A Milan-based cybersecurity startup that uses artificial intelligence to find vulnerabilities in software executables has quietly closed a pre-seed round, according to startup databases Wellfound and CB Insights. BynarIO, which made headlines last summer after discovering dozens of macOS flaws in a matter of weeks, appears to have secured backing from PranaVentures, though the funding remains unconfirmed and financial details are undisclosed.
The funding narrative is somewhat opaque. Wellfound records show a January 2026 close with an undisclosed amount. CB Insights, meanwhile, dates PranaVentures' investment to February 1, 2026. The discrepancy may be administrative rather than meaningful. What is clear: PranaVentures itself underwent a transformation shortly after, merging into Italian fund manager P101 in June 2026 to form Prana101, a €100 million vehicle aimed at early-stage deeptech, AI, and cybersecurity plays.
Hunting Bugs in the Wild
BynarIO's approach sidesteps a fundamental constraint in traditional vulnerability research. Most security tools require access to source code, the human-readable instructions that developers write. BynarIO's platform instead analyzes compiled binaries—the machine-readable executables that actually run on users' devices. This matters because third-party auditors, enterprise buyers, and even governments often lack source code for the software they deploy.
The startup says it goes beyond merely flagging potential issues. Its system performs exploitability analysis, attempting to determine whether a candidate bug can be weaponized into a genuine security flaw. "BynarIO can identify vulnerabilities in any software, not just in the source code," founder and CEO Alfredo Pesoli wrote in a November 2025 blog post. Pesoli previously worked at Immunity Inc., a Florida-based firm known for selling exploit tools to government clients.
BynarIO markets three products—Atlas, Aegis, and Precog—targeting sectors where software failures carry steep consequences: aerospace, defense, and financial services.
Apple's Bug Bounty Backlash
The company entered the public conversation last August when the Financial Times reported that BynarIO had uncovered more than 50 macOS vulnerabilities in three weeks. The timing was awkward. Apple had recently capped the number of concurrent bug submissions researchers could file, responding to what insiders described as a deluge of AI-assisted vulnerability reports—many of them low-quality or redundant.

"It is a very difficult time in the industry," Pesoli told the Financial Times at the time. "Maintainers have been flooded by the sheer amount of bugs being found."
The comment captured a growing tension in cybersecurity. AI-powered tools can surface flaws faster than human researchers ever could, but the same automation risks overwhelming the engineers responsible for fixing them. In July, tech news site The Hacker News cited BynarIO's discovery of a Linux kernel vulnerability, later assigned the identifier CVE-2026-31694.
Small Team, Big Ambitions
Co-founder Lorenzo Cavallaro, who serves as chief scientific officer, holds a full professorship in computer science at University College London. LinkedIn data suggests the team remains lean—somewhere between two and 10 employees—though the company is actively recruiting for roles in vulnerability research and large language model fine-tuning. The LLM positions hint at how BynarIO's system likely works under the hood, though the company has not detailed its technical architecture publicly.

BynarIO faces competition from established players and fellow startups. RevEng.AI, a binary analysis firm, raised a $15 million Series A in May 2026. GrammaTech, a longer-tenured company spun out of Cornell University research, sells CodeSentry for similar use cases. Whether BynarIO's approach proves differentiated enough to carve out a defensible market position remains an open question, particularly as larger cybersecurity vendors experiment with their own AI-driven vulnerability scanning.
For now, the startup appears focused on proving its tools can deliver results at scale. In regulated industries where software audits carry legal weight, that may be enough to build a business—assuming the bug reports hold up.
