Act Security's Ploy to Tackle Cloud Vulnerabilities Lacks Substance Amid AI Surge
VENDOR ADVISORY PERSONA OP ED MARA-BELL

Act Security's Ploy to Tackle Cloud Vulnerabilities Lacks Substance Amid AI Surge

Act Security aims to address cloud vulnerabilities, but their approach raises questions about effectiveness amidst a looming surge of AI-driven CVEs.

Act Security Emerges from Stealth

Act Security, a new entrant in the cybersecurity landscape, has recently emerged from stealth mode with a focus on addressing vulnerabilities exacerbated by artificial intelligence within cloud environments. The firm, founded in 2025 and based in Tel Aviv, has secured $60 million in funding, which includes a notable $20 million seed round and a $40 million Series A round. This funding is intended to tackle critical issues related to access sprawl in cloud infrastructures, a problem that has significantly increased the number of unnecessary permissions that attackers can exploit. However, the effectiveness of their proposed solutions remains a cause for skepticism, particularly in light of the trajectory of vulnerability discovery as AI technologies continue to evolve.

The Looming Vulnerability Crisis

The urgency of the vulnerability crisis cannot be overstated. According to projections from the Forum of Incident Response and Security Teams (FIRST), around 59,000 new Common Vulnerabilities and Exposures (CVEs) are anticipated to be discovered in 2026, which translates to a staggering approximate rate of 161 new vulnerabilities daily. Leading software vendors such as Oracle and Microsoft have publicly recognized this mounting challenge by issuing significant patches, with Oracle reporting over 1,400 patched vulnerabilities during its July 2026 update and Microsoft documenting 622 in the same month. These responses, while commendable, spotlight the difficulty organizations face in keeping up with this surge in vulnerabilities, raising fundamental questions about the overall effectiveness of existing mitigation strategies.

Act Security’s Access Sprawl Approach

Act Security's strategy predominantly revolves around minimizing access surfaces within cloud environments to mitigate the risks posed by unpatched vulnerabilities. While this is a noteworthy initiative, it is crucial to assess whether such a preventative approach can truly stem the tide of vulnerabilities that organizations are grappling with. The concerns regarding access proliferation are valid—excess permissions can lead to substantial security gaps—but without a directly effective method to patch or address known vulnerabilities, the company’s approach may fall short in the long run. The question looms large: can reducing access effectively counter the rapid increase in exploitable vulnerabilities, particularly those emerging from AI advancements?

The Tech vs. Management Divide

Crucially, the challenges presented by AI-driven vulnerabilities emphasize that cybersecurity is as much a management problem as it is a technological one. Organizations face a pressing need not only for robust technology solutions but for sound governance frameworks that ensure proper risk management. The growing reliance on cloud environments demands careful oversight of access controls and permissions. Act Security's emphasis on mitigating access risks is pertinent, but it should not overshadow the need for comprehensive vulnerability management processes. Detailing how their strategies align with broader governance frameworks will be vital for establishing both credibility and effectiveness.

Assessing Accountability in Cybersecurity

Moreover, the emergence of firms like Act Security introduces an important conversation about accountability within cybersecurity. As technology evolves, so too must the responsibilities of organizations in managing their security postures. The failure to properly patch vulnerabilities is symptomatic of broader systemic failures within organizations, often exacerbated by a lack of clear accountability. While Act Security positions itself as a solution provider, it is imperative for stakeholders to carefully evaluate how these emerging entities plan to navigate the complexities of operational risk management and accountability moving forward. The cybersecurity landscape demands that all players, old and new, are ready to face these pressing challenges or risk becoming part of the problem rather than the solution.

The Takeaway for Leaders

In conclusion, Act Security's emergence in addressing the pressing need for cloud security solutions is a welcome development, yet its effectiveness remains uncertain against the backdrop of an impending wave of AI-driven vulnerabilities. As organizations forecast a significant uptick in CVEs, leadership must prioritize not only the adoption of innovative solutions but also ensure that these solutions are embedded within solid governance frameworks. The gap between access control and vulnerability management must be bridged. As stakeholders assess Act Security and similar firms, a thorough examination of accountability measures and the integration of risk management processes will be fundamental to navigating the complex landscape of cybersecurity vulnerabilities. Leaders are advised to monitor these developments closely, ensuring proactive strategies are in place that address the nuances of both technology and management in their security governance efforts.

This perspective is generated by AI and represents an analytical viewpoint based on current industry trends and data.

Sources

https://www.securityweek.com/act-security-emerges-from-stealth-to-fight-the-patch-problem

4 MIN READ  ·  734 WORDS  ·  ID:8934
// ANALYST
Mara Bell
Mara Bell, Governance Editor
Mara treats cybersecurity like a board-level risk discipline and assumes every shiny claim needs a compliance trail.
← BACK TO ALL ARTICLES act-security-cloud-vulnerabilities-s4342-mara-bell