Pentera, a Boston-based security validation company, has acquired DevOcean, an Israeli startup specializing in vulnerability remediation and workflow automation. The acquisition aims to address a critical gap in Pentera's platform by operationalizing the remediation of attack findings, enabling organizations to more efficiently resolve security issues identified during attack simulations. DevOcean, founded in 2021 and led by Doron Naim, the former head of security research at CyberArk, brings a team of 15 employees and a strong background in integrating with over 100 security tools. The company has raised $6 million in seed funding, with its most recent round led by Glilot Capital Partners in December 2022. Pentera's CEO, Amitai Ratzon, highlighted that DevOcean's artificial intelligence-based prioritization engine was a key factor in the acquisition, as it streamlines complex and traditionally labor-intensive remediation workflows. The integration of DevOcean's technology is expected to deliver a unified platform that combines attack simulation with automated remediation, reducing the time and effort required for security teams to address vulnerabilities. This move reflects a broader industry trend toward automating and prioritizing vulnerability management to keep pace with evolving threats and the increasing volume of security findings. By leveraging DevOcean's capabilities, Pentera aims to provide customers with a more seamless and effective way to transition from identifying security gaps to closing them. The acquisition also underscores the importance of interoperability in modern security operations, as DevOcean's platform is designed to work with a wide array of existing security tools. Both companies see the partnership as highly complementary, with DevOcean's expertise in remediation filling a strategic need for Pentera's customers. The deal is expected to enhance Pentera's value proposition in the competitive security validation and vulnerability management market. Industry observers note that the acquisition could set a precedent for further consolidation in the cybersecurity sector, particularly among vendors seeking to offer end-to-end solutions. The leadership of both companies expressed optimism about the integration process and the potential for innovation in automated security operations. Customers of both Pentera and DevOcean are anticipated to benefit from improved efficiency and effectiveness in their vulnerability management programs. The acquisition is also likely to accelerate the development of new features that bridge the gap between attack simulation and actionable remediation. As organizations face mounting pressure to address vulnerabilities quickly, the combined Pentera-DevOcean platform is positioned to deliver significant operational advantages. The move highlights the growing role of artificial intelligence in prioritizing and automating security tasks. Ultimately, the acquisition is expected to help organizations better defend against cyber threats by closing the loop between detection and remediation.

Track how attackers are adapting to this technology.
1 event from the most recent confirmed update back to the earliest known activity.
Pentera announced its acquisition of DevOcean, a move aimed at streamlining vulnerability remediation and improving how security findings are translated into fixes. The two provided references report the same acquisition event.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.