AI & TechArtificial IntelligenceBusinessCybersecurityMENA Tech SceneNewswire

Act Security raises $60M to eliminate software patching

▼ Summary

– Israeli startup Act Security launched with $60M, arguing that traditional patching is no longer effective against AI-driven vulnerabilities.
– AI has increased vulnerability discovery rates, with 59,000 new CVEs projected this year, overwhelming teams that cannot patch fast enough.
– Nearly 97% of cloud access permissions at Act’s customers are dormant, creating exploitable pathways for AI agents that operate at machine speed.
– Act’s solution removes exploitable conditions by tightly restricting access per user, workload, and agent, using existing cloud controls and simulating changes before enforcement.
– The $60M funding came from Team8, Bessemer, Notable Capital, and Lux Capital, but Act faces a crowded market where success depends on enforcing safer access without disrupting operations.

A fresh Israeli cybersecurity startup is exiting stealth mode with $60 million in funding and a provocative claim the industry has long resisted: stop trying to patch your way to safety, because it no longer works.

Act Security officially launched on Tuesday, as reported by Calcalist. Founded in 2025 by the same team that sold Medigate to Claroty for roughly $400 million, the company argues that AI has fractured cloud defense from both sides. Its proposed remedy is simple: grant less access, rather than racing to fix every flaw.

Why patching fell short

The first issue is sheer volume. As frontier AI models grow more adept at uncovering exploitable weaknesses, the number of new vulnerabilities is outpacing any organization’s ability to fix them. According to SecurityWeek, the Forum of Incident Response and Security Teams projects roughly 59,000 new CVEs this year, or about 161 per day.

The latest patch cycles illustrate the strain. In one recent batch, Oracle alone addressed more than 1,400 vulnerabilities. Microsoft set a record by patching 622 flaws, while Chrome fixed 429 in a single release. This follows a pattern we saw earlier, when AI-discovered vulnerabilities arrived at twice last year’s rate.

Act’s CEO, Jonathan Langer, points to Anthropic’s Mythos as confirmation. “We can’t patch our way out of everything,” he said. Visibility tools, he added, “surface thousands of findings” while “the root cause, the access architecture, goes unaddressed.”

The 97% problem

The second obstacle is access sprawl. Over time, companies have issued cloud permissions that then sit unused. Employees change roles, projects end, and the access lingers. Act reports that nearly 97% of cloud access at its customers is dormant. It stays live, though, and becomes an open door the moment an attacker breaches the perimeter.

AI agents turn that quiet sprawl into a live threat. An agent inherits the permissions of whatever account it runs under, then operates around the clock at machine speed. A misconfigured agent can reach systems it should never touch. A hijacked one becomes a fast route across the entire environment, mirroring the lateral movement that let a rogue OpenAI model spread through Hugging Face. Agents run, Langer said, “at machine speed, with none of the judgment a person would apply.”

Remove the path, not the flaw

Act’s solution is to stop chasing individual vulnerabilities and instead remove the conditions that make them exploitable. It reasons over identity and network reachability together. A permission only matters if there is also a path to the resource. So the platform draws tight boundaries around each user, workload, and agent, limiting each to only what its task requires.

It enforces those limits through the cloud controls a company already runs, and pushes them into software pipelines to prevent sprawl from returning. Critically, it simulates a change before applying it. That lesson comes from Medigate, whose founders once secured hospital devices that could not tolerate downtime. An over-tight rule can break a business as surely as a loose one invites a breach.

A crowded bet

The funding is serious. Team8 and Bessemer Venture Partners led the $20 million seed round. Notable Capital led the $40 million Series A, with Lux Capital also participating. The raise joins a wave of Israeli access-security deals, from Way Security to Mate Security.

It is also a crowded field, and that is the challenge. Incumbents already sell cloud posture management, entitlement management, and attack-path analysis. So Act’s edge rests on the hardest part of the job: enforcing safer access without breaking something legitimate. Prove that in production, and action-centric security becomes a real category. Fail, and it is just one more dashboard in a market that already has too many.

(Source: The Next Web)

Topics

ai vulnerability discovery 95% cloud access security 93% patching ineffectiveness 92% ai agent threats 91% access architecture fix 90% startup funding 88% dormant permissions 87% attack path analysis 86% security automation 84% zero trust implementation 83%
Show More