Emerging from stealth mode, Act Security, a Tel Aviv-based company founded in 2025, is addressing the critical issue of AI-induced vulnerabilities in cloud environments. With a substantial total funding of $60 million, comprising a $20 million Seed round led by Team8 and Bessemer Venture Partners, and a $40 million Series A round led by Notable Capital, the firm is poised to make significant strides in cybersecurity.
Confronting the Cloud Vulnerability Epidemic
Act Security aims to reduce the severe patching challenges posed by artificial intelligence’s capacity to uncover new vulnerabilities. The company highlights a concerning accumulation of unnecessary cloud permissions, which can be exploited by both external attackers and AI agents lacking human judgment. This issue is compounded by the increasing speed at which AI models discover vulnerabilities, posing a hefty challenge for security teams.
According to the Forum of Incident Response and Security Teams (FIRST), approximately 59,000 new CVEs are projected for 2026, averaging 161 newly discovered vulnerabilities daily. This surge is placing immense pressure on software vendors to rapidly identify and patch these security risks.
The Struggle of Software Vendors
Software developers are finding it increasingly difficult to keep up with the barrage of new vulnerabilities. For instance, Oracle recently announced over 1,400 patched vulnerabilities in its July 2026 Critical Patch Update, while Microsoft released patches for a record-breaking 622 vulnerabilities. Google also made strides by promoting Chrome 149, which included patches for 429 vulnerabilities.
Despite these efforts, enterprises remain overwhelmed by the sheer volume of patches, while malicious actors continue exploiting weaknesses before they can be addressed. Act Security’s approach focuses on minimizing the exploitable access surface within cloud infrastructures, rather than directly patching vulnerabilities.
Innovative Solutions and Future Prospects
Act Security’s strategy involves implementing deterministic boundaries that restrict the reach of human users, workloads, and AI agents. According to CEO Jonathan Langer, a significant portion of cloud access is inactive, yet AI agents are inheriting these permissions, operating without the discernment humans apply.
The company’s platform offers the capability to eliminate exposed paths used by attackers, enforce secure boundaries around AI workloads, and ensure compliance with standards such as NIST 800-53, PCI DSS, and HIPAA. This proactive approach aims to structurally secure cloud environments before attacks can occur.
The founding team, consisting of Jonathan Langer, Itay Kirshenbaum, and Pini Pinhasov, previously established Medigate, which was acquired by Claroty for $400 million in January 2022. As Act Security moves forward, it promises to reshape how enterprises manage vulnerabilities in the rapidly evolving digital landscape.
