The Symmetry is Gone. Why We Backed Beelzebub

July 27th, 2026

In December 2025, a Docker server sat exposed on the open internet — the kind of misconfigured, forgotten box that automated tools scan for and hit thousands of times a day. One of the year’s most aggressive campaigns found it within hours and moved in. It was a trap: the server was a Beelzebub decoy.

Rather than simply record the intrusion, Beelzebub’s researchers traced the campaign back to its command-and-control server — whose operational metrics had been left publicly accessible — and published its own figures in their research, Operation PCPcat. A group calling itself Team PCP had scanned more than 91,000 targets in 33 hours and compromised over 59,000 servers in under 48 hours, at a 64.6% success rate, harvesting credentials at industrial scale through a single critical Next.js vulnerability. At the time, the group was little known. Months later it breached GitHub’s internal repositories and made off with thousands of them, one of the most consequential software supply-chain compromises of the year. Beelzebub had documented the actor before most of the industry knew its name.

No human team works at that speed or scale. For most of its history, cybersecurity did not have to contend with one that could. It was a symmetric contest: humans attacked, and humans defended, both bound by the same limit — human speed. Reconnaissance was manual, exploits were built by hand, targets were taken one at a time, and the analysts on the other side were, more or less, an even match. The fight was slow, costly, and survivable.

That symmetry has broken. Attackers are now AI-enabled while defenders remain, overwhelmingly, human. A single operator can run thousands of campaigns in parallel; exploits ship within minutes of disclosure; frontier models reason like senior operators; and the marginal cost of an attack is collapsing toward zero. On the other side sits a security team of fewer than ten people who cannot hire their way out of the gap because talent is scarce and onboarding is slow. The contest is no longer symmetric, and at human speed it is no longer survivable.

This is the problem Beelzebub was built to solve, and it is why we led its €3M seed round. Founded as an open-source research project in Milan in 2021 by Mario Candela and incorporated in 2025, Beelzebub is an AI-native security platform built on a single premise: assumed breach. It does not try to keep attackers out. It assumes one is already inside the network, and it engineers the environment so that the intruder reveals themselves the moment they move. That is a deliberate architectural choice and a thesis about where defense must occur once the perimeter is no longer the line that matters.

The platform runs as a single automated loop across three products. Arcangelo, the offensive layer, continuously simulates a frontier-model adversary against the live perimeter and flags newly disclosed vulnerabilities within seconds. Beelzebub Cloud, the defensive layer, seeds the infrastructure with LLM-powered decoys that are indistinguishable from real production systems and reshape themselves in real time to mimic the newest CVEs (Common Vulnerabilities and Exposures) as they are published — so that dormant intruders are drawn into the open, every alert is a confirmed breach attempt rather than noise, and compromised systems are isolated on contact. Caronte, the analysis layer, reverse-engineers each captured payload and produces a full incident report in minutes rather than the days or weeks a human analyst would need. Offense and defense feed one another, with no handoffs between tools or vendors.

What makes the company defensible is not any single capability but the loop itself. Each layer was designed with the others in mind, and the system improves the more it is attacked: more than 60 independent researchers feed live threat intelligence into the platform as new techniques appear in the wild — the same open-source engine that has passed 2,100 GitHub stars and is in daily use by security engineers at some of the most demanding infrastructure organizations in the world. Threat-hunting teams used it to deploy a decoy on the open web and capture live attacks in real time. It is a posture that turns every attempted intrusion into an advantage.

On Mario

It is rare to meet a founder whose technical authority and product instinct align as completely with the problem in front of them. Mario Candela started coding at nine and founded a hacker community at fourteen. He trained as a computer engineer, wrote his thesis on automated penetration testing, and spent more than a decade in senior technical roles across Daimler, Sky, Wolters Kluwer, HackerOne, Zurich, and NTT Data. He is a member of The Honeynet Project, the international organization devoted to studying live attacker behavior, and the creator of the Beelzebub open-source project.

Beelzebub did not begin as a company, and the open-source project remains its foundation. Mario built it on the side, and the company grew up around the project rather than in place of it: the code was good enough that enterprises came to rely on it — filing issues, requesting features, and treating a research effort as critical infrastructure until sustaining it became impossible on its own. Demand pulled the company into existence, and the project it was built on is still open and still core. In a domain where technical judgment is the primary source of defensibility, a project that earns that kind of dependence is the clearest signal we look for, and one we rarely see this cleanly.

Built in Italy, hiring for the frontier

Beelzebub is being built from Milan, and that matters to us. Italy has produced world-class security talent for a generation and exported much of it. The opportunity now is to keep that talent and to draw it back. The company is assembling a research team around Mario, including experienced vulnerability researchers, and will open commercial offices in Rome and San Francisco by the end of 2026 — but its center of gravity, its research and its hardest engineering, stays in Italy.

The problem it is working on is among the most demanding in software: adversaries that move at machine speed, an attack surface expanding faster than any team can cover by hand, and a research frontier — the security of AI agents themselves — that barely existed two years ago. As enterprises put agents into production, they are opening a surface almost no one is equipped to defend. Beelzebub extends the same deception logic to it, planting decoy tools an agent should never call, so that a hijacked agent gives itself away the instant it reaches for one. For engineers and researchers who want to work at that frontier — on real adversaries rather than synthetic benchmarks, with their work visible in an open-source project used worldwide — there are few better places to be.

Beelzebub is the kind of company we look for and rarely find: a category-defining approach to a large and structurally growing market, led by a founder whose expertise is the source of the company’s edge, at the earliest stage at which conviction can be expressed. When offensive AI scales faster than any human team can respond, the only viable defense is one that operates at the same speed and intelligence. Beelzebub is building it.

What the round enables

The €3M brings Beelzebub’s total funding to €3.3M, following a pre-seed from strategic investors and advisors. The capital will expand the research team, open the Rome and San Francisco offices, and accelerate client acquisition across Europe, which is now operating under NIS2 and the Cyber Resilience Act. The near-term priority is people: the researchers and operators who will turn a validated platform into the category standard.

We are proud to be working with Mario and the team he is building. For most of computing history, defenders could count on moving at the same speed as their attackers. That assumption is gone — and Beelzebub is the most convincing answer we have found to the question it leaves behind.

Read next