AI Is Finding Software Flaws Faster Than Companies Can Fix Them. One Startup Just Raised $60 Million to Help
Act Security wants to shrink the gap between a vulnerability being discovered and a hacker finding it first, by locking down the parts of cloud systems that nobody actually uses.

Key points
- Act Security, founded in Tel Aviv in 2025, raised $60 million by July 2026 to tackle cloud security risks created by AI.
- Around 59,000 new software vulnerabilities are expected to be discovered in 2026, roughly 161 per day, according to the Forum of Incident Response and Security Teams.
- In July 2026, Oracle patched more than 1,400 flaws and Microsoft fixed 622; Google addressed 429 in a single Chrome update in June 2026.
- Act Security argues that 97% of cloud permissions, the access rights granted to software and users, sit unused and create unnecessary risk.
Artificial intelligence can now scan vast stretches of code in hours. That speed is genuinely useful for defenders. It also means attackers have a powerful new tool for finding weaknesses, and the number of vulnerabilities, meaning flaws in software that hackers can exploit, is climbing fast.
As first reported by ThreatVectr, Act Security raised $60 million to address exactly this problem. The Tel Aviv startup, founded in 2025, believes the traditional approach of patching every flaw can't scale quickly enough.
How bad is the vulnerability problem right now?
Very bad, and getting worse. The Forum of Incident Response and Security Teams expects roughly 59,000 new software vulnerabilities to surface in 2026 alone, about 161 fresh problems every single day.
The patch totals the big vendors published this summer make the scale concrete.
| Company | Flaws patched | When |
|---|---|---|
| Oracle | 1,400+ | July 2026 |
| Microsoft | 622 | July 2026 |
| Google (Chrome) | 429 | June 2026 |
Every day between a flaw being discovered and a patch being installed is a window hackers can climb through. Our 22 July story on Anthropic's Mythos bug-finding system found exactly this: most attackers walk through doors that should have been locked months ago, not the newest ones.
What does Act Security actually do?
Instead of racing to patch every hole, Act Security focuses on shrinking what attackers can reach. The company targets cloud environments, the remote computing infrastructure that most businesses now rely on to store data and run software.
Co-founder and CEO Jonathan Langer points to a striking figure: nearly 97% of permissions in a typical cloud setup, the access rights controlling which software and which people can read or change which data, sit permanently unused. AI systems that plug into these environments inherit all of those permissions automatically. That's a lot of unlocked doors.
Act Security's software maps those unused access paths and closes them off, enforcing strict rules so that AI systems and employees can only reach what they genuinely need. A hacker who breaks in finds far less to work with. The company also aligns its controls with NIST 800-53 and PCI DSS, the compliance frameworks many industries require.
The honest question worth watching is whether "reduce the attack surface" proves durable as a standalone product or becomes a feature inside broader platforms. Okta's acquisition of Permiso for around $200 million on 30 July, a deal built on the same logic of tracking what AI agents can access, suggests the big incumbents are circling this space.
Should ordinary employees be worried?
Not personally alarmed, but aware. These vulnerabilities live inside business software and cloud systems. If your employer runs cloud services, their IT team is the one racing against this clock. The sensible step for any organisation is to audit who and what has access to its cloud systems, then strip back anything not strictly necessary.
Common questions
What is a cloud environment, and why does it matter here?
A cloud environment is computing infrastructure run by a provider like Amazon or Microsoft and accessed over the internet, rather than on computers your company physically owns. Most businesses now store sensitive data there, which makes it a prime target.
Do I need to patch my own devices because of this?
The vulnerabilities discussed here mainly affect business software and cloud infrastructure. The Google Chrome patches mentioned above do affect everyday browsers, so keeping Chrome updated is always worth doing.



