Abnormal Security (Abnormal AI) - Experts & Thought Leaders
Latest Abnormal Security (Abnormal AI) news & announcements
Abnormal AI, the pioneer in AI-native behavioral security, announces the launch of Attune 1.0, a behavioral foundation model for cybersecurity. Trained on more than one billion derived behavioral signals, Attune now powers 85%1 of detections across the Abnormal Behavior Platform and establishes a shared intelligence layer for the company’s expanding security portfolio. Communication is how organizations build trust. Today, that trust is being weaponised by attackers using AI to launch campaigns that are highly personalized for each and every target. This evolution requires defenders to assume that every attack is a novel attack. Static threat intelligence Traditional security tools, which rely on rules and static threat intelligence, are struggling to keep pace with this shift. Attune 1.0 addresses this by bringing together Abnormal’s eight years of behavioral understanding into a single, unified model that is easier to manage and improve. "Attackers are leveraging AI to imitate trusted Behavior so convincingly that static rules and threat feeds struggle in the era of AI-driven attacks," said Evan Reiser, CEO and Co-Founder of Abnormal AI. "Attune 1.0 is how we close that gap—with a behavioral foundation model that understands normal organizational communication patterns. It gives customers a single intelligence layer that understands known good Behavior, catches what isn’t, and strengthens every product we ship as part of the Abnormal Behavior Platform.” Unified multimodal architecture Unlike earlier detection systems that treated identity, Behavior, and content as separate signals, Attune 1.0 utilizes a unified multimodal architecture. By learning these modalities jointly, the model better understands how signals reinforce or contradict one another to reveal patterns that attackers work hardest to hide. From inception, Abnormal has focused on knowing what’s normal in customers’ environments, enabling it to detect and block novel, AI-driven attacks when a deviation in Behavior is found. Key milestones of the Attune 1.0 milestone include: Efficacy Gains at Scale: Trained on large-scale behavioral signals, Attune is already detecting approximately 150,000 more attack campaigns per week than earlier systems, catching highly sophisticated messages that were previously undetectable. Higher Precision: By training on a larger volume of diverse data, the model delivers 50% higher precision compared to earlier systems. Stopping Novel Attack Campaigns: Attune recently identified and blocked a novel Microsoft Teams OAuth phishing campaign two months before it was publicly documented. Platform-Wide Intelligence: Attune already powers 85% of detections across the Abnormal Behavior Platform, providing higher precision and fewer false positives. This foundation establishes a shared behavioral layer across email, identity, and account takeover protection, catching more lateral attacks to better secure the entire employee lifecycle. Attune 1.0 is Generally Available today. Natural language descriptions With the release of Attune 1.0, Abnormal continues on its promise of delivering a powerful, automated AI engine designed to prevent modern email-based attacks. Alongside this automation, Abnormal is delivering greater visibility and control, so customers can understand the platform’s autonomous detections and fine-tune them when needed: Detection 360 Insights (GA): Provides visibility into the behavioral reasoning behind every AI determination, helping analysts understand exactly why a message was flagged. Custom AI Models (Early Access): Enables security teams to influence and control the AI by defining environment-specific patterns using simple natural language descriptions. This allows users to influence and augment the AI specific to their environment. Actual simulation interactions Abnormal is also delivering updates for AI Phishing Coach, transforming how organizations manage the human element of security and best train their employees. Abnormal is replacing one-size-fits-all compliance training with an automated, AI-driven system that helps turn real-world threats into personalized coaching. As the underlying behavioral layer within Abnormal improves, our ability to train on those results also improves: Phishing Risk Scoring (GA): Provides a continuously updated phishing-readiness signal based on actual simulation interactions, reporting activity, and training outcomes. BEC and VEC Simulations (GA): New simulation types, with data from the Abnormal relationship graph, mirror manager, colleague, and vendor interactions.
Abnormal AI, the pioneer in AI-native human behavior security, announced it has been recognized as a Leader in the 2025 Gartner® Magic Quadrant™ for Email Security, marking the company’s second consecutive year in the Leaders Quadrant. Gartner evaluated vendors based on their Completeness of Vision and Ability to Execute. Among 14 vendors evaluated, Abnormal was placed furthest right on the Vision axis. API-based approach In the report, Gartner highlights that “the high volume of sophisticated, email-enabled social engineering attacks, combined with the difficulty in consistently quantifying true detection efficacy across the market, justifies organizations utilizing multiple vendors for comprehensive protection.” To better combat these sophisticated threats, there is growing potential in solutions that utilize behavioral AI and natural language processing to analyze user behavior and help detect anomalies. The Abnormal Behavior Platform analyzes identity, behavior, and contextual signals in order to baseline normal activity and help identify deviations indicative of malicious activity. This API-based approach is designed to enable autonomous protection against a wide range of attacks — including business email compromise, credential phishing, and account takeover — without requiring cumbersome mail routing changes or complex configurations. AI-native approach “Being named a Leader in the Gartner Magic Quadrant for the second year in a row—while maintaining the furthest placement on Vision—is an incredible milestone for us,” said Evan Reiser, chief executive officer of Abnormal AI. “We’re proud to see our AI-native approach continuing to drive innovation and impact as we build toward a future where understanding human behavior is the cornerstone of keeping people and organizations safe.” AI Phishing Coach and AI Data Analyst This recognition follows a year of exceptional growth and innovation for Abnormal AI. In 2025, Abnormal launched its first autonomous AI agents—AI Phishing Coach and AI Data Analyst—to help organizations detect, remediate, and train themselves against threats in real time. The company also achieved FedRAMP Moderate Authorization and earned the ISO/IEC 42001 AI governance certification, underscoring its commitment to both security and responsible AI. Abnormal now protects more than 25% of the Fortune 500 and continues its global expansion, recently entering new markets in Germany, Japan, and France. The year also brought strong industry and customer validation—from featuring on the CNBC Disruptor 50, to the Forbes Cloud 100, and the Fortune Cyber 60. Abnormal was also named a Gartner Peer Insights™ Customers’ Choice for Email Security Platforms in July 2025, earning a 99% “Would Recommend” rating and, in our opinion, reaffirming the trust placed in Abnormal’s AI-native approach.
Abnormal AI, the pioneer in AI-native human behavior security, announced its updated Security Posture Management product, bringing AI-driven protection, automated prioritization, and remediation guidance to customers’ Microsoft 365 environments. As Microsoft 365 environments become more complex, accidental misconfigurations are now a major cause of cloud email vulnerabilities. The growing number of applications, layered settings, and fragmented ownership create blind spots and accidental openings that threat actors like Midnight Blizzard have exploited in the past. Microsoft 365 integration The new Security Posture Management add-on continuously detects misconfigurations across users, apps With deep Microsoft 365 integration and a proven ability to stop advanced email threats, Abnormal is ideally positioned to uncover these configuration risks. The new Security Posture Management add-on continuously detects misconfigurations across users, apps, and tenants, giving security teams the visibility and control they need to stay ahead of attackers. “Thousands of organizations rely on Abnormal to stop email-based attacks like phishing and account compromise. But attackers are also exploiting misconfigurations to bypass phishing defenses,” said Evan Reiser, CEO of Abnormal AI. Detect hidden risks “Because we already integrate deeply with Microsoft 365 to protect inbound email, we can extend our API-based architecture to detect these hidden risks. Security Posture Management gives security teams continuous visibility into misconfiguration risks across their entire Microsoft 365 environment,” continued Evan Reiser. Key capabilities include: Comprehensive Visibility: Continuously uncovers risky Microsoft 365 misconfigurations using CIS benchmarks and Abnormal threat intelligence. Automated Prioritization: Surfaces the most dangerous risks first by factoring in impact, prevalence, and environment. Remediation Guidance: Provides clear, actionable fixes with no manual audits or scripting. Additional Resources: Visit Abnormal at Black Hat 2025: Abnormal will be showcasing new Security Posture Management capabilities throughout the week at the CyBRR Cafe, located in front of the Expo Hall at Mandalay Bay.