Security News

Cybersecurity news aggregator

💰
INFO News SecurityWeek

Act Security Emerges from Stealth to Fight the Patch Problem

  • What: Act Security emerges to tackle AI-driven patch problems
  • Impact: Addresses growing challenges in vulnerability management
Read Full Article →

Funding/M&A Act Security Emerges from Stealth to Fight the Patch Problem Act Security tackles the spiraling patch problem caused by AI’s ability to find new vulnerabilities in existing cloud environments. By Kevin Townsend | July 28, 2026 (7:00 AM ET) Flipboard Reddit Whatsapp Whatsapp Email Keeping pace with new CVEs resulting from AI vulnerability discovery is a constant and losing battle . Founded in 2025, Tel-Aviv Israel based Act Security has emerged from stealth with total funding of $60 million. The funding comprises a $20 million Seed round led by Team8 and Bessemer Venture Partners (with participation from Hetz Ventures and Claltech); and a $40 million Series A round led by Notable Capital (with participation from Startpoint Capital and SVCI). Act Security tackles the spiraling patch problem caused by AI’s ability to find new vulnerabilities in existing cloud environments. It warns that organizations have accumulated massive access sprawl across their cloud environments, with the vast majority of granted cloud permissions unneeded and unused. These access paths are used by external attackers to exploit vulnerabilities, and untethered AI agents to perform unintended actions. The speed and scale at which frontier AI models find and allow bad actors to exploit new vulnerabilities is a major and increasing problem for security teams. The Forum of Incident Response and Security Teams (FIRST) projects roughly 59,000 new CVEs in 2026, which is –about 161 new vulnerabilities discovered every day. Software vendors attempt to keep pace with fixing these and releasing patches. This month Oracle announced more than 1,400 patched vulnerabilities in its July 2026 Critical Patch Update, while Microsoft announced patches for a record-breaking 622 vulnerabilities. In June, Google “promoted Chrome 149 to the stable channel with patches for 429 vulnerabilities, a record for a single Chrome refresh.” Vendors are struggling to keep up with this AI-induced surge in vulnerabilities. Enterprises are floundering under the weight of new patches. And bad actors are increasingly able to exploit vulnerabilities before the vendors can patch them. Act Security offers assistance by reducing or eliminating the access surface in cloud infrastructures that make unpatched vulnerabilities exploitable. It doesn’t patch the vulnerabilities but removes the potential for them to be exploited before they can be patched. Advertisement. Scroll to continue reading. The approach is to enforce deterministic boundaries that limit what humans, workloads, and AI agents can reach. “Based on what we are seeing from our customers, close to 97% of cloud access sits dormant and unused, and now AI agents are inheriting those same old human permissions, running around the clock, at machine speed, with none of the judgment a person would apply,” comments Jonathan Langer, co-founder and CEO of Act Security. “We can’t patch our way out of everything, no matter how hard we try. Visibility tools surface thousands of findings and leave teams triaging symptoms one by one, while the root cause, the access architecture, goes unaddressed. Instead of chasing findings, we remove the conditions that turn risk into a breach, making the cloud structurally secure before attacks unfold.” The Act Security platform enables enterprises to remove the exposed paths used by attackers; deploy their own agents safely by enforcing boundaries around AI workloads so they can only reach what they need; and achieve compliance by mapping directly to controls required by NIST 800-53, PCI DSS, HIPAA and more. Act was founded by Jonathan Langer (CEO), Itay Kirshenbaum (CTO), and Pini Pinhasov (CPO). This is the same team that founded Medigate in 2017 and sold it to Claroty for $400 million in January 2022. Related : Is Patching Dead? Vulnerability Management in the Post-Mythos Era Related : OpenAI Says Its AI Models Broke Loose and Hacked Hugging Face Related : SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch Related : CISA Urges Immediate Patching of Exploited SharePoint Vulnerabilities Written By Kevin Townsend Kevin Townsend is a Senior Contributor at SecurityWeek. He has been writing about high tech issues since before the birth of Microsoft. For the last 15 years he has specialized in information security; and has had many thousands of articles published in dozens of different magazines – from The Times and the Financial Times to current and long-gone computer magazines. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Kevin Townsend MedusaHVNC Malware Uses Hidden Windows Desktops to Evade Detection What’s Hiding in Your Mobile Apps? Lookout MSEC Aims to Find Out OpenAI Fixes ChatGPT Agent Flaw That Could Let Attackers Forge an AI Insider Vibe-Coded Apps Riddled With Exploitable Security Flaws Cisco Launches Low-Cost AI Models for Source Code Security CISO Conversations: Andreas Gaetje – From Economics to CISO at Körber AG AI Data Centers Are Being Built Faster Than They Can Be Secured Windows Bind Link Attacks Can Hide Malware From EDR Tools Latest News Microsoft Unveils MAI-Cyber-1-Flash, Its First Cybersecurity AI Model Hacker Conversations: Tal Kollander’s Journey From Black Hat to Hack Blocker Hush Security Raises $30 Million for AI Agent Governance Google Adopts New Threat Actor Naming System Unpatched Fastjson Vulnerability Exploited in Attacks Critical Arista VeloCloud Orchestrator Vulnerability Exploited as Zero-Day Origin Energy Data Breach Affects 900,000 Australians For Some, So-Called ‘Skynet Day’ Came too Close to Sci-Fi After a Rogue Agent Hacked Into a Startup Trending Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Closing the Exploitation Gap July 22, 2026 Join this live webinar as we explore why exploitation is outpacing remediation, where risk is growing fastest, and what security leaders can do to close the gap before attackers take advantage. Register Virtual Event: CodeSecCon 2026 August 19, 2026 CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps! Register People on the Move Barry Childe has joined data sciences tech company Datavault AI as Chief Information Security Officer. John DeSimone, the former CEO of Nightwing, has been named Chief Operating Officer at Everfox. Sectigo has appointed Prem Hareesh as Corporate Chief Technology Officer. More People On The Move Expert Insights Is Patching Dead? Vulnerability Management in the Post-Mythos Era You cannot out-patch a machine that writes a working exploit from a vulnerability description in twenty hours. Stop trying to optimize a game you cannot win. (Danelle Au) When Identity Verification Fails: Lessons from a Real-World SIM Swap and Near Account Takeover Identity confidence changes throughout every interaction and should be reassessed continuously as new risk signals emerge. (Torsten George) Legacy Systems, Real-World Impacts: The Reality of OT Security Legacy systems, safety concerns, and critical infrastructure risks make OT vulnerability disclosure one of cybersecurity's most challenging balancing acts. (Tod Beardsley) The Shift Toward Business-Aligned Risk Management Moving from isolated, technical data to a continuous risk lifecycle can help organizations align security controls with actual business consequences. (Steve Durbin) How to Conduct a Successful Audit of AI-Driven Software Development As AI-generated code becomes commonplace, CISOs need new audit strategies to measure developer practices, govern AI tool usage, and identify software risks before they reach production. (Matias Madou) Flipboard Reddit Whatsapp Whatsapp Email

Share this article