← All stories
● Covered by 1 source · 1 reportMedium impact1 neutral

Act Security Launches with $60 Million to Address Cloud Vulnerability Exploitation

🔄 Updated 1d ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Act Security raised $60 million in Seed and Series A funding.
  • The company addresses the exploitation of unpatched cloud vulnerabilities.
  • It reduces access sprawl to limit what humans, workloads, and AI agents can reach.
  • 97% of cloud access is dormant and unused, according to Act Security.

Act Security Emerges from Stealth

Act Security, founded in 2025 and based in Tel-Aviv, Israel, has officially launched from stealth mode. The company announced total funding of $60 million, secured through a $20 million Seed round and a $40 million Series A round. The Seed round was led by Team8 and Bessemer Venture Partners, with participation from Hetz Ventures and Claltech. Notable Capital led the Series A round, with participation from Startpoint Capital and SVCI.

Addressing the Patch Problem

Act Security aims to combat the increasing challenge of vulnerability exploitation in cloud environments, particularly those exacerbated by AI-driven vulnerability discovery. The company highlights that organizations have accumulated extensive access sprawl in their cloud infrastructures, with most granted permissions being unnecessary and unused. These excessive access paths are identified as a primary target for external attackers and untethered AI agents to exploit vulnerabilities.

The Challenge of Surging Vulnerabilities

The security industry faces a growing number of Common Vulnerabilities and Exposures (CVEs), partly due to the speed at which frontier AI models can identify new weaknesses. The Forum of Incident Response and Security Teams (FIRST) projects approximately 59,000 new CVEs in 2026, averaging 161 new vulnerabilities daily. Software vendors are struggling to keep pace with patching these, as evidenced by Oracle's 1,400 patched vulnerabilities in July 2026 and Microsoft's 622 patches, and Google's 429 patches for Chrome 149.

Act Security's Approach

Instead of patching vulnerabilities, Act Security focuses on reducing or eliminating the access surface in cloud infrastructures that makes unpatched vulnerabilities exploitable. The company's strategy involves enforcing deterministic boundaries to limit the reach of humans, workloads, and AI agents. Act Security states that close to 97% of cloud access remains dormant and unused, and AI agents are inheriting these same permissions, operating continuously at machine speed without human judgment.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~7 min · 6 stories · Aug 15

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

Act Security has emerged from stealth with $60 million in funding to tackle the problem of unpatched cloud vulnerabilities being exploited. The company focuses on reducing access sprawl in cloud environments to prevent the exploitation of vulnerabilities, rather than patching them directly.