Act Security Aims to Tackle Cloud Vulnerability Challenges with $60 Million in Funding

Act Security emerges from stealth to address cloud security issues caused by AI-discovered vulnerabilities, armed with substantial funding and a novel approach.

ThreatVectr Newsdesk· 3 min read
Photoreal news-editorial style, 16:9 framing, full-frame edge-to-edge composition
Share

Key points

  • Act Security raised $60 million by July 2026 to address cybersecurity issues.
  • The company focuses on reducing exploitable access in cloud environments.
  • AI models are predicted to discover around 59,000 new vulnerabilities in 2026.

What's happening with AI and vulnerabilities?

Act Security, a company founded in 2025 in Tel Aviv, is addressing a new wave of challenges in cybersecurity caused by artificial intelligence (AI). AI systems are discovering new vulnerabilities, or software weaknesses, at an unprecedented rate. This trend is putting immense pressure on software vendors to develop and release patches, which are fixes to these weaknesses, to protect organizations. According to the Forum of Incident Response and Security Teams (FIRST), about 59,000 new vulnerabilities are expected to be found in 2026, which amounts to roughly 161 new issues daily.

How does Act Security plan to help?

Act Security aims to make cloud environments safer by reducing unnecessary access points that hackers could exploit. Instead of trying to patch every single vulnerability, the company focuses on limiting what can be accessed within a cloud environment. This is achieved by enforcing strict boundaries around AI systems and human users, ensuring they only access what is necessary. Jonathan Langer, co-founder and CEO of Act Security, highlights that nearly 97% of cloud permissions are unused, yet AI systems inherit these permissions, potentially leading to unintended consequences.

How are vendors coping with the surge in discovered vulnerabilities?

Software vendors are struggling to keep up with the rapid pace of vulnerability discovery driven by AI. In July 2026, Oracle released more than 1,400 patches, while Microsoft addressed a record 622 vulnerabilities. Google also patched 429 issues in a single update for its Chrome browser. Although vendors are working hard to release fixes, the sheer volume makes it challenging to protect organizations promptly before hackers can exploit these vulnerabilities.

Company Vulnerabilities Patched Date
Oracle 1,400+ July 2026
Microsoft 622 July 2026
Google 429 June 2026

Why is this important for businesses?

Businesses must understand the risks associated with cloud environments and AI. Act Security's approach can help them secure their cloud infrastructures by preventing hackers from exploiting unneeded access paths. By mapping controls to important security standards like NIST 800-53 and PCI DSS, the company also supports compliance efforts.

Common questions

How can businesses prepare for the surge in vulnerabilities?

Businesses should regularly review and limit cloud access permissions, ensuring they are necessary and justified.

What role does AI play in cybersecurity now?

AI systems are both a tool for discovering vulnerabilities and a potential risk if they are not properly managed and secured.

© 2026 Threat Vectr