Fundraise

RapidFort raises $42M for software supply chain defence as breaches double

What's the deal? RapidFort has raised $42M in Series A funding led by Blue Cloud VenturesDealroom has a profile for this one. Try Dealroom → and Forgepoint CapitalDealroom has a profile for this one. Try Dealroom →, with participation from prior lead investor Felicis Ventures. The San Francisco-based startup provides continuous vulnerability remediation for software supply chains, automatically eliminating security flaws in containerised applications and CI/CD pipelines. The platform combines automated vulnerability removal with near-zero-CVE container images across major Linux distributions, enabling teams to reduce attack surfaces by up to 90%.​

Why now? The funding arrives as third-party involvement in data breaches has doubled to 30%, whilst vulnerability exploitation has surged by 34%, according to Verizon's 2025 Data Breach Investigations Report. Vulnerability exploitation now accounts for 20% of breaches, nearly matching credential abuse at 22%. AI has accelerated both software development and attacker capability simultaneously, collapsing the window between vulnerability disclosure and exploitation. Research shows containers average 604 known vulnerabilities, with over 45% being two to 10-plus years old. More than 4% of critical or high-severity CVEs identified were weaponised vulnerabilities known to spread ransomware.

The software supply chain security market is estimated at approximately $15.8B in 2025, with a projected compound annual growth rate of 12.5% through 2033. Red Hat reports that 67% of organisations have delayed or slowed application deployment due to security concerns related to containers and Kubernetes.​

What could go wrong? Organisations face persistent challenges including misconfigured clouds and uncertainty over who owns container security throughout the software lifecycle. Traditional container scanning tools that rely on software manifests have significant visibility gaps, with one in eight components lacking formal metadata. The complexity of modern software architectures and the shortage of skilled cybersecurity professionals could limit effective implementation.​

The signal: The market is shifting from reactive vulnerability detection to continuous, automated elimination. RapidFort founder and chief executive officer Mehran FarimaniDealroom has a profile for this one. Try Dealroom →said the problem isn't that organisations don't know they have vulnerabilities — it's that they can't fix them fast enough. The company will use the funding to accelerate go-to-market expansion, platform innovation, enterprise adoption in regulated industries, and end-to-end software supply chain assurance. This reflects a broader industry evolution from "scan-and-pray" security to continuous remediation embedded directly into software delivery pipelines.​

Sources:
Business Wire
Verizon
DiMarket
Help Net Security
Mordor Intelligence
Azul

B.S.

More top stories