Search/fireeye
Vendor

fireeye

Known CVEs
0
Highest CVSS
In KEV
0
Vendor
central management
Connections
10 relationships
Kevin Mandia’s Armadin Launches With $190 Million in Funding
Kevin Mandia, who previously founded Mandiant and sold the incident response and threat intelligence firm to FireEye in a $1 billion deal in 2014 before its later $5.4 billion acquisition by Google, has launched a new cybersecurity startup. San Francisco based Armadin announced a massive Seed and Series A Funding round of $189.9M in what is effectively its public launch (the firm has simultaneously published a blog by Mandia titled Introducing Armadin). Armadin uses AI-powered red teaming to find and exploit weaknesses in the same way that attackers attack them. The funding was led by Accel, with participation from Google Ventures, Kleiner Perkins, Menlo Ventures, In-Q-Tel, and follow-on investment from 8VC and Ballistic Ventures — and is claimed to be the largest seed and series A funding in cybersecurity history. The firm was first announced quietly in late 2025 with an initial seed of $24 million. Now, with the formal launch, Mandia’s co-founders have been named as Travis Lanham (CTO), Evan Peña (chief offensive security officer), and David Slater (chief architect). Mandia is CEO. Armadin can be described as a red team on steroids. The steroids are AI. “I believe within the next few years virtually all cyberattacks will be AI-based – swarming, tailored, and relentless,” writes Mandia in his blog. “They will be untethered to human limitations and capable to execute on a scale we have never witnessed before.” Armadin intends to fight fire with fire. “In a world of machine-speed attacks, defense must become autonomous. You cannot have a human in the loop for every defense decision and expect to win,” he adds in the ‘launch’ document. We are building the most formidable offense to give organizations the greatest defense. It’s important to national security.” The ‘formidable offense’ comes from a team of specialist red teamers and AI researchers and engineers. The intent is to provide a platform that can perform AI-directed offensive security as fast as attackers can attack – to close or at least reduce the traditional agility gap – with its own autonomous, agentic attacker swarm. “Before Armadin, you could not put a nation state level adversary inside every network 24/7,” said Lanham. “We’ve built the ultimate attacker – it doesn’t just follow a script, it reasons and learns as it swarms your defenses. We train our models and build agents to the standards of a world-class red team with safety at the foundation and unleash them to identify exploitable risk at machine speed.” Traditional red teaming cannot cope with the dawning age of AI-driven attacks. Armadin intends to solve this with AI red teaming. Related: Palo Alto Networks Founder Nir Zuk Unveils New Startup Cylake Related: AI Security Firm JetStream Launches With $34 Million in Seed Funding Related: Fig Security Launches With $38 Million to Bolster SecOps Resilience Related: Aisy Launches Out of Stealth to Transform Vulnerability Management
securityweek.comMar 10, 2026extracted
U.S. DOJ Charges 54 in ATM Jackpotting Scheme Using Ploutus Malware
The U.S. Department of Justice (DoJ) this week announced the indictment of 54 individuals in connection with a multi-million dollar ATM jackpotting scheme. The large-scale conspiracy involved deploying malware named Ploutus to hack into automated teller machines (ATMs) across the U.S. and force them to dispense cash. The indicted members are alleged to be part of Tren de Aragua (TdA, Spanish for "the train of Aragua"), a Venezuelan gang designated a foreign terrorist organization by the U.S. State Department. In July 2025, the U.S. government announced sanctions against the group's head, Hector Rusthenford Guerrero Flores (aka Niño Guerrero), and five other key members for their involvement in the "illicit drug trade, human smuggling and trafficking, extortion, sexual exploitation of women and children, and money laundering, among other criminal activities." The Justice Department said an indictment returned on December 9, 2025, has charged a group of 22 people for supposedly committing bank fraud, burglary, and money laundering. Prosecutors also alleged that TdA has leveraged jackpotting schemes to siphon millions of dollars in the U.S. and transfer the ill-gotten proceeds among its members and associates. Another 32 individuals have been charged in a second, related indictment returned on October 21, 2025, accusing them of "one count of conspiracy to commit bank fraud, one count of conspiracy to commit bank burglary and computer fraud, 18 counts of bank fraud, 18 counts of bank burglary, and 18 counts of damage to computers." If convicted, the defendants could face a maximum penalty of anywhere between 20 and 335 years in prison. "These defendants employed methodical surveillance and burglary techniques to install malware into ATM machines, and then steal and launder money from the machines, in part to fund terrorism and the other far-reaching criminal activities of TDA, a designated Foreign Terrorist Organization," said Acting Assistant Attorney General Matthew R. Galeotti of the Justice Department’s Criminal Division. The jackpotting operation is said to have relied on the TdA recruiting an unspecified number of individuals to deploy the malware across the nation. These individuals would then conduct initial reconnaissance to assess external security measures installed at various ATMs and then attempt to open the ATM's hood to check if they triggered any alarm or a law enforcement response. Following this step, the threat actors would install Ploutus by either replacing the hard drive with one that came preloaded with the malicious program or by connecting a removable thumb drive. The malware is equipped to issue unauthorized commands associated with the Cash Dispensing Module of the ATM in order to force currency withdrawals. "The Ploutus malware was also designed to delete evidence of malware in an effort to conceal, create a false impression, mislead, or otherwise deceive employees of the banks and credit unions from learning about the deployment of the malware on the ATM," the DoJ said. "Members of the conspiracy would then split the proceeds in predetermined portions." Ploutus was first detected in Mexico in 2013. In a 2014 report, Symantec detailed how Windows XP-based ATMs compromised by the malware could be exploited to allow cybercriminals to withdraw cash simply by sending an SMS command. A subsequent analysis from FireEye (now part of Google Mandiant) in 2017 detailed its ability to control Diebold ATMs and run on various Windows versions. "Once deployed to an ATM, Ploutus-D makes it possible for a money mule to obtain thousands of dollars in minutes," it explained at the time. "A money mule must have a master key to open the top portion of the ATM (or be able to pick it), a physical keyboard to connect to the machine, and an activation code (provided by the boss in charge of the operation) in order to dispense money from the ATM." According to the agency, a total of 1,529 jackpotting incidents have been recorded in the U.S. since 2021, with about $40.73 million lost to the international criminal network as of August 2025. "Many millions of dollars were drained from ATM machines across the United States as a result of this conspiracy, and that money is alleged to have gone to Tren de Aragua leaders to fund their terrorist activities and purposes," U.S. Attorney Lesley Woods said.
thehackernews.comDec 20, 2025extracted