Act Security Emerges from Stealth to Revolutionize Patch Management
Act Security, a Tel Aviv-based cybersecurity startup, has revealed its operations after securing $60 million in funding, focusing on addressing vulnerabilities in cloud environments through proactive risk mitigation.
Company Founding and Funding
Founded in 2025, Act Security has secured $60 million in funding, including a $20 million seed round led by Team8 and Bessemer Venture Partners, with additional support from Hetz Ventures and Claltech, followed by a $40 million series A round spearheaded by Notable Capital, joined by Startpoint Capital and SVCI.
Funding Details
The financial backing highlights the growing demand for solutions to cloud security challenges, with the company targeting vulnerabilities exposed by artificial intelligence and excessive access permissions in cloud infrastructures.
The Escalating Vulnerability Challenge
Organizations face increasing risks due to unused access permissions in cloud environments, which attackers exploit. AI systems inherit these permissions, enabling unintended actions. The rapid pace of AI-driven vulnerability discovery outstrips traditional patching efforts, creating a critical gap for security teams.
Statistical Insights
FIRST, a global incident response organization, forecasts approximately 59,000 new Common Vulnerabilities and Exposures (CVEs) in 2026, equating to over 160 vulnerabilities discovered daily. Software vendors struggle to keep up, as seen in recent patch updates from Oracle, Microsoft, and Google.
Act Security’s Solution
Act Security’s platform minimizes the attack surface in cloud environments by enforcing strict access boundaries for humans, workloads, and AI systems. This approach ensures access is limited to necessary resources, addressing the root cause of vulnerabilities rather than relying on patching alone.
Proactive Risk Mitigation
“Patching alone is insufficient,” Langer stated. “Current visibility tools generate thousands of alerts, but they fail to address the root cause: flawed access architecture. Our approach eliminates the conditions that enable breaches by restructuring cloud security before threats materialize.”
Compliance and Security Standards
The platform helps enterprises remove exploitable access paths, deploy AI agents securely with restricted permissions, and meet compliance requirements aligned with standards such as NIST 800-53, PCI DSS, and HIPAA.
Company Leadership
Act Security was founded by Jonathan Langer (CEO), Stephan Goldberg (CPO), Itay Kirshenbaum (CTO), and Ilai Fallach (VP R&D). The team previously established Medigate in 2017, which was acquired by Claroty for $400 million in 2022.
Shifting Cybersecurity Priorities
Act Security’s strategy reflects a shift in cybersecurity priorities, emphasizing proactive risk mitigation over reactive patch management. As AI-driven vulnerability discovery accelerates, the need for structural security improvements in cloud infrastructures becomes increasingly urgent.
