Oligo Security team photo
Image Credits:Oligo Security
Enterprise

Oligo raises $28M to secure open source libraries at runtime

Oligo Security, a Tel Aviv-based startup that focuses on runtime application security and observability to detect and prevent open source vulnerabilities, is coming out of stealth today and announcing that it has raised a total of $28 million in seed and Series A funding.

The company’s investors include Lightspeed Venture Partners, Ballistic Ventures and TLV Partners, as well as angel investors like Mallanox CEO and founder Eyal Waldman, Snyk CTO Adi Sharabani and former Google Cloud VP Eyal Manor. Cyber Club London (CCL), Kmehin Ventures and OperAngels also participated. The company also participated in Intel’s Ignite accelerator in 2022.

Oligo’s dashboard, presenting application security posture based on runtime context.
Oligo’s dashboard, presenting application security posture based on runtime context. Image Credits: Oligo Security

Oligo’s technology is based on eBPF, the increasingly popular technology to run sandboxed code in the Linux kernel — and gain access to very detailed monitoring capabilities because of that without any major overhead. That’s a different approach from other security startups that focus on open source libraries. Instead of alerting security teams to every potential vulnerability — even if a library isn’t actually used in an application — Oligo focuses on monitoring applications at runtime, both in pre-production and production environments. This, ideally, cuts down on unnecessary alerts. Indeed, Oligo argues that 85% of open source vulnerabilities that traditional scanners flag to developers aren’t even used in production.

Co-founded by Nadav Czerninski (CEO), Gal Elbaz (CTO) and Avshalom Hilu (CPO), Oligo works across clouds and supports all major modern programming languages, including Python, Go, Java and Node.

“We have our patent-pending technology, which is based on eBPF. It allows us to safely and efficiently monitor the runtime environment and then first identify which vulnerabilities are actually relevant. That saves tons of time and money for developers, for security teams, for DevOps,” explained Czerninski.

As the team explained, in first observing how every library should work in normal usage across different environments, Oligo can then detect when something changes — likely because of an exploit. A library like NumPy, for example, is typically only used for computations, but if it suddenly wants to access the network, something is clearly amiss.

“Solving the open source security challenge starts with the ability to accurately assess the actual risk of code vulnerabilities,” said Alex Nayshtut, head of Security at Intel Strategy Office. “Oligo is set to increase the productivity of AppSec teams and reduce the risk of using open source by contextually prioritizing vulnerabilities according to actual versus perceived risk.”

Techcrunch event

Disrupt 2026: The tech ecosystem, all in one room

Your next round. Your next hire. Your next breakout opportunity. Find it at TechCrunch Disrupt 2026, where 10,000+ founders, investors, and tech leaders gather for three days of 250+ tactical sessions, powerful introductions, and market-defining innovation. Register now to save up to $400.

Save up to $300 or 30% to TechCrunch Founder Summit

1,000+ founders and investors come together at TechCrunch Founder Summit 2026 for a full day focused on growth, execution, and real-world scaling. Learn from founders and investors who have shaped the industry. Connect with peers navigating similar growth stages. Walk away with tactics you can apply immediately

Offer ends March 13.

San Francisco, CA | October 13-15, 2026

Topics

, , , , , , ,
Loading the next article
Error loading the next article