Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Bugcrowd announced on November 4, 2025, that it had acquired Mayhem Security. The companies say Mayhem’s automated code, API, fuzzing, symbolic-execution and runtime software-bill-of-materials (SBOM) capabilities will complement Bugcrowd’s network of human security researchers, extending testing from development into production. The financial terms were not disclosed.

What did Bugcrowd acquire?

Bugcrowd acquired Mayhem Security, an application-security company whose tools automate testing of software and APIs. Mayhem’s product materials describe a dashboard for code, API and SBOM security, with network-aware fuzzing, symbolic execution and automated triage. Its Dynamic SBOM product is designed to observe application behavior at runtime and help identify vulnerable dependencies that are actually reachable.

Those capabilities give the deal a specific technical scope: automated code and API testing, runtime-informed dependency analysis, vulnerability triage and regression testing. They are intended to complement Bugcrowd’s human-led security testing, rather than replace it.

Why did Bugcrowd make the acquisition?

Bugcrowd’s stated rationale is to bring machine-scale testing earlier into software development while retaining human testing against deployed systems. The company argues that conventional approaches can find flaws only after software is deployed; its proposed combined model is to test continuously during development and use human researchers to examine live systems.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall

Bugcrowd CEO Dave Gerry described the aim as combining “the collective ingenuity of our global hacker community” with the speed and precision of AI offensive-security testing. He also called the intended integration an “adaptive security platform.” Those phrases describe Bugcrowd’s strategy and positioning, not independently verified results or proof that every capability is already integrated.

How do AI-powered security tests work?

In Mayhem’s published product descriptions, automation includes several complementary methods. Fuzzing feeds software or an API many generated inputs to expose crashes or unexpected behavior. Symbolic execution analyzes possible program paths by reasoning about input conditions, which can help discover edge cases that ordinary test inputs miss. Network-aware testing can account for how an application interacts with other services.

Mayhem’s Dynamic SBOM approach adds runtime context to dependency analysis: instead of treating every listed component as equally exposed, it aims to identify which dependencies are exercised by the running application and prioritize vulnerabilities in reachable components. The company describes AI-driven behavior testing, more than a dozen testing methods, triage and regression testing as part of this offering.

Automation can run repeatedly and produce reproduction evidence for developers, but it does not eliminate the value of human judgment. Security researchers can investigate how vulnerabilities combine, assess context and test deployed systems in ways that a fixed automated workflow may not anticipate. Bugcrowd’s acquisition thesis is to connect those complementary forms of testing.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What changes for application-security teams?

The strategic change is a proposed security loop across more of the software lifecycle. The capabilities described by the companies map to distinct stages and questions:

Area What Mayhem describes How it could fit the combined approach
Code and APIs Automated code and API testing, including fuzzing and symbolic execution. Repeated testing during development can surface defects before release.
Dependencies Runtime-informed SBOM analysis intended to prioritize reachable, exploitable vulnerabilities. Teams can focus remediation on dependencies that matter to application behavior.
Triage and fixes Automated triage, remediation evidence and regression testing are described in Mayhem materials. Developers can investigate findings and check whether fixes prevent recurrence.
Deployed software Bugcrowd describes its human researcher network as testing deployed software. Human-led adversarial testing can add context and creativity beyond automated checks.

These are capability areas and the companies’ intended model, not a guarantee of a particular workflow for every customer. The public materials cited here do not establish exactly how Mayhem will be packaged inside Bugcrowd, which integrations will be available, or how findings will be routed between automated tests and human researchers.

What is Mayhem Security’s background?

Mayhem Security was previously ForAllSecure. In October 2024, the company announced the name change and described its roots in Carnegie Mellon research. The company said its technology had developed from a DARPA Cyber Grand Challenge prototype into a commercial application-security platform.

DARPA reported in August 2016 that Mayhem, created by the ForAllSecure team, was the presumptive winner of the Cyber Grand Challenge, which had nearly $4 million in prizes. The competition demonstrated the potential of automated cyber defense, but its result should not be confused with proof that a commercial product can autonomously secure every modern application.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

ForAllSecure/Mayhem also announced a $2 million initiative in 2022 to improve open-source software security and said Mayhem for Code and Mayhem for API would be free for personal use. In its 2024 name-change announcement, the company reported 275% year-over-year platform ARR growth and said 78% of customers expanded their Mayhem footprint at or before their first subscription renewal. Those figures are vendor-reported and are not independent measures of product effectiveness.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What should buyers verify?

The acquisition announcement establishes the strategic direction, but not the commercial or operational details a security team needs to make a purchase decision. Buyers should confirm directly with Bugcrowd:

  • Whether Mayhem products are available as standalone tools, bundled services or add-ons, and how pricing and contract terms work.
  • Which deployment options, data-handling controls and retention policies apply to source code, API traffic and runtime observations.
  • Which development and issue-management integrations are supported, and whether findings can be exported in formats the team already uses.
  • How automated findings are prioritized, validated and escalated to Bugcrowd researchers, and what evidence developers receive.
  • Whether regression tests can be retained and run against later builds, and how teams track remediation across releases.
  • What service levels, support arrangements and product availability apply after the acquisition.

The acquisition announcement does not provide those terms or confirm the exact integration timetable. Teams should treat the continuous development-to-production model as Bugcrowd’s stated goal until product documentation or a customer agreement specifies what is available to them.

Quick Recap

Bestseller No. 1
Penetration Tester's Open Source Toolkit
Penetration Tester's Open Source Toolkit
Used Book in Good Condition
$93.24

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.