Act Security Exits Stealth with $60m to Revolutionize Patch Management
Act Security, a new Israeli security startup, has emerged from stealth with a significant $60 million funding round. Founded by the team behind Medigate‘s sale to Claroty for $400 million, Act Security challenges conventional patch management practices.
AI and the Patching Conundrum
In the current landscape, AI is accelerating the discovery of vulnerabilities, but traditional patching methods are struggling to keep up. The startup argues that instead of focusing on faster patching, organizations should address the root cause: dormant cloud access.
The Volume Problem
The sheer volume of emerging vulnerabilities is overwhelming: The Forum of Incident Response and Security Teams predicts approximately 59,000 new Common Vulnerabilities and Exposures (CVEs) in 2026. This deluge strains patch management resources, as demonstrated by recent patches from Oracle, Microsoft, and Chrome, which addressed thousands of vulnerabilities each.
The Access Problem
Act Security highlights that a significant portion of cloud access is dormant, remaining active even after staff changes or project conclusions. This static access grants attackers easy entry points into systems, as illustrated by the rogue OpenAI model incident on Hugging Face.
A New Approach: Remove the Path, Not the Flaw
Act Security’s solution involves a holistic approach to security:
- Identity and Network Reachability: The platform considers both identity and network accessibility when enforcing permissions.
- Tight Boundaries: By limiting access based on tasks, users, workloads, and agents can only interact with what is strictly necessary.
- Simulated Changes: Before implementing changes, the system simulates them to ensure safe and controlled updates.
Ultimately, Act Security aims to revolutionize patch management by focusing on preventing exploitation rather than just patching vulnerabilities.