Cloudflare's security team spent the last few weeks testing Anthropic's Mythos against fifty of our own repositories. What we learned about offensive AI, why faster patching is the wrong reaction, and what the architecture around vulnerabilities has to look like next. https://t.co/RSrRtIhgaV
Fine, I'll say the thing that no-one is saying...
There's a bunch of AI companies with $1-10M "ARR" raising big VC money on what I'll call "curiosity revenue" - not real sustainable ARR.
Basically, what's happening right now is a lot of people have high willingness to try AI products. They'll sign up for a free trial, maybe even convert to paid for a couple months out of curiosity. This creates a temporary revenue spike that looks like product-market fit but isn't.
They call it ARR, but it's more like "hey I'll try this product revenue".
Of course there are companies like Replit, Cursor or Bolt that are building real products solving actual workflow problems. These companies have genuine retention and expanding usage.
And hey, companies like Bolt had been building for like 6 years prior to adding any AI features. Replit has a similar story I think.
But many AI startups are riding a wave of novelty and FOMO, not solving real problems. They're showing investors nice growth curves that will flatten in 6-12 months when customers realize the product isn't actually improving their work.
A slick demo reel + stripe payment +novel feature might be good enough to try but may not be enough to be a true ARR type of customer.
And then we will see a bunch of zombie AI companies.
The people who will get hurt will be the employees who think their stock is worth millions but then the founders go and try to raise more money but try raising money when revenue is down 65%.
The real tell is retention. Are people still using the product 6 months in? Are they using it more over time? Or did they try it a few times, got the "wow" moment, and then slowly stopped?
By the way, even companies with true PMF are at risk.
The AI landscape shifts so rapidly that your PMF can be temporary. Example: we're seeing people switch from ChatGPT Pro at $200/month to Grok/Perplexity Deep Research for free with barely a second thought.
Unlike previous tech cycles (mobile, web), where advantages could last years, AI competitive moats are filling in weekly.
We're probably 18 months away before we start seeing a bunch of zombie companies.
The AI companies that survive will be the ones that focused on solving real problems, iterating as the market changes, building true community and not just demo-ing cool sizzle reel after sizzle reel.
Am I wrong?
WRONG. Being a Founder creates the most billionaires. This is not limited to tech. Founders of grocery stores, fast food franchises, private equity funds and more have all become billionaires.
There are basically 5 ways to accumulate a billion dollars:
1) Profiting from a monopoly
2) Insider-trading
3) Political payoffs
4) Fraud
5) Inheritance
Don’t believe the self-made myth.
1/ Every InfoSec category is a symphony of people, processes, and technology. No matter how much automation is applied, people will always be essential. 🧑💻🔐
At $10M ARR many founders get it backwards: They hire VPs and step away completely.
They read reports instead of joining customer calls. They skip interviews because "my VP can handle it."
This is precisely how companies die.
Your executives will bring deep expertise but never true ownership. They solve problems but don't feel the existential pressure you do.
And when things break, they'll update their LinkedIn profiles while you're left holding the pieces.
Your job isn't to micromanage. You need to maintain constant awareness through customer calls, interview panels, deep KPI knowledge, and daily operational visibility.
Scaling requires delegation.
*Not abdication.*
Because at $10M ARR, what you don't know absolutely can kill you(r business).
We’re hiring an investor to join @firstround and work alongside me on every aspect of pre-product market fit investing — from finding extraordinarily talented founders to doing all that we can to support their ambitions as their companies start to take shape.
Partnering with founders at the earliest stages is my life's work. I’m looking for someone who thinks it might be theirs, too.
If you’re a fit for this role, you’re technical and likely in the first few innings of your career. You don't need to have previous investing experience, but it’s also fine if you do.
You may not be certain about your path just yet, but you can at least picture devoting your professional life to becoming an extraordinary partner to pre-product market fit founders.
Here is more on what I’m looking for:
-You don’t see a tradeoff between being technical and commercial. You’re as likely to geek out on the technical aspects of a new AI model, as you are to dig into the details of how ServiceNow became a $183B company.
-You’re an aspiring student of startups and business. That means you’re probably a builder of sorts yourself, and at the very least, embedded in the startup ecosystem. You understand, perhaps from firsthand experience, the challenges of creating something from nothing.
-You tend to be an obsessive type and your happy place is going unreasonably deep on obscure ideas. You see the world in systems, and you pride yourself on an ability to get up to speed on complex topics, fast.
-You’re based in the Bay Area or willing to move.
-You build relationships easily, and you’re always looking to expand your orbit and meet interesting people.
-You’re often one of the first users of new products.
-You’d describe yourself as intensely curious. You’re a “learn-it-all,” not a “know-it-all.” You know when to share what you think you know — and when to listen and learn.
-You have a desire to work outrageously hard. You’d describe yourself as high agency and high ownership. You work all the time — because you love it, not because you are required to. If work-life balance is a priority, this role isn’t for you.
If your motivation is to “lead investments” as soon as you join, this role isn’t a fit. Instead, this is a chance to be an apprentice in the truest sense of the word.
You’d spend your first couple of years at First Round focused on developing your craft by working closely with our team on every aspect of pre-product-market fit investing.
You’d get an inside look at all we’ve learned in the last two decades, while building a long-term career of your own here, too.
The work is demanding and often unglamorous. But you will learn and grow more than in any job you’ve had before. I will partner with you closely every day to make sure that’s true.
If the above sounded like something interesting to you, you can apply by following the link below.
The problem isn’t that the update was malformed.
The problem isn’t that the validator they wrote didn’t catch the error before it was deployed.
The real problem is that they didn’t have any canary system to which they deployed the update before rolling it out to millions of endpoints all at once.
Since no external factors — like the driver of another vendor (see the Kaspersky issue with Intel drivers years ago) — were involved, a single $400 canary machine could have prevented this disaster. The absence of such a machine and a staged rollout could be interpreted as gross negligence in court, and that’s why everyone at CrowdStrike is worried.
Mistakes and slips are human. No one would be angry about that. But having only a simple and possibly flawed validator between an analyst and a kernel driver on millions of systems worldwide could be seen as grossly negligent.
It’s the only thing that matters. Everything else they describe, added to their testing, and improved processes is just filler, possibly to distract from the one relevant fact.
Crowdstrike has now released an initial post-mortem and set of lessons learned.
The big takeaway:
CS did not actually test the specific sensor config update in question.
Instead, it relied on a content validator + lack of problems with similar updates.
https://t.co/miUh4JNaqe
you’d be amazed at how many security teams fought to deploy kernel modules in prod, and were incensed if platform engineering teams blocked them from doing so
there’s a reason why security vendors get away with this, or using EoL libraries, or other software quality ills…
I’ve been in the AI trenches since 2009, and LLMs are certainly a game-changer. But they also seem to be a warm-up act for the main event—the next cycle of AI innovation, coming in the next 12-18 months.
Here are 3 areas we’re looking at to fuel this cycle, where founders can make real AI magic →
Multimodality 📸
Multiple agents 🤖🤖🤖
Post-transformer architectures 🛠️
Latest blog: https://t.co/0D706dgfVk
Huge fan of Skyline College as a smaller Community College for in-person. Skyline, College of San Mateo and Canada are all part of same system for excellent online choices. You can mix and match which is awesome.
In California, the community colleges offer so many online courses for free or super low cost. Huge fan of the community colleges for both in-person and online. Real professors teaching online too.
@AnnaIvey Not wrong at all. Also, stifles all problem solving ability because the student gets punished for getting the right answer even if done more elegantly. This method is not teaching innovation, creative thinking or problem solving. Yuck!
From volume perspective it’s probably:
1.) “Glean” / or QandA for XYZ role (sales, CSM, PM, marketing) or XYZ industry (legal)
2.) BI / data analytics
3.) horizontal productivity agent
4.) LLM evals / observability
5.) Devins for QA
6.) foundation models for xyz industry / function
7.) the rag ecosystem (more early last year vs now)