Daily Tech Briefing
AI 科技速览

每天 5 分钟内学习 AI。获取最新的人工智能新闻,理解其重要性,并学习如何将其应用于您的工作。

AI 快讯
Unite.AI · 2026/7/28 12:27:23
Act Security Emerges From Stealth With $60M to Reduce Cloud Access Risk

Act Security Emerges From Stealth With $60M to Reduce Cloud Access Risk

AI 中文解读
Act Security 这家云安全初创公司近日带着 6000 万美元融资走出隐身模式,它的核心思路很独特:与其给安全团队堆砌海量漏洞告警,不如直接“拆桥”,把黑客能利用的访问路径彻底砍掉。该公司由前医疗网络安全公司 Medigate 的团队于 2025 年创立,目前已完成 2000 万美元种子轮和 4000 万美元 A 轮融资,投资方包括 Team8、Bessemer 和 Notable Capital 等。传统云安全工具擅长发现暴露的服务、错误配置或过高的权限,但问题太多了,安全团队根本修不完。Act Security 的做法是同时分析身份权限和网络可达性——一个账号也许有权限访问某个资源,但黑客还要有实际网络路径才能到达;反过来,即使能访问,权限控制不到位也一样危险。它把这两层信息结合起来,为用户、应用、工作负载甚至 AI 代理建立云边界,比如在微软 Azure 环境中,它可以模拟策略变更后再执行,通过现有 Azure 功能实现最小权限控制。对企业来说,这意味着少了很多无用的告警和疲于奔命式的修复,安全团队能真正关掉那些最危险的“后门”;对我们普通用户而言,企业云服务更安全,自己的账号、支付数据被窃取的概率也会显著降低。
Funding Act Security Emerges From Stealth With $60M to Reduce Cloud Access Risk Published July 28, 2026 By Antoine Tardif, CEO & Founder of Unite.AI Add Unite.AI to your preferred sources on Google Act Security has emerged from stealth with $60 million in funding and a cloud security platform designed to reduce the access paths that allow attackers to move through enterprise infrastructure.Founded in 2025 by members of the team behind healthcare cybersecurity company Medigate, Act Security is entering the market with a $20 million seed round and a $40 million Series A. Team8 and Bessemer Venture Partners led the seed round, with participation from Hetz Ventures and Claltech. Notable Capital led the Series A, joined by Startpoint Capital and the Silicon Valley CISO Investments syndicate.Rather than adding another layer of vulnerability alerts, the company is concentrating on the permissions, network connections, and infrastructure relationships that determine what a compromised identity can actually reach.Moving Beyond Cloud Security AlertsCloud security platforms have become increasingly effective at finding exposed services, vulnerable software, excessive permissions, and configuration mistakes. The difficulty is that security teams can receive thousands of findings without a practical way to address all of them.Act Security is approaching the problem from a different direction. Instead of treating every vulnerability as an isolated remediation task, the platform attempts to remove the access paths that would make those vulnerabilities useful to an attacker.This involves analyzing identity permissions and network reachability together. An identity may technically have permission to access a resource, for example, but an attacker also needs a viable network path to reach it. Conversely, a reachable workload may remain protected when authorization controls prevent meaningful access.Act Security combines these layers to establish cloud perimeters around users, applications, workloads, and AI agents. Its Microsoft Azure offering can model effective permissions across Microsoft Entra ID, Network Security Groups, and virtual network policies, simulate proposed changes before enforcement, and apply least-privilege controls through existing Azure infrastructure.Why AI Agents Make Excessive Access More DangerousExcessive cloud permissions are not a new problem, but AI agents could make the consequences more immediate.Act Security says its analysis of customer environments indicates that close to 97% of granted cloud access is dormant or unused. These permissions may have accumulated as employees changed roles, applications evolved, temporary projects became permanent, and service accounts received broader access than necessary.The introduction of AI agents adds another class of identity to this environment. Agents may inherit the permissions of human users or existing service accounts while operating continuously and executing actions much faster than a person could.This creates risks even when an agent is functioning as intended. An incorrectly configured agent could access sensitive systems outside its intended role, while a compromised agent could give an attacker a fast-moving route through connected cloud resources.Act Se
分享
阅读原文