Act Security emerges from stealth mode with $60 million to address the patching issue.

Act Security emerges from stealth mode with $60 million to address the patching issue.

      A new Israeli security startup has emerged from stealth mode with $60 million in funding, presenting an argument that the industry has long resisted: it is no longer effective to rely solely on patching for safety, and companies should stop trying to do so.

      Act Security officially launched on Tuesday, as reported by Calcalist. Established in 2025 by the team that sold Medigate to Claroty for around $400 million, its premise is straightforward: advancements in AI have rendered traditional cloud defenses ineffective from two angles, and the solution lies in limiting access rather than simply accelerating the patching process.

      Reasons Patching is Ineffective

      The primary issue is the sheer volume of vulnerabilities. As cutting-edge models improve at detecting exploitable flaws, new vulnerabilities are emerging at a pace that exceeds the ability to address them. The Forum of Incident Response and Security Teams estimates about 59,000 new Common Vulnerabilities and Exposures (CVEs) this year, according to SecurityWeek, translating to approximately 161 per day.

      The strain on patching is evident in the volume of fixes. In a recent patch cycle, Oracle alone addressed over 1,400 vulnerabilities, while Microsoft issued a record 622 patches and Chrome fixed 429 in one update. This mirrors the trend observed when AI-detected vulnerabilities began appearing at double the rate observed last year.

      Jonathan Langer, Act’s CEO, noted that Anthropic’s Mythos corroborated this viewpoint. “We can’t patch our way out of everything,” he asserted. He emphasized that visibility tools “surface thousands of findings” while neglecting the fundamental issue: the access architecture remains unexamined.

      Another significant challenge is access. Over time, organizations have granted cloud permissions that often go unused. As staff change roles and projects conclude, these access permissions linger. Act claims that nearly 97% of cloud access among its clients is dormant and becomes active the moment an attacker gains entry.

      AI agents are able to exploit this dormant access, inheriting the permissions of the accounts they operate under and functioning continuously at machine speed. A misconfigured agent can access systems it shouldn’t, while a hijacked agent can quickly traverse the entire environment, similar to the lateral movement that allowed a rogue OpenAI model to proliferate through Hugging Face. As Langer pointed out, agents operate “at machine speed, without the judgment that a human would apply.”

      Focus on Removing Access Paths Rather Than Flaws

      Act's solution revolves around ceasing the pursuit of individual vulnerabilities and instead eliminating the conditions that render them exploitable. It considers identity and network accessibility in tandem, positing that a permission is only relevant if there is also a path to the resource. Consequently, the platform establishes strict boundaries around each user, workload, and agent, allowing each to access only what is necessary for their respective tasks.

      These limits are enforced using existing cloud controls that companies already employ, while also integrating them into software pipelines to prevent sprawl from recurring. Crucially, it simulates any changes before implementing them. This approach reflects the lessons learned from Medigate, where its founders secured hospital devices that could not afford downtime; an overly stringent rule could disrupt business operations just as easily as a loose one could lead to a breach.

      A Competitive Investment

      The financing is significant, with Team8 and Bessemer Venture Partners spearheading the $20 million seed round. Notable Capital led the $40 million Series A, with Lux Capital also providing support. This funding comes amidst a surge of Israeli access-security initiatives, including Way Security and Mate Security.

      However, the landscape is highly competitive. Established companies already offer cloud posture management, entitlement management, and attack-path analysis. Therefore, Act's advantage hinges on successfully implementing safer access without disrupting legitimate operations. If they can validate this approach in real-world applications, action-centric security could emerge as a legitimate category. Conversely, failing to do so might result in their solution becoming just another dashboard in a saturated market.

Other articles

eBay agrees to pay $56 million regarding its harassment campaign involving bloody pig masks. eBay agrees to pay $56 million regarding its harassment campaign involving bloody pig masks. eBay and three former executives will compensate the couple they harassed with cockroaches and a bloody pig mask nearly $56 million. The more significant consequence: no non-disclosure agreement. Shein reveals that it is under investigation by the FTC while attempting to go public. Shein reveals that it is under investigation by the FTC while attempting to go public. Shein revealed an unpublicized FTC consumer-protection investigation in its IPO filing in Hong Kong. The agency oversees 'dark patterns', which are the deceptive techniques utilized by Shein's app. AI transformed a disgraced President, who is under house arrest, into a live avatar for a new election campaign. AI transformed a disgraced President, who is under house arrest, into a live avatar for a new election campaign. An AI-generated version of Jair Bolsonaro publicly supported his son's presidential campaign, even though the former Brazilian president is under house arrest, banned from elections, and facing limitations on public communication. Apple's new Upgrade plan will not impose restrictions for missed payments; however, accumulating three missed payments could result in the termination of your lease. Apple's new Upgrade plan will not impose restrictions for missed payments; however, accumulating three missed payments could result in the termination of your lease. Apple states that missed payments on its Klarna-supported Upgrade plan will not limit app access or device functionalities; however, three consecutive missed payments may result in the termination of the lease. Apple reaches a $5 trillion valuation by avoiding the competition in AI spending. Apple reaches a $5 trillion valuation by avoiding the competition in AI spending. Apple briefly reached a $5 trillion valuation, becoming only the second company to achieve this milestone, as investors moved away from the AI capital expenditure frenzy towards the one major player that remained on the sidelines. eBay agrees to pay $56 million regarding its harassment campaign involving bloody pig masks. eBay agrees to pay $56 million regarding its harassment campaign involving bloody pig masks. eBay and three former executives will pay close to $56 million to the couple they tormented with cockroaches and a bloody pig mask. The larger consequence: no nondisclosure agreement.

Act Security emerges from stealth mode with $60 million to address the patching issue.

Act Security emerges from stealth with $60 million investment from the founders of Medigate. The strategy is that AI will advance faster than patching, allowing them to eliminate the existing dormant cloud access vulnerabilities.