Unit 42 is putting the latest frontier cyber models to work across customer environments to find, validate and help remediate the attack paths that matter most.
In May, we introduced Frontier AI Defense with a warning: the window to get ahead of AI-enabled attacks was shorter than most people realized. Since then, we have briefed more than 1,000 security teams around the world and introduced our Frontier AI Defense service to hundreds of customers.
Today, through our partnership with OpenAI, we are expanding Unit 42 Frontier AI Exposure Analysis to put advanced frontier cyber models directly to work in customer environments. Under Unit 42 direction, these models can find exposures, test whether they are exploitable, validate attack paths and help customers prioritize what to fix first.
Our early work shows why this approach matters: 36% of the exposures we identified map to no known CVE, often because they involve multiple gaps that have to be discovered, chained and tested together.
Bringing the Latest Frontier Cyber Capabilities to Defenders
Palo Alto Networks has been among a limited group of organizations with early access to advanced cyber capabilities from the leading frontier AI labs. Through our partnership with OpenAI, Unit 42 can now bring its latest advanced cyber capabilities, including GPT-5.6 Daybreak, to security testing and validation for our customers. Until now, GPT-5.6 Daybreak has not been available for commercial use.
Frontier models have helped inform the work of our experts. Now they can increasingly perform complex offensive security tasks directly, at machine speed and under Unit 42 direction. That allows us to go deeper than traditional vulnerability discovery by testing exploitability, reasoning across multiple weaknesses and determining how an attacker could use them to achieve an objective.
There is no single best model for every cyber task. Our research has shown that different models have different strengths and find vulnerabilities others miss. A multi-model harness routes work to the model best suited for the task, improving efficacy and coverage while managing the cost of frontier AI at scale. As stronger models emerge, we can incorporate them without rebuilding the offering around a single model or provider.
Unit 42 experts remain central to the process. We combine frontier models with our offensive security expertise, Palo Alto Networks telemetry and Unit 42 Threat Intelligence to validate findings, connect exposures into attack paths and understand what an attacker could ultimately achieve.
Built to Find What Attackers Can Exploit
The expanded service brings five capabilities together:
Leading cyber models: Apply the latest advanced cyber models to improve exposure discovery, testing and validation.
Multi-model harness: Use the right model for the right task to improve efficacy, expand coverage and optimize cost.
Exposure discovery: Find vulnerabilities, misconfigurations, leaked credentials, unmanaged attack surface and other posture gaps across applications and network assets.
Advanced adversary simulation: Actively test exploitability and validate end-to-end attack paths to understand how an attacker could compromise the environment.
Custom remediation plan: Prioritize the fixes that break the most important attack paths and feed those findings into existing IT, development and security workflows.
Most security teams already have more findings than they can act on. The harder problem is knowing which ones create a real path to compromise. Attackers look across applications, infrastructure, identity and cloud for weaknesses they can combine to achieve an objective. Frontier AI Exposure Analysis applies that same adversarial perspective, helping defenders understand which paths matter and what to fix first.
The Asymmetry Runs Both Ways Now
For the past several months, frontier AI has been a story about what is coming for defenders: vulnerability discovery at scale, exploit chaining that sees full-stack logic no scanner catches, and attack cycles compressed to seconds from initial access to exfiltration.
All of that is still true. Our answer has been to put everything we learn testing these frontier models into the hands of defenders. Today, that gets more direct: not just what frontier models have taught us, but the models themselves, working in your environment for your defenders before those same capabilities are working for the attacker.
The window is still closing. We intend to spend it building on the side of the defenders.
As organizations race to deploy agentic AI, legacy network security solutions are ill-equipped to keep up, forcing productivity tradeoffs while exposing coverage gaps. At the same time, Frontier AI is proving capable of discovering vulnerabilities and creating exploits in real-time. Navigating this shift requires more than incremental feature enhancements; it requires a bold, market-defining vision backed by relentless customer focused execution.ย
Today, weโre proud to announce that Gartnerยฎ has once again recognized Palo Alto Networks as a Leader in the 2026 Magic Quadrantโข reports for both Security Service Edge and SASE Platforms. This marks the fourth consecutive year that Palo Alto Networks has been recognized, making us the only security vendor to be recognized as a Leader in both reports for four years in a row.
In this yearโs Magic Quadrant for SSE, Palo Alto Networks was placed highest in ability to execute and furthest in completeness of vision forPrisma Access.
Every day we focus relentlessly on understanding the needs of our customers and channeling that back into products and services that create real value for them. Our product strategy centers on where our customers' environments and security needs are heading, not just where it sits today.
Vision Matters More than Ever in the AI Era
The AI landscape is changing daily - in this new reality, we strive to be the visionary leaders to serve our customers. GenAI and Agentic AI are exposing enterprises to novel categories of risks like prompt injection, over-privileged agents, and poisoned models. At the same time, Frontier AI is accelerating vulnerability discovery and attack speed resulting inattack timelines being compressed by over 95%.
Gartner projects that by the end of this year,40% of enterprise applications will feature embedded agents, up from less than 5% today. And by 2028, 60% of brands will use agentic AI to facilitate streamlined one-to-one interactions. Operating a business in this new reality requires security architecture engineered to anticipate threats that haven't yet emerged. Success cannot be achieved by retrofitting legacy products with support for AI infrastructure. It demands a unified future-ready foundation that natively secures users, applications, sensitive data, and non-human identities across every touchpoint. The platform enterprises use today determines whether they'll be prepared for tomorrow's threats.
As the cybersecurity landscape undergoes its biggest shift in decades, to us, the Gartner recognition as a Leader on vision and execution across both reports means more than ever before. In our opinion, it not only validates Palo Alto Networkโs ability to serve the worldโs largest enterprises but also celebrates our strategic product capabilities as shaping the future of cybersecurity through industry leading innovation such as securing AI traffic flows and agents that simplify manageability of SASE operations.
Vision Backed by Relentless Execution
We believe being placed highest in execution and furthest in vision is only as valuable as the ability to execute on it, and Palo Alto Networks has a proven record of creating value for our customers. Our recent milestone of crossing the$1.6 billion ARR mark while growing 40% year over year for Prisma SASE reflects the trust customers have placed in us. Over 6,800 organizations, including over one third of the fortune 500, trust us because we consistently turn market-defining innovation into enterprise-grade reality. Our execution leadership is built on a strong foundation:
Security powered by Precision AI: Our platform delivers universal zero trust through distributed and flexible enforcement points. We inspect traffic as close to the user as possible to ensure that whether your teams are at the corporate HQ, a remote branch, a coffee shop or working from home, they receive the same protection at their precise point of interaction.
Unmatched performance and resilience: By leveraging global hyperscalers, we provide the massive scale and reach that modern organizations require. For specialized, high-performance and sensitive needs, SASE Private Location brings that same cloud-delivered resilience directly to private campuses.
Unified platform: With a truly unified policy engine, data platform and operations, we ensure that as enterprises adapt to the future, our architecture remains an accelerator for secure productivity rather than a bottleneck. We accelerate vendor consolidation for enterprise customers, replacing fragmented legacy point products with a single platform that slashes operational overhead and reduces total cost of ownership (TCO) by up to 50%.
Building for the Futureย
As the rules of cybersecurity are rewritten in real time, leading the market requires more than following past trends, it requires setting the trajectory. Our aim is to continuously be at the forefront of defining the future of cybersecurity to power the agentic enterprise of tomorrow.
Protecting with AI
Palo Alto Networks continues to innovate to keep enterprises safe at the speed of AI. Our Precision AI security service blocks over 30B threats every single day defeating sophisticated and highly evasive tactics. When combined with our virtual patching and IP defense security services, organizations receive proactive defense that secures at the speed of Frontier AI with flexible enforcement that provides consistent protection everywhere. We are delivering comprehensive security across network, edge, and cloud infrastructure to stop hidden threats that are invisible to traditional networks security solutions.ย
This AI-powered defense in depth strategy operates across the entire attack lifecycle to enable proactive protection that shifts enterprise security postures from reactive incident response to preemptive defense.ย
Securing AIย
Safely enabling employee adoption of AI tools and agents requires special considerations to mitigate risks around data leaks, intellectual property exposure, and compliance. Prisma SASE and Prisma Access solve these challenges by discovering all AI usage and agentic actions, enforcing granular least privilege access for human and non-human identities, and preventing exposure of risky data to AI and agents. Through AI Access Securityโข, Prisma SASE provides unified data security across the AI lifecycle by integrating GenAI app visibility and control, real-time prompt analysis, shadow data discovery, andย protection on endpoint. Prisma Browser provides a secure AI workspace that safeguards both human and autonomous agent workflows across any LLM by defending against data leaks, prompt injections, and agent hijacking.ย
To secure the rapid adoption of AI agents by enterprises, Prisma Access will natively integrate with Prisma AIRS AI Gateway to provide a unified LLM, MCP, and A2A gateway giving security teams a single pane of glass for AI observability, cost governance, and runtime inspection.
This innovative approach represents an evolution away from traditional device and user centric fabrics towards an agent-aware platform capable of securing AI for the enterprise of tomorrow, today.ย
Operating with AI
We continue to invest in capabilities that make our platforms proactive, efficient and easier to use. Our new deployment agents enable customers to onboard their SSE or SASE environment more efficiently, reducing their time to value while increasing productivity. Once onboarded, autonomous AI agents within Strata Cloud Manager continuously evaluate network and security posture to proactively identify configuration drift, performance degradation, and security policy gaps. By uncovering potential disruptions before they impact users or expose the organization to risk weโve created automated systems capable of finding issues and automatically remediating them, with human-in-the-loop oversight calibrated to the administrator's comfort level, from guided recommendations to full autonomy.
The practical outcome is a dramatic reduction in mean time to resolution (MTTR) and a measurable reduction in total cost of ownership (TCO) while significantly reducing administrative burdens and making Palo Alto Networks products easier to maintain and operate.
Learn More
Download your complimentary copies of the 2026 Gartnerยฎ Magic Quadrantโข reports to learn why Palo Alto Networks has been recognized as a Leader in both SASE and SSE for the fourth consecutive year.
ย
Gartner, Magic Quadrant for Security Service Edge, 29 July 2026, John Watts Et Al.
Gartner, Magic Quadrant for SASE Platforms, 28 July 2026, By Jonathan Forest Et Al.
Gartner does not endorse any company, vendor, product or service depicted in its publications, and does not advise technology users to select only those vendors with the highest ratings or other designation. Gartner publications consist of the opinions of Gartnerโs business and technology insights organization and should not be construed as statements of fact. Gartner disclaims all warranties, expressed or implied, with respect to this publication, including any warranties of merchantability or fitness for a particular purpose.
Gartner and Magic Quadrant are a trademark of Gartner, Inc., and/or its affiliates.
This graphic was published by Gartner, Inc. as part of a larger research document and should be evaluated in the context of the entire document. The Gartner document is available upon request from Palo Alto Networks.
Palo Alto Networks works closely with OpenAI across our product platform and Unit 42, leveraging advanced frontier model capabilities. Furthermore, we are a partner in the OpenAI Daybreak Cyber Partner Program, working with OpenAI to bring trusted, AI-powered cyber defense to more organizations. Today, weโre announcing native integration of Prisma AIRS Runtime API with OpenAI Codex. This milestone deepens our partnership and drives our shared mission forward: equipping defenders with the industry's most advanced tools.
AI coding assistants have transformed software development, accelerating shipping velocity and changing how engineers solve problems. But as integration of AI coding assistants deepens across development teams, security and compliance teams constantly struggle with enabling developer productivity while helping protect proprietary source code and credentials, and reducing the risk of runtime threats entering the codebase.
Streamlined Security in Minutes
We designed this integration to eliminate complex traffic steering and heavy client-side hooks. Securing your entire developer organization takes just a few clicks inside Codex Enterprise Management UI. Here is how you can enable it:
Retrieve Credentials: Generate your API key and endpoint from the Prisma AIRS management console.
Configure Codex: Paste the Prisma AIRS API key and endpoint directly into your Global Admin Console.
Activate Org-Wide Scanning: Once saved, all user prompts across your entire organization in Codex are automatically routed through the Prisma AIRS Runtime API for real-time inspection.
What Prisma AIRS Brings to OpenAI Codex
By connecting the Codex in ChatGPT for Enterprise workspace to the Prisma AIRS Runtime API, security teams gain comprehensive, automated security controls across two critical vectors:
1. Enterprise Data Loss Prevention (DLP)
Developers frequently paste context โ logs, config snippets, or functions โ into AI coding assistants. Prisma AIRS scans inputs to help identify sensitive data before it is submitted.
Secrets & Credentials: Intercept API keys, hardcoded passwords, tokens, and private keys.
PII & Financial Data: Automatically detect personally identifiable information and regulated data patterns.
Proprietary Code & IP: Enforce custom pattern rules to help prevent sensitive internal code, architecture details, or trade secrets from being submitted.
2. Advanced Threat & Malicious Code Detection
AI prompts and contextual inputs can contain content that introduces security risks into development workflows. Prisma AIRS Runtime API inspects incoming developer inputs for:
Malicious Code Patterns: Detect obfuscated scripts, dangerous command executions, or known exploit patterns within developer prompts.
Malicious URLs & Links: Flag unverified, phishing, or malicious domain references before they influence generated code or enter internal repos.
Prompt Manipulation Attacks: Detect adversarial inputs that may attempt to bypass system controls or alter model behavior.
Built for DevSecOps Alignment
Security controls only work if developers actually use them. Because the inspection happens at the platform administrative level via API, developers continue working natively in Codex without changing their IDE setup or downloading local hooks. SecOps gain centralized visibility, consistent policy enforcement, and audit-ready logging capabilities across the entire engineering organization, while developers keep the speed and experience they expect.
Key Takeaways
Security as Invisible Infrastructure: Prisma AIRS integrates at the Codex administrative layer, applying security and DLP controls without requiring additional developer workflow changes. Developers can continue working in Codex while security teams maintain centralized policy controls.
Unified Governance for Frontier Models: Prisma AIRS acts as an inline security layer that scans AI traffic in real-time before prompts ever reach the destination model. This architecture can help organizations identify sensitive information moving outward while detecting prompt manipulation and potentially malicious content moving into development workflows. If Prisma AIRS API detects a threat, a block verdict is sent to OpenAI Codex, and the prompt does not reach the destination model or MCP server.
Organization-Wide Compliance: Deployment speed is a strategic advantage, not just an IT convenience. By configuring the Prisma AIRS API within the Global Admin Console, organizations can achieve org-wide governance without complex traffic steering. This can help development teams shift from unmanaged AI use toward more consistent, auditable security practices.
Getting Started
The Prisma AIRS integration helps organizations maintain consistent security controls while preserving the speed and productivity gains of Codex. Organizations can combine Palo Alto Networksโ security capabilities with OpenAI Codex to maintain centralized security and governance controls.
Choose your path forward:
Attending Black Hat 2026: Stop by the Palo Alto Networks booth to check out the Prisma AIRS live demo.
This blog contains forward-looking statements that involve risks, uncertainties and assumptions, including, without limitation, statements regarding the benefits, impact, or performance or potential benefits, impact or performance of our products and technologies or future products and technologies. These forward-looking statements are not guarantees of future performance, and there are a significant number of factors that could cause actual results to differ materially from statements made in this blog. We identify certain important risks and uncertainties that could affect our results and performance in our most recent Annual Report on Form 10-K, our most recent Quarterly Report on Form 10-Q, and our other filings with the U.S. Securities and Exchange Commission from time-to-time, each of which are available on our website at investors.paloaltonetworks.com and on the SEC's website at www.sec.gov. All forward-looking statements in this blog are based on information available to us as of the date hereof, and we do not assume any obligation to update the forward-looking statements provided to reflect events that occur or circumstances that exist after the date on which they were made.
As AI adoption shifts from experimental tools to the business core, enterprises are deploying AI agents and assistants across every department. Developers are accelerating software delivery with Claude Code and business functions are collaborating in Claude.ai, ClaudeCowork, and ClaudeDesign, using Anthropic's Claude to fundamentally rewire how they operate and drive complex, autonomous workflows across their most critical tasks.
Broad AI adoption has forced enterprise security into a difficult paradox: secure the business without stalling innovation. Today, security teams must answer three critical questions: How do we prevent sensitive data from leaking into AI models? How do we intercept runtime attacks, like prompt injection, before they execute? And how do we enforce these guardrails consistently across every AI interaction, in real-time?
Synchronous Governance at the Speed of AI: Enforce critical runtime policy guardrails instantly before model inference occurs. By evaluating every Claude interaction in real-time, security teams can confidently enable high-speed AI innovation without introducing unacceptable risk or operational bottlenecks.
Extending Proven DLP to AI Workflows: Safeguard PII, intellectual property, and proprietary code across all Claude environments (Claude Code, Claude.ai, Claude Cowork) seamlessly. By directly leveraging your organizationโs existing enterprise DLP policies, you get consistent, unified data protection without the friction of managing disparate rule sets.
Neutralizing AI-Specific Threats Proactively: Deploy enterprise AI with confidence by intercepting malicious activity before it executes. Proactively block sophisticated runtime threats, including prompt injections, jailbreaks, and toxic inputs, enabling your AI workflows to remain secure and your business operations uninterrupted.
How It Works
Setting up zero-trust governance for your Claude Enterprise environment takes just a few clicks:
Configure Claude Enterprise: In your Claude Enterprise organization settings, navigate to inference hooks, set the hook endpoint URL to your designated Prisma AIRS webhook URL, and include your custom Prisma AIRS API key in the custom headers (x-pan-token).
Activate Cryptographic Verification in Prisma AIRS: Claude generates a unique, one-time signing secret. You simply drop this signing secret into the Prisma AIRS UI.
Prisma AIRS securely stores the signing secret in an encrypted edge Key-Value Map (KVM) to cryptographically verify the authenticity of every incoming request before processing.
Unified Governance Across All Claude Surfaces
Before Claude reads a prompt, Claude POSTs the payload to Prisma AIRS, which evaluates the input against the configured security profile and returns a synchronous allow or deny verdict back to Claude.
Removing the Data Inspection Blind Spot
This Prisma AIRS integration natively leverages the Palo Alto Networks Enterprise DLP engine your organization already runs. Your current policies, custom definitions of "confidential," and compliance dashboards now instantly govern Claude. No redundant rule creation, and no new management overhead. Every prompt is classified in real-time, before anything reaches the model. Data Policy updates reach Claude the moment they reach everything else, and Claude events land in the same dashboards and audit reporting as every other channel. AI stops being the exception to your data protection strategy and becomes just another channel that is covered.
In practice, this helps prevent:
Accidental exposure of PII and regulated data: a Social Security number, card number, or patient record pasted into a prompt is detectedย on the spot by advanced RegEx patterns and ML classifiers,ย with Exact Data Matching (EDM) recognizing your actual customer records. ย When policy requires, Prisma AIRS enforces a deny policy to help keep Claude usage stays aligned with GDPR, HIPAA, and PCI-DSS requirements.
Misuse of credentials in code: Developers working in Claude Code can't inadvertently submit hardcoded API keys, private tokens, or environment credentials into prompt context.
Disclosure of confidential business matters. Document classifiers flag prompts touching M&A, legal, or HR material โ even when they contain no identifier a pattern could match.
AI Safety & Runtime Threat Protection
Simultaneously, Prisma AIRS inspects payloads for operational risks specific to large language models:
Prompt Injection & Jailbreak Attacks: Intercepts malicious attempts to manipulate model context or bypass system instructions.
Malicious Code & Malicious URLs: Prevents execution or processing of untrusted scripts and risky links embedded within prompts.
Toxic Content & Topic Guardrails: Enforces compliance with corporate policies and custom business topics.
If a prompt violates your security policy, Prisma AIRS issues a deny verdict. Claude immediately blocks the prompt, optionally presenting a user-facing explanation while returning a unique audit correlation code to your security telemetry dashboards.
Deploy Claude Without the Risk
The Prisma AIRS integration with Claude transforms security from a deployment bottleneck into a business enabler. You no longer have to choose between the operational control of Palo Alto Networks and the cognitive velocity of Claude.
Choose Your Path Forward:
Attending Black Hat 2026?ย Stop by the Palo Alto Networks booth to check out the Prisma AIRS live demo.
Ready to build?ย Visit the Prisma AIRS Documentation to connect your Claude inference hooks in minutes.
ย
Forward-Looking Statements
This blog contains forward-looking statements that involve risks, uncertainties and assumptions, including, without limitation, statements regarding the benefits, impact, or performance or potential benefits, impact or performance of our products and technologies or future products and technologies. These forward-looking statements are not guarantees of future performance, and there are a significant number of factors that could cause actual results to differ materially from statements made in this blog. We identify certain important risks and uncertainties that could affect our results and performance in our most recent Annual Report on Form 10-K, our most recent Quarterly Report on Form 10-Q, and our other filings with the U.S. Securities and Exchange Commission from time-to-time, each of which are available on our website at investors.paloaltonetworks.com and on the SEC's website at www.sec.gov.ย All forward-looking statements in this blog are based on information available to us as of the date hereof, and we do not assume any obligation to update the forward-looking statements provided to reflect events that occur or circumstances that exist after the date on which they were made.
Modern enterprise security is at a pivotal moment where CIOs and CISOs have a clear opportunity to build a cybersecurity architecture for both todayโs environment, and for the future. Doing so requires redefining enterprise resilience across three critical dimensions.ย
First, Frontier AI driven threat velocity and novelty. Frontier AI models have automated the entire attack lifecycle. Adversaries arenโt just compressing exploit windows to near-zero timelines, they are also generating novel, highly evasive threats at machine speed, bypassing traditional signatures and often before patches are generated.ย
Second, surging network traffic is overwhelming traditional defenses. Driven by AI workloads, inter-datacenter traffic will nearly triple1 over the next decade dramatically expanding the volume of data teams must inspect and secure.ย
Finally, major shifts are forcing a โcryptographic reset.โ Shrinking certificate lifecycles, internet-scale distrust events, and quantum computers powerful enough to crack public key cryptography are combining to shake the foundation of all digital communications.ย
Meeting these challenges requires more than incremental fixes. Today, we are proud to introduce PAN-OS 12.2 Ceres, a landmark release representing a major leap forward in network security.ย
Ceres brings to market 55+ innovations, including three flagship, core capabilities, designed to shift the balance of power back to defenders.
Introducing Frontier Virtual Patching: Preemptive Defense Against Frontier AI Exploits
Today, Palo Alto Networks is giving defenders the ultimate advantage with the launch of Frontier Virtual Patching. By harnessing Frontier AI to discover unknown vulnerabilities, and deploying protections in hours, we are collapsing the exposure window from the industry-average 55 days2 it takes to deploy a traditional patch down into a near-zero window of exposure. This isnโt just about faster patching; itโs about eliminating the attackerโs chance by neutralizing exploits before they ever reach your network.
The new reality: Exploitation far outpaces patch deployment
Weโve built this capability as a collaborative, force-multiplying ecosystem, with our industry partnerships across the enterprise software and OT vendor landscape to accelerate vulnerability disclosure, remediation and customer protection. This includes our collaboration with Project Lightwell, which combines our rapid network-level protection with software remediation to help organizations reduce exposure to emerging threats. Weโre also partnering with vulnerability clearinghouses, software maintainers, and industry initiatives to continuously expand a real-time pool of protected vulnerabilities.
This approach builds on recent Unit 42 research, where the autonomous AI system NOVA identified more than 14,000 previously unknown vulnerabilities in just two months โ a clear signal that defenders must pair AI-powered discovery with equally fast, coordinated protection. We have built an all-new detection engine, โvaulted protection," that enables us to deliver these rapid protections in a safe and responsible manner.When one participant identifies a threat, the entire ecosystem is protected instantly. Individual discovery becomes global protection.ย
This is especially valuable for operational technology (OT), critical infrastructure, healthcare, and IoT: environments where systems canโt be taken offline to patch, where patch cycles can stretch for months, and where a single unpatched device can expose an entire network. Frontier Virtual Patching closes that gap in the network, blocking the exploit without applying a patch, rebooting a system, or causing any downtime to critical operations.
Bad actors will lean into Frontier AI to reduce the attack lifecycle from months to minutes. To keep pace, organizations require security partners to match that machine speed. To this end, Palo Alto Networks is raising the bar with its Frontier Virtual Patching, moving beyond compensating controls. By safely and efficiently discovering undisclosed vulnerabilities and deploying protection long before traditional patches can be rolled out, Palo Alto Networks deep security capabilities are flipping network defense from a reactive to proactive operational model.
Will Townsend Chief Analyst, LoneStar Advisory & Research
And for existing Palo Alto Networks network security customers, getting started is effortless.ย Frontier Virtual Patching is available as a PAN-OS software upgrade with persistent, automatic content updates, so protections keep arriving as new threats emerge, with no new hardware and no manual intervention.ย
Clearly, Network Security is evolving quickly. Frontier Virtual Patching is part of a huge set of innovations that the team at Palo Alto Networks is delivering in PAN-OS Ceres 12.2 to enable you to stay protected.
Advanced IP Defense: Blocking attacker infrastructure before they can strike
Modern threat actors continuously work to hide their attacks and evade existing controls. Adversaries are increasingly evading traditional perimeter detection of their command-and-control traffic by leveraging direct-to-IP connection techniques that bypass DNS and URL inspection entirely. Attackers are also weaponizing massive proxy networks and hundreds of thousands of residential IP addresses to conduct stealthy, large-scale scanning, brute-force attacks, and exploitation that bypass traditional defenses such as IP reputation and blocklists.
To counter this, Palo Alto Networks is introducing a new preventative solution, Advanced IP Defense, with three powerful new capabilities:
Real-time IP-layer intelligence. We leverage global telemetry from over 70,000 customers to track and block attacker infrastructure inline across the entire attack lifecycle. Our researchers track these threats 24/7, so your team doesnโt have to.
Zero-Trust IP enforcement. We donโt just look at an IPโs past reputation. We verify the intent of the connection itself. By validating that every network connection maps to a legitimate DNS resolution, we provide a critical guardrail against attackers attempting to evade detection.
Powerful IP-layer context. We continuously monitor every connection across more than 40 distinct security attributes, letting you proactively shrink your attack surface and block high-risk traffic from the internetโs โbad neighborhoodsโ with confidence.
The transition to the Frontier AI era isn't a distant future. Itโs happening right now. The organizations that thrive won't be those trying to run old, reactive playbooks faster; they have to scale their defenses to match a whole new velocity of risk. When threats occur at machine speed, relying on human-scale operations is no longer an option. That is why AI and automation are becoming essential tools to meet these challenges head-on.
Varinder Singh CIO, NXP Semiconductors
Network Security Agents: Making admins superhuman
When threats execute in minutes, human-only operations become a bottleneck. To reduce fatigue and accelerate response, weโre launching an elite suite of AI agents for every major role a network administrator performs.
These six specialized AI-powered Network Security Agents, available through Strata Cloud Manager, are trained on your enterprise context and operational workflows. From onboarding and configuration to threat assessment and troubleshooting, they automate the hundreds of routine, repetitive tasks that consume an adminโs day. And you stay in control: for each workflow, you choose the level of oversight that matches your risk tolerance โ human-in-the-loop, human-on-the-loop, or human-out-of-the-loop.
Expanding platform protection across every edge
Securing the modern enterprise means extending these AI-powered capabilities across every surface, from data center cores to remote industrial sites, and from custom AI applications to the web browser.
Today weโre introducing PAN-OS Ceres 12.2, which, in addition to the innovations above, expands our platform across five more areas:
Quantum-safe & next-generation trust security. Automates digital certificate lifecycle management and accelerates post-quantum cryptographic readiness, including a cryptographic inventory spanning network security, endpoint, SIEM, and vulnerability management integrations for a complete view of enterprise readiness.
5th-generation ML-optimized hardware. New high-performance PA-Series firewalls equipped with 400G interfaces, and 300 Gbps of threat inspection, and active clustering, these platforms eliminate capacity limits for AI-era data centers. These firewalls alsoย scale to 1.4Tbps of throughput while delivering 5-microsecond latency ensuring peak performance.ย
Modernized OT & critical infrastructure defense. Purpose-built PA-50R ruggedized 5G firewalls that extend real-time, AI-powered threat prevention to remote, extreme-environment OT networks and critical infrastructure.
AI and agent security. Prisma AIRS is now delivered as a scalable, cloud-native service explicitly engineered to secure AI models, applications, and autonomous agent workflows. The same platform on which we built CloudNGFW has now been extended to provide security for AI with the addition of Prisma AIRS.
Browser-to-firewall integration. Imagine the browser as a secure fast-lane that doesnโt just protect users, it empowers them. By integrating Prisma Browser with our NGFWs, weโve eliminated the need to decrypt on the endpoint while delivering full Layer 7 protection. This is proactive security that neutralizes threats before they can even touch your network. For security admins, policy is fully unified from device to network, delivering a streamlined, automated experience.
The path forward
We are investing heavily in the innovations you need to defeat todayโs threats while future-proofing your enterprise for tomorrow.
The transition to the Frontier AI era demands a bold strategy. The winners will be the organizations that adopt a prevention-first architecture capable of stopping threats long before weaponization occurs. With PAN-OS Ceres 12.2, Palo Alto Networks is giving defenders the speed, scale, and platform foundation to turn the tables on modern adversaries.
ย
Forward-Looking Statementsย
This blog contains forward-looking statements that involve risks, uncertainties and assumptions, including, without limitation, statements regarding the benefits, impact, or performance or potential benefits, impact or performance of our products and technologies or future products and technologies. Any unreleased services or features (and any services or features not generally available to customers) referenced in this or other press releases or public statements are not currently available (or are not yet generally available to customers) and may not be delivered when expected or at all. Customers who purchase Palo Alto Networks applications should make their purchase decisions based on services and features currently generally available.
Join Palo Alto Networks virtual InterSECt 2026 event on Aug. 19โ20ย to see PAN-OS 12.2 Ceres and learn how to preempt AI-driven network attacks. Secure your spot
Secure your future at the edge of the frontier
Explore our leading Frontier AI Ecosystem and essential resources Learn more
The Future of Vulnerability Discovery Is Here
4,000 projects. 14,000 previously unknown vulnerabilities. Two months. Read Unit 42's latest research on why defenders must prepare for a dramatically faster threat landscape. Read the report
The HIPAA Security Ruleโs Technical Safeguards (ยง164.312) define five standards and nine implementation specifications covering access control, audit controls, integrity, authentication, and transmission security.
The guidance also covers the 2025 NPRM proposed changes,including encryption at rest and in transit becoming required, multi-factor authentication (MFA) becoming mandatory for all electronic Personal Health Information (ePHI) access, and new specifications for network segmentation, configuration management, anti-malware protection, patch management, software removal, incident response and breach notification.
Key topics included
Shared responsibility for HIPAA on AWS โ A responsibility matrix mapping each ยง164.312 specification to what AWS manages nd what the customer must configure and operate.
ePHI boundary architecture โ Guidance on establishing a defined ePHI boundary
ePHI data flow and encryption โ A reference architecture tracing ePHI with the applicable ยง164.312 specification
Foundation checklist โ Prerequisite recommendation before configuring individual Technical Safeguard controls.
This guidance is written for cloud architects, security engineers, CISOs, and compliance teams at covered entities and business associates building or operating AWS healthcare workloads. It assumes familiarity with AWS services and is intended as a practical implementation reference, not a legal or regulatory interpretation. This guidance focuses exclusively on Technical Safeguards.
HHS published a Notice of Proposed Rulemakingin January 2025, proposing significant updates to the HIPAA Security Ruleโincluding eliminating the Addressable designation, making encryption, MFA, and asset inventory mandatory, and introducing new technical requirements not present in the current rule. As of June 2026, the final rule has not been published. This guidance covers both the current rule and the proposed changes and recommends treating all specifications as Required for new workloads.
For questions about HIPAA readiness on AWS, including Administrative Safeguards, Physical Safeguards, risk analysis, and assessment preparation, contact the AWS Security Assurance Services teamor your AWS account representative.
This guidance is provided by AWS Security Assurance Services, LLC, a HITRUST External Assessor Firm and PCI-QSAC along with contribution from AWS HCLS, AWS Compliance teams. It is for informational and guidance purposes only and does not constitute legal, regulatory, or compliance advice. Recipients are solely responsible for determining applicability to their specific environments and legal obligations.
If you have feedback about this post, submit comments in the Comments section below.
Every modern enterprise is moving from an organization run by software to one orchestrated by AI, creating a tension between velocity and control. To resolve this tension, organizations require a unified architecture. Today, we are announcing the general availability of the Prisma AIRS AI Gateway, the AI control plane for the enterprise.ย
Driven by the absolute conviction that an AI Gateway is foundational to the modern AI infrastructure stack, we are bringing AI innovations from the Portkey acquisition to Prisma AIRS just six weeks after closing. You can now scale AI at machine speed without compromising on enterprise-grade security and control.
Your AI Footprint is Outpacing Controls
Our next-generation firewall telemetry reveals that MCP activity climbed from 11% late last year to 41.4% by mid-2026. Monthly AI transaction volume grew twelve-fold over the same six months; some individual sessions moved hundreds of megabytes of enterprise data outbound. The AI footprint you can govern today is the smallest it will ever be.
Some of the most rapid AI adoption is happening with โ coding assistants, enterprise agents and copilots.
Coding agents access code repositories, file systems, configurations, and credentials. When this context, including source code and secrets, is sent to a frontier model, it risks exposing sensitive data, and a runaway loop could burn a fortune in tokens overnight.
Enterprise agents run with broad access and standing privileges sharing context with each other. A single agent stretched beyond its scope can massively increase the risk of data breach, impact business reputation and customer trust.
Copilots now sit inside the SaaS and productivity tools employees already use. Copilots with broad access can surface data an employee was never meant to see.
As this enterprise data leaves when an AI request goes out, it creates a security and governance challenge at an unprecedented scale and speed.
What breaks when every team adopts AIย
AI adoption rapidly outpaces the security and governance infrastructure meant to secure it:
Shadow AI (Cost and usage are both hidden): You can't see the AI your teams already use or what it costs.ย
Data Exposure (Sensitive data leaves without a trace): AI interactions can expose sensitive data, bypass policy and trigger unsafe outputs.
Agents Overstep (Actions run without accountability): Agents act across systems without clear identity, permission, or accountability. Keys get shared and agents run with broad, standing privileges, so no one can say which identity authorized a specific action or reverse it when an agent takes a wrong turn at machine speed.
Faced with this, most leaders either block traffic entirely or stay permissive and promise to govern later. Both approaches fail because they skip the critical step: seeing what agents do at runtime and controlling their actions while they happen.
Accelerate AI Adoption with Control
To scale AI adoption safely, you need a single control plane sitting between every AI interaction and the backend models. Prisma AIRS AI Gateway brings AI governance, identity and runtime controls together in one place. With the AI Gateway, you can:
Discover AI usage: Know exactly which apps, models, users, teams and agents are active, what they are accessing, and what they cost in a single unified view.
Govern AI interactions: Enforce central rules for model access, tool use and budgets while inspecting prompts and responses inline to prevent data leaks.
Secure every agent: Verify agent identities and enforce just-in-time, least-privilege access so autonomous systems only touch what they need, when they need it.
How the AI Gateway worksย
Prisma AIRS AI Gateway sits inline between every AI interaction, model provider, and agentic interaction (Agent/AI App to LLMs, MCP Tool Calls, and A2A). It acts as a unified LLM, MCP, and A2A Gateway with a single enforcement point for all operational and security controls. Your teams keep using their existing coding assistants, enterprise agents, and copilots, while enforcement moves to the infrastructure layer where the platform team can own it.
Capabilities delivered through this unified control plane are:
Observability
Every request maps to a single unified view: tracking usage, users, projects, token counts, latency and cost so you can retire shadow AI infrastructure immediately.
Governance
Centrally define approved models, tools, and access without touching developer configurations. To drive FinOps and usage management, track every request's cost, tokens, and latency by team or project. Answer cost questions instantly, shut down unsanctioned AI usage, and proactively enforce budgets and rate limits before access is granted.
Coding Assistant Security
Protect credentials, proprietary code and development systems from risky AI actions. The gateway replaces raw provider keys with scoped credentials per user and team.
Operational Controls
Apply data protection, usage limits and policy checks as AI interactions happen. Traffic distributes via a Universal API across providers ensuring quotas are enforced and outages never stall your pipeline.
Agent IdentitySecurity
Establish trusted identities by binding a verifiable, ephemeral identity to agents at execution. The AI Gateway acts as an enforcement point to enable only authenticated agents to make approved calls.
Runtime Securityย
Powered by Prisma AIRS AI Runtime Security, the gateway inspects every prompt and response inline, stopping source code, secrets and customer data from leaving the network while neutralizing prompt injection attempts aligned with the OWASP LLM Top 10 and OWASP Top 10 for Agentic Applications.
Prisma AIRS AI Gateway brings AI governance, identity and runtime controls together in one place. Point products filter text strings or route a single API call and they buckle under real enterprise volume. Most products fail at scale. Prisma AIRS AI Gateway is built on an architecture tested in the most demanding enterprises for their ever evolving AI workloads:ย
68 Trillion+ tokens processed in the last month alone.
Sub-millisecond routing latency and inline inspection secures AI interactions without degrading user experience.
99.999% availability helps ensure your AI operational pipeline does not experience a single point of failure.
Learn about Prisma AIRS AI Gateway and register for our webinar to see the AI Gateway in action.ย
By Yogesh Ranade from Palo Alto Networks, and Senthil Ramakrishnan from AT&T
The digital world is currently navigating a dual-speed revolution. Acceleration of AI and hyperconnectivity is unlocking unprecedented economic value. The silent but rapid progress of quantum computing is fundamentally threatening the cryptographic foundation upon which that value is built.
As leaders in global networking and cybersecurity, Palo Alto Networks and AT&T Business launchedSecure Connectivity solutions for Business Customers. We recognize that quantum-readiness is no longer a distant milestone; it is now a strategic imperative. With threatening data longevity and Trust Now, Forge Later targeting digital identities, the risks are already looming.ย
By integratingPrisma SD-WANโs cryptographic innovation with AT&Tโs global network, Palo Alto Networks and AT&T Business are proud to deliver the Quantum-Resilient SASE Fabric.
The Quantum Shift Towards Building Resilience for Tomorrowโs Reality
For over 30 years, the difficulty of mathematics has been our primary defense. Classical algorithms, like RSA and Diffie-Hellman, provided the shield for our global economy because they were computationally impossible for classical machines to solve. However, quantum computing fundamentally changes this landscape by providing an exponential speed-up. By leveraging Shorโs Algorithm, quantum computers can break these classical cryptographic foundations, turning a decryption process that would take a classic supercomputer millennia into a task of mere hours.
Neutralizing the Quantum Crisis
Palo Alto Networks is embedding Post-Quantum Cryptography (PQC) as a native pillar of the Prisma SASE fabric. We are moving beyond the forklift-upgrade model to a software-defined, standards-based foundation, which is built on strict separation of management and data plane components:
Universal Control Plane Hardening (TLS 1.3): We have transitioned all control plane traffic to TLS 1.3 (Transport Layer Security 1.3), the global gold standard for Internet encryption. This secures the "brain" of the network (where routing configurations and security policies are managed), making it immune to quantum-enabled impersonation and credential theft.
PQC-Hardened Data Plane (IETF Standards): We are operationalizing PQC across the entire fabric by adopting official standards published by the Internet Engineering Task Force (IETF), specifically RFC 9370, 9242, and 8784. In plain terms, these standards allow us to use "hybrid key exchanges." This means we wrap your data in two layers of protection at once: a classical mathematical shield for immediate compatibility, and a quantum-resistant shield to protect against future decryption threats, all without causing packet fragmentation or network slowdowns.
Logs and Telemetry Plane: All network telemetry and metadata (the automated operational logs and traffic pattern data generated by the network, rather than the actual content of your business files) are encrypted in transit via TLS 1.3. This architecture guarantees that even this secondary network metadata is geofenced to your chosen region with no cross-region aggregation, satisfying the most stringent data residency mandates.
Crypto-Agility as a Standard: "Crypto-agility" is natively built into our systems, which means the software is designed to adopt new mathematical algorithms. As the National Institute of Standards and Technology (NIST) refines its guidelines, our systems can be upgraded seamlessly via simple, automated cloud updates without requiring expensive hardware replacements to ensure our customersโ security posture.
Secure Boot Support: Palo Alto Networks Prisma SD-WAN ION hardware supports Secure Boot to ensure that only cryptographically signed bootloaders, kernels, and trusted applications are executed during the boot process. This establishes a chain of trust from the BIOS firmware to the operating system, preventing the execution of unauthorized or tampered software. ION hardware appliances ship with an integrated, dedicated Trusted Platform Module (TPM), which provides hardware-level root-of-trust by securely storing cryptographic keys, certificates, and sensitive data to prevent unauthorized physical tampering and ensure secure device authentication. The OS/software layers use PQC algorithms to negotiate and secure the management, control plane and data plane tunnels. This ensures quantum readiness without requiring an immediate, widespread rip-and-replace of physical branch hardware.
The AT&T Perspective Views Security at Global Scale
From the perspective of a global leader like AT&T, PQC is an operational mandate. Providing connectivity to the worldโs most regulated industries means that security cannot be bolted on. Security must be an inherent property of the transport layer and the connectivity infrastructure itself.
Turning Complexity into a Strategic Advantage
Managing a global footprint that spans across 5G, fiber, and legacy underlays requires an institutional expertise that few can match. For AT&T, the move to a more secure quantum-ready fabric with Dynamic Defense is about providing security where it matters most: the network. Our customers shouldn't have to worry about whether their data is traveling over an MPLS circuit or the public internet.
Through this collaboration, AT&T expands the delivery of Dynamic Defense:
Cross-Underlay Consistency: We enable PQC protection to be applied uniformly across all transport mediums, eliminating the "weak links" that often exist in hybrid environments where data moves between private and public circuits.
Automated PQC Policy Orchestration: New branch locations are seamlessly integrated into the quantum-ready fabric through automated policy distribution. The moment a device is activated via zero touch provisioning, the branch is enabled to be protected against HNDL threats from the first packet without requiring manual site-by-site intervention.
Compliance: With mandates like NIS2/DORA in Europe and NORA/CNSA 2.0 in the U.S., our clients face a closing window for compliance. AT&T provides the verifiable chain of trust required to prove "Quantum Readiness" across the entire circuit path, ensuring your fabric is audit-ready and compliant with global standards.
The Power of the Post-Quantum Secure Fabric
The true value of this relationship lies in the synergy between the network and the security stack. By combining our strengths, we have built a solution that is significantly more resilient than the sum of its parts.
The SPI Advantage Is Performance Without Compromise
Through Service Provider Interconnect (SPI), Palo Alto Networks' security platforms natively integrate with AT&Tโs private network core to deliver a seamless quantum-safe on-ramp. This means business traffic can connect directly to a secure AT&T network without having to build slow, complex software tunnels over the public internet, preserving high performance while delivering next-generation encryption. Historically, high-level encryption meant a "performance tax" on latency and throughput. Our combined architecture allows quantum-safe traffic to flow over AT&Tโs network backbone, enabling organizations to modernize their security without sacrificing the user experience.
Securing the Decentralized Perimeter (The Branch as the Edge)
In todayโs highly distributed business landscape, the traditional corporate "headquarters" is no longer the center of gravity. The network perimeter has shifted to the branch (decentralized edge locations like retail storefronts, remote clinics, regional bank offices, and warehouse hubs) and the individual 5G-connected devices employees use. Securing these remote, local edge points is critical because they represent the primary gateway where sensitive company data first enters the network.ย
By utilizing AT&Tโs leadership in WAN, 5G and cellular technologies, we leverage Hybrid Public Key Infrastructure (PKI) to secure these edge locations. Hybrid PKI is a digital identity framework that issues dual security credentials to every device: one "classical" identity to ensure compatibility with existing networks today, and one "quantum-resistant" identity. This double-verification guarantees that a cellular-connected remote branch or a mobile site is just as immune to quantum decryption or identity spoofing as a fortified corporate data center.
The Path Forward Is a Vision for Long-Term Trust
The transition to a quantum-ready future is a marathon, not a sprint, and the first steps must be taken now. Palo Alto Networks and AT&T Business are offering a clear, practical path to quantum resilience.
We are delivering more than a simple software update as we prepare customers for the next generation of digital commerce. Together, we are designing our network to help ensure the data of today remains protected against the threats of tomorrow, securing the digital integrity of every enterprise we serve.
As we redefine the boundaries of security in connectivity, we invite you to join us in helping secure your organizationโs digital future. Contact your orPalo Alto Networks account representative today to begin a strategic Quantum-Readiness Assessment and experience the power of the Quantum-Resilient SASE Fabric.
Microsoft Corp. today released software updates to plug at least 570 security holes in its Windows operating systems and other software, almost triple the number of vulnerabilities the software giant fixed in its record-smashing Patch Tuesday release last month. Microsoft attributed the burgeoning patch counts to vulnerability discoveries aided by artificial intelligence.
Nearly 60 of the bugs quashed in Julyโs Patch Tuesday earned a โcriticalโ severity rating, meaning miscreants or malware could use them to seize remote control over a Windows device with little or no help from the user. Microsoft also addressed three zero-day flaws, including two that are already being exploited in the wild.
Two of the zero-day weaknesses allow an attacker to elevate their user rights on a Windows system, as do approximately 250 other elevation of privilege flaws fixed this month; they include CVE-2026-56155 โ an Active Directory Federation Services bug โ and CVE-2026-56164, a Microsoft Sharepoint vulnerability.
CVE-2026-50661 is a security feature bypass in Windows BitLocker that could allow attackers to gain access to encrypted data if they have physical access to the device. Microsoft said this bug has been detailed publicly, but that it is not aware of any active exploitation.
In a blog post on July 9, Microsoft Executive Vice President Pavan Davuluri wrote that Windows users will notice โa higher volume of security updates included in each security releaseโ as a result of AI aiding in the discovery of vulnerabilities.
โThe pace of vulnerability discovery is changing with advances in AI making it possible to find more issues, faster, across more code, with new mechanisms that can accelerate both discovery and analysis,โ Davuluri wrote.
Jack Bicer, director of vulnerability research at Action1, called attention to CVE-2026-48561, a remote code execution flaw in Microsoft Copilot (with a 9.6 CVSS threat score) that allows an unauthorized attacker to execute code over the network. Microsoft says an attacker could exploit this bug by hosting a malicious website that causes Microsoft Edge for Android to automatically send crafted prompts to Copilot when a user visits the site.
As AI advances the state of vulnerability discovery and remediation, it is also making it easier for attackers to quickly devise working exploits for known software flaws. Microsoft has long labeled security bugs using its โexploitability index,โ which is Redmondโs best guess as to how likely it is that attackers will be able to figure out a reliable way to exploit a given vulnerability.
But Satnam Narang, senior staff research engineer at Tenable, argues that Microsoftโs exploitability index needs to do a better job of shifting with the machine speed of discovery. For example, Microsoft originally gave this monthโs SharePoint zero-day an exploitability rating of โless likely,โ although the flaw was added to CISAโs Known Exploited Vulnerabilities list on July 1.
โAnthropicโs Red Teamโs own findings for known vulnerabilities (n-days) revealed how fragile this system has become, with its Mythos Preview model being able to produce proof-of-concept exploits for 13 of 14 vulnerabilities that were rated โExploitation Less Likelyโ or โExploitation Unlikely,'โ Narang said. โWhat this means is that our way of looking at Patch Tuesday has changed, because the exploitability index is centered around humans, not AI tools, and as these tools continue to improve, defense needs to improve alongside it.โ
Chris Goettl at Ivanti observed that the record patch numbers from Microsoft come as a number of other major software makers are increasing their patch cadence, including Adobe which announced today it is moving to twice-monthly security bulletins published on the 2nd and 4th Tuesday of each month (Adobe also cited AI for accelerating their patch cycles). Cisco, Mozilla and Oracle also are shipping updates more frequently, while Googleโs patch batches in June 2026 totaled more than 900 security fixes, Goettl noted.
Backing up your Windows system and/or data is always a good idea before applying operating system updates. Given the volume of patches addressed this month it may be wise for end users to wait a few days before applying these fixes. Itโs not uncommon for security patches to introduce system stability issues, and those chances probably increase quite a bit with the gigantic patch count released today.
Palo Alto Networks is pleased to announce the successful completion of a new Cloud Medium security assessment conducted by the Canadian Centre for Cyber Security (Cyber Centre), significantly expanding the number of Palo Alto Networks cloud services assessed for Protected B / Medium Integrity / Medium Availability (PBMM) environments. This assessment includes a broad range of capabilities across our Cortexยฎ, Cortex Cloud and Strataโข platforms. By achieving this milestone, Palo Alto Networks enablesย organizations handling Canadaโs most sensitive data to leverage a unified, AI-driven security architecture without compromising on compliance or operational resilience.
For years, many organizations viewed PBMM as something that only mattered to the Canadian federal government. It was often seen as a procurement requirementโa framework tied to public sector cloud adoption, relevant for departments handling Protected B information, but not necessarily for the private sector.
That assumption is changing.
The reality is that the challenges driving PBMM are no longer unique to government environments. Banks, energy providers, transportation networks, healthcare organizations, crown corporations, and other critical infrastructure operators are now facing many of the same pressures:
Expanding attack surfaces across hybrid and multi-cloud environments.
Increased regulatory scrutiny and privacy obligations.
Greater operational dependence on cloud and AI technologies.
Increased reliance on third-party providers and software supply chains.
The need to maintain operational resilience during cyber incidents and disruptions.
A growing expectation that organizations can demonstrateโnot just claimโsecurity maturity.
That is why PBMM matters far beyond Ottawa. At its core, PBMM represents a rigorous approach to validating whether enterprise-grade security platforms can operate securely in environments where trust, resilience, and operational continuity are critical.
Increasingly, that level of assurance matters to everyone.
What PBMM Really Represents
PBMM, a rigorous cybersecurity and data classification standard used by theย Canadian Centre for Cyber Security, stands for Protected B / Medium Integrity / Medium Availability. While often associated with federal cloud security requirements, PBMM is not simply a checkbox exercise. It is a comprehensive assessment framework aligned to Canadian cybersecurity guidance and operational security expectations.
What makes PBMM important is that it evaluates whether platforms and services can securely support sensitive and mission-critical workloads in real-world environments.
Palo Alto Networks meeting these rigorous PBMM requirements through three core pillars:
Strata (Network Security): Secures data resiliency and zero trust connectivity, driving robust perimeter and cloud edge protection.
Cortex Cloud (Cloud Security): Provides complete visibility, security governance, and data protection across complex cloud-native architectures.
Cortex (Security Operations): Powers the agentic SOC, combining unified data, AI, and automation to detect and respond to threats in real time.
These are not theoretical requirements. They are practical operational expectations designed for environments where downtime, visibility gaps, or security failures can have significant consequences.
Organizations today are no longer evaluating cybersecurity solely based on features. They are evaluating whether platforms can be trusted to support critical operations at scale.
Why Security Expectations Are Changing
The cybersecurity landscape has evolved dramatically. Infrastructure is distributed across cloud providers, SaaS applications, remote users, third-party integrations, operational technology (OT), AI platforms, and interconnected supply chains. At the same time, attacks have become faster, more automated, and more disruptive.
In this environment, security can no longer be treated as a compliance exercise. Organizations need confidence that their platforms, operational processes, and security controls can function effectively under pressure.
This is why Palo Alto Networks has undertaken independent PBMM assessments across its portfolio, providing customers with greater assurance and trust. By meeting these rigorous standards into Strata and Cortex, we enable non-government entitiesโlike financial institutions and utility providersโto deploy the same defensive rigor used to protect national security systems.
Transforming Critical Infrastructure with a Unified Platform
To effectively manage risk, critical infrastructure operators require a platform approach that helps eliminate security silos, reduce manual intervention, and accelerate threat mitigation.
Key Portfolio Advantages for Critical Infrastructure & Enterprise:
AI-Driven Threat Detection & Response:Cortex XSIAMยฎ and Cortex XDRยฎ unify telemetry across endpoints, network, and cloud to deliver unparalleled visibility and automated threat stitching, neutralizing advanced cyberthreats before they disrupt operations.
Comprehensive Cloud Native Protection:Cortex Cloud secures applications from code to cloud to SOC, offering posture security, data protection, and continuous compliance monitoring tailored to stringent Canadian data standards.
Zero Trust Network Security:Strata enables secure access and consistent policy enforcement across campus, branch, and data center environments, protecting critical OT and IT systems from lateral threat movement.
Elite Incident Response: Backed by Unit 42ยฎ, organizations gain access to threat intelligence and rapid incident response services to augment their teams and build long-term cyber resilience.
Operational Resilience Is Becoming a Strategic Requirement
One of the most significant shifts occurring across industries today is the growing focus on operational resilience. Organizations are increasingly asking questions that extend beyond traditional cybersecurity controls:
Can we maintain critical services during a cyber attack?
Do we have visibility across our cloud environments and supply chain dependencies?
Can we rapidly detect, respond to, and recover from disruptions?
Are our governance processes keeping pace with cloud adoption and AI innovation?
As organizations adopt cloud-native architectures, AI-driven technologies, and interconnected digital ecosystems, resilience has become a board-level concern. The ability to prevent incidents remains important, but organizations are equally focused on their ability to withstand, respond to, and recover from them.
This is where frameworks like PBMM provide value. Beyond evaluating security controls, PBMM assesses the governance, operational processes, monitoring capabilities, and risk management practices that help organizations operate securely.
For critical infrastructure operators, resilience is no longer simply an IT objectiveโit is a business imperative. Increasingly, the organizations that earn trust are those that can demonstrate they are prepared to operate effectively when disruption occurs.
Final Thoughts: PBMM Reflects the Future of Trust
PBMM may have started solely as a government assessment framework, but its relevance now extends far beyond federal environments. It represents something universal: the ability to operate securely, reliably, and transparently in environments where trust matters most.
By expanding our PBMM-assessed offerings across Cortex and Strata, Palo Alto Networks underscores its commitment to securing Canada's digital future. We provide the validated foundation organizations need to innovate with confidence, protect sensitive data, and maintain operational continuity under any circumstance.
Ready to modernize your defenses with PBMM-assessed solutions? Schedule a demo with our team or contact Unit 42 to learn how we can help elevate your organization's resilience against emerging cyber threats.
The release of OMB Memo M-26-14("Ensuring Effective and Efficient Agency Logging and Network Visibility to Defend Against Evolving Cyber Threats") marks a historic turning point in federal cybersecurity. By officially rescinding the M-21-31 directive, the White House has delivered a clear message to federal IT leaders: the era of compliance-driven data hoarding is officially over.
While the previous framework was a well-intentioned response to the SolarWinds breach, its mandate to collect and retain vast oceans of unstructured logging data created unintended, unsustainable operational burdens. For the past several years, federal agencies have faced skyrocketing cloud storage bills and overwhelmed Security Operations Centers (SOCs). Crucially, they have been left with vast quantities of cold data that lacked clear operational utility.
As OMB noted, retaining endless data without operational focus is neither cost-effective nor operationally feasible. With M-26-14, the federal government is pivoting to a smarter, sleeker, and far more decisive strategy: a risk-based, prioritized logging framework driven by AI and machine-speed defense.
The Core Shifts: What Federal Leaders Must Understand
M-26-14 strips away administrative "red tape" to focus on how modern cybersecurity risks have evolved. Nation-state threat actors are actively leveraging advanced automation and Artificial Intelligence (AI) to orchestrate attacks at unprecedented speeds. They move laterally across agencies in minutes, hiding behind legitimate corporate credentials.
To beat machine-speed threats, your data layer must operate at machine-scale. The new memo reorganizes federal visibility around two foundational pillars:
1. Continuous Event Monitoring โ Owning the Present
Continuous Event Monitoring demands that logging infrastructure shift from a passive archiving tool to a live-streaming asset. Agencies are now required to monitor network and asset activity in real time, rapidly flag anomalous behavior via behavioral analytics, and initiate immediate mitigation actions directly through their SOCs.
2. Threat Hunting, Investigation, Response, and Forensics โ Dominating the Post-Compromise
When a compromise is suspected, agencies can no longer spend days running slow database queries or pulling disconnected csv files. M-26-14 mandates that agencies keep 6 months of logs "hot and searchable" and 1 year fully "retrievable." This allows defenders to immediately stitch together cross-domain attack patterns, perform rapid root-cause forensics, and share threat intelligence seamlessly with CISA and the FBI.
3. Expanding the Blast Radius: Entering IoT and OT
Perhaps the most significant structural change is the explicit inclusion of Internet of Things (IoT) and Operational Technology (OT) systems. Adversaries do not respect the boundary between your corporate IT network and your physical infrastructure. Under M-26-14, your logging and threat-hunting capabilities must aggressively cover the entire enterpriseโfrom public cloud workloads to the physical facility controls and critical infrastructure grids running on an agency's behalf.
The Clock is Ticking: The Aggressive Maturity Deadlines
Agencies cannot afford a passive approach. The timeline established by OMB M-26-14 moves quickly:
T+90 Days: CISA will publish the new Logging Reference Architecture (LRA) codifying hybrid/centralized deployments, Zero Trust Maturity Model (ZTMM) integration, and AI-driven monitoring guidelines.
LRA +90 Days: Agencies must submit their comprehensive Agency Logging Plans.
Activating OMB M-26-14 with Palo Alto Networks Cortex
Trying to retrofit a legacy SIEM architecture to meet the advanced or optimal effectiveness tiers of M-26-14 is an engineering and budgetary dead end. Legacy SIEMs scale costs linearly with ingestion and rely on static, human-written correlation rules that fail against AI-fueled threats.
The FedRAMP Certified Palo Alto Networks Cortex platformโanchored by Cortex XSIAM (Extended Security Intelligence and Automation Management)โwas engineered from the ground up to solve the exact problems this new memo addresses.
From Disconnected Columns to Cross-Domain "Stitching"
Legacy logging stores data in isolated silos. An analyst trying to track an adversary has to manually look at an identity log, cross-reference it with a network firewall alert, and match it to an endpoint execution.
Cortex XSIAM features a revolutionary Analytics Engine that automatically stitches multi-vendor logs across cloud, network, endpoint, and identity at the moment of ingestion. It transforms raw text into a single, cohesive, context-rich story, instantly aligning incidents with the MITRE ATT&CK framework.ย Cortex XSIAM doesnโt just ingest data, it understands the data which enables stitching of multiple data elements into a single, multi-context construct which accelerates analysis via AI and machine learning.
Replacing Static Rules with Cloud-Scale AI
Adversaries use AI to evade signature detection. Cortex XSIAM fights fire with fire, applying out-of-the-box, unsupervised machine learning models to baseline normal behavioral patterns across your entire federal enterprise. When an anomalous lateral movement, data exfiltration attempt, or credential abuse event occurs, XSIAM flags the threat instantlyโwithout requiring your team to spend weeks writing custom correlation code.
Accelerating Continuous Event Monitoring (CEM) and Threat Hunting, Investigation, Response and Forensics (THIRF)
There is more to CEM than just monitoring network activity.ย Activity on endpoints, within your identity management solution(s) and in the cloud are just as important.ย Understanding the data, knowing which log records are related to each other across multiple log sources, which events are relevant and the context they provide is required.ย ย
Understanding these events and their contextual relationships is fundamental to providing THIRF in an efficient manner.ย Cortex XSIAM provides over 2,900 machine learning models out of the box, models that are trained on the data in your environment so they detect anomalous activity based on what is โnormalโ in your environment, not trained on generic data from other customers or a lab.ย These models can identify threats based on data stitched together from multiple sources to provide a more complete context yielding more accurate and consistent results while decreasing time to value.
Securing the Unmanageable: Agentless IoT/OT Defense
You cannot install an EDR logging agent on a smart building HVAC system or an industrial programmable logic controller (PLC). Palo Alto Networks utilizes non-disruptive, passive network analysis to continuously discover, profile, and generate high-fidelity security logs for IoT and OT infrastructure. These logs stream directly into XSIAM, eliminating critical federal blind spots and protecting your High Value Assets (HVAs) from cross-boundary pivot attacks.
Solving the Storage Conundrum Safely
Keeping six months of high-velocity event logs fully "hot and searchable" under a traditional database indexing model creates a crushing financial burden. Cortex XSIAM fundamentally resets the Total Cost of Ownership (TCO) equation by leveraging an index-free, cloud-native data lake architecture that decouples storage costs from analytical performance. By eliminating legacy ingestion taxes and infrastructure overhead, federal defenders can search petabytes of data in secondsโeffortlessly meeting the 6-month searchable and 1-year retrievable thresholds. Furthermore, integrated data masking rules strip away sensitive PII or low-value data noise before it hits the SOC, ensuring agencies only pay for operationally vital intelligence.
ย
The Bottom Line for Federal Leaders
OMB M-26-14 is a massive step forward for federal cybersecurity. It frees CISOs from the operational gridlock of untargeted data archiving and empowers them to build faster, modern, and highly responsive security operations.
Meeting the strict 120-to-320-day maturity milestones requires moving past the tools of the last decade. By partnering with Palo Alto Networks and deploying the Cortex suite, federal agencies can seamlessly transition into a risk-aligned, AI-driven SOC. They can confidently check the box on OMB compliance while achieving what the directive actually intends: protecting the resilience and integrity of the federal mission at machine speed.
Palo Alto Networksโ Cortex XSIAM is FedRAMP certified at both the moderate and high levels.
Want to learn more about how to structure your upcoming Agency Logging Plan to meet CISA's upcoming Logging Reference Architecture?ย
Contact the Palo Alto Networks Federal Team today to schedule an architectural deep-dive.
Microsoft today released software updates to plug nearly 200 security holes across its Windows operating systems and supported software, a record number of fixes for the companyโs monthly Patch Tuesday cycle. Nearly three dozen of those bugs earned Microsoftโs most dire โcriticalโ rating, and exploit code for at least three of the weaknesses is now publicly available.
The software giant said in a blog post last month that both its engineers and the security community are increasing using artificial intelligence tools to find bugs, meaning this monthโs heavy Patch Tuesday may start to become the norm, said Satnam Narang, senior staff research engineer at Tenable.
โSome surveys put AI usage among security professionals generally at 90%, so itโs unsurprising that this volume of patches may be the norm,โ Narang said. โPandoraโs proverbial box has been opened, and as more advanced AI models become available, we expect the norm to continue upward across the board, not just for Patch Tuesday.โ
Juneโs zero-day bugs include CVE-2026-49160, a denial of service vulnerability affecting a range of web servers, including Microsoft Internet Information Services (IIS). Microsoft says the flaw was reported by OpenAIโs Codex.
Two of the zero-days addressed this month appear to stem from recent vulnerability disclosures by Nightmare Eclipse, the nickname chosen by a security researcher who has been dropping exploits for various Windows flaws. One of those, dubbed โGreenPlasma,โ leverages an elevation of privilege weakness in the Windows Collaborative Translation Framework, the same framework patched today in CVE-2026-45586.
Nightmare Eclipse also last month released โYellowKey,โ an exploit for a Windows BitLocker vulnerability that allows an attacker with physical access to view encrypted data, and CVE-2026-50507 is a patch for an elevation of privilege bug in BitLocker.
Microsoft received heavy blowback on social media last month after it said in a blog post that it was considering taking legal action against the security researcher. The company later clarified on Twitter/X that while it has no intention of pursuing legal actions against researchers, it would report them to authorities if they break the law. The advisories for CVE-2026-49160 and CVE-2026-50507 do not credit any researchers in the acknowledgement section, saying only that โMicrosoft recognizes the efforts of those in the security community who help us protect customers through coordinated vulnerability disclosure.โ
Nightmare Eclipse claims to be a former employee of Microsoft, although Microsoft has not responded to questions about this claim. Rapid7 notes that a recent blog post by Nightmare Eclipse included an image of Albert Wesker, a character from the Resident Evil video game series who formerly worked as a researcher for a technology company before going rogue.
Nightmare Eclipse has pledged to release even more zero-day exploits for Windows in what they called a โbone shatteringโ drop planned for July 14 (the same day as next monthโs Patch Tuesday). Immediately following the release of Microsoft patches today, the researcher published an exploit for what they claimed was a zero-day bug in Windows Defender.
While 200 vulnerabilities may be a record for Patch Tuesday, the actual number of security flaws Microsoft addressed this month is far higher, said Rapid7โs Adam Barnett.
โSo far this month, Microsoft has provided patches to address 360 browser vulnerabilities, which is an order of magnitude more than has been typical in any given month over the past few years,โ Barnett wrote. โAs usual, browser [flaws] are not included in the Patch Tuesday count above. Indeed, the vast, and presumably sustained, uptick in the number of browser vulnerabilities has led to Microsoft no longer enumerating Chromium CVEs in the Security Update Guide.โ
Microsoft also patched a zero-day vulnerability in Visual Studio Code that allows attackers to steal GitHub tokens with a single click. The company was forced to push a stopgap fix for the flaw on June 3, after a researcher published instructions showing how to exploit it. The researcher said they opted not to work with Microsoft because of a recent experience wherein Redmond silently patched a flaw they reported without offering credit or recognition.
Microsoft battled its own internal zero-day emergencies last week, after at least 72 of the companyโs public code repositories were infected with a variant of the Shai-Hulud worm. Researchers found that all of the affected packages were connected to Microsoft official Azure Durable Task SDK, which got hit by the same Shai-Hulud worm in May.
Other major software makers are also shipping outsized update bundles this month. Adobe has released updates to fix a massive number of critical vulnerabilities across a range of products, including Adobe Experience Manager, Acrobat Reader and Cold Fusion. On June 3, Google resolved a whopping 429 vulnerabilities in its latest Chrome browser update (Chrome automatically downloads updates but installing them usually requires a complete restart of the browser).
As ever, please consider backing up your data before applying operating system updates, and drop a note in the comments if you run into any problems with this monthโs patches.
The evolved NextWave Partner Program raises expectations while strengthening enablement, incentives and the Partner Development Fund to support partner growth and reinvestment.
Levels and specializations are more closely aligned to next-generation security priorities, helping partners deepen expertise and making partner distinctions more meaningful for customers.
These changes help create a more capable partner ecosystem, with deeper capabilities, greater alignment with customer needs, and a stronger foundation to support the future of security.
Cybersecurity partnerships are operating in a more demanding environment. As customers consolidate vendors, modernize security architectures and adopt artificial intelligence (AI) across the enterprise, theyโre placing greater expectations on partners to help guide decisions across network, cloud and security operations. They also want clearer evidence that their selected partners have invested in growing the skills and expertise needed to support more integrated and fast-changing security priorities.
The Palo Alto Networks NextWave Partner Program has evolved to help partners meet these heightened expectations. As security delivery becomes broader and more strategic, customers are placing more weight on what a partnerโs credentials actually represent. Thatโs why stronger performance and enablement requirements are part of our reimagined program. The new requirements help partners better understand what they need to build real capability and advance within our program. They also give more substance to the designations customers see when choosing a partner.
Our objective was never simply to raise the standards for engagement in our program. It was to inspire partners at all levels โ Registered, Innovator, Platinum and Diamond โ to invest deliberately and continuously in learning, so they can deepen their proficiency and earn specializations that will help them stay competitive and build and deliver the future of security.
Why Requirements and Incentives Had to Evolve Together
Raising performance expectations was only part of the work in evolving the NextWave program. We also wanted to give our partners compelling reasons to invest in the capabilities Palo Alto Networks wants to see scale. That meant looking more closely at how standards, specializations and incentives fit together, and how we can help accelerate mutual success.
We are providing our partners with better access, better visibility and better support for learning and enablement. In turn, we are recognizing and rewarding partners for their efforts to develop and maintain the competency, capability and capacity needed to go to market successfully with Palo Alto Networks.
This approach, shaped largely by partner feedback, is designed to make incentives easier to access while still directing partner investment toward deeper specialization and next-gen security capabilities. Program levels and product specializations help define what partners need to do to grow within our program and to excel at selling, supporting or delivering Palo Alto Networks products and services.
The programโs Partner Development Fund adds another dimension to this evolved model. It gives all partners a more deliberate way to reinvest a portion of their earned incentives into the capabilities they need to stay competitive and innovate, including training, certification, workshops, demos and other strategic activities that help strengthen their teamโs overall readiness over time. In that sense, the program is both rewarding current performance and driving mutual growth.
Training and Enablement that Move with the Market
As we continue to strengthen our partner program, Palo Alto Networks is refreshing courses, updating certification paths and redesigning training to better reflect the customer needs that partners are helping to address today, including emerging areas like AI security.
Notable improvements:
Introduced more online, on-demand learning experiences across all products and across all roles, including sales, technical presales and post-sales professionals.
Expanded access to lab environments for hands-on experiences, as well as access to perform demos for customers.
Injected AI roleplay into learning experiences to help sales and presales teams improve their ability to educate customers about our products and services while addressing questions or concerns.
Instituted a continuous education component that encourages partners to stay current with certifications and other program requirements, so they donโt need to be tested annually.
Our aim with these changes is to keep learning options relevant, practical and easier to engage in and apply in practice. We believe product and services training should help partners deepen expertise, validate skills and stay current as technologies, customer expectations and threats shift. It should also recognize the experience many professionals already bring to the table, with learning paths that are rigorous without being repetitive or unnecessarily burdensome.
Ultimately, the impact of providing more effective enablement for our partners (and outlining clear requirements for advanced specializations and total certified staff for specific partner paths) positively impacts the customer experience through more informed conversations, stronger design guidance and more consistent support across the entire security lifecycle.
A More Focused Program to Help Accelerate Next-Generation Security
Part of what makes the current evolution of the NextWave program so significant is its focus on helping partners build the bench strength they will need to stay competitive as security becomes more platform-driven, AI-influenced and interconnected across domains. The program also encourages bookings tied to next-generation security priorities, helping direct partner investment toward the areas customers are prioritizing most. That focus is especially visible in areas such as Idiraยฎ,ย Prismaยฎ SASE, Cortexยฎ Cloud and Cortex, where customer demand and program priorities are increasingly aligned.
The benefits of that alignment extend beyond the partner organization. Customers gain access to partners that are better prepared to support more connected security strategies without adding unnecessary complexity. They can work with partners that are building expertise around the technologies and use cases becoming more central to modern enterprise security programs.
This kind of alignment also strengthens the broader ecosystem. It creates a clearer connection between customer needs, partner capabilities and Palo Alto Networks platform strategy. Itโs the value exchange in cybersecurity in action: Ongoing investment in knowledge, skills and services that helps partners grow while giving customers faster time-to-value realization.
What Stronger Program Requirements Mean for Customers
For customers, stronger requirements for our Nextwave program can make partner distinctions more meaningful. A specialization or program level should point to something real, such as training completed, certifications maintained and expertise developed. While those accomplishments donโt guarantee security outcomes, they do provide evidence that a partner has built the depth needed to support more complex environments.
Partner distinctions are also reinforced through an active compliance framework rather than treated as a one-time achievement. Partners have ongoing visibility into their progress and can be recognized immediately throughout the year as they meet requirements. Reviews take place on a defined cycle, and status changes are subject to oversight. Taken together, these elements add credibility to the designations customers see and give them more weight in the partner selection process.
This becomes increasingly important as customers look for security partners that can do more than support a single transaction or product decision. Many are seeking guidance at the architecture stage and during implementation, and expecting continuity as IT environments evolve and new risks emerge. It also raises the level of scrutiny that partner selection deserves:
Is a partner specialized in the areas most relevant to the customerโs priorities?
Do they have the certifications and technical expertise required to support the solutions being considered?
Can they provide the level of guidance, implementation support and ongoing engagement the relationship will require over time?
In a fast-moving security market, questions like these can help customers make more informed decisions about which partners are best equipped to deliver long-term value.
What Partners Should Do Now
Now that weโve introduced our new program requirements, partners should take stock of whether their certifications, specializations and go-to-market priorities are aligned to where customer demand and the future of security are headed. Steps partners can take:
Evaluate your current book of business: Consider where you may be missing growth opportunities because the right specializations arenโt yet in place. Those gaps can affect both business momentum and the ability to earn incentives.
Reflect on the current direction of your practice: Which customer conversations are signaling the need for deeper expertise? Which areas of next-generation security are becoming more central to your future? These questions can help guide your next investments by clarifying where your practice needs to build more depth sooner rather than later.
Review certifications and specializations with growth in mind: Look at where new specializations could open the door to additional incentives and stronger alignment with customer demand, while ensuring your teamโs existing certifications and specializations remain on track for the next compliance cycle.
Partners that take the time now to assess our new requirements and create a plan to meet them will be better positioned to advance within and benefit from our partner program, while developing the capabilities needed to help build the future of security.
Partners with a designated Palo Alto Networks Channel Business Manager can get detailed data and analysis now on their progress and performance in the Nextwave program, including the status of their certifications and which team members have engaged in training, demos and more. In the second half of 2026, we plan to make the same dashboard capabilities and insights directly available to all partners, so they can understand exactly what they need to do to excel in our program. These red-yellow-green dashboards are simple but powerful tools, and we are eager to put them in our partnersโ hands soon.
Over the past few weeks, we have reached a critical turning point in cybersecurity. Following the launch of our Frontier AI Defense initiative, weโve continued testing the latest frontier models (including Anthropicโs Mythos and Claude Opus 4.7, as well as OpenAIโs GPT-5.5-Cyber) as part of the Trusted Access for Cyber program.
The urgency to innovate continues to ramp up. As Lee Klarich recently detailed in his Defender's Guide to the Frontier AI Impact on Cybersecurity, our current landscape is defined by a brief three-to-five-month window to gain a strategic advantage over attackers. To outsmart AI-based exploits, enterprises must decisively address vulnerabilities across their code and stand up the right security stack to enable real-time, automated defenses.
With such a ticking clock in front of us, acting rapidly and at-scale to support our customers is paramount. Today, we exponentially grow our scale of delivery by expanding our Frontier AI Alliance.
Since introducing this initiative, our collaboration with initial partners โ Accenture, Deloitte, IBM, NTT DATA, and PwC โ has already begun changing the defensive math for our customers. This is a moment that calls for radical collaboration across the entire security ecosystem, so today we are proud to welcome a new cohort of strategic partners โ Cognizant, HCLTech, Kyndryl, TCS, Infosys, McKinsey & Company, Orange Cyberdefense, and Wipro โ who will join us in delivering AI readiness at scale.
While this expansion significantly increases our reach, this is only the beginning. We are committed to a continuous evolution of this alliance and will be adding more critical partners in the future across the globe to ensure our customers have the most robust defense network possible.
By combining our technology with these partnersโ deep consulting expertise, we are delivering:
Machine-Speed Security: Natively integrating Frontier AI to provide real-time, automated defense against autonomous threats.
Intelligence-Led Resilience: Leveraging Unit 42ยฎ experts to fast-track the discovery and remediation of exposures at machine speed.
Hardened Defenses: Utilizing early access to frontier models from partners like OpenAI and Anthropic to simulate and block attack chains before they hit the mainstream.
The stakes are high. The attack cycle has compressed with the time from initial access to data exfiltration collapsing to just 39 seconds. Machine-speed MTTR (mean time to respond) is no longer an ambitious goal, it is a requirement.
This initiative underscores our commitment to providing every client with integrated, real-time protection.
This blog contains forward-looking statements that involve risks, uncertainties and assumptions, including, without limitation, statements regarding the benefits, impact, or performance or potential benefits, impact or performance of our products and technologies or future products and technologies. These forward-looking statements are not guarantees of future performance, and there are a significant number of factors that could cause actual results to differ materially from statements made in this blog. We identify certain important risks and uncertainties that could affect our results and performance in our most recent Annual Report on Form 10-K, our most recent Quarterly Report on Form 10-Q, and our other filings with the U.S. Securities and Exchange Commission from time-to-time, each of which are available on our website at investors.paloaltonetworks.com and on the SEC's website at www.sec.gov.ย All forward-looking statements in this blog are based on information available to us as of the date hereof, and we do not assume any obligation to update the forward-looking statements provided to reflect events that occur or circumstances that exist after the date on which they were made.
Built on the Pioneers of PAM (privileged access management): Idira is Palo Alto Networks next-generation identity security platform, extending privileged access controls to every human, machine and AI agent identity in the AI enterprise.
Zero Standing Privilege by Default: Idira replaces static, always-on access with dynamic privilege, granted just-in-time on a single control plane.
AI-Driven Identity: AI runs natively inside Idira to surface hidden entitlements, unmanaged accounts, recommend least privilege, and remediate to close the gap between attackers who move in 72 minutes and defenders who historically took days.
Since Palo Alto Networks and CyberArk came together in February, customers have been asking me the same question: What does the future of identity security actually look like?
I am proud to introduce Idira, the next-generation identity security platform from Palo Alto Networks. Idira secures every identity in the AI enterprise (human, machine, AI agent) on a single control plane that discovers risk, applies privilege dynamically, and governs the full lifecycle from first access to last session.
Idira begins with a belief shaped by more than 20 years of working on this problem. Privilege is the most challenging aspect of identity security. For a generation, the industry learned how to manage it well for a small population โ administrators inside the most security-sensitive organizations in the world. That was necessary. But it is no longer enough.
The moment has come to extend that same rigor to every identity, because every identity today carries the power to move the business, or enable an attacker. That is the journey Idira takes us on. From privilege controls for administrators, to privilege controls for every identity.
Attackers Are Not Breaking In. They Are Logging In.
For most of the last two decades, identity security was built on a comfortable assumption: One can maintain a firm divide between a small number of powerful administrators and a much larger number of ordinary users; that is enough to secure the organization. That assumption no longer holds.
Our Chairman and CEO, Nikesh Arora, calls it the โIAM fallacy,โ and the data in the 2026 Identity Security Landscape Report makes clear why it is time to retire this assumption.
Machine identities now outnumber humans by 109 to 1. Of those, 79 are AI agents.
91% of organizations already run autonomous agents in production.
90% of organizations suffered an identity-related breach in the past 12 months. 83% of organizations suffered two or more incidents.
The old model is not failing because identity became less important. It is failing because identity and privilege became universal and ubiquitous.
Every major breach I have studied over the last two years follows the same pattern. An attacker steals a credential. They move laterally using standing access that should have expired. They escalate privilege. They reach the data, the infrastructure or the business systems they came for: Okta, MGM, Microsoft. Different industries. Different scales. The same pattern.
One overprivileged identity unlocks the entire enterprise.
And when defenders have a chance to respond, they are already behind and disadvantaged. 97% of practitioners tell us that fragmented tools add 12 hours to every identity incident response time. All while Unit 42ยฎ has observed the fastest attackers move from a first foothold to exfiltration in as little as 72 minutes.
Identity is now the enterprise perimeter. And the perimeter was built for a threat model that no longer exists.
Every Identity Is Privileged โ Idiraโs First Fundamental Principle
The premise of Idira is simple. Every identity in your organization is privileged.
Every login, every token, every service account, every workload, every AI agent can trigger a workflow, call an API, or reach sensitive data. Some can create and destroy infrastructures, direct organizational spend, or create new identities. Privilege is no longer reserved for a small class of administrators. It is distributed across the enterprise, quietly and continuously, every second of the day.
The controls that protect privilege cannot be reserved for the few, either.
Idira changes three things from day one.
First, We Discover
Idira continuously finds every identity, every entitlement and every access path across your entire environment: humans, machines, workloads, secrets, certificates and AI agents everywhere โ on the network, in the cloud, on servers and endpoints, in the browser. If someone or something can authenticate, Idira knows it is there, knows what it can reach, and evaluates how much of that access is actually necessary.
Second, We Control
Idira replaces static, always-on accounts attackers rely on with dynamic privileges that exist only in the moment of use. Zero standing privilege moves from aspiration to default, and it applies equally to the administrator logging into production, the developer deploying code, and the AI agent calling a tool. This is the shift to identity-centric active security.
Third, We Govern
Idira automates the identity lifecycle end-to-end. Governance stops being a quarterly compliance exercise and becomes a continuous enforcement loop. The 12-hour fragmentation tax closes.
This is what I mean when I say we are democratizing privilege controls. We are not loosening them. We are extending the strongest privilege controls the industry has ever built to every identity that now carries the weight of the business, without penalizing these identities for the powers they carry.
Already Better Together
Idira is not launching into an empty runway. We have been executing against this roadmap since the day we joined Palo Alto Networks, and the early results give us real confidence in what comes next.
Earlier this year at the RSA Conference, we launched Next-Generation Trust Securityย (NGTS), the first network-native platform to automate certificate lifecycle management and accelerate post-quantum readiness. That matters because 71% of organizations have not yet automated certificate renewal. As public TLS lifetimes compress to 47 days and manual workloads multiply, that gap becomes more than an operational burden. It becomes a business continuity risk.
NGTS closes it in the network itself.
As one of the core platforms of Palo Alto Networks along with Strataยฎ and Cortexยฎ, Idira is providing deep identity integrations across the entire portfolio to enhance platform value for customers. Prismaยฎ Browser delivers privileged access directly in the place where enterprise users work. Prisma AIRS 3.0 natively integrates with Idira to extend deep identity security and privilege controls to AI agents. Cortex will receive first-party identity signals to sharpen detection and take automatic identity- and privilege-driven response actions when indicators of compromise are detected.
Customers are already seeing the impact. Northern Trust improved password compliance by 137 percent. Panasonic Information Systems rebuilt its security operations around identity. Healthfirst grounded its zero trust program in identity-first controls. PDS Health secured clinical access for more than 900 practices. They had different problems with the same answer.
Different challenges. One answer. One platform. Consistent privilege controls applied to every identity that matters.
AI Makes This Urgent. AI Makes This Possible.
AI has changed the speed, scale and economics of identity risk.
Frontier models have crossed a threshold. Anthropic's Claude Mythos Preview has already identified thousands of zero-day vulnerabilities across the operating systems and browsers that businesses rely on every day. Every exposed secret, every standing admin path, every forgotten service account can now be discovered, validated and weaponized faster than most security teams can respond. 55% of the decision-makers in our 2026 survey named AI-enabled threats as their top identity concern.
If frontier models are rewriting the economics of attack, the only credible response is to rewrite the economics of defense with the same technology.
Idira is how we do that in identity. AI is built into the platform to surface hidden entitlements, identify risky access combinations, recommend the least privilege automatically, and drive surgical remediation. That same intelligence lets attackers find the weakest link in 72 minutes and helps defenders close it in seconds.
When code cannot be patched fast enough, identity becomes the control plane that can still adapt at machine speed.
Same Mission, Stronger Together
For more than two decades, the pioneers of privileged access have management-built controls trusted to safeguard the world's most critical environments. That mission created a category and earned the trust that made today possible.
Idira carries that mission forward and expands it to match the scale of the problem we now face.
This is the first wave, not the last. The roadmap extends privilege controls to workforce identity, advances machine and agentic identity security, and unifies a fragmented market into one platform. We are building it in the open, shaped by the customers in the room with us at IMPACT and by the realities they face every day.
The future of identity security will not be defined by access alone. It will be defined by control. See what Idira is built to deliver.
Forward-Looking Statements
This blog contains forward-looking statements that involve risks, uncertainties and assumptions, including, without limitation, statements regarding the benefits, impact, or performance or potential benefits, impact or performance of our products and technologies or future products and technologies. Any unreleased services, integrations or features (and any services or features not generally available to customers) referenced in this or other press releases or public statements are not currently available (or are not yet generally available to customers) and may not be delivered when expected or at all. Customers who purchase Palo Alto Networks applications should make their purchase decisions based on services and features currently generally available.
For the last several months, we have had early, unbounded access to the latest frontier AI models. What weโve seen from that vantage point has made it clear that the window for organizations to get ahead of whatโs coming is shorter than most leaders realize.
We have moved past the era of incremental AI improvements into a threat landscape shift. Our testing has revealed a step-change in capability that demonstrates an intuitive understanding of software vulnerabilities. This is more than faster code generation, it is a shift from AI as an assistant to AI as an autonomous agent capable of discovering and chaining flaws at a scale that most defenders arenโt prepared for.
These capabilities will not stay confined to controlled environments for long. When Mythos first launched, we predicted a six-month window before attackers gained access. We now believe that timeline has accelerated significantly.
To meet this inflection point, defense must operate at the speed of the adversary. That is why Palo Alto Networks has introduced Frontier AI Defense. This initiative unites our AI-native security platforms with Unit 42ยฎ consulting and threat expertise with strategic partners to deliver continuous protection, prioritized risk mitigation and autonomous remediation.
What the Threat Looks Like Now
The latest frontier models, including OpenAIโs GPT-5.5-Cyber, Anthropicโs Mythos and Claude Opus 4.7, and the specialized variants emerging across major labs, represent roughly a 50% improvement in coding efficiency over their predecessors. That number sounds incremental, but in practice, itโs the threshold at which AI crosses from a helpful assistant into an autonomous operator.
Based on our testing and review, we found four key developments that, taken together, redefine the modern threat landscape:
Vulnerability Discovery at Scale: Frontier AI is exceptionally effective at identifying vulnerabilities across massive, complex codebases. In our testing, three weeks of model-assisted analysis matched a full year of manual penetration testing, with broader coverage.
Exploit Chaining & Synthesis: What is more consequential than individual discovery is the modelsโ ability to think like an attacker. They link multiple lower-severity issues into single, critical exploit paths, seeing full-stack logic, including SaaS and public-facing surfaces, in ways traditional scanners cannot.
Attack Cycle Compression: In AI-assisted scenarios, the time from initial access to exfiltration has collapsed to as little as 25 minutes. Detection and response measured in hours is no longer a viable standard; single-digit MTTR (Mean Time to Respond) is the new floor.
The Unsupervised Attack Surface: Rapid AI development and decentralized innovation are creating a massive, unsupervised attack surface in real-time. As local AI agents become commonplace, every desktop is now effectively a server, yet most organizations lack visibility into the code their own employees are generating and deploying.
Our Approach
These emerging threats form the foundation of how we have architected our platform response for the agentic era โ Frontier AI Defense. Our approach moves beyond traditional, reactive defense to provide a comprehensive framework built to outpace frontier-AI-enabled attackers. This initiative is defined by:
Advanced Access: We leverage early access to frontier AI models to harden defenses and simulate attacks before they reach the mainstream.
Intelligence-Led Resilience: Unit 42 experts leverage frontier AI to fast-track discovery and remediation of exposures at machine speed through our Unit 42 Frontier AI Defense service.
Unified Global Ecosystem: We provide the scale required for global protection through our Frontier AI Alliance of elite partners, including Accenture, Armadin, Deloitte, IBM, NTT DATA, and PwC.
Machine Speed Security: By natively integrating Frontier AI across our platforms, we deliver the automated, real-time defense necessary to counter autonomous threats.
The Window Is Open. It Wonโt Be for Long.
The capabilities we tested under early-access conditions are expected to become widely available over the next several months. Success in this new environment requires adapting your cybersecurity stack before these tools are in the hands of every adversary.
The threat has never been more sophisticated. The window to prepare for this shift is closing. And we're here to help secure your future at the edge of the frontier.
Modern phishing campaigns are no longer trying to convince users. They are trying to outrun them. By forcing an automatic progression from click to download, attackers eliminate the moment of hesitation entirely by forcing files to download instantly using trusted cloud platforms like Dropbox and Google Drive.
Detecting when these legitimate SaaS auto-download features are being weaponized is an immense challenge for traditional defenses. This is exactly where Cortexยฎ Email Security steps in. By combining deep static analysis with advanced behavioral intelligence, the module can distinguish in this attack between a benign file share and a malicious, forced-momentum trigger.
This technical detection is vital because while the autodownload method is the primary cause of infection, its effectiveness relies on a clever strategy, using a wide range of changing social engineering lures. By alternating between lures like 'Invoices' or 'Quotes,' attackers rotate their themes to catch a wider variety of victims. This strategy allows attackers to convert trusted email links into rapid, dangerous file executions that effectively evade standard security measures.
How Forced Momentum Drives Auto-Downloads
The core of this attack leverages the infrastructure of real SaaS providers to eliminate the user's preview buffer. Typically, cloud sharing directs users to a webpage for file examination. In this campaign, however, forced-download parameters (such as ?dl=1 on Dropbox) are used instead. To ensure the victim executes the file once it lands on their machine, attackers hide the danger behind "visual anchors." By using double extensions like PDF and .EXE, the threat actor exploits default settings in certain operating systems that hide known extensions. The user's eyes stop at the familiar ".PDF" or ".ZIP," leading them to believe the file is a harmless document rather than a malicious executable.
When the targeted victim clicks the link in the email, it triggers an immediate file download in the browser, effectively bypassing any intermediary steps.
Attack Flow: From Email to Execution
The Bait: A highly personalized email arrives, using a trusted cloud link (like Dropbox) to lower the victim's guard.
The Trap: Clicking the link skips the usual "preview" screen and instantly drops a file onto the victim's computer.
The Disguise: The file is cleverly named to look like a safe PDF or document, hiding its true identity as a harmful program.
The Lock: In many cases, the attacker ensures only the intended victim can open the file, preventing security tools from scanning it first.
The Takeover: Once the victim opens the file, the attacker gains remote access to the system.
Multi-step attack flow, starting from targeted phishing email, to bypass security and establish persistence.
The Library of Lures Strategy
To fuel the autodownload machine, attackers employ a flexible strategy by switching between various social engineering themes. This spear phishing campaign targets specific inboxes, such as "Orders," to exploit professional routines. Some common lures found in this campaign include:
Financial Urgency โ Fake "Invoices" or "Receipts" that induce anxiety. These often set close-day payment deadlines, pressuring recipients to click quickly.
Business Operations โ "Quote Requests" or "Purchase Orders" that exploit professional habits.
Deceptive Naming โ Concealing the download as a safe document, using display text like "invoice.pdf" in the email body to hide the underlying Dropbox URL.
Government Domain Impersonation
Attackers often leverage high-authority lures designed to paralyze a user's critical thinking. In one sophisticated wave, we observed threats impersonating a government entity by exploiting the high-reputation, official government domain. By borrowing the reputational authority associated with official infrastructure, the attacker successfully maneuvered an "Unidentified Payment Notice" past standard "Untrusted Sender" filters. To the recipient, the email carries the weight of a sanctioned document. Fearing legal or financial ramifications, they feel a heightened sense of urgency to click "View Invoice" to resolve the issue immediately.
Employee Impersonation
When government authority isnโt the angle, attackers shift to impersonating internal staff. In one case, the senderโs display name was spoofed to match a real employee in the target organization. Attackers rely on a โMomentum of Trustโ tied to familiar names to overwhelm user judgment. Even when a generic Gmail address is used, users, especially those on mobile devices, rarely pause to check the underlying headers.
Internal Trust Amplification ("Human Relay")
The most effective aspect of this campaign occurs through Internal Laundering, where the threat shifts from external suspicion to a trusted internal message. This was observed when a Finance Department employee received a "Quote Analysis" file and, believing it to be a valid inquiry, mistakenly forwarded the link to the Procurement department.
At that stage, the attack no longer depended on deception, it propagated through trusted human workflows. These various tactics illustrate the sophistication and adaptability of phishing campaigns and highlight the importance of vigilance in email security.
How We Uncovered a Single Threat Actor
Although the lures appeared diverse, a deeper technical analysis revealed that they were all orchestrated by a single, coordinated threat actor.
By mapping the campaign, we uncovered a significant pattern: Each autodownload link pointed to a different file hash to evade signature detection, but all unique executables were ultimately associated with the same parent installer hash.
The file was identified as a specific Remote Monitoring and Management (RMM) executable, an administrative software used to manage computers remotely. Because RMM tools are legitimate, they often trigger fewer alerts than traditional Trojans. This allows the attacker to maintain persistent access under the guise of โauthorizedโ system activity.
How Cortex Email Security Addresses the Threat
To defend against a campaign that emphasizes speed and rotation, behavioral analysis is essential.
The Cortexยฎ Email Security Module addresses this threat:
Advanced URL Analysis โ Detection of forced-download parameters, combined with delivery of high-risk files via URLs.
Deep Metadata Correlationโ Correlating sender identity with behavioral anomalies to flag threats that traditional scanners might overlook.
The security engine triggers an alert by synthesizing LLM analysis with real-time email telemetry, global threat intelligence and behavioral signals.
Securing the Click
The combination of autodownload links and rotating lures is crafted to exploit user momentum and the "psychology of trust."
This campaign represents a shift from deception to acceleration. Attackers no longer need perfect lures, they only need to remove friction. Defenders must evolve accordingly, focusing not only on what a link is, but on what it forces a user to do.
Palo Alto Networks Cortex Advanced Email Security was built for this evolution. By moving beyond static file analysis to identify the behavioral "red flags" of autodownloads and forced-momentum URLs, we provide the visibility needed to stop these attacks before they reach the device.
The module examines email metadata, content, and behavior to uncover hidden malicious intent and sophisticated impersonation, including AI-crafted threats. By assigning precise risk scores to every detection, the system filters out the noise, allowing analysts to move past alert fatigue and focus on the most critical threats first.
Why is the "Auto-Download" parameter so effective? It removes the "moment of doubt." By bypassing the preview page, the attacker forces the file onto the computer instantly, prompting the user to "Open" it out of habit.
How does the use of rotating lures benefit the attacker? It maximizes both psychological and technical success. People have different "blind spots" (e.g., finance professionals are likely to click on invoices), and variety increases the chances of finding a template that can bypass specific customers' security filters.
Why might a sandbox fail to catch the malicious file? Because the link was "Identity-Bound." To the scanner, the link appeared to lead to a harmless error page (cloaking), resulting in a false negative.
Cloaking involves showing different content to security scanners than what is presented to the victim. By using Identity-Bound access, the file only reveals itself to the intended target.
A new generation of frontier AI models is fundamentally changing how cyber attacks are created and executed, introducing a level of speed, scale, and accessibility the industry has not faced before. Early testing of advanced models, including Claudeโs Mythos model, shows that they can identify vulnerabilities in code, connect them into viable attack paths, and generate working exploits with minimal effort. What once required deep expertise and significant time can now be executed rapidly, and at scale, across a wide range of environments. These are not simply AI-assisted attacks, they are attacks powered by frontier AI models. The new models [โฆ]
Frontier AI is changing what is possible for attackers. To meet this escalating threat, Palo Alto Networks is teaming up with Armadin, the new offensive security company founded by Kevin Mandia. This partnership expands our newly introduced Unit 42 Frontier AI Defense service, scaling our ability to identify and remediate AI-driven exposures, and accelerating protection across the enterprise.
Over the past few weeks, weโve spoken with hundreds of CISOs who universally feel the urgency on the frontlines. Security leaders need to know exactly where they stand against the AI-driven attacks happening right now, and the ones coming in the next six months.
Expanding Frontier AI Defense โ The External AI Hyperattack Assessment
For organizations seeking to actively pressure-test their perimeter, this partnership introduces an autonomous, AI-driven offensive assessment of your external attack surface.
This added layer identifies real attack paths and proves exploitability across internet-facing assets. The platform begins with passive discovery, validating publicly exposed assets, cloud resources and secrets. Next, Armadin deploys a coordinated swarm of autonomous AI attack agents, operating at machine speed across your external footprint.
These agents execute active reconnaissance, launch attacks and exploit vulnerabilities in parallel, using over 50,000 templates. Upon initial access, the swarm simulates post-exploitation behavior to demonstrate impact, logging every attack chain as decision-grade evidence of exploitable risk.
Decision-Grade Proof of Exploitable Risk
With this added layer of autonomous simulation, Unit 42 Frontier AI Defense provides an even more rigorous, pressure-tested view of an organization's external attack surface. This allows our experts to accurately simulate the tradecraft of the most capable, AI-equipped threat actors, compressing complex attack lifecycles from days into minutes.
AI may change what is possible for attackers, but in the hands of defenders, it becomes a decisive advantage. This partnership is another important step in making sure that advantage stays with the defenders.
A member of Project Glasswing and OpenAIโs Trusted Access for Cyber (TAC) program, Palo Alto Networks remains the only company equipped to deliver this strategic level of partnership through Unit 42 Frontier AI Defense and the Frontier AI Alliance, driven to integrate cutting-edge technologies into our products and services.
Expand Strategic Collaboration to Secure the AI Enterprise
The transition from generative AI to agentic AI represents one of the most significant shifts in the history of enterprise technology. As organizations move from simple chatbots to autonomous agents that can execute business processes, the attack surface isn't just changing, it's exploding.
At Google Cloud Next 2026 in Las Vegas, Palo Alto Networks is proud to announce a series of groundbreaking integrations with Google Cloud. These innovations are designed to do more than just monitor the new AI-driven landscape; they are built to secure it by design. AI deployment is currently outpacing AI governance. By embedding our security platform into Google Cloudโs infrastructure, we are giving todayโs enterprises the foundation to become the autonomous organizations of tomorrow.
Here is a look at the four major milestones of our partnership being unveiled this week.
Secure AI Agents with Google Cloud + Prisma AIRS
As autonomous AI agents become the new enterprise standard, security can no longer be an afterthought; it must be architectural. By integrating Prisma AIRSโข natively with Google Cloud Gemini Enterprise Agent Platform, we provide the proactive defenses required to govern complex agentic workflows. This integration ensures that as you scale your autonomous workforce, your security scales with it, providing comprehensive operational integrity without hindering the speed of innovation.
We are delivering capabilities across three critical pillars:
Protecting Agent-Specific Runtime Risks: In an agentic ecosystem, the primary risk is unauthorized or a destructive action taken by the AI agents themselves. Prisma AIRS secures the "agent-to-tool" interface, preventing poisoned context from triggering malicious scripts or destructive actions. The solution monitors agent execution in real-time, so agents cannot leak sensitive credentials or tool schemas, maintaining the boundary between agents and their access to enterprise data.
Securing the GenAI Application Surface: Modern AI applications and agents require a secure-by-design approach. Prisma AIRS AI Runtime Securityโข provides prevention of more than 30 adversarial prompt injection and jailbreak techniques, as well as malicious code and URLs within LLM outputs. Prisma AIRS utilizes over 1,000 predefined patterns out of the box and ML-powered Enterprise DLP to stop sensitive data leakage.
Enforcing Enterprise AI Safety and Grounding: Trust in AI is built on the consistency and safety of its output. Prisma AIRS allows organizations to define safety policies in natural language and filter toxic content across eight distinct categories to protect brand reputation. Using contextual grounding, Prisma AIRS can prevent misleading outputs that contradict internal RAG data, keeping agents tied to real facts.
This integration ensures that as you scale your autonomous workforce, your security posture scales with it, providing operational integrity without hindering the speed of innovation.
Security-as-Code for Prisma AIRS Integration with Application Design Center (ADC)
The traditional bolt-on approach to security is no longer viable in a cloud-first world. Google Cloudโs Application Design Center (ADC) is revolutionizing how applications are built, using an intuitive canvas and natural language via Gemini Code Assist.
Palo Alto Networks is announcing that it will be published as a template within the Application Design Center, providing more capabilities to engineering teams:
Drag-and-Drop Security โ Visually "snap" VM-Series firewalls and Prisma AIRS AI protections directly into network flows.
AI-Driven Architecture โ Use natural language prompts to generate secure-by-default, multiregion architectures.
Simultaneous Deployment โ Deploy entire application stacks and security services in a single, unified workflow, ensuring protection is present from the very first minute of deployment.
Zero-Day Protection at Scale with Advanced Malware Sandboxing for Google Cloud NGFW Enterprise
The battle against malware has shifted to the cloud. Modern attacks are faster, more evasive and capable of bypassing traditional defenses.
That is why we are excited to announce Advanced WildFireยฎ, powered by Palo Alto Networks, natively integrated into Google Cloud NGFW Enterprise, delivering AI-driven malware prevention directly within Google Cloud environments.
This integration embeds inline sandboxing and real-time threat intelligence directly into Google Cloudโs distributed firewall to stop advanced and unknown threats before they impact workloads, enabling:
Secure Detonation โ Suspicious files are safely executed in a controlled sandbox environment to uncover hidden and unknown threats.
Inline Traffic Inspection โ Inbound and outbound traffic is analyzed in real time to prevent lateral movement of malicious payloads across cloud environments.
AI-Driven Threat Prevention โ Leverages global threat intelligence by Palo Alto Networks to block zero-day threats before they compromise workloads.
With Advanced WildFire embedded directly into Google Cloud NGFW Enterprise, organizations can extend consistent protection across their cloud infrastructure while maintaining operational simplicity.
Cloud NGFW Enterprise Advanced Malware Sandboxing will be available in Public Preview soon.
Defining the Future with the Google Cloud Marketplace
Palo Alto Networks has joined the Google Cloud Marketplace Agent-as-a-Service as a launch partner to introduce the Prisma AIRS Model Security agent. Operating as an Agent-as-a-Service, this solution scans AI models for vulnerabilities and policy noncompliance before they reach production.
Available in the Agent Gallery inside Gemini Enterprise, this marketplace offering runs entirely within the customerโs own Google Cloud environment, providing both new and existing Prisma AIRS users a seamless and simple deployment experience inside Gemini Enterprise.
Securing AI Innovation at Scale
The collaboration between Palo Alto Networks and Google Cloud is built on a shared vision: Security should be an accelerator for innovation, not a bottleneck. As we look toward the future of the AI-powered enterprise, our commitment remains to provide the most robust, platform-driven security for every workload, every agent and every interaction.
Want to see these integrations in action? Contact your Palo Alto Networks representative to learn more about how we are securing the future of the cloud together. If youโre attending Google Cloud Next 2026, join us at these sponsored sessions: