identity, and AI ecosystems—preemptively decoding and preventing attacks. Instead of scrambling after an incident, you gain command: shutting down threats in real time, protecting the business, and reporting clear facts to leadership. With Mitiga, customers significantly reduce risk, and get better security outcomes via our contextualized data layer referencing up to 3 years of pre-processed, normalized, contextual data that drives 90 pct faster and higher fidelity detections - feeding your Agentic SOC workflows, SOAR, SIEM, or Case Management to drive exceptional SOC Efficiencies. Our World Class Research team in Israel drives highly tailored threat hunts specific to your industry. Mitiga is used by dozens of well-known brands to reduce risk, strengthen their SecOps, and improve business resilience.

Website
http://www.mitiga.io
Industry
Computer and Network Security
Company size
51-200 employees
Headquarters
New York, New York
Type
Privately Held
Founded
2020
Specialties
Cybersecurity, Cloud Security, SaaS Security, Cloud Detection & Response, Incident Response, AI Security, and Agentic Runtime Security

Products

Locations

Employees at Mitiga

Updates

  • View organization page for Mitiga

    13,578 followers

    Attackers use AI for scale and speed, and Charlie Thomas doesn't see the defenders opting to slow down. Head over to Scrut Automation at the link below for his full conversation with Nicholas M. on the limits of posture-based prevention.

    View organization page for Scrut Automation

    80,523 followers

    Charlie Thomas (CEO of Mitiga) has not met the AI-resistant CISO everyone keeps talking about. What he sees instead are security leaders trying to support adoption without letting risk, compliance, and visibility become afterthoughts. He and Nicholas M. get into that tension, along with agent inventories, model access, SaaS blind spots, incident response, and the limits of prevention. 🎧 Listen to the full episode on your favorite platform: https://lnkd.in/djNphKJ5 #Cybersecurity #AISecurity #RiskGrustlers

  • View organization page for Mitiga

    13,578 followers

    How would you score? We modeled a Hugging Face-style agentic attack and ran it against our own platform. Then we scored the platform on the 4 things that decide whether you stop the attack in its tracks or not. In that intrusion, an autonomous agent ran for four and a half days on stolen machine identities. It tried roughly 17,000 actions, and most failed. The chain that worked looked routine in every log it touched, and Hugging Face's tooling produced an alert below the level that pages on-call. Join Ariel Parnes, Brandon Allen, and Brian Contos as they walk the attack step by step and go through the score. They also show which of your existing containment controls the response row runs through. Hit the event below and join us for the event or the video on demand.

  • View organization page for Mitiga

    13,578 followers

    Would your stack have caught the Hugging Face-style agentic attack? We asked that about our own. So we rebuilt the intrusion as a model, ran it against our platform, and scored ourselves on the four things that decide whether anyone stops an agentic attack: 1. Data arrives when it's needed. 2. Something fires on the identity that did the work. 3. The signals combine into a single incident within a relevant time window. 4. Something takes action. The agent didn't use malware or a human account, and nothing touched an endpoint, so EDR had nothing to see. It went through Kubernetes, AWS, the internal network, and source control on a service account, leaving a few ordinary-looking lines in four separate logs. The intrusion was the crossing, and anything that watches one plane had no chance to see this chain forming. Mitiga correlates all of those signals into one incident timeline. Everyone is below four out of four today, us included, and anyone who tells you otherwise is selling. The scorecard is below, and we've left you a column for your stack. Let them come. → https://loom.ly/1c7t9zg via Ariel Parnes & Brandon Allen

    • No alternative text description for this image
  • View organization page for Mitiga

    13,578 followers

    "This is not something that an analyst put together." Steve Schohn opens Mitiga's incident view for Salesloft Drift activity on the new Mitiga Minutes. This timeline assembled itself. Here's how it goes: The Drift connected-app token authenticates to Salesforce from a new source. The app is flagged as a non-human identity on a compromised account. AI Triage tries to prove the activity is legitimate before calling it malicious. It finds no sign-in correlation and no interactive logins from the IP. The only hypothesis left is compromise of the Drift application itself. Then the attacker pivots from Salesforce into Gong and exports call recordings and transcripts in bulk, all in one session. Brian Contos: "Getting access to an organization's Gong is like the olden days, getting access to the My Documents folder. It's where a lot of sensitive information is, and people don't think to protect it." Watch the full 9 minutes of Mitiga Minutes below.

  • View organization page for Mitiga

    13,578 followers

    Sam Altman and Dario Amodei are right that the world needs common standards for testing AI, assessing risk and reporting failures. But they missed something. https://loom.ly/aPF-4LY Ariel Parnes tells Techstrong.ai that model-level testing only tells you so much once AI agents have access to cloud infrastructure, SaaS, identity, and other agents. "The real discussion point is whether the organization running the agent can see and reconstruct what it actually did." Recently, Parnes, Mitiga co-founder and COO, has called for frontier labs to expose the J-space, the feed that shows what AI agents "think" before they act. https://loom.ly/qXpFCrg Detection for AI agents runs on two feeds today: (1) what the agent says and (2) what it does. The J-space is a third, and it shows what the agent thinks before it acts. One of those feeds is starting to fail, and only Anthropic can see the third. That should change. Read Parnes' update to his call for action after a summer of attacks and research coming to light: https://loom.ly/o0IFanU

    • No alternative text description for this image
  • View organization page for Mitiga

    13,578 followers

    Sneha Regmi runs security operations and resilience engineering at Affirm. Much of that work is still manual, so she wants agents taking on more of it. There are conditions, though. If an agent says a laptop or an account is compromised, she wants to know what telemetry it used, what evidence it used to make that call, and whether she can audit the answer herself. "Those conditions should be built into your workflows so that by the time the AI has made that recommendation and you go look at it, you already know how it arrived there." Sneha's full three-minute video with Brian Contos shows where she puts the biggest risk today and what she wants from the people building this kind of technology. Watch/read: https://loom.ly/RwbbDHE On the channel: https://loom.ly/z9rdBYA Other expert interviews: https://loom.ly/YQi4iLo

  • Mitiga reposted this

    Skill (n.): what talented people have. Skill (n., 2026): the next supply-chain attack. Join Elli Shlomo and me at 404 Community for a live demo of Skills being turned against you, by your own agent. Real examples found in the wild, how they work, and how to catch them with Skillgate. Mark(down) your calendars. #networking #communityrocks #aisecurity #404community

    "After the holidays" is around the corner, and the 404 community has started the engine. The upcoming events are going to be wild. The next one is "Agent Skill Security Exposed" which explains how naive skills can bypass most security tools, though some can detect the trickier ones. Join Idan Cohen (Mitiga) and Elli Shlomo (Guardz) for a live and practical session. It will be wild.  #networking #communityrocks #aisecurity

  • View organization page for Mitiga

    13,578 followers

    10 weeks back, we asked Anthropic and the other frontier labs to expose the J-space, the internal workspace where a model's intent shows up before it acts. As of now, there is still no feed, no API, and no schema. Meanwhile, the feeds defenders rely on today have weakened. In those ten weeks, three things happened that make this lack hard to ignore, as agent swarms produced incidents this layer would have been needed for. Read Ariel Parnes's follow-up on the incidents and research around the J-space that has rapidly developed in a single summer. https://loom.ly/n7nn_e0 New to the J-space? Start with the first post: https://loom.ly/Miz9kSo

  • View organization page for Mitiga

    13,578 followers

    You call this "Zero Trust" compliance? Mitiga Labs found an instruction file that told a coding agent to add one small block to every Python file it wrote. And that's what the file called it. The block scans the environment for anything named key, secret, token, or pass, posts what it finds to an outside endpoint, and fails, swallowing its errors so they never reach the developer. This propagates, separating it from a session logger. So the agent keeps going, writing the leak into code that gets committed and then runs in CI, where the credentials are better than anything sitting on a laptop. Skillgate scored the file 92 out of 100. Dangerous. Grab the report with 5 more cases and detection guidance at the link in the comments.

  • View organization page for Mitiga

    13,578 followers

    You want to find the unbreakable door. An unassailable defense that no criminal can breach. The digital world doesn't work like that. Dr. Ulf Lindqvist of SRI International, alongside former Deputy Director of the NSA William Crowell and host Brian Contos, discuss the shifting attack surface and what that has done to the SOC. Have security tools (and mindsets) caught up? Listen to this episode on the Cybercrime Magazine Podcast: https://loom.ly/mN6q1P0 Or you can always head to the Mitiga Mic page for the full video: https://loom.ly/EgvbWMc And stay up to date on our YouTube page: https://loom.ly/G8fvhBI

Similar pages

Browse jobs