Act Security emerges to tackle access sprawl. However, it won't fix the patch problem with AI vulnerabilities increasing rapidly.
The cybersecurity landscape just got more alarming with Act Security's entrance into the fray. While the Tel Aviv-based firm aims to tackle the burgeoning issue of vulnerabilities proliferating in cloud environments, this may be an exercise in futility. With projections estimating around 59,000 new Common Vulnerabilities and Exposures by 2026, their strategy of reducing access sprawl offers little assurance against the real problem at hand: relentless and unchecked expansion of vulnerabilities.
Act Security claims to target the expansive access sprawl in cloud infrastructures, which is an undeniably valid point. However, the approach of merely reducing permissions raises skepticism. The core issue isn't the number of permissions granted but the vulnerabilities themselves. Access reduction can minimize risk, but it doesn't eliminate the risk of potentially exploitable software flaws, especially as new vulnerabilities emerge at a staggering rate. Organizations will still find themselves in the crosshairs of threat actors, armed with an ever-increasing arsenal of exploits that post-patch proliferation can't keep up with.
The reality is that the speed of vulnerability discovery is outpacing remediation efforts. Oracle’s announcement of over 1,400 patched vulnerabilities in July 2026 and Microsoft's record of 622 vulnerabilities patched in the same month illustrate a frantic response to an ongoing crisis. The patches themselves are symptoms of a far larger issue. With FIRST projecting 161 new CVEs daily, any claim from Act Security that access management could mitigate risks feels like trying to put a Band-Aid on a gaping wound. It isn’t addressing the lighting strike of new threats that could exploit both existing and newly discovered vulnerabilities.
No matter how effectively Act Security can reduce access or permissions in cloud environments, the stark truth is that unpatched vulnerabilities will continue to exist. Organizations, especially those playing catch-up in securing their cloud architectures, will struggle to keep pace with the influx of new vulnerabilities. An access management platform might help slightly; however, it won't substitute for the fundamental need for robust vulnerability management frameworks that can keep up in an environment where CVEs are not just numerous but evolving.
To truly stay ahead of attack vectors, organizations need to adopt a comprehensive approach that encompasses threat hunting, real-time monitoring, and adaptive response strategies. This dynamic includes empowering DevSecOps teams to prioritize crucial vulnerabilities over minor ones and ensuring that security operations are tightly integrated into the CI/CD pipelines. Act Security’s focus on permissions might be just a small part of a broader picture, but it doesn't fix the basic rule of thumb in cybersecurity: patch first, prevent second.
In conclusion, while the emergence of Act Security is a signal that cybersecurity firms are aware of the inadequacies in addressing modern vulnerabilities, their method of targeting access sprawl seems insufficient. The patch problem won’t disappear simply because access isn’t managed properly. As AI continues to exacerbate the growing list of vulnerabilities, organizations need to prepare for a long fight ahead, which involves more strategic planning, immediate action on patches, and a reaction to the continuously evolving threat landscape.