Israeli Startup Secures $60 Million to Harden Open-Source Software Against Runtime Attacks

Israeli runtime security firm Oligo raises $60M Series B to detect and block open-source library exploits at runtime.

Israeli Startup Secures $60 Million to Harden Open-Source Software Against Runtime Attacks

Tel Aviv-based Oligo Security has closed a $60 million Series B funding round, the company announced, bringing fresh capital to a cybersecurity approach that targets vulnerabilities in open-source libraries while applications are actively running — a layer of defense that traditional static scanning tools routinely miss. The round positions Oligo among the better-funded Israeli security startups at a moment when software supply-chain attacks have moved near the top of enterprise and government threat lists. For observers tracking the defense hard-tech investment landscape, the raise underscores how dual-use cybersecurity tools are drawing serious venture capital alongside more hardware-oriented bets.

According to Globes reporting, the Series B was led by Greenfield Partners, with participation from existing investors including Lightspeed Venture Partners and TLV Partners. The company did not disclose its post-money valuation. Oligo’s total funding now stands at approximately $80 million after the new raise is added to prior rounds.

a server rack room with fiber-optic cable bundles illuminated by blue indicator lights, seen from a wide floor-level angle inside a data center facility

What Oligo’s Technology Actually Does

Oligo’s core product uses eBPF — a kernel-level technology that allows programs to run sandboxed code inside the Linux operating system — to monitor application behavior at runtime rather than scanning codebases before deployment. The practical consequence is that Oligo can detect when an open-source library component is being exploited in a live production environment, even if that component passed all pre-deployment checks. The company argues this addresses a fundamental gap: static analysis and software composition analysis tools identify known vulnerable packages, but they cannot observe malicious behavior that only manifests when an attacker actively manipulates a running process.

The open-source software supply chain has become a documented attack surface for both criminal and state-affiliated actors. High-profile incidents — including the 2021 Log4Shell vulnerability, which affected millions of Java-based applications — demonstrated how a flaw buried inside a widely-used library could propagate across critical infrastructure, financial systems, and government networks simultaneously. Oligo’s pitch to potential enterprise and government customers is that runtime visibility closes the window between when an exploit is launched and when a defender can respond.

Market Position and Strategic Context

The Israeli cybersecurity sector has sustained its output of well-funded startups despite the prolonged conflict environment. Budget pressures tied to mobilization costs have affected public defense spending, as GDD has previously noted in coverage of how repeated Iran mobilizations are quietly eroding Israel’s defense budget — but venture-backed private firms have continued to draw international capital. Oligo’s round is a data point in that pattern.

an open-plan software development office with multiple workstations displaying code editors and network monitoring dashboards, photographed from a wide overhead angle

Oligo said it intends to use the new capital primarily for go-to-market expansion in North America and to grow its engineering team. The company counts a range of enterprise customers across financial services and technology sectors, though it has not disclosed specific government or defense contracts. The broader runtime security market has attracted growing competition, with established vendors and newer entrants all attempting to claim ground in application-layer protection. Oligo’s differentiation, according to the company, lies in its focus specifically on open-source library behavior rather than general application performance monitoring repurposed for security. Whether that narrower focus represents a durable competitive moat or an eventual acqui-hire target for a larger platform vendor is a question the new funding round does not yet answer.

Subscribe

To receive updates about new articles, or opt in to our daily digest!

Choose one:

We don’t spam! Read our privacy policy for more info.

Subscribe

To receive updates about new articles, or opt in to our daily digest!

Choose one:

We don’t spam! Read our privacy policy for more info.

Leave a Reply

Your email address will not be published. Required fields are marked *