Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

2938+ Articles
167+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. SpiderSilk Hunts External Threats With AI-Based Scanner
SpiderSilk Hunts External Threats With AI-Based Scanner
NEWS

SpiderSilk Hunts External Threats With AI-Based Scanner

Dubai startup SpiderSilk uses AI to scan billions of IPs for exposed assets, leaked data, and zero-days from just a company name.

Dylan H.

News Desk

September 20, 2026
3 min read

Overview

Dubai-based spiderSilk, founded in 2019, is using AI to scan billions of internet-facing IP addresses on behalf of customers, hunting for exposed assets, leaked credentials, and zero-day vulnerabilities before attackers find them first. The company recently closed a $9 million Series A round led by Saudi Aramco Entrepreneurship Ventures, with participation from Global Ventures and STV, funding a platform that aims to give defenders the same outside-in view an attacker would have.

How It Works

Where most external attack surface tools need a customer to hand over a list of known domains and IP ranges, spiderSilk's platform reportedly needs only a company's name to get started. From there, its scanning technology sweeps billions of IP addresses looking for infrastructure, leaked data, exposed systems, and compromised credentials the organization never intended to expose — mimicking how an outside attacker would go about mapping a target rather than relying on an internal asset inventory that's often already stale.

Co-founder and Chief Security Officer Mossab Hussein says the system also assesses what it finds — analyzing a page's content, code, and even visual branding elements like logos — to determine whether a given exposure is an internal system misconfiguration or simply commercially hosted software, before deciding what's worth flagging to a customer.

Built for Zero-Day Response

The platform, which spiderSilk calls SilkNet, continuously aggregates open source and darknet data at scale and can kick off fresh, targeted internet scans the moment a new zero-day vulnerability is disclosed, pushing a threat report straight into a customer's internal systems. A newer SOC Autonomous AI Agent layer goes a step further, configured to act on confirmed exposures directly — isolating a compromised host, blocking a suspicious IP, or locking an account — without waiting on a human analyst to act first.

Track Record

spiderSilk has a history of surfacing major exposures well before this AI-driven platform existed, including the Blind anonymous-network leak, an exposed Samsung source code repository, a Clearview AI code and app leak, and an unencrypted MoviePass card-number spill. The company says its research has collectively uncovered exposures affecting more than 120 million people, and its customer base now spans telecommunications, energy, financial services, healthcare, and retail across North America, Europe, and Asia-Pacific.

Why It Matters

External attack surface management has largely been a story of inventory: knowing what you own well enough to defend it. spiderSilk's pitch is that AI now makes it practical to skip straight to an attacker's-eye view of an organization instead — discovering exposures that never made it into an asset list in the first place, and doing it fast enough to matter on the same day a new zero-day drops rather than weeks later during a scheduled scan.

#Attack Surface Management#AI Security#Startup#DarkReading

Related Articles

The Top 10 Attack Surface Exposures in 2026

A comprehensive breakdown of the most dangerous attack surface exposures organizations face in 2026 — from exposed admin panels and credential reuse to...

6 min read

The Zero-Day Scramble Is Avoidable: Why Attack Surface

Security teams racing to patch every new zero-day are fighting the symptom, not the cause. Intruder's Head of Security argues that most organizations have...

6 min read

From 17,000 to 1.1 Million Assets: How Lumen Technologies Rebuilt Exposure Management

Lumen Technologies discovered it had 60x more assets than previously known after consolidating 40+ disconnected inventory systems with Axonius. The...

3 min read
Back to all News