🧔♂️ A friendly human may check it before it goes live. More news here
Cybersecurity startup Hopper bags $7.6m seed funding
Cybersecurity startup Hopper has announced its emergence from stealth mode following US$7.6 million in seed funding to overhaul how open-source security is done.
The funding round was co-led by Meron Capital and New Era, with additional contributions from the Sequoia Scout Fund, M-Fund, and other investors.
The funding will support product development, including expanded language and framework capabilities.
It will also help scale Hopper’s operations in the US.
🔗 Source: Calcalist
🧠 Food for thought
1️⃣ The shift from detection overload to precision is transforming open-source security economics
Traditional Software Composition Analysis (SCA) tools have created a costly “alert fatigue” problem in the industry, with Hopper’s customers reporting they previously spent up to 8% of total development time addressing security alerts1.
This inefficiency has become a significant hidden cost as organizations increasingly rely on open-source software, with approximately 97% of modern applications utilizing open-source code2.
The economic impact is substantial. When security teams are overwhelmed with false positives and non-exploitable vulnerabilities, development velocity decreases while actual risks may remain unaddressed, creating both security and business challenges.
This explains why a new generation of tools is focusing on precision rather than simply detection volume, prioritizing vulnerabilities that are actually exploitable through techniques like function-level reachability analysis rather than reporting every theoretical issue3.
Harvard Business School estimates it would cost $8.8 trillion to replace open-source software with proprietary alternatives, highlighting why improving security tools rather than abandoning open-source is the only economically viable path forward4.
2️⃣ Hidden dependency chains represent the most challenging frontier in open-source security
The true security challenge in open-source isn’t just vulnerabilities in directly imported components, but the complex web of transitive dependencies they introduce—with 64% of open-source components being identified as transitive dependencies in recent audits5.
These indirect dependencies create a significant blind spot, as development teams often have limited visibility into dependencies that are multiple levels removed from their direct imports but still impact application security.
The complexity is exacerbated by maintenance issues, with 91% of audited applications containing outdated open-source components that may not receive security updates5.
Stay updated on the go with our mobile app.
Get latest insights with smoother, more personalized experience through TIA mobile app.




