×

Book a Demo

*First Name

*Last Name

*Work Email

*Company

Tell Us How We Can Be Successful Together

Submit →

Thank you. The form was submitted successfully. You can now close this modal.

BLOG

Mimic x Cosine: Built for the Real Threat Landscape

Mimic and Cosine partner to combine Red Teaming and Virtual Patching to take on today’s cyberthreats

August 12, 2026

Last week at Black Hat, Mimic and Cosine announced their partnership.  Mimic will integrate Cosine’s Lumen Sovereign into its platform to perfect virtual patching. This comes at a crucial time in cybersecurity, as enterprise patch cycles still run 30 to 45 days, while the average vulnerability is exploited in hours.

The Evolving Threat Landscape

During a dinner at Black Hat hosted by Mimic, Kevin Mandia spoke about the evolving threat landscape. He made the point that this landscape has changed and red teaming as well as enforcement must now run at machine speed because that’s the speed at which the attacks run. Moving faster than the traditional cycle compresses the feedback loop, taking the human out of the loop just long enough to give security teams time to test and get into a normal patch cycle instead of scrambling under pressure.

A theme that came up repeatedly during the dinner was speed of testing. There's a real parallel between what red teaming is doing to compress the feedback loop on offense and what virtual patching does on defense: both are about moving faster than the traditional cycle allows. The two approaches complement each other well: red teaming stress-tests where you're exposed, and virtual patching gives you a way to actually close that exposure without waiting on a vendor timeline.

The idea that resonated most was taking the human out of the critical path just long enough to matter. Mimic Virtual patching buys a security team real time; time to properly test a fix and time to work it into a normal patch cycle, instead of scrambling under pressure. And there's a practical advantage that's easy to overlook: reverting one of our patches is simple if something doesn't work as expected. Reverting a vendor patch, once it's out in production, is a much harder and messier proposition

How Mimic and Cosine Work Together

Powered by Lumen Sovereign, an LLM trained specifically for cybersecurity, Cosine’s AI-native Red Team acts as an autonomous adversary, mapping attack surfaces, running adversarial exploitation against the exact scope a customer approves, and finding and proving exact exploit paths in a customer’s environment. Instead of waiting weeks for a vendor patch, Mimic instantly neutralizes the threat at the kernel level. Enforcing known-good behavior, it blocks unauthorized changes, stopping any variant of the original exploit. Rather than evaluating whether a change matches a known attack, Mimic evaluates whether a change was authorized, allowing the mitigation to cover variants of the same technique rather than only the proof of concept that was demonstrated. Cosine's Red Team then automatically retests the attack path, definitively proving the vulnerability is closed.

Crucially, this capability is built for environments where data cannot leave the perimeter. Because Cosine's Lumen models can run entirely on-premises under the customer's complete control, including in fully air-gapped, no-connectivity environments, this joint solution reaches UK, EU, defence, and highly regulated organizations that cloud-hosted AI simply can't serve. 

Mimic's virtual patch is just as easy to rollback as it is to apply. Vendor patches don't offer the same flexibility. Once a vendor patch is deployed and something breaks, undoing them often means a second maintenance window, a rollback plan of its own, or living with the fallout until the next release Mimic’s flexibility is precisely what flips the traditional patching response model: instead of racing to patch thousands of servers before an exploit lands (and accepting the operational risk that comes with pushing vendor patches broadly and fast), teams can push a Mimic rule that blocks the malicious behavior immediately, then patch the underlying vendor software on their own schedule. If that virtual patch turns out to be too aggressive or causes unexpected friction, backing it out doesn't cost another change window or a custom rollback plan; it costs retracting the same rule applied minutes or hours earlier.

Speed is Power

This lands at a moment when speed isn't optional; it's the difference between staying ahead of attackers and falling behind them. By connecting AI-driven exploit discovery to kernel-level enforcement, the partnership turns a finding from a line in a report into a durable control.

A man and woman working at a desk

See why the world's most targeted organizations trust Mimic to protect what matters most.