Daily Tech Briefing
AI 科技速览

每天 5 分钟内学习 AI。获取最新的人工智能新闻,理解其重要性,并学习如何将其应用于您的工作。

AI 快讯
Unite.AI · 2026/7/30 16:59:37
Bloom Security Emerges from Stealth with $20M to Secure the AI-Native Endpoint

Bloom Security Emerges from Stealth with $20M to Secure the AI-Native Endpoint

AI 中文解读
一家名为Bloom Security的安全公司近日带着2000万美元种子资金从隐形模式中亮相,专门解决企业网络安全的一大盲区:员工电脑上越来越多的AI助手、浏览器插件、代码包和自动化工具。这笔融资由Glilot Capital Partners领投,多家知名安全企业的创始人参与,目前其平台已在美国和欧洲数十家大企业运行。 通俗点说,过去企业管电脑安全主要看是不是装了病毒或可疑程序,但现在员工可以随意安装编程助手、AI代理、浏览器扩展等,这些“小工具”往往绕过了企业正规采购流程。浏览器和开发环境变成了软件超市,AI助手甚至能自己安装依赖包,导致每台电脑都像是个不断变化的软件生态园。安全团队不仅要判断工具是否恶意,还得看它是否适合特定员工、设备和数据环境——比如一个浏览器插件在普通电脑上没事,但装在高管的设备上就可能危险。 对普通人来说,以后在公司用AI工具会更放心,不用怕不小心让AI接触敏感数据,企业也能更好地管理哪些工具能用、谁能用。这项技术让“AI原生端点”不再是安全黑洞,企业能看清每个员工电脑上到底运行了什么东西,从而堵住风险。
Funding Bloom Security Emerges from Stealth with $20M to Secure the AI-Native Endpoint Published July 30, 2026 By Antoine Tardif, CEO & Founder of Unite.AI Add Unite.AI to your preferred sources on Google Bloom Security has emerged from stealth with $20 million in seed funding to address a growing blind spot in enterprise cybersecurity: the expanding collection of AI agents, browser extensions, plugins, code packages, and local automation operating on employee devices.The round was led by Glilot Capital Partners, with participation from Ten Eleven Ventures, Okta Ventures, and Runtime Ventures. Angel investors include founders of cybersecurity companies Dig Security, Demisto, Snyk, and Talon. Bloom is launching with a 30-person team and says its platform is already deployed at dozens of large enterprises in the United States and Europe.The Enterprise Endpoint Is Becoming Harder to DefineTraditional endpoint security was built for managed devices running approved software, with endpoint detection and response tools focused primarily on malware and suspicious processes.Generative AI has disrupted that model. Employees can now add coding assistants, AI agents, browser extensions, open-source packages, and local automation outside traditional procurement channels. Browsers and development environments have become software marketplaces, while agents can install dependencies independently.As a result, endpoints are evolving into constantly changing software ecosystems. Security teams must now assess not only whether a tool is malicious, but whether a legitimate tool is appropriate for a particular user, device, and data environment.A browser extension may be low risk on one laptop but dangerous on an executive’s device. Similarly, an approved AI agent may become overprivileged if it can access production credentials, customer data, or financial records.Building an Inventory of What Is Actually RunningBloom’s platform maintains a continuously updated inventory of software across an organization’s endpoint fleet, including applications, browser extensions, development environment plugins, AI tools, Model Context Protocol servers, and local code libraries.Model Context Protocol, or MCP, allows AI agents to connect with external tools, data sources, and business systems. While these connections expand what agents can do, they may also expose sensitive information or enable actions on a user’s behalf.Bloom analyzes each component’s developer, origin, permissions, configuration, and access to corporate resources. It also tracks changes over time, helping security teams identify software introduced through marketplaces, package managers, background updates, or automated agent activity.This is particularly relevant in software development, where a coding agent may select frameworks and install multiple dependencies before a developer reviews the resulting application.Evaluating Risk in ContextBeyond identifying software, Bloom evaluates the context in which each component operates. The platform combines marketplace intelligence, static analysis, and behavioral sandboxing to assess configurations, permissions, data access, vulnerable packages, policy bypasses, and interactions between tools.Risk is measured according to factors such a
分享
阅读原文