The Daily Paper

Overnight desk: Night Shift

Friday, September 25, 2026 Morning Edition Tech · Business · AI

Above the fold

Executive summary

  • Island raised $400M Series F at a $6.4B valuation to expand from enterprise browser into an agentic control plane — one policy engine and audit trail across browsers, devices, apps, networks, and data.
  • Cyera took a $400M Goldman Sachs Growth Equity extension to Series G (>~$12B valuation) to unite data and identity for every human, machine, and AI agent — including endpoint agents like Claude Code and Cursor.
  • Databricks acquired Row Zero so Genie gets a native governed spreadsheet: live Unity Catalog data, Genie Ontology context, and auditable agent actions without “spreadmart” copies.
  • Snorkel AI closed a $350M Series E at $3.5B (ARR run rate ~$375M) to scale its agentic data-development platform for expert evaluation and last-mile adaptation.
  • UiPath launched Cartographer: a living Map of Work that turns process exceptions and judgment calls into build-ready agent/workflow specs with a Decision Ledger — owners approve every change.
  • Anthropic’s September threat report shows multi-agent frameworks now orchestrating recon, exploitation, and exfiltration for state and criminal actors — AI API keys treated as loot, compute, and cover.

Technology & business

Governance capital

Island’s $400M Series F: enterprise browser becomes agent control plane

Island priced a $400 million Series F on September 24 at a $6.4 billion valuation, led by Evolution Equity Partners. Existing backers including Sequoia, Coatue, Insight, Cyberstarts, J.P. Morgan Growth Equity, and CrowdStrike co-founder Dmitri Alperovitch joined. That follows a March 2025 Series E at $4.8 billion; CTech puts ARR near $200 million with roughly 1,000 employees and eight of the world’s ten largest banks on the enterprise browser.

The pitch has shifted. Island still starts at the browser, but now sells an “agentic control plane”: one policy engine and one audit trail across browsers, endpoints, apps, networks, and data. Enterprise AI adds identity controls, guardrails, human approvals, and cost limits for agents — model-agnostic. CTO Dan Amiga’s line is the product brief: agents do not live in one stack layer, so they cannot be governed from one.

Sources: The Next Web — Island $400M Series F, CTech — Island $6.4B valuation

AI security

Cyera’s $400M Goldman extension: data + identity for every agent

Cyera secured a $400 million investment from Growth Equity at Goldman Sachs Alternatives on September 24 as an extension to its Series G (led by Evolution Equity). The company is valued at more than $12 billion, with Accel, Blackstone, Cyberstarts, Georgian, Lightspeed, and Sequoia among prior backers. Capital funds the AI Security roadmap, federal expansion, and growth across EMEA and APAC.

Cyera’s bet is that agents are the fastest-growing security threat because they reason, adopt identities, call tools, and touch sensitive data at machine speed — while most security architecture still assumes people and apps. Agent Guardian and Cyera Endpoint track prompts, responses, tool calls, database queries, and actions from cloud to laptop, including local agents such as Claude Code and Cursor. The Oasis Security acquisition folds non-human identity management into the same system so enterprises can see where sensitive data sits and who or what can reach it.

Sources: FinTech Global — Cyera $400M Goldman

Enterprise data

Databricks buys Row Zero: governed spreadsheets for Genie (and agents)

Databricks announced on September 24 that it acquired Row Zero, the spreadsheet built for humans and agents to work on live data. Terms were undisclosed; Row Zero raised $10 million in May 2025. The product plugs into Genie — Databricks’ AI coworker — so finance, ops, sales, and marketing can explore, model, and collaborate in a familiar sheet while staying on Genie Ontology, Unity Catalog, and Unity Gateway.

The problem statement is blunt: every export into an ungoverned “spreadmart” is an ungoverned pipeline, and agents cannot safely act on sensitive data of unknown lineage. Row Zero connects directly to live sources, honors user permissions, can lock down exports, and keeps agent actions interpretable in spreadsheet syntax. CEO Ali Ghodsi told TechCrunch Databricks intends “many more” acquisitions like this after a busy 2026 shopping year (Quotient AI, SiftD, Panther, Electric/PGlite) and an August raise that pushed annualized revenue run rate to $7 billion.

Sources: Databricks — Row Zero acquisition, TechCrunch — Databricks buys Row Zero

Funding

Snorkel AI’s $350M Series E: expert data for agent evaluation and adaptation

Snorkel AI raised $350 million Series E at a $3.5 billion valuation, announced September 22 and widely covered by September 24. Insight Partners and S32 co-led, with significant participation from Addition; new investors include March Capital, Blumberg, Allegis, Frontline, Standard VC, and Third Point alongside Greylock, Lightspeed, GV, and others. Valuation nearly triples the $1.3 billion mark from its May 2025 $100 million round. Snorkel says it crossed an annualized revenue run rate of about $375 million after data-as-a-service grew more than 18-fold in roughly a year.

The company is pushing what CEO Alex Ratner calls Data 2.0 — last-mile, precisely targeted expert data for adaptation, alignment, evaluation, and long-running task environments that resist reward hacking — versus volume labeling. Its agentic data platform uses specialized models and agents to help human experts build datasets and training environments, then feeds human feedback back to improve those agents. Funding expands vertical and enterprise AI, new modalities, and open benchmarking.

Sources: Slator — Snorkel AI $350M Series E

Agent platforms

UiPath Cartographer: Map of Work for agents that actually know the process

UiPath launched Cartographer on September 23 as a generally available product for building a Map of Work — a living, governed artifact of how an enterprise process really runs, not how the slide deck says it should. Analysts capture documents, steps, rules, and exceptions through guided conversation; the Map becomes the customer-owned source of truth with a named owner who approves every change. From that Map, Cartographer generates design docs and build-ready specs for agents, workflows, and Maestro orchestration.

Runtime judgment calls land in a Decision Ledger and return as proposed Map updates — nothing auto-mutates production knowledge. Prebuilt Maps and a Process Atlas cover common industry flows (loan origination, claims, source-to-pay); highly governed orgs can build proprietary maps. Cartographer inherits UiPath Platform identity, security, and governance. Founder Daniel Dines framed the gap: enterprises digitized data without capturing the operational context of how that data is put to work.

Sources: UiPath — Cartographer Map of Work, UiPath IR — Cartographer launch

Threat intel

Anthropic threat report: multi-agent cyber ops treat AI keys as loot and compute

Anthropic’s September 2026 threat-intelligence report (covering December 2025–August 2026) documents how threat actors moved Claude from assistant to orchestrator across cyber, influence, surveillance, fraud, and related harm areas. Multi-agent frameworks now execute reconnaissance, exploitation, and exfiltration in parallel; humans still pick targets and review loot, but autonomy compresses attacker cost. Public offensive agent frameworks such as PentAGI reproduce scaffolding once limited to well-resourced state actors.

Case studies span suspected Russian espionage (GTG-20006) automating implant rebuilds when detections fire, ShinyHunters-linked smash-and-grab affiliates using “vibe hacking” to finish breaches in hours, and Chinese-speaking operators running agent swarms plus zero-day research loops. A recurring theme: stolen AI API keys are loot, free attack compute, and attribution cover — sometimes harvested via fake discounted Claude resellers. Anthropic says it disrupted the activity, hardened safeguards, and shared intel with partners; Haiku/Sonnet/Opus appeared in misuse cases, with Fable/Mythos largely absent aside from one distillation case.

Sources: Anthropic — September 2026 threat intelligence