Keeping pace with new CVEs resulting from AI vulnerability discovery is a constant and losing battle.
Founded in 2025, Tel-Aviv Israel based Act Security has emerged from stealth with total funding of $60 million. The funding comprises a $20 million Seed round led by Team8 and Bessemer Venture Partners (with participation from Hetz Ventures and Claltech); and a $40 million Series A round led by Notable Capital (with participation from Startpoint Capital and SVCI).
Act Security tackles the spiraling patch problem caused by AI’s ability to find new vulnerabilities in existing cloud environments. It warns that organizations have accumulated massive access sprawl across their cloud environments, with the vast majority of granted cloud permissions unneeded and unused. These access paths are used by external attackers to exploit vulnerabilities, and untethered AI agents to perform unintended actions.
The speed and scale at which frontier AI models find and allow bad actors to exploit new vulnerabilities is a major and increasing problem for security teams. The Forum of Incident Response and Security Teams (FIRST) projects roughly 59,000 new CVEs in 2026, which is –about 161 new vulnerabilities discovered every day.
Software vendors attempt to keep pace with fixing these and releasing patches. This month Oracle announced more than 1,400 patched vulnerabilities in its July 2026 Critical Patch Update, while Microsoft announced patches for a record-breaking 622 vulnerabilities. In June, Google “promoted Chrome 149 to the stable channel with patches for 429 vulnerabilities, a record for a single Chrome refresh.”
Vendors are struggling to keep up with this AI-induced surge in vulnerabilities. Enterprises are floundering under the weight of new patches. And bad actors are increasingly able to exploit vulnerabilities before the vendors can patch them. Act Security offers assistance by reducing or eliminating the access surface in cloud infrastructures that make unpatched vulnerabilities exploitable. It doesn’t patch the vulnerabilities but removes the potential for them to be exploited before they can be patched.
The approach is to enforce deterministic boundaries that limit what humans, workloads, and AI agents can reach. “Based on what we are seeing from our customers, close to 97% of cloud access sits dormant and unused, and now AI agents are inheriting those same old human permissions, running around the clock, at machine speed, with none of the judgment a person would apply,” comments Jonathan Langer, co-founder and CEO of Act Security.
“We can’t patch our way out of everything, no matter how hard we try. Visibility tools surface thousands of findings and leave teams triaging symptoms one by one, while the root cause, the access architecture, goes unaddressed. Instead of chasing findings, we remove the conditions that turn risk into a breach, making the cloud structurally secure before attacks unfold.”
The Act Security platform enables enterprises to remove the exposed paths used by attackers; deploy their own agents safely by enforcing boundaries around AI workloads so they can only reach what they need; and achieve compliance by mapping directly to controls required by NIST 800-53, PCI DSS, HIPAA and more.
Act was founded by Jonathan Langer (CEO), Stephan Goldberg (CPO), Itay Kirshenbaum (CTO), and Ilai Fallach (VP R&D).. This is the same team that founded Medigate in 2017 and sold it to Claroty for $400 million in January 2022.
Related: Is Patching Dead? Vulnerability Management in the Post-Mythos Era
Related: OpenAI Says Its AI Models Broke Loose and Hacked Hugging Face
Related: SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch
Related: CISA Urges Immediate Patching of Exploited SharePoint Vulnerabilities

Leave A Comment