AI Is Finding Software Flaws Faster Than Companies Can Fix Them. One Startup Just Raised $60 Million to Help

Act Security wants to shrink the gap between a vulnerability being discovered and a hacker finding it first, by locking down the parts of cloud systems that nobody actually uses.

AI2Day Newsdesk4 min read
Photoreal news-editorial 16:9 image of a vast server room at night, rows of glowing rack-mounted hardware receding into darkness, cool blue and amber indicator
Share

Key points

  • Act Security, founded in Tel Aviv in 2025, raised $60 million by July 2026 to tackle cloud security risks created by AI.
  • Around 59,000 new software vulnerabilities are expected to be discovered in 2026, roughly 161 per day, according to the Forum of Incident Response and Security Teams.
  • In July 2026 alone, Oracle patched more than 1,400 flaws, Microsoft fixed 622, and Google addressed 429 in a single Chrome browser update.
  • Act Security argues that 97% of cloud permissions, the access rights granted to software and users, sit unused and create unnecessary risk.

Artificial intelligence can now scan vast stretches of code in hours. That speed is genuinely useful for defenders. It also means attackers have a powerful new tool for finding weaknesses, and the number of vulnerabilities, meaning flaws in software that hackers can exploit, is climbing fast.

As first reported by ThreatVectr, a cybersecurity news outlet, Act Security raised $60 million to address exactly this problem. The Tel Aviv startup, founded in 2025, believes the traditional approach of patching every flaw cannot scale quickly enough.

How bad is the vulnerability problem right now?

Very bad, and getting worse. The Forum of Incident Response and Security Teams expects roughly 59,000 new software vulnerabilities to surface in 2026 alone. That works out to about 161 fresh problems every single day.

The scale shows up clearly in the patch totals the big vendors published this summer.

Company Flaws patched When
Oracle 1,400+ July 2026
Microsoft 622 July 2026
Google (Chrome) 429 June 2026

Every day between a flaw being discovered and a patch being installed is a window hackers can climb through.

What does Act Security actually do?

Instead of racing to patch every hole, Act Security focuses on shrinking what attackers can reach in the first place. The company targets cloud environments, the remote computing infrastructure that most businesses now rely on to store data and run software.

Co-founder and CEO Jonathan Langer points to a striking figure: nearly 97% of permissions in a typical cloud setup, the access rights that control which software and which people can read or change which data, sit permanently unused. AI systems that plug into these cloud environments inherit all of those permissions automatically. That is a lot of unlocked doors.

Act Security's software maps out those unused access paths and closes them off, enforcing strict rules so that both AI systems and human employees can only reach what they genuinely need. The idea is that a hacker who breaks in finds far less to work with.

For businesses, the practical upside is twofold. Fewer open access paths means less exposure even when a patch is slow to arrive. The company also aligns its controls with established security standards including NIST 800-53 and PCI DSS, the compliance frameworks that many industries require companies to follow.

Should ordinary employees be worried?

Not personally alarmed, but aware. The vulnerabilities here live inside business software and cloud systems, not on your laptop. If your employer runs cloud services, their IT team is the one racing against this clock. The sensible step for any organisation is to audit who and what has access to its cloud systems, and strip back anything that is not strictly necessary.

Common questions

What is a cloud environment, and why does it matter here?

A cloud environment is computing infrastructure run by a provider like Amazon, Microsoft or Google and accessed over the internet, rather than on computers your company physically owns. Most businesses now store sensitive data there, which makes it a prime target.

Do I need to patch my own devices because of this?

The vulnerabilities discussed here mainly affect business software and cloud infrastructure. That said, the Google Chrome patches mentioned above do affect everyday browsers, so keeping Chrome updated on any device you use is always a good habit.

© 2026 AI2Day