TLDRocket
Sign in

Ossprey secures $2.65M to stop software supply chain attacks

Tech.eu Tamara Djurickovic

UK startup Ossprey just raised $2.65M to hunt for malware hiding in open-source code before it hits production. AI is making devs pull in more open-source packages faster than ever, and that's exactly what attackers are exploiting.

Based on reporting by Tech.eu, Tamara Djurickovic — read the original for the full story.

Summary, retelling and take written by AI under human oversight; images are AI-generated illustrations. How we work · Report an error

Ossprey, a UK-based software supply chain security startup, has closed a $2.65 million pre-seed round, and the company says it was oversubscribed. Episode 1 Ventures led the deal, with Osney Capital and Octopus Ventures also chipping in. The cash is earmarked for product development, growing the engineering and commercial teams, and pushing into new markets beyond the UK.

The pitch from co-founders Nate Dunning and David Read centers on a problem that sounds almost boring until you sit with it: roughly 90 per cent of enterprise software leans on open-source components. That's the plumbing nobody thinks about until it leaks. Attackers know this, and they've gotten good at slipping malicious code into trusted packages, using the everyday habits of development teams as their entry point rather than trying to break down the front door.

Ossprey's platform continuously scans those open-source packages, looking for malware before it ever reaches a live environment. The idea is to catch the bad stuff without forcing engineers to slow down or add friction to their workflow — a tension that Dunning, who serves as CEO, says existing security tools never really solved. He argues the old approaches simply weren't built for how fast teams now ship code, especially with AI coding assistants in the mix generating more code, more quickly, than humans alone ever could.

That AI angle is really the origin story here. As coding assistants push more volume into production pipelines, the exposure grows too — more code, more dependencies, more chances for something malicious to hitch a ride. Dunning frames the company's mission as removing the false choice between shipping fast and shipping safely, which is a nice way of saying the industry has been picking speed and hoping for the best.

For now, Ossprey is aiming its efforts at enterprise organisations building software at scale across the UK, Europe, and North America. The company is already talking about a larger funding round down the line, which suggests this pre-seed is meant to prove the concept works before asking for real money to scale it.

My take — AI-written commentary, not fact-checked reporting

Ninety percent of enterprise software running on open-source components is the kind of stat that should keep more people up at night than it does, and AI coding assistants pumping out code faster than anyone can review it only widens that exposure. A scanner that catches malicious packages before production is a sane, unglamorous fix rather than a moonshot, and unglamorous fixes are usually the ones that actually work. The real test won't be this pre-seed round — it'll be whether Ossprey can convince slow-moving enterprise buyers to adopt new security tooling at the same pace their engineers are being told to ship faster.

Read more about this at: Tech.eu

Related stories

The daily briefing

Every AI story that matters, in your inbox by 8am.

TLDRocket reads all relevant sources, removes duplicate coverage, and summarises the day in two minutes. Follow companies and topics for alerts, or get the briefing in Slack. Free, no spam, unsubscribe anytime.