LevelBlue, a managed security services provider formerly known as AT&T Cybersecurity, has announced a definitive agreement to acquire Cybereason, a Boston-based cybersecurity firm specializing in extended detection and response (XDR) platforms and digital forensics. The acquisition is part of LevelBlue's strategy to enhance its managed detection and response (MDR) offerings by integrating Cybereason’s XDR platform, threat intelligence team, and digital forensics and incident response (DFIR) capabilities. According to LevelBlue CEO Bob McCullen, the combination of Cybereason’s technologies with LevelBlue’s AI-powered MDR and incident response will enable the company to deliver unified, proactive, and scalable protection against evolving cyber threats. Cybereason, founded in 2012 by former Israeli Defense Forces signals intelligence members, has been a competitor in the endpoint detection and threat intelligence market alongside firms like CrowdStrike and SentinelOne. The company experienced significant growth, reaching a $3.1 billion valuation in 2021 after a $325 million funding round, but later faced a dramatic decline in valuation and multiple restructurings. Cybereason’s workforce peaked at around 1,500 employees but has since reduced to 573. The acquisition follows a broader trend of consolidation in the cybersecurity industry, as companies seek to offer comprehensive solutions under unified brands. Earlier in the year, Cybereason had merged with managed service provider Trustwave, but that deal was terminated in March 2025. LevelBlue’s acquisition of Cybereason comes just two months after LevelBlue itself acquired Trustwave, further expanding its global reach and capabilities. The integration of Cybereason’s XDR and DFIR technologies is expected to provide LevelBlue’s clients with stronger threat detection, faster incident response, and broader global coverage. The deal is seen as a strategic move to position LevelBlue as a leading cybersecurity partner for organizations facing increasingly sophisticated threats. Cybereason’s journey from near-IPO status to acquisition highlights the volatility and competitive pressures in the cybersecurity sector. The acquisition is anticipated to bolster LevelBlue’s offerings in endpoint security, governance, risk management, and managed detection and response. Both companies have emphasized the importance of unified, AI-driven security solutions to address the challenges posed by modern cyber adversaries. The transaction underscores the ongoing evolution of the cybersecurity landscape, where scale, integration, and advanced technology are critical for success. LevelBlue’s leadership believes the addition of Cybereason will enable the company to deliver more comprehensive and effective security services to its global client base. The acquisition is pending regulatory approval and is expected to close in the coming months.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.