A new Israeli security startup has emerged from stealth with $60m. It arrives with an argument the industry has resisted for decades. You cannot patch your way to safety any more, so stop trying.
Act Security launched on Tuesday, Calcalist reported. It was founded in 2025 by the team that sold Medigate to Claroty for about $400m. Its pitch is simple: AI has broken cloud defence from two sides, and the fix is less access, not faster patching.
Why patching stopped working
The first problem is volume. As frontier models get better at finding exploitable flaws, new vulnerabilities are piling up faster than anyone can fix them. The Forum of Incident Response and Security Teams projects roughly 59,000 new CVEs this year, SecurityWeek reported. That is about 161 a day.
The patch dumps show the strain. In one recent cycle, Oracle alone fixed more than 1,400 vulnerabilities. Microsoft patched a record 622, and Chrome 429 in one release. It is the same trend we saw when AI-found vulnerabilities began arriving at twice last year’s rate.











