AI Security AI安全 2h ago Updated 1h ago 更新于 1小时前 48

Act Security Emerges from Stealth to Fight the Patch Problem Act Security 从隐身状态浮现,致力于解决补丁问题

Act Security, a Tel-Aviv based startup founded in 2025, has raised $60 million in funding to address the growing challenge of AI-induced vulnerabilities in cloud environments. The company focuses on reducing access sprawl by enforcing deterministic boundaries that limit what humans, workloads, and AI agents can reach, thereby mitigating the risk of unpatched vulnerabilities being exploited. Act Security's approach aims to make cloud infrastructures structurally secure before attacks unfold, rath Act Security 是一家成立于2025年的以色列AI安全初创公司,已完成6000万美元融资(种子轮2000万+ A轮4000万),旨在解决AI加速漏洞发现导致的云环境权限泛滥问题。 该公司不直接修补漏洞,而是通过消除未使用的云访问权限路径,从根源上阻止攻击者利用未修复漏洞进行横向移动或AI代理滥用。 其平台支持强制确定性边界、合规映射(NIST 800-53/PCI DSS/HIPAA),并基于创始人曾成功出售Medigate至Claroty(4亿美元)的行业经验构建。 行业背景显示:2026年预计新增CVE达5.9万个(日均161个),Oracle/微软/谷歌单月补丁数屡创新高,传统

75
Hot 热度
60
Quality 质量
65
Impact 影响力

Analysis 深度分析

TL;DR

  • Act Security, a Tel-Aviv based startup founded in 2025, has raised $60 million in funding to address the growing challenge of AI-induced vulnerabilities in cloud environments.
  • The company focuses on reducing access sprawl by enforcing deterministic boundaries that limit what humans, workloads, and AI agents can reach, thereby mitigating the risk of unpatched vulnerabilities being exploited.
  • Act Security's approach aims to make cloud infrastructures structurally secure before attacks unfold, rather than relying solely on patching vulnerabilities as they are discovered.
  • The platform helps enterprises remove exposed paths used by attackers, deploy AI agents safely, and achieve compliance with standards such as NIST 800-53, PCI DSS, and HIPAA.

Why It Matters

The rapid pace at which AI models discover new vulnerabilities is overwhelming traditional patch management strategies, making it crucial for organizations to adopt more proactive security measures. Act Security's approach of reducing access sprawl and enforcing deterministic boundaries offers a strategic solution to this growing problem, potentially setting a new standard for cloud security practices.

Technical Details

  • Funding and Team: Act Security secured $60 million in total funding, including a $20 million Seed round and a $40 million Series A round. The founding team includes Jonathan Langer (CEO), Itay Kirshenbaum (CTO), and Pini Pinhasov (CPO), who previously founded Medigate, sold to Claroty for $400 million.
  • Core Problem: The article highlights the increasing number of CVEs projected for 2026, with over 161 new vulnerabilities discovered daily. This surge is driven by the capabilities of frontier AI models to identify and exploit vulnerabilities faster than vendors can patch them.
  • Solution Approach: Act Security's platform focuses on reducing the attack surface by limiting access permissions to only those necessary for operations. This involves enforcing deterministic boundaries around human users, workloads, and AI agents to prevent unauthorized actions and reduce the risk of exploitation.
  • Compliance and Safety: The platform supports compliance with various regulatory frameworks, including NIST 800-53, PCI DSS, and HIPAA, ensuring that enterprises can maintain security while adhering to industry standards.

Industry Insight

  • Shift from Reactive to Proactive Security: The rise of AI in vulnerability discovery necessitates a shift from reactive patching to proactive security measures. Companies like Act Security are leading this change by focusing on reducing access sprawl and enforcing strict access controls.
  • Importance of Deterministic Boundaries: Enforcing deterministic boundaries is becoming a critical strategy for securing cloud environments. This approach not only mitigates the risk of unpatched vulnerabilities but also ensures that AI agents operate within safe and defined parameters.
  • Regulatory Compliance: As regulatory requirements become more stringent, solutions that help enterprises comply with multiple standards simultaneously will be highly valued. Act Security's platform addresses this need, making it an attractive option for organizations looking to enhance their security posture while maintaining compliance.

TL;DR

  • Act Security 是一家成立于2025年的以色列AI安全初创公司,已完成6000万美元融资(种子轮2000万+ A轮4000万),旨在解决AI加速漏洞发现导致的云环境权限泛滥问题。
  • 该公司不直接修补漏洞,而是通过消除未使用的云访问权限路径,从根源上阻止攻击者利用未修复漏洞进行横向移动或AI代理滥用。
  • 其平台支持强制确定性边界、合规映射(NIST 800-53/PCI DSS/HIPAA),并基于创始人曾成功出售Medigate至Claroty(4亿美元)的行业经验构建。
  • 行业背景显示:2026年预计新增CVE达5.9万个(日均161个),Oracle/微软/谷歌单月补丁数屡创新高,传统“打补丁”模式已无法应对AI驱动的漏洞爆发速度。
  • 核心洞察:97%的云权限处于闲置状态,AI代理正继承人类遗留权限且无判断力,导致风险结构未被根本性治理。

为什么值得看

本文揭示了AI时代下网络安全范式的根本转变——从被动修补转向主动消除攻击面,对云原生架构下的权限管理与AI代理安全具有战略指导意义。Act Security提出的“结构性安全”理念,为应对指数级增长的CVE提供了可落地的替代方案,尤其适合关注云零信任与自动化威胁防御的企业安全团队。

技术解析

  • 核心机制:通过识别并移除云环境中97%以上闲置的访问权限路径,切断攻击者利用未修复漏洞的横向移动通道,而非依赖传统补丁管理。
  • 边界控制模型:实施确定性边界策略,限制人类用户、工作负载及AI agent仅能访问必要资源,防止AI代理以机器速度执行无授权操作。
  • 合规集成能力:平台内置对NIST 800-53、PCI DSS、HIPAA等主流安全框架的直接映射,帮助企业同时满足安全加固与监管合规需求。
  • 团队技术背书:创始团队来自Medigate(IoT安全独角兽,2022年被Claroty以4亿美金收购),具备企业级安全产品规模化落地经验。
  • 市场痛点响应:针对FIRST组织预测的2026年日均161个新CVE,以及厂商如Oracle单次发布超1400个补丁的压力,提出“不追症状、治本根”的架构级解决方案。

行业启示

  • 安全范式转移:随着AI加速漏洞挖掘,“补丁战”将不可持续,企业应转向最小权限原则与静态访问控制,优先消除可利用的攻击面而非等待厂商修复。
  • AI代理治理刚需:AI agent需 inherit human permissions但缺乏人工判断力,必须部署独立于身份体系的运行时边界控制,避免自动化行为引发连锁泄露。
  • 投资风向标:Act Security获Top-tier VC(Team8, Bessemer, Notable Capital)青睐,表明资本市场高度认可“预防性云安全”赛道,建议关注同类聚焦权限治理与AI约束的初创企业。

Disclaimer: The above content is generated by AI and is for reference only. 免责声明:以上内容由 AI 生成,仅供参考。

Security 安全 Funding 融资