Act Security emerges from stealth mode with $60 million aimed at resolving the patch issue.
A new Israeli security startup has come out of stealth mode with $60 million in funding. It presents a proposition that the industry has resisted for many years: it's time to stop trying to patch your way to safety.
According to a report by Calcalist, Act Security made its debut on Tuesday. Founded in 2025 by the same team that sold Medigate to Claroty for around $400 million, the company's message is straightforward: AI has compromised cloud defenses on two fronts, and the solution lies in reducing access rather than accelerating patching efforts.
Reasons why patching is no longer effective
The first issue is the sheer volume of vulnerabilities. As advanced models become more adept at identifying exploitable flaws, new vulnerabilities are accumulating more quickly than they can be addressed. As noted by SecurityWeek, the Forum of Incident Response and Security Teams anticipates approximately 59,000 new CVEs this year, translating to around 161 each day.
The overwhelming number of patches illustrates this pressure. In a recent cycle, Oracle addressed over 1,400 vulnerabilities, while Microsoft released 622 patches, a record for them, and Chrome fixed 429 in a single update. This mirrors the trend observed when AI-discovered vulnerabilities started increasing at twice the rate of the previous year.
Jonathan Langer, the CEO of Act, stated that Anthropic’s Mythos confirmed their position. "We can’t patch our way out of everything," he noted. He added that visibility tools "surface thousands of findings," yet the underlying issue of access architecture remains unaddressed.
The second challenge is access. Over the years, organizations have granted cloud permissions that often go unused. As staff move between roles and projects conclude, these permissions linger. Act claims that nearly 97% of cloud access among its clients is inactive. However, the moment an attacker gains entry, this access becomes a threat.
AI agents can exploit this dormant access, operating at machine speed and inheriting whatever permissions the account provides. A misconfigured agent may access systems it shouldn't, while a hijacked one can swiftly traverse the entire environment. This lateral movement is analogous to how a rogue OpenAI model spread through Hugging Face. Agents, Langer explained, "operate at machine speed, without the judgment a human would apply."
Eliminating the pathway, not just the flaw
Act proposes a different approach: rather than pursuing individual vulnerabilities, the focus should be on removing the factors that make them exploitable. The company considers identity and network accessibility together, reasoning that a permission is only significant if a path to the resource exists. Consequently, the platform establishes strict boundaries around each user, workload, and agent, allowing access only to what is necessary for their tasks.
It implements these restrictions using the existing cloud controls of an organization. Additionally, it integrates these measures into software pipelines, preventing the re-emergence of sprawl. Importantly, the platform simulates changes before they are applied. This is a lesson learned from Medigate's founders, who secured hospital devices that could not afford downtime; a too-restrictive rule can disrupt business operations just as easily as a loose rule can lead to a breach.
A competitive landscape
The funding is substantial, with Team8 and Bessemer Venture Partners leading the $20 million seed round. Notable Capital spearheaded the $40 million Series A, with support from Lux Capital. This funding comes in the midst of a surge in Israeli access-security investments, including Way Security and Mate Security.
However, the market is already crowded, which presents a challenge. Existing players are already offering cloud posture management, entitlement management, and attack-path analysis. Thus, Act's success hinges on navigating the most difficult aspect of the task: ensuring safer access without disrupting legitimate operations. If they can demonstrate this in a real-world setting, action-centric security could emerge as a viable category. If not, it may simply add another dashboard to a market that is already oversaturated.
Другие статьи
Act Security emerges from stealth mode with $60 million aimed at resolving the patch issue.
Act Security steps out of stealth mode with $60 million from the founders of Medigate. The wager: AI advances faster than patching, allowing for the elimination of dormant cloud access vulnerabilities.
