VulnCheck, a Massachusetts startup with ambitious plans in the vulnerability intelligence space, has attracted $3.2 million in seed-stage funding from several prominent investors.
The early-stage financing round was led by Sorenson Ventures and included equity stakes for In-Q-Tel, Lux Capital, and Aviso Ventures.
Based in Lexington, Mass., VulnCheck is building technology that promises exploit intelligence for vulnerability prioritization and an early-warning system for in-the-wild software exploitation activity.
Founded in 2021, VulnCheck is the brainchild of Anthony Bettini, former head of Tenable research and former founder and CEO of FlawCheck and Appthority.
The company has ambitious plans in a category that spans threat-intelligence, attack surface management, red-teaming and penetration testing.
VulnCheck is promising threat intelligence services to help organizations wade through the growing volume of publicly announced vulnerabilities and preemptively take action to stave off malicious hacker attacks.
The VulnCheck offerings include:
- VulnCheck Vulnerability Intelligence: a commercial alternative to the NIST National Vulnerability Database (NVD). VulnCheck claims its product includes more data, fields, sources, exploit and remediation intelligence, and provides data weeks earlier.
- VulnCheck Exploit Intelligence: helps organizations track all of the world’s exploit proof-of-concept code, exploited in-the-wild information, and exploit metadata, including timelines, to focus remediation resources on the right vulnerabilities.
- VulnCheck Initial Access Intelligence: provides organizations the detection artifacts, such as Snort or Suricata signatures, YARA rules, PCAPs, and private exploit PoCs, to defend against initial access vulnerabilities, recently exploited or likely to be soon.
The company and its investors are betting there’s revenue to be found in managing vulnerability and exploit data overload. The idea, according to VulnCheck, is to enrich vulnerability data with information about exploit activity to give security teams visibility and tools to prioritize remediation based on a real-time assessment of live exploitation.
Related: Investors Bet on Cyberpion in Attack Surface Management Space
Related: Cyber Insights 2023 | Attack Surface Management
Related: IBM to Acquire Randori for Attack Surface Management Tech

Ryan Naraine is Editor-at-Large at SecurityWeek and host of the popular Security Conversations podcast series. He is a security community engagement expert who has built programs at major global brands, including Intel Corp., Bishop Fox and GReAT. Ryan is a founding-director of the Security Tinkerers non-profit, an advisor to early-stage entrepreneurs, and a regular speaker at security conferences around the world.
More from Ryan Naraine
- Anti-Bot Software Firm DataDome Banks $42M Financing
- Malware Hunters Spot Supply Chain Attack Hitting 3CX Desktop App
- LeapXpert Banks $22M Funding to Secure Corporate Messaging With Consumer Apps
- Spera Banks $10 Million to Tackle Identity and Access Sprawl
- Mandiant Catches Another North Korean Gov Hacker Group
- Microsoft Puts ChatGPT to Work on Automating Cybersecurity
- Microsoft: No-Interaction Outlook Zero Day Exploited Since Last April
- Tesla Hacked Twice at Pwn2Own Exploit Contest
Latest News
- Italy Temporarily Blocks ChatGPT Over Privacy Concerns
- FDA Announces New Cybersecurity Requirements for Medical Devices
- Report: Chinese State-Sponsored Hacking Group Highly Active
- Votiro Raises $11.5 Million to Prevent File-Borne Threats
- Lumen Technologies Hit by Two Cyberattacks
- Leaked Documents Detail Russia’s Cyberwarfare Tools, Including for OT Attacks
- Mandiant Investigating 3CX Hack as Evidence Shows Attackers Had Access for Months
- Severe Azure Vulnerability Led to Unauthenticated Remote Code Execution
