
Italian cybersecurity startup Bynario has raised €2.1 million in pre-seed funding as the rapid growth of AI-assisted security research creates a new challenge for organisations: handling the growing number of potential software vulnerabilities being identified.
The Milan-based company said the round was led by 360 Capital Partners, with participation from Prana Ventures. Bynario was founded in 2025 and plans to use the new funding to accelerate product development, expand its engineering team and support growing demand from enterprise customers.
The company is developing software designed to identify vulnerabilities, assess their significance, prioritise security findings and assist with remediation across software and infrastructure environments.
Bynario’s approach extends beyond conventional vulnerability scanning. Its platform is designed to analyse source code, cloud infrastructure, third-party components, dependencies and compiled software, including proprietary binaries that may not be available for source-code inspection.
The funding announcement comes after Bynario gained attention for security research involving Apple’s macOS operating system.
According to reporting by the Financial Times, Bynario used AI-assisted research to identify more than 50 vulnerabilities in Apple’s latest Mac operating system in about three weeks.
The company had previously reported 13 Apple vulnerabilities during 2025 and early 2026, according to the same report.
Bynario’s research involved an automated workflow using artificial intelligence to examine software behaviour and investigate potential security weaknesses. In a technical disclosure published by the company, researchers said GPT-5.5 was used in the discovery and validation process for one of the vulnerabilities.
That vulnerability, identified as CVE-2026-43760, affected macOS Screen Sharing.
Apple’s own security advisory says the issue involved Screen Sharing and was addressed through improved state management. Apple also confirmed that the vulnerability was fixed in its software releases, including macOS Sonoma 14.8.8 and macOS Tahoe 26.6.
Bynario’s technical analysis described the flaw as a logic and authorisation problem rather than a traditional memory-safety vulnerability. The researchers said an authentication path involving legacy VNC configurations could cause privileged operations to run with root-level authority.
The researchers said they were able to use the issue to read protected files and create files as root, which they then used as part of a route toward remote root command execution.
Bynario said the vulnerability did not depend on a buffer overflow, use-after-free or other conventional memory-corruption technique. Instead, the problem emerged from interactions between authentication, protocol state, helper processes and privilege boundaries.
The company assigned its own assessment of 8.0 High under CVSS 3.1 to the vulnerability based on the behaviour it demonstrated.
Apple’s official advisory gives CVE-2026-43760 a lower CVSS 3.1 score of 5.5 and describes the impact differently. The two assessments should therefore be treated separately.
The macOS research also highlighted a growing operational problem for software vendors.
As AI systems become more capable of assisting security research, they can produce potential vulnerability reports at a much higher volume. Security teams still need to examine those findings, determine whether they are valid and assess their actual security impact.
The Financial Times reported that Apple changed its vulnerability-reporting system in June after receiving a growing number of AI-generated submissions. The system introduced a limit on the number of open reports a researcher could maintain and a 30-day cooldown, while allowing researchers to request a higher quota.
Bynario reportedly encountered Apple’s reporting limit during its research.
The episode illustrates a problem on both sides of the security process. AI can help researchers identify legitimate weaknesses more quickly, but it can also generate large numbers of reports that require human review.
Apple is also using AI in its own security work. The Financial Times reported that Apple credited tools from Anthropic and OpenAI in security updates that helped identify vulnerabilities, with the releases containing substantially more security fixes than previous update cycles.
Bynario’s research extends beyond Apple’s operating systems.
Its published research includes work on the Linux kernel, where the company has described an AI-assisted vulnerability discovery process involving issues such as a CAN-module use-after-free and a FUSE page-cache vulnerability.
The company’s broader product strategy is focused on reducing the amount of security noise organisations have to process. Rather than simply producing a long list of vulnerabilities, Bynario says its technology is intended to establish whether findings are exploitable, determine their relevance to a specific environment and help security teams decide what should be addressed first.
Bynario has also promoted products called Atlas and Precog. Atlas is positioned around AI-assisted research involving code and binaries, while Precog is aimed at continuous exposure management and the validation and prioritisation of vulnerabilities in production environments.
On its website, Bynario claims its technology can reduce security research costs by as much as 50 times. That figure is a company claim and has not been independently established in the sources reviewed.
The startup was founded in Milan by Alfredo Pesoli, Giancarlo Russo, Marco Valleri, Alberto Ornaghi and Lorenzo Cavallaro, according to Italian financial reporting.
The Italian financial press reported that the founding team includes members with backgrounds in cybersecurity research and security technology.
Discover more from Aree Blog
Subscribe now to keep reading and get access to the full archive.


