Reading view

Putting OpenAI Cyber Models to Work for Defenders

Unit 42 is putting the latest frontier cyber models to work across customer environments to find, validate and help remediate the attack paths that matter most.

In May, we introduced Frontier AI Defense with a warning: the window to get ahead of AI-enabled attacks was shorter than most people realized. Since then, we have briefed more than 1,000 security teams around the world and introduced our Frontier AI Defense service to hundreds of customers.

Today, through our partnership with OpenAI, we are expanding Unit 42 Frontier AI Exposure Analysis to put advanced frontier cyber models directly to work in customer environments. Under Unit 42 direction, these models can find exposures, test whether they are exploitable, validate attack paths and help customers prioritize what to fix first.

Our early work shows why this approach matters: 36% of the exposures we identified map to no known CVE, often because they involve multiple gaps that have to be discovered, chained and tested together.

Bringing the Latest Frontier Cyber Capabilities to Defenders

Palo Alto Networks has been among a limited group of organizations with early access to advanced cyber capabilities from the leading frontier AI labs. Through our partnership with OpenAI, Unit 42 can now bring its latest advanced cyber capabilities, including GPT-5.6 Daybreak, to security testing and validation for our customers. Until now, GPT-5.6 Daybreak has not been available for commercial use.

Frontier models have helped inform the work of our experts. Now they can increasingly perform complex offensive security tasks directly, at machine speed and under Unit 42 direction. That allows us to go deeper than traditional vulnerability discovery by testing exploitability, reasoning across multiple weaknesses and determining how an attacker could use them to achieve an objective.

There is no single best model for every cyber task. Our research has shown that different models have different strengths and find vulnerabilities others miss. A multi-model harness routes work to the model best suited for the task, improving efficacy and coverage while managing the cost of frontier AI at scale. As stronger models emerge, we can incorporate them without rebuilding the offering around a single model or provider.

Unit 42 experts remain central to the process. We combine frontier models with our offensive security expertise, Palo Alto Networks telemetry and Unit 42 Threat Intelligence to validate findings, connect exposures into attack paths and understand what an attacker could ultimately achieve.

Built to Find What Attackers Can Exploit

The expanded service brings five capabilities together:

  • Leading cyber models: Apply the latest advanced cyber models to improve exposure discovery, testing and validation.
  • Multi-model harness: Use the right model for the right task to improve efficacy, expand coverage and optimize cost.
  • Exposure discovery: Find vulnerabilities, misconfigurations, leaked credentials, unmanaged attack surface and other posture gaps across applications and network assets.
  • Advanced adversary simulation: Actively test exploitability and validate end-to-end attack paths to understand how an attacker could compromise the environment.
  • Custom remediation plan: Prioritize the fixes that break the most important attack paths and feed those findings into existing IT, development and security workflows.

Most security teams already have more findings than they can act on. The harder problem is knowing which ones create a real path to compromise. Attackers look across applications, infrastructure, identity and cloud for weaknesses they can combine to achieve an objective. Frontier AI Exposure Analysis applies that same adversarial perspective, helping defenders understand which paths matter and what to fix first.

The Asymmetry Runs Both Ways Now

For the past several months, frontier AI has been a story about what is coming for defenders: vulnerability discovery at scale, exploit chaining that sees full-stack logic no scanner catches, and attack cycles compressed to seconds from initial access to exfiltration.

All of that is still true. Our answer has been to put everything we learn testing these frontier models into the hands of defenders. Today, that gets more direct: not just what frontier models have taught us, but the models themselves, working in your environment for your defenders before those same capabilities are working for the attacker.

The window is still closing. We intend to spend it building on the side of the defenders.

Visit Palo Alto Networks Frontier AI Defense to learn more.

The post Putting OpenAI Cyber Models to Work for Defenders appeared first on Palo Alto Networks Blog.

  •  

Palo Alto Networks Recognized as the Only Vendor to be Named a 4X Leader in SASE and SSE Gartner Magic Quadrant Reports

As organizations race to deploy agentic AI, legacy network security solutions are ill-equipped to keep up, forcing productivity tradeoffs while exposing coverage gaps. At the same time, Frontier AI is proving capable of discovering vulnerabilities and creating exploits in real-time. Navigating this shift requires more than incremental feature enhancements; it requires a bold, market-defining vision backed by relentless customer focused execution. 

Today, we’re proud to announce that Gartner® has once again recognized Palo Alto Networks as a Leader in the 2026 Magic Quadrant™ reports for both Security Service Edge and SASE Platforms. This marks the fourth consecutive year that Palo Alto Networks has been recognized, making us the only security vendor to be recognized as a Leader in both reports for four years in a row.

In this year’s Magic Quadrant for SSE, Palo Alto Networks was placed highest in ability to execute and furthest in completeness of vision for Prisma Access.

Every day we focus relentlessly on understanding the needs of our customers and channeling that back into products and services that create real value for them. Our product strategy centers on where our customers' environments and security needs are heading, not just where it sits today.

Vision Matters More than Ever in the AI Era

The AI landscape is changing daily - in this new reality, we strive to be the visionary leaders to serve our customers. GenAI and Agentic AI are exposing enterprises to novel categories of risks like prompt injection, over-privileged agents, and poisoned models. At the same time, Frontier AI is accelerating vulnerability discovery and attack speed resulting in attack timelines being compressed by over 95%.

Gartner projects that by the end of this year, 40% of enterprise applications will feature embedded agents, up from less than 5% today. And by 2028, 60% of brands will use agentic AI to facilitate streamlined one-to-one interactions. Operating a business in this new reality requires security architecture engineered to anticipate threats that haven't yet emerged. Success cannot be achieved by retrofitting legacy products with support for AI infrastructure. It demands a unified future-ready foundation that natively secures users, applications, sensitive data, and non-human identities across every touchpoint. The platform enterprises use today determines whether they'll be prepared for tomorrow's threats.

As the cybersecurity landscape undergoes its biggest shift in decades, to us, the Gartner recognition as a Leader on vision and execution across both reports means more than ever before. In our opinion, it not only validates Palo Alto Network’s ability to serve the world’s largest enterprises but also celebrates our strategic product capabilities as shaping the future of cybersecurity through industry leading innovation such as securing AI traffic flows and agents that simplify manageability of SASE operations.

Vision Backed by Relentless Execution

We believe being placed highest in execution and furthest in vision is only as valuable as the ability to execute on it, and Palo Alto Networks has a proven record of creating value for our customers. Our recent milestone of crossing the $1.6 billion ARR mark while growing 40% year over year for Prisma SASE reflects the trust customers have placed in us. Over 6,800 organizations, including over one third of the fortune 500, trust us because we consistently turn market-defining innovation into enterprise-grade reality. Our execution leadership is built on a strong foundation:

  • Security powered by Precision AI: Our platform delivers universal zero trust through distributed and flexible enforcement points. We inspect traffic as close to the user as possible to ensure that whether your teams are at the corporate HQ, a remote branch, a coffee shop or working from home, they receive the same protection at their precise point of interaction.
  • Unmatched performance and resilience: By leveraging global hyperscalers, we provide the massive scale and reach that modern organizations require. For specialized, high-performance and sensitive needs, SASE Private Location brings that same cloud-delivered resilience directly to private campuses.
  • Unified platform: With a truly unified policy engine, data platform and operations, we ensure that as enterprises adapt to the future, our architecture remains an accelerator for secure productivity rather than a bottleneck. We accelerate vendor consolidation for enterprise customers, replacing fragmented legacy point products with a single platform that slashes operational overhead and reduces total cost of ownership (TCO) by up to 50%.

Building for the Future 

As the rules of cybersecurity are rewritten in real time, leading the market requires more than following past trends, it requires setting the trajectory. Our aim is to continuously be at the forefront of defining the future of cybersecurity to power the agentic enterprise of tomorrow.

Protecting with AI

Palo Alto Networks continues to innovate to keep enterprises safe at the speed of AI. Our Precision AI security service blocks over 30B threats every single day defeating sophisticated and highly evasive tactics. When combined with our virtual patching and IP defense security services, organizations receive proactive defense that secures at the speed of Frontier AI with flexible enforcement that provides consistent protection everywhere. We are delivering comprehensive security across network, edge, and cloud infrastructure to stop hidden threats that are invisible to traditional networks security solutions. 

This AI-powered defense in depth strategy operates across the entire attack lifecycle to enable proactive protection that shifts enterprise security postures from reactive incident response to preemptive defense. 

Securing AI 

Safely enabling employee adoption of AI tools and agents requires special considerations to mitigate risks around data leaks, intellectual property exposure, and compliance. Prisma SASE and Prisma Access solve these challenges by discovering all AI usage and agentic actions, enforcing granular least privilege access for human and non-human identities, and preventing exposure of risky data to AI and agents. Through AI Access Security™, Prisma SASE provides unified data security across the AI lifecycle by integrating GenAI app visibility and control, real-time prompt analysis, shadow data discovery, and  protection on endpoint. Prisma Browser provides a secure AI workspace that safeguards both human and autonomous agent workflows across any LLM by defending against data leaks, prompt injections, and agent hijacking. 

To secure the rapid adoption of AI agents by enterprises, Prisma Access will natively integrate with Prisma AIRS AI Gateway to provide a unified LLM, MCP, and A2A gateway giving security teams a single pane of glass for AI observability, cost governance, and runtime inspection.

This innovative approach represents an evolution away from traditional device and user centric fabrics towards an agent-aware platform capable of securing AI for the enterprise of tomorrow, today. 

Operating with AI

We continue to invest in capabilities that make our platforms proactive, efficient and easier to use. Our new deployment agents enable customers to onboard their SSE or SASE environment more efficiently, reducing their time to value while increasing productivity. Once onboarded, autonomous AI agents within Strata Cloud Manager continuously evaluate network and security posture to proactively identify configuration drift, performance degradation, and security policy gaps. By uncovering potential disruptions before they impact users or expose the organization to risk we’ve created automated systems capable of finding issues and automatically remediating them, with human-in-the-loop oversight calibrated to the administrator's comfort level, from guided recommendations to full autonomy.

The practical outcome is a dramatic reduction in mean time to resolution (MTTR) and a measurable reduction in total cost of ownership (TCO) while significantly reducing administrative burdens and making Palo Alto Networks products easier to maintain and operate.

Learn More

Download your complimentary copies of the 2026 Gartner® Magic Quadrant™ reports to learn why Palo Alto Networks has been recognized as a Leader in both SASE and SSE for the fourth consecutive year.


 

Gartner, Magic Quadrant for Security Service Edge, 29 July 2026, John Watts Et Al.
Gartner, Magic Quadrant for SASE Platforms, 28 July 2026, By Jonathan Forest Et Al.
Gartner does not endorse any company, vendor, product or service depicted in its publications, and does not advise technology users to select only those vendors with the highest ratings or other designation. Gartner publications consist of the opinions of Gartner’s business and technology insights organization and should not be construed as statements of fact. Gartner disclaims all warranties, expressed or implied, with respect to this publication, including any warranties of merchantability or fitness for a particular purpose.
Gartner and Magic Quadrant are a trademark of Gartner, Inc., and/or its affiliates.
This graphic was published by Gartner, Inc. as part of a larger research document and should be evaluated in the context of the entire document. The Gartner document is available upon request from Palo Alto Networks.

The post Palo Alto Networks Recognized as the Only Vendor to be Named a 4X Leader in SASE and SSE Gartner Magic Quadrant Reports appeared first on Palo Alto Networks Blog.

  •  

Strengthening Security of AI Coding: Prisma AIRS API Integration with OpenAI Codex

Palo Alto Networks works closely with OpenAI across our product platform and Unit 42, leveraging advanced frontier model capabilities. Furthermore, we are a partner in the OpenAI Daybreak Cyber Partner Program, working with OpenAI to bring trusted, AI-powered cyber defense to more organizations. Today, we’re announcing native integration of Prisma AIRS Runtime API with OpenAI Codex. This milestone deepens our partnership and drives our shared mission forward: equipping defenders with the industry's most advanced tools.

AI coding assistants have transformed software development, accelerating shipping velocity and changing how engineers solve problems. But as integration of AI coding assistants deepens across development teams, security and compliance teams constantly struggle with enabling developer productivity while helping protect proprietary source code and credentials, and reducing the risk of runtime threats entering the codebase.

Streamlined Security in Minutes

We designed this integration to eliminate complex traffic steering and heavy client-side hooks. Securing your entire developer organization takes just a few clicks inside Codex Enterprise Management UI. Here is how you can enable it:

  1. Retrieve Credentials: Generate your API key and endpoint from the Prisma AIRS management console.
  2. Configure Codex: Paste the Prisma AIRS API key and endpoint directly into your Global Admin Console.
  3. Activate Org-Wide Scanning: Once saved, all user prompts across your entire organization in Codex are automatically routed through the Prisma AIRS Runtime API for real-time inspection.

What Prisma AIRS Brings to OpenAI Codex

By connecting the Codex in ChatGPT for Enterprise workspace to the Prisma AIRS Runtime API, security teams gain comprehensive, automated security controls across two critical vectors:

1. Enterprise Data Loss Prevention (DLP)

Developers frequently paste context – logs, config snippets, or functions – into AI coding assistants. Prisma AIRS scans inputs to help identify sensitive data before it is submitted.

  • Secrets & Credentials: Intercept API keys, hardcoded passwords, tokens, and private keys.
  • PII & Financial Data: Automatically detect personally identifiable information and regulated data patterns.
  • Proprietary Code & IP: Enforce custom pattern rules to help prevent sensitive internal code, architecture details, or trade secrets from being submitted.

2. Advanced Threat & Malicious Code Detection

AI prompts and contextual inputs can contain content that introduces security risks into development workflows. Prisma AIRS Runtime API inspects incoming developer inputs for:

  • Malicious Code Patterns: Detect obfuscated scripts, dangerous command executions, or known exploit patterns within developer prompts.
  • Malicious URLs & Links: Flag unverified, phishing, or malicious domain references before they influence generated code or enter internal repos.
  • Prompt Manipulation Attacks: Detect adversarial inputs that may attempt to bypass system controls or alter model behavior.

Built for DevSecOps Alignment

Security controls only work if developers actually use them. Because the inspection happens at the platform administrative level via API, developers continue working natively in Codex without changing their IDE setup or downloading local hooks. SecOps gain centralized visibility, consistent policy enforcement, and audit-ready logging capabilities across the entire engineering organization, while developers keep the speed and experience they expect.

Key Takeaways

  • Security as Invisible Infrastructure: Prisma AIRS integrates at the Codex administrative layer, applying security and DLP controls without requiring additional developer workflow changes. Developers can continue working in Codex while security teams maintain centralized policy controls.
  • Unified Governance for Frontier Models: Prisma AIRS acts as an inline security layer that scans AI traffic in real-time before prompts ever reach the destination model. This architecture can help organizations identify sensitive information moving outward while detecting prompt manipulation and potentially malicious content moving into development workflows. If Prisma AIRS API detects a threat, a block verdict is sent to OpenAI Codex, and the prompt does not reach the destination model or MCP server.
  • Organization-Wide Compliance: Deployment speed is a strategic advantage, not just an IT convenience. By configuring the Prisma AIRS API within the Global Admin Console, organizations can achieve org-wide governance without complex traffic steering. This can help development teams shift from unmanaged AI use toward more consistent, auditable security practices.

Getting Started

The Prisma AIRS integration helps organizations maintain consistent security controls while preserving the speed and productivity gains of Codex. Organizations can combine Palo Alto Networks’ security capabilities with OpenAI Codex to maintain centralized security and governance controls.

Choose your path forward:


Forward-Looking Statements

This blog contains forward-looking statements that involve risks, uncertainties and assumptions, including, without limitation, statements regarding the benefits, impact, or performance or potential benefits, impact or performance of our products and technologies or future products and technologies. These forward-looking statements are not guarantees of future performance, and there are a significant number of factors that could cause actual results to differ materially from statements made in this blog. We identify certain important risks and uncertainties that could affect our results and performance in our most recent Annual Report on Form 10-K, our most recent Quarterly Report on Form 10-Q, and our other filings with the U.S. Securities and Exchange Commission from time-to-time, each of which are available on our website at investors.paloaltonetworks.com and on the SEC's website at www.sec.gov. All forward-looking statements in this blog are based on information available to us as of the date hereof, and we do not assume any obligation to update the forward-looking statements provided to reflect events that occur or circumstances that exist after the date on which they were made.

The post Strengthening Security of AI Coding: Prisma AIRS API Integration with OpenAI Codex appeared first on Palo Alto Networks Blog.

  •  

Prisma AIRS - Unified Data Protection for Claude

As AI adoption shifts from experimental tools to the business core, enterprises are deploying AI agents and assistants across every department. Developers are accelerating software delivery with Claude Code and business functions are collaborating in Claude.ai, Claude Cowork, and Claude Design, using Anthropic's Claude to fundamentally rewire how they operate and drive complex, autonomous workflows across their most critical tasks.

Broad AI adoption has forced enterprise security into a difficult paradox: secure the business without stalling innovation. Today, security teams must answer three critical questions: How do we prevent sensitive data from leaking into AI models? How do we intercept runtime attacks, like prompt injection, before they execute? And how do we enforce these guardrails consistently across every AI interaction, in real-time?

We are thrilled to announce that Palo Alto Networks Prisma AIRS API now directly integrates with Claude Enterprise via inference hooks.

Key Takeaways:

  • Synchronous Governance at the Speed of AI: Enforce critical runtime policy guardrails instantly before model inference occurs. By evaluating every Claude interaction in real-time, security teams can confidently enable high-speed AI innovation without introducing unacceptable risk or operational bottlenecks.
  • Extending Proven DLP to AI Workflows: Safeguard PII, intellectual property, and proprietary code across all Claude environments (Claude Code, Claude.ai, Claude Cowork) seamlessly. By directly leveraging your organization’s existing enterprise DLP policies, you get consistent, unified data protection without the friction of managing disparate rule sets.
  • Neutralizing AI-Specific Threats Proactively: Deploy enterprise AI with confidence by intercepting malicious activity before it executes. Proactively block sophisticated runtime threats, including prompt injections, jailbreaks, and toxic inputs, enabling your AI workflows to remain secure and your business operations uninterrupted.

How It Works

Setting up zero-trust governance for your Claude Enterprise environment takes just a few clicks:

  • Configure Claude Enterprise: In your Claude Enterprise organization settings, navigate to inference hooks, set the hook endpoint URL to your designated Prisma AIRS webhook URL, and include your custom Prisma AIRS API key in the custom headers (x-pan-token).
  • Activate Cryptographic Verification in Prisma AIRS: Claude generates a unique, one-time signing secret. You simply drop this signing secret into the Prisma AIRS UI.

Prisma AIRS securely stores the signing secret in an encrypted edge Key-Value Map (KVM) to cryptographically verify the authenticity of every incoming request before processing.

Unified Governance Across All Claude Surfaces

Before Claude reads a prompt, Claude POSTs the payload to Prisma AIRS, which evaluates the input against the configured security profile and returns a synchronous allow or deny verdict back to Claude.

Removing the Data Inspection Blind Spot

This Prisma AIRS integration natively leverages the Palo Alto Networks Enterprise DLP engine your organization already runs. Your current policies, custom definitions of "confidential," and compliance dashboards now instantly govern Claude. No redundant rule creation, and no new management overhead. Every prompt is classified in real-time, before anything reaches the model. Data Policy updates reach Claude the moment they reach everything else, and Claude events land in the same dashboards and audit reporting as every other channel. AI stops being the exception to your data protection strategy and becomes just another channel that is covered.

In practice, this helps prevent:

  • Accidental exposure of PII and regulated data: a Social Security number, card number, or patient record pasted into a prompt is detected  on the spot by advanced RegEx patterns and ML classifiers,  with Exact Data Matching (EDM) recognizing your actual customer records.   When policy requires, Prisma AIRS enforces a deny policy to help keep Claude usage stays aligned with GDPR, HIPAA, and PCI-DSS requirements.
  • Misuse of credentials in code: Developers working in Claude Code can't inadvertently submit hardcoded API keys, private tokens, or environment credentials into prompt context.
  • Disclosure of confidential business matters. Document classifiers flag prompts touching M&A, legal, or HR material — even when they contain no identifier a pattern could match.

AI Safety & Runtime Threat Protection

Simultaneously, Prisma AIRS inspects payloads for operational risks specific to large language models:

  • Prompt Injection & Jailbreak Attacks: Intercepts malicious attempts to manipulate model context or bypass system instructions.
  • Malicious Code & Malicious URLs: Prevents execution or processing of untrusted scripts and risky links embedded within prompts.
  • Toxic Content & Topic Guardrails: Enforces compliance with corporate policies and custom business topics.

If a prompt violates your security policy, Prisma AIRS issues a deny verdict. Claude immediately blocks the prompt, optionally presenting a user-facing explanation while returning a unique audit correlation code to your security telemetry dashboards.

Deploy Claude Without the Risk

The Prisma AIRS integration with Claude transforms security from a deployment bottleneck into a business enabler. You no longer have to choose between the operational control of Palo Alto Networks and the cognitive velocity of Claude.

Choose Your Path Forward:

 


Forward-Looking Statements

This blog contains forward-looking statements that involve risks, uncertainties and assumptions, including, without limitation, statements regarding the benefits, impact, or performance or potential benefits, impact or performance of our products and technologies or future products and technologies. These forward-looking statements are not guarantees of future performance, and there are a significant number of factors that could cause actual results to differ materially from statements made in this blog. We identify certain important risks and uncertainties that could affect our results and performance in our most recent Annual Report on Form 10-K, our most recent Quarterly Report on Form 10-Q, and our other filings with the U.S. Securities and Exchange Commission from time-to-time, each of which are available on our website at investors.paloaltonetworks.com and on the SEC's website at www.sec.gov.  All forward-looking statements in this blog are based on information available to us as of the date hereof, and we do not assume any obligation to update the forward-looking statements provided to reflect events that occur or circumstances that exist after the date on which they were made.

The post Prisma AIRS - Unified Data Protection for Claude appeared first on Palo Alto Networks Blog.

  •  

Redefining Network Security for the Frontier AI Era

Modern enterprise security is at a pivotal moment where CIOs and CISOs have a clear opportunity to build a cybersecurity architecture for both today’s environment, and for the future. Doing so requires redefining enterprise resilience across three critical dimensions. 

First, Frontier AI driven threat velocity and novelty. Frontier AI models have automated the entire attack lifecycle. Adversaries aren’t just compressing exploit windows to near-zero timelines, they are also generating novel, highly evasive threats at machine speed, bypassing traditional signatures and often before patches are generated. 

Second, surging network traffic is overwhelming traditional defenses. Driven by AI workloads, inter-datacenter traffic will nearly triple1 over the next decade dramatically expanding the volume of data teams must inspect and secure. 

Finally, major shifts are forcing a “cryptographic reset.” Shrinking certificate lifecycles, internet-scale distrust events, and quantum computers powerful enough to crack public key cryptography are combining to shake the foundation of all digital communications. 

Meeting these challenges requires more than incremental fixes. Today, we are proud to introduce PAN-OS 12.2 Ceres, a landmark release representing a major leap forward in network security. 

Ceres brings to market 55+ innovations, including three flagship, core capabilities, designed to shift the balance of power back to defenders.

Introducing Frontier Virtual Patching: Preemptive Defense Against Frontier AI Exploits

Today, Palo Alto Networks is giving defenders the ultimate advantage with the launch of Frontier Virtual Patching. By harnessing Frontier AI to discover unknown vulnerabilities, and deploying protections in hours, we are collapsing the exposure window from the industry-average 55 days2 it takes to deploy a traditional patch down into a near-zero window of exposure. This isn’t just about faster patching; it’s about eliminating the attacker’s chance by neutralizing exploits before they ever reach your network.

Frontier AI models - Collapse the patch window

The new reality: Exploitation far outpaces patch deployment

We’ve built this capability as a collaborative, force-multiplying ecosystem, with our industry partnerships across the enterprise software and OT vendor landscape to accelerate vulnerability disclosure, remediation and customer protection. This includes our collaboration with Project Lightwell, which combines our rapid network-level protection with software remediation to help organizations reduce exposure to emerging threats. We’re also partnering with vulnerability clearinghouses, software maintainers, and industry initiatives to continuously expand a real-time pool of protected vulnerabilities.

This approach builds on recent Unit 42 research, where the autonomous AI system NOVA identified more than 14,000 previously unknown vulnerabilities in just two months – a clear signal that defenders must pair AI-powered discovery with equally fast, coordinated protection. We have built an all-new detection engine, “vaulted protection," that enables us to deliver these rapid protections in a safe and responsible manner. When one participant identifies a threat, the entire ecosystem is protected instantly. Individual discovery becomes global protection. 

This is especially valuable for operational technology (OT), critical infrastructure, healthcare, and IoT: environments where systems can’t be taken offline to patch, where patch cycles can stretch for months, and where a single unpatched device can expose an entire network. Frontier Virtual Patching closes that gap in the network, blocking the exploit without applying a patch, rebooting a system, or causing any downtime to critical operations.

Bad actors will lean into Frontier AI to reduce the attack lifecycle from months to minutes. To keep pace, organizations require security partners to match that machine speed. To this end, Palo Alto Networks is raising the bar with its Frontier Virtual Patching, moving beyond compensating controls. By safely and efficiently discovering undisclosed vulnerabilities and deploying protection long before traditional patches can be rolled out, Palo Alto Networks deep security capabilities are flipping network defense from a reactive to proactive operational model.


Will Townsend
Chief Analyst, LoneStar Advisory & Research

And for existing Palo Alto Networks network security customers, getting started is effortless.  Frontier Virtual Patching is available as a PAN-OS software upgrade with persistent, automatic content updates, so protections keep arriving as new threats emerge, with no new hardware and no manual intervention. 

Clearly, Network Security is evolving quickly. Frontier Virtual Patching is part of a huge set of innovations that the team at Palo Alto Networks is delivering in PAN-OS Ceres 12.2 to enable you to stay protected.

Advanced IP Defense: Blocking attacker infrastructure before they can strike

Modern threat actors continuously work to hide their attacks and evade existing controls. Adversaries are increasingly evading traditional perimeter detection of their command-and-control traffic by leveraging direct-to-IP connection techniques that bypass DNS and URL inspection entirely. Attackers are also weaponizing massive proxy networks and hundreds of thousands of residential IP addresses to conduct stealthy, large-scale scanning, brute-force attacks, and exploitation that bypass traditional defenses such as IP reputation and blocklists.

To counter this, Palo Alto Networks is introducing a new preventative solution, Advanced IP Defense, with three powerful new capabilities:

  • Real-time IP-layer intelligence. We leverage global telemetry from over 70,000 customers to track and block attacker infrastructure inline across the entire attack lifecycle. Our researchers track these threats 24/7, so your team doesn’t have to.
  • Zero-Trust IP enforcement. We don’t just look at an IP’s past reputation. We verify the intent of the connection itself. By validating that every network connection maps to a legitimate DNS resolution, we provide a critical guardrail against attackers attempting to evade detection.
  • Powerful IP-layer context. We continuously monitor every connection across more than 40 distinct security attributes, letting you proactively shrink your attack surface and block high-risk traffic from the internet’s “bad neighborhoods” with confidence.

The transition to the Frontier AI era isn't a distant future. It’s happening right now. The organizations that thrive won't be those trying to run old, reactive playbooks faster; they have to scale their defenses to match a whole new velocity of risk. When threats occur at machine speed, relying on human-scale operations is no longer an option. That is why AI and automation are becoming essential tools to meet these challenges head-on.

Varinder Singh
CIO, NXP Semiconductors

Network Security Agents: Making admins superhuman

When threats execute in minutes, human-only operations become a bottleneck. To reduce fatigue and accelerate response, we’re launching an elite suite of AI agents for every major role a network administrator performs.

These six specialized AI-powered Network Security Agents, available through Strata Cloud Manager, are trained on your enterprise context and operational workflows. From onboarding and configuration to threat assessment and troubleshooting, they automate the hundreds of routine, repetitive tasks that consume an admin’s day. And you stay in control: for each workflow, you choose the level of oversight that matches your risk tolerance — human-in-the-loop, human-on-the-loop, or human-out-of-the-loop.

Expanding platform protection across every edge

Securing the modern enterprise means extending these AI-powered capabilities across every surface, from data center cores to remote industrial sites, and from custom AI applications to the web browser.

Today we’re introducing PAN-OS Ceres 12.2, which, in addition to the innovations above, expands our platform across five more areas:

  • Quantum-safe & next-generation trust security. Automates digital certificate lifecycle management and accelerates post-quantum cryptographic readiness, including a cryptographic inventory spanning network security, endpoint, SIEM, and vulnerability management integrations for a complete view of enterprise readiness.
  • 5th-generation ML-optimized hardware. New high-performance PA-Series firewalls equipped with 400G interfaces, and 300 Gbps of threat inspection, and active clustering, these platforms eliminate capacity limits for AI-era data centers. These firewalls also  scale to 1.4Tbps of throughput while delivering 5-microsecond latency ensuring peak performance. 
  • Modernized OT & critical infrastructure defense. Purpose-built PA-50R ruggedized 5G firewalls that extend real-time, AI-powered threat prevention to remote, extreme-environment OT networks and critical infrastructure.
  • AI and agent security. Prisma AIRS is now delivered as a scalable, cloud-native service explicitly engineered to secure AI models, applications, and autonomous agent workflows. The same platform on which we built CloudNGFW has now been extended to provide security for AI with the addition of Prisma AIRS.
  • Browser-to-firewall integration. Imagine the browser as a secure fast-lane that doesn’t just protect users, it empowers them. By integrating Prisma Browser with our NGFWs, we’ve eliminated the need to decrypt on the endpoint while delivering full Layer 7 protection. This is proactive security that neutralizes threats before they can even touch your network. For security admins, policy is fully unified from device to network, delivering a streamlined, automated experience.

Pan-OS 12.2 Ceres

The path forward

We are investing heavily in the innovations you need to defeat today’s threats while future-proofing your enterprise for tomorrow.

The transition to the Frontier AI era demands a bold strategy. The winners will be the organizations that adopt a prevention-first architecture capable of stopping threats long before weaponization occurs. With PAN-OS Ceres 12.2, Palo Alto Networks is giving defenders the speed, scale, and platform foundation to turn the tables on modern adversaries.

 

Forward-Looking Statements 

This blog contains forward-looking statements that involve risks, uncertainties and assumptions, including, without limitation, statements regarding the benefits, impact, or performance or potential benefits, impact or performance of our products and technologies or future products and technologies. Any unreleased services or features (and any services or features not generally available to customers) referenced in this or other press releases or public statements are not currently available (or are not yet generally available to customers) and may not be delivered when expected or at all. Customers who purchase Palo Alto Networks applications should make their purchase decisions based on services and features currently generally available.

 

​​Sources
1 https://www.nokia.com/artificial-intelligence/explainer-network-traffic-is-fundamentally-changing-in-the-ai-supercycle/
2 According to the Verizon 2024 Data Breach Investigations Report

 

The future of Frontier AI network security

Join Palo Alto Networks virtual InterSECt 2026 event on Aug. 19–20 
to see PAN-OS 12.2 Ceres and learn how to preempt AI-driven network attacks.
Secure your spot

Secure your future at the edge of the frontier

Explore our leading Frontier AI Ecosystem and essential resources
Learn more

The Future of Vulnerability Discovery Is Here

4,000 projects. 14,000 previously unknown vulnerabilities. Two months. Read Unit 42's latest research on why defenders must prepare for a dramatically faster threat landscape.
Read the report

The post Redefining Network Security for the Frontier AI Era appeared first on Palo Alto Networks Blog.

  •  

HIPAA Security Rule on AWS – Technical Safeguards Implementation and Readiness Guidance

Today, we’re releasing the HIPAA Security Rule on AWS: Technical Safeguards Implementation and Readiness Guidance. This helps covered entities and business associates configure, implement, and evidence compliance with the HIPAA Security Rule Technical Safeguard requirements (45 CFR §164.312) when building healthcare workloads on AWS.

The HIPAA Security Rule’s Technical Safeguards (§164.312) define five standards and nine implementation specifications covering access control, audit controls, integrity, authentication, and transmission security.

The guidance also covers the 2025 NPRM proposed changes, including encryption at rest and in transit becoming required, multi-factor authentication (MFA) becoming mandatory for all electronic Personal Health Information (ePHI) access, and new specifications for network segmentation, configuration management, anti-malware protection, patch management, software removal, incident response and breach notification.

Key topics included

  • Shared responsibility for HIPAA on AWS – A responsibility matrix mapping each §164.312 specification to what AWS manages nd what the customer must configure and operate.
  • ePHI boundary architecture – Guidance on establishing a defined ePHI boundary
  • ePHI data flow and encryption – A reference architecture tracing ePHI with the applicable §164.312 specification
  • Foundation checklist – Prerequisite recommendation before configuring individual Technical Safeguard controls.

This guidance is written for cloud architects, security engineers, CISOs, and compliance teams at covered entities and business associates building or operating AWS healthcare workloads. It assumes familiarity with AWS services and is intended as a practical implementation reference, not a legal or regulatory interpretation. This guidance focuses exclusively on Technical Safeguards.

HHS published a Notice of Proposed Rulemaking in January 2025, proposing significant updates to the HIPAA Security Rule—including eliminating the Addressable designation, making encryption, MFA, and asset inventory mandatory, and introducing new technical requirements not present in the current rule. As of June 2026, the final rule has not been published. This guidance covers both the current rule and the proposed changes and recommends treating all specifications as Required for new workloads.

Download HIPAA Security Rule on AWS: Technical Safeguards Implementation and Readiness Guidance.

For questions about HIPAA readiness on AWS, including Administrative Safeguards, Physical Safeguards, risk analysis, and assessment preparation, contact the AWS Security Assurance Services team or your AWS account representative.

This guidance is provided by AWS Security Assurance Services, LLC, a HITRUST External Assessor Firm and PCI-QSAC along with contribution from AWS HCLS, AWS Compliance teams. It is for informational and guidance purposes only and does not constitute legal, regulatory, or compliance advice. Recipients are solely responsible for determining applicability to their specific environments and legal obligations.

If you have feedback about this post, submit comments in the Comments section below.


Abdul Javid

Abdul Javid

Abdul is a Senior Security Assurance Consultant at AWS Security Assurance Services. He holds HITRUST certifications and has led HITRUST r2 and i1 engagements across multiple healthcare technology companies. Abdul holds multiple security and auditing certifications and supports customers building responsible AI governance programs on AWS. He has over 25 years of experience and holds certifications across AWS, CMMC, PCI DSS, PMI, ISC2, and ISACA.

Shreya Singh

Shreya Singh

Shreya is a Security Assurance Consultant at AWS with more than eight years of experience in governance, risk, compliance, and cloud security. She holds the CISA and HITRUST Certified CSF Practitioner (CCSFP) certifications and supports healthcare and technology organizations with HITRUST, HIPAA, SOC 2, risk management, and audit readiness initiatives.She holds a Master of Engineering in Cybersecurity from the University of Maryland, College Park.

Kapil Temghare

Kapil Temghare

Kapil is a Security Industry Specialist at AWS with over 10 years of experience spanning compliance, cloud security, and regulatory operations. He manages HIPAA compliance within the Regulatory Operations Center (ROC), including service eligibility assessments, controls validation, and compliance sign-off. Beyond healthcare, Kapil supports various regulatory programs such as FedRAMP and the EU Data Act and holds CISSP certification.

Hector Rodriguez

Hector Rodriguez

Hector is a Principal Industry Specialist and Executive Security Advisor, AWS Health & Life Sciences. He has over 25 years of experience enabling Health & Life Sciences business and clinical transformation and innovation and with multiple industry and academic groups. He is a board advisor for healthcare startups, a founding member of the HITRUST Business Associate Council and a health industry and cybersecurity curriculum advisor and lecturer.

  •  

Announcing the General Availability of Prisma AIRS AI Gateway

Every modern enterprise is moving from an organization run by software to one orchestrated by AI, creating a tension between velocity and control. To resolve this tension, organizations require a unified architecture. Today, we are announcing the general availability of the Prisma AIRS AI Gateway, the AI control plane for the enterprise. 

Driven by the absolute conviction that an AI Gateway is foundational to the modern AI infrastructure stack, we are bringing AI innovations from the Portkey acquisition to Prisma AIRS just six weeks after closing. You can now scale AI at machine speed without compromising on enterprise-grade security and control.

Your AI Footprint is Outpacing Controls

Our next-generation firewall telemetry reveals that MCP activity climbed from 11% late last year to 41.4% by mid-2026. Monthly AI transaction volume grew twelve-fold over the same six months; some individual sessions moved hundreds of megabytes of enterprise data outbound. The AI footprint you can govern today is the smallest it will ever be.

Some of the most rapid AI adoption is happening with – coding assistants, enterprise agents and copilots.

  • Coding agents access code repositories, file systems, configurations, and credentials. When this context, including source code and secrets, is sent to a frontier model, it risks exposing sensitive data, and a runaway loop could burn a fortune in tokens overnight.
  • Enterprise agents run with broad access and standing privileges sharing context with each other. A single agent stretched beyond its scope can massively increase the risk of data breach, impact business reputation and customer trust.
  • Copilots now sit inside the SaaS and productivity tools employees already use. Copilots with broad access can surface data an employee was never meant to see.

As this enterprise data leaves when an AI request goes out, it creates a security and governance challenge at an unprecedented scale and speed.

What breaks when every team adopts AI 

AI adoption rapidly outpaces the security and governance infrastructure meant to secure it:

  • Shadow AI (Cost and usage are both hidden): You can't see the AI your teams already use or what it costs. 
  • Data Exposure (Sensitive data leaves without a trace): AI interactions can expose sensitive data, bypass policy and trigger unsafe outputs.
  • Agents Overstep (Actions run without accountability): Agents act across systems without clear identity, permission, or accountability. Keys get shared and agents run with broad, standing privileges, so no one can say which identity authorized a specific action or reverse it when an agent takes a wrong turn at machine speed.

Faced with this, most leaders either block traffic entirely or stay permissive and promise to govern later. Both approaches fail because they skip the critical step: seeing what agents do at runtime and controlling their actions while they happen.

Accelerate AI Adoption with Control

To scale AI adoption safely, you need a single control plane sitting between every AI interaction and the backend models. Prisma AIRS AI Gateway brings AI governance, identity and runtime controls together in one place. With the AI Gateway, you can:

  • Discover AI usage: Know exactly which apps, models, users, teams and agents are active, what they are accessing, and what they cost in a single unified view.
  • Govern AI interactions: Enforce central rules for model access, tool use and budgets while inspecting prompts and responses inline to prevent data leaks.
  • Secure every agent: Verify agent identities and enforce just-in-time, least-privilege access so autonomous systems only touch what they need, when they need it.

How the AI Gateway works 

Prisma AIRS AI Gateway sits inline between every AI interaction, model provider, and agentic interaction (Agent/AI App to LLMs, MCP Tool Calls, and A2A). It acts as a unified LLM, MCP, and A2A Gateway with a single enforcement point for all operational and security controls. Your teams keep using their existing coding assistants, enterprise agents, and copilots, while enforcement moves to the infrastructure layer where the platform team can own it.

Capabilities delivered through this unified control plane are:

Observability

Every request maps to a single unified view: tracking usage, users, projects, token counts, latency and cost so you can retire shadow AI infrastructure immediately.

Governance

Centrally define approved models, tools, and access without touching developer configurations. To drive FinOps and usage management, track every request's cost, tokens, and latency by team or project. Answer cost questions instantly, shut down unsanctioned AI usage, and proactively enforce budgets and rate limits before access is granted.

Coding Assistant Security

Protect credentials, proprietary code and development systems from risky AI actions. The gateway replaces raw provider keys with scoped credentials per user and team.

Operational Controls

Apply data protection, usage limits and policy checks as AI interactions happen. Traffic distributes via a Universal API across providers ensuring quotas are enforced and outages never stall your pipeline.

Agent Identity Security

Establish trusted identities by binding a verifiable, ephemeral identity to agents at execution. The AI Gateway acts as an enforcement point to enable only authenticated agents to make approved calls.

Runtime Security 

Powered by Prisma AIRS AI Runtime Security, the gateway inspects every prompt and response inline, stopping source code, secrets and customer data from leaving the network while neutralizing prompt injection attempts aligned with the OWASP LLM Top 10 and OWASP Top 10 for Agentic Applications.

Watch Anand Oswal break down why an AI gateway is foundational to this architecture.

the ai control plane of every enterprise

The AI Control Plane for the Enterprise

Prisma AIRS AI Gateway brings AI governance, identity and runtime controls together in one place. Point products filter text strings or route a single API call and they buckle under real enterprise volume.
Most products fail at scale. Prisma AIRS AI Gateway is built on an architecture tested in the most demanding enterprises for their ever evolving AI workloads: 

  • 68 Trillion+ tokens processed in the last month alone.
  • Sub-millisecond routing latency and inline inspection secures AI interactions without degrading user experience.
  • 99.999% availability helps ensure your AI operational pipeline does not experience a single point of failure.

Learn about Prisma AIRS AI Gateway and register for our webinar to see the AI Gateway in action. 

Your developers have already adopted their agents. The agentic enterprise is a reality. As the recently named "company to beat" in AI Security Platforms by Gartner, Palo Alto Networks is uniquely positioned to help you. Let’s build it securely, together.

The post Announcing the General Availability of Prisma AIRS AI Gateway appeared first on Palo Alto Networks Blog.

  •  

Palo Alto Networks and AT&T - Delivering Quantum-Resilient SASE Fabric

By Yogesh Ranade from Palo Alto Networks, and Senthil Ramakrishnan from AT&T

The digital world is currently navigating a dual-speed revolution. Acceleration of AI and hyperconnectivity is unlocking unprecedented economic value. The silent but rapid progress of quantum computing is fundamentally threatening the cryptographic foundation upon which that value is built.

As leaders in global networking and cybersecurity, Palo Alto Networks and AT&T Business launched Secure Connectivity solutions for Business Customers. We recognize that quantum-readiness is no longer a distant milestone; it is now a strategic imperative. With threatening data longevity and Trust Now, Forge Later targeting digital identities, the risks are already looming. 

By integrating Prisma SD-WAN’s cryptographic innovation with AT&T’s global network, Palo Alto Networks and AT&T Business are proud to deliver the Quantum-Resilient SASE Fabric.

The Quantum Shift Towards Building Resilience for Tomorrow’s Reality

For over 30 years, the difficulty of mathematics has been our primary defense. Classical algorithms, like RSA and Diffie-Hellman, provided the shield for our global economy because they were computationally impossible for classical machines to solve. However, quantum computing fundamentally changes this landscape by providing an exponential speed-up. By leveraging Shor’s Algorithm, quantum computers can break these classical cryptographic foundations, turning a decryption process that would take a classic supercomputer millennia into a task of mere hours.

Neutralizing the Quantum Crisis

Palo Alto Networks is embedding Post-Quantum Cryptography (PQC) as a native pillar of the Prisma SASE fabric. We are moving beyond the forklift-upgrade model to a software-defined, standards-based foundation, which is built on strict separation of management and data plane components:

  • Universal Control Plane Hardening (TLS 1.3): We have transitioned all control plane traffic to TLS 1.3 (Transport Layer Security 1.3), the global gold standard for Internet encryption. This secures the "brain" of the network (where routing configurations and security policies are managed), making it immune to quantum-enabled impersonation and credential theft.
  • PQC-Hardened Data Plane (IETF Standards): We are operationalizing PQC across the entire fabric by adopting official standards published by the Internet Engineering Task Force (IETF), specifically RFC 9370, 9242, and 8784. In plain terms, these standards allow us to use "hybrid key exchanges." This means we wrap your data in two layers of protection at once: a classical mathematical shield for immediate compatibility, and a quantum-resistant shield to protect against future decryption threats, all without causing packet fragmentation or network slowdowns.
  • Logs and Telemetry Plane: All network telemetry and metadata (the automated operational logs and traffic pattern data generated by the network, rather than the actual content of your business files) are encrypted in transit via TLS 1.3. This architecture guarantees that even this secondary network metadata is geofenced to your chosen region with no cross-region aggregation, satisfying the most stringent data residency mandates.
  • Crypto-Agility as a Standard: "Crypto-agility" is natively built into our systems, which means the software is designed to adopt new mathematical algorithms. As the National Institute of Standards and Technology (NIST) refines its guidelines, our systems can be upgraded seamlessly via simple, automated cloud updates without requiring expensive hardware replacements to ensure our customers’ security posture.
  • Secure Boot Support: Palo Alto Networks Prisma SD-WAN ION hardware supports Secure Boot to ensure that only cryptographically signed bootloaders, kernels, and trusted applications are executed during the boot process. This establishes a chain of trust from the BIOS firmware to the operating system, preventing the execution of unauthorized or tampered software. ION hardware appliances ship with an integrated, dedicated Trusted Platform Module (TPM), which provides hardware-level root-of-trust by securely storing cryptographic keys, certificates, and sensitive data to prevent unauthorized physical tampering and ensure secure device authentication. The OS/software layers use PQC algorithms to negotiate and secure the management, control plane and data plane tunnels. This ensures quantum readiness without requiring an immediate, widespread rip-and-replace of physical branch hardware.

The AT&T Perspective Views Security at Global Scale

From the perspective of a global leader like AT&T, PQC is an operational mandate. Providing connectivity to the world’s most regulated industries means that security cannot be bolted on. Security must be an inherent property of the transport layer and the connectivity infrastructure itself.

Turning Complexity into a Strategic Advantage

Managing a global footprint that spans across 5G, fiber, and legacy underlays requires an institutional expertise that few can match. For AT&T, the move to a more secure quantum-ready fabric with Dynamic Defense is about providing security where it matters most: the network. Our customers shouldn't have to worry about whether their data is traveling over an MPLS circuit or the public internet.

Through this collaboration, AT&T expands the delivery of Dynamic Defense:

  • Cross-Underlay Consistency: We enable PQC protection to be applied uniformly across all transport mediums, eliminating the "weak links" that often exist in hybrid environments where data moves between private and public circuits.
  • Automated PQC Policy Orchestration: New branch locations are seamlessly integrated into the quantum-ready fabric through automated policy distribution. The moment a device is activated via zero touch provisioning, the branch is enabled to be protected against HNDL threats from the first packet without requiring manual site-by-site intervention.
  • Compliance: With mandates like NIS2/DORA in Europe and NORA/CNSA 2.0 in the U.S., our clients face a closing window for compliance. AT&T provides the verifiable chain of trust required to prove "Quantum Readiness" across the entire circuit path, ensuring your fabric is audit-ready and compliant with global standards.

The Power of the Post-Quantum Secure Fabric

The true value of this relationship lies in the synergy between the network and the security stack. By combining our strengths, we have built a solution that is significantly more resilient than the sum of its parts.

The SPI Advantage Is Performance Without Compromise

Through Service Provider Interconnect (SPI), Palo Alto Networks' security platforms natively integrate with AT&T’s private network core to deliver a seamless quantum-safe on-ramp. This means business traffic can connect directly to a secure AT&T network without having to build slow, complex software tunnels over the public internet, preserving high performance while delivering next-generation encryption. Historically, high-level encryption meant a "performance tax" on latency and throughput. Our combined architecture allows quantum-safe traffic to flow over AT&T’s network backbone, enabling organizations to modernize their security without sacrificing the user experience.

Securing the Decentralized Perimeter (The Branch as the Edge)

In today’s highly distributed business landscape, the traditional corporate "headquarters" is no longer the center of gravity. The network perimeter has shifted to the branch (decentralized edge locations like retail storefronts, remote clinics, regional bank offices, and warehouse hubs) and the individual 5G-connected devices employees use. Securing these remote, local edge points is critical because they represent the primary gateway where sensitive company data first enters the network. 

By utilizing AT&T’s leadership in WAN, 5G and cellular technologies, we leverage Hybrid Public Key Infrastructure (PKI) to secure these edge locations. Hybrid PKI is a digital identity framework that issues dual security credentials to every device: one "classical" identity to ensure compatibility with existing networks today, and one "quantum-resistant" identity. This double-verification guarantees that a cellular-connected remote branch or a mobile site is just as immune to quantum decryption or identity spoofing as a fortified corporate data center.

The Path Forward Is a Vision for Long-Term Trust

The transition to a quantum-ready future is a marathon, not a sprint, and the first steps must be taken now. Palo Alto Networks and AT&T Business are offering a clear, practical path to quantum resilience.

We are delivering more than a simple software update as we prepare customers for the next generation of digital commerce. Together, we are designing our network to help ensure the data of today remains protected against the threats of tomorrow, securing the digital integrity of every enterprise we serve.

As we redefine the boundaries of security in connectivity, we invite you to join us in helping secure your organization’s digital future. Contact your or Palo Alto Networks account representative today to begin a strategic Quantum-Readiness Assessment and experience the power of the Quantum-Resilient SASE Fabric.

The post Palo Alto Networks and AT&T - Delivering Quantum-Resilient SASE Fabric appeared first on Palo Alto Networks Blog.

  •  

Securing Canada’s Digital Future: Why PBMM Matters Beyond Government

Palo Alto Networks is pleased to announce the successful completion of a new Cloud Medium security assessment conducted by the Canadian Centre for Cyber Security (Cyber Centre), significantly expanding the number of Palo Alto Networks cloud services assessed for Protected B / Medium Integrity / Medium Availability (PBMM) environments. This assessment includes a broad range of capabilities across our Cortex®, Cortex Cloud and Strata™ platforms. By achieving this milestone, Palo Alto Networks enables  organizations handling Canada’s most sensitive data to leverage a unified, AI-driven security architecture without compromising on compliance or operational resilience.

For years, many organizations viewed PBMM as something that only mattered to the Canadian federal government. It was often seen as a procurement requirement—a framework tied to public sector cloud adoption, relevant for departments handling Protected B information, but not necessarily for the private sector.

That assumption is changing.

The reality is that the challenges driving PBMM are no longer unique to government environments. Banks, energy providers, transportation networks, healthcare organizations, crown corporations, and other critical infrastructure operators are now facing many of the same pressures:

  • Expanding attack surfaces across hybrid and multi-cloud environments.
  • Increased regulatory scrutiny and privacy obligations.
  • Greater operational dependence on cloud and AI technologies.
  • Increased reliance on third-party providers and software supply chains.
  • The need to maintain operational resilience during cyber incidents and disruptions.
  • A growing expectation that organizations can demonstrate—not just claim—security maturity.

That is why PBMM matters far beyond Ottawa. At its core, PBMM represents a rigorous approach to validating whether enterprise-grade security platforms can operate securely in environments where trust, resilience, and operational continuity are critical.

Increasingly, that level of assurance matters to everyone.

What PBMM Really Represents

PBMM, a rigorous cybersecurity and data classification standard used by the  Canadian Centre for Cyber Security, stands for Protected B / Medium Integrity / Medium Availability. While often associated with federal cloud security requirements, PBMM is not simply a checkbox exercise. It is a comprehensive assessment framework aligned to Canadian cybersecurity guidance and operational security expectations.

What makes PBMM important is that it evaluates whether platforms and services can securely support sensitive and mission-critical workloads in real-world environments.

Palo Alto Networks meeting these rigorous PBMM requirements through three core pillars:

  • Strata (Network Security): Secures data resiliency and zero trust connectivity, driving robust perimeter and cloud edge protection.
  • Cortex Cloud (Cloud Security): Provides complete visibility, security governance, and data protection across complex cloud-native architectures.
  • Cortex (Security Operations): Powers the agentic SOC, combining unified data, AI, and automation to detect and respond to threats in real time.

These are not theoretical requirements. They are practical operational expectations designed for environments where downtime, visibility gaps, or security failures can have significant consequences.

Organizations today are no longer evaluating cybersecurity solely based on features. They are evaluating whether platforms can be trusted to support critical operations at scale.

Why Security Expectations Are Changing

The cybersecurity landscape has evolved dramatically. Infrastructure is distributed across cloud providers, SaaS applications, remote users, third-party integrations, operational technology (OT), AI platforms, and interconnected supply chains. At the same time, attacks have become faster, more automated, and more disruptive.

In this environment, security can no longer be treated as a compliance exercise. Organizations need confidence that their platforms, operational processes, and security controls can function effectively under pressure.

This is why Palo Alto Networks has undertaken independent PBMM assessments across its portfolio, providing customers with greater assurance and trust. By meeting these rigorous standards into Strata and Cortex, we enable non-government entities—like financial institutions and utility providers—to deploy the same defensive rigor used to protect national security systems.

Transforming Critical Infrastructure with a Unified Platform

To effectively manage risk, critical infrastructure operators require a platform approach that helps eliminate security silos, reduce manual intervention, and accelerate threat mitigation.

Key Portfolio Advantages for Critical Infrastructure & Enterprise:

  • AI-Driven Threat Detection & Response: Cortex XSIAM® and Cortex XDR® unify telemetry across endpoints, network, and cloud to deliver unparalleled visibility and automated threat stitching, neutralizing advanced cyberthreats before they disrupt operations.
  • Comprehensive Cloud Native Protection: Cortex Cloud secures applications from code to cloud to SOC, offering posture security, data protection, and continuous compliance monitoring tailored to stringent Canadian data standards.
  • Zero Trust Network Security: Strata enables secure access and consistent policy enforcement across campus, branch, and data center environments, protecting critical OT and IT systems from lateral threat movement.
  • Elite Incident Response: Backed by Unit 42®, organizations gain access to threat intelligence and rapid incident response services to augment their teams and build long-term cyber resilience.

Operational Resilience Is Becoming a Strategic Requirement

One of the most significant shifts occurring across industries today is the growing focus on operational resilience. Organizations are increasingly asking questions that extend beyond traditional cybersecurity controls:

  • Can we maintain critical services during a cyber attack?
  • Do we have visibility across our cloud environments and supply chain dependencies?
  • Can we rapidly detect, respond to, and recover from disruptions?
  • Are our governance processes keeping pace with cloud adoption and AI innovation?

As organizations adopt cloud-native architectures, AI-driven technologies, and interconnected digital ecosystems, resilience has become a board-level concern. The ability to prevent incidents remains important, but organizations are equally focused on their ability to withstand, respond to, and recover from them.

This is where frameworks like PBMM provide value. Beyond evaluating security controls, PBMM assesses the governance, operational processes, monitoring capabilities, and risk management practices that help organizations operate securely.

For critical infrastructure operators, resilience is no longer simply an IT objective—it is a business imperative. Increasingly, the organizations that earn trust are those that can demonstrate they are prepared to operate effectively when disruption occurs.

Final Thoughts: PBMM Reflects the Future of Trust

PBMM may have started solely as a government assessment framework, but its relevance now extends far beyond federal environments. It represents something universal: the ability to operate securely, reliably, and transparently in environments where trust matters most.

By expanding our PBMM-assessed offerings across Cortex and Strata, Palo Alto Networks underscores its commitment to securing Canada's digital future. We provide the validated foundation organizations need to innovate with confidence, protect sensitive data, and maintain operational continuity under any circumstance.

Read the Assessment Summary Report

To learn more about the Palo Alto Networks Cloud Medium security assessment, review the publicly available assessment summary report issued by the Canadian Centre for Cyber Security.

Ready to modernize your defenses with PBMM-assessed solutions? Schedule a demo with our team or contact Unit 42 to learn how we can help elevate your organization's resilience against emerging cyber threats.

The post Securing Canada’s Digital Future: Why PBMM Matters Beyond Government appeared first on Palo Alto Networks Blog.

  •  

Shifting from Data Hoarding to Active Defense: Navigating the New Era of OMB M-26-14

The release of OMB Memo M-26-14 ("Ensuring Effective and Efficient Agency Logging and Network Visibility to Defend Against Evolving Cyber Threats") marks a historic turning point in federal cybersecurity. By officially rescinding the M-21-31 directive, the White House has delivered a clear message to federal IT leaders: the era of compliance-driven data hoarding is officially over.

While the previous framework was a well-intentioned response to the SolarWinds breach, its mandate to collect and retain vast oceans of unstructured logging data created unintended, unsustainable operational burdens. For the past several years, federal agencies have faced skyrocketing cloud storage bills and overwhelmed Security Operations Centers (SOCs). Crucially, they have been left with vast quantities of cold data that lacked clear operational utility.

As OMB noted, retaining endless data without operational focus is neither cost-effective nor operationally feasible. With M-26-14, the federal government is pivoting to a smarter, sleeker, and far more decisive strategy: a risk-based, prioritized logging framework driven by AI and machine-speed defense.

The Core Shifts: What Federal Leaders Must Understand

M-26-14 strips away administrative "red tape" to focus on how modern cybersecurity risks have evolved. Nation-state threat actors are actively leveraging advanced automation and Artificial Intelligence (AI) to orchestrate attacks at unprecedented speeds. They move laterally across agencies in minutes, hiding behind legitimate corporate credentials.

To beat machine-speed threats, your data layer must operate at machine-scale. The new memo reorganizes federal visibility around two foundational pillars:

1. Continuous Event Monitoring — Owning the Present

Continuous Event Monitoring demands that logging infrastructure shift from a passive archiving tool to a live-streaming asset. Agencies are now required to monitor network and asset activity in real time, rapidly flag anomalous behavior via behavioral analytics, and initiate immediate mitigation actions directly through their SOCs.

2. Threat Hunting, Investigation, Response, and Forensics — Dominating the Post-Compromise

When a compromise is suspected, agencies can no longer spend days running slow database queries or pulling disconnected csv files. M-26-14 mandates that agencies keep 6 months of logs "hot and searchable" and 1 year fully "retrievable." This allows defenders to immediately stitch together cross-domain attack patterns, perform rapid root-cause forensics, and share threat intelligence seamlessly with CISA and the FBI.

3. Expanding the Blast Radius: Entering IoT and OT

Perhaps the most significant structural change is the explicit inclusion of Internet of Things (IoT) and Operational Technology (OT) systems. Adversaries do not respect the boundary between your corporate IT network and your physical infrastructure. Under M-26-14, your logging and threat-hunting capabilities must aggressively cover the entire enterprise—from public cloud workloads to the physical facility controls and critical infrastructure grids running on an agency's behalf.

The Clock is Ticking: The Aggressive Maturity Deadlines

Agencies cannot afford a passive approach. The timeline established by OMB M-26-14 moves quickly:

  • T+90 Days: CISA will publish the new Logging Reference Architecture (LRA) codifying hybrid/centralized deployments, Zero Trust Maturity Model (ZTMM) integration, and AI-driven monitoring guidelines.
  • LRA +90 Days: Agencies must submit their comprehensive Agency Logging Plans.
  • LRA +120 Days: Achieve Basic Level 1 Maturity.
  • LRA +180 Days: Achieve Intermediate Level 2 Maturity.
  • LRA +320 Days: Achieve Advanced Level 3 Maturity (Advanced/Optimal Effectiveness).

Activating OMB M-26-14 with Palo Alto Networks Cortex

Trying to retrofit a legacy SIEM architecture to meet the advanced or optimal effectiveness tiers of M-26-14 is an engineering and budgetary dead end. Legacy SIEMs scale costs linearly with ingestion and rely on static, human-written correlation rules that fail against AI-fueled threats.

The FedRAMP Certified Palo Alto Networks Cortex platform—anchored by Cortex XSIAM (Extended Security Intelligence and Automation Management)—was engineered from the ground up to solve the exact problems this new memo addresses.

From Disconnected Columns to Cross-Domain "Stitching"

Legacy logging stores data in isolated silos. An analyst trying to track an adversary has to manually look at an identity log, cross-reference it with a network firewall alert, and match it to an endpoint execution.

Cortex XSIAM features a revolutionary Analytics Engine that automatically stitches multi-vendor logs across cloud, network, endpoint, and identity at the moment of ingestion. It transforms raw text into a single, cohesive, context-rich story, instantly aligning incidents with the MITRE ATT&CK framework.  Cortex XSIAM doesn’t just ingest data, it understands the data which enables stitching of multiple data elements into a single, multi-context construct which accelerates analysis via AI and machine learning.

Replacing Static Rules with Cloud-Scale AI

Adversaries use AI to evade signature detection. Cortex XSIAM fights fire with fire, applying out-of-the-box, unsupervised machine learning models to baseline normal behavioral patterns across your entire federal enterprise. When an anomalous lateral movement, data exfiltration attempt, or credential abuse event occurs, XSIAM flags the threat instantly—without requiring your team to spend weeks writing custom correlation code.

Accelerating Continuous Event Monitoring (CEM) and Threat Hunting, Investigation, Response and Forensics (THIRF)

There is more to CEM than just monitoring network activity.  Activity on endpoints, within your identity management solution(s) and in the cloud are just as important.  Understanding the data, knowing which log records are related to each other across multiple log sources, which events are relevant and the context they provide is required.  

Understanding these events and their contextual relationships is fundamental to providing THIRF in an efficient manner.  Cortex XSIAM provides over 2,900 machine learning models out of the box, models that are trained on the data in your environment so they detect anomalous activity based on what is “normal” in your environment, not trained on generic data from other customers or a lab.  These models can identify threats based on data stitched together from multiple sources to provide a more complete context yielding more accurate and consistent results while decreasing time to value.

Securing the Unmanageable: Agentless IoT/OT Defense

You cannot install an EDR logging agent on a smart building HVAC system or an industrial programmable logic controller (PLC). Palo Alto Networks utilizes non-disruptive, passive network analysis to continuously discover, profile, and generate high-fidelity security logs for IoT and OT infrastructure. These logs stream directly into XSIAM, eliminating critical federal blind spots and protecting your High Value Assets (HVAs) from cross-boundary pivot attacks.

Solving the Storage Conundrum Safely

Keeping six months of high-velocity event logs fully "hot and searchable" under a traditional database indexing model creates a crushing financial burden. Cortex XSIAM fundamentally resets the Total Cost of Ownership (TCO) equation by leveraging an index-free, cloud-native data lake architecture that decouples storage costs from analytical performance. By eliminating legacy ingestion taxes and infrastructure overhead, federal defenders can search petabytes of data in seconds—effortlessly meeting the 6-month searchable and 1-year retrievable thresholds. Furthermore, integrated data masking rules strip away sensitive PII or low-value data noise before it hits the SOC, ensuring agencies only pay for operationally vital intelligence.

 

The Bottom Line for Federal Leaders

OMB M-26-14 is a massive step forward for federal cybersecurity. It frees CISOs from the operational gridlock of untargeted data archiving and empowers them to build faster, modern, and highly responsive security operations.

Meeting the strict 120-to-320-day maturity milestones requires moving past the tools of the last decade. By partnering with Palo Alto Networks and deploying the Cortex suite, federal agencies can seamlessly transition into a risk-aligned, AI-driven SOC. They can confidently check the box on OMB compliance while achieving what the directive actually intends: protecting the resilience and integrity of the federal mission at machine speed.

Palo Alto Networks’ Cortex XSIAM is FedRAMP certified at both the moderate and high levels.

Want to learn more about how to structure your upcoming Agency Logging Plan to meet CISA's upcoming Logging Reference Architecture? 

Contact the Palo Alto Networks Federal Team today to schedule an architectural deep-dive.

The post Shifting from Data Hoarding to Active Defense: Navigating the New Era of OMB M-26-14 appeared first on Palo Alto Networks Blog.

  •  

The “Why” Behind NextWave’s New Requirements

Helping Partners Stay Competitive for the Future

Key Takeaways

  • The evolved NextWave Partner Program raises expectations while strengthening enablement, incentives and the Partner Development Fund to support partner growth and reinvestment.
  • Levels and specializations are more closely aligned to next-generation security priorities, helping partners deepen expertise and making partner distinctions more meaningful for customers.
  • These changes help create a more capable partner ecosystem, with deeper capabilities, greater alignment with customer needs, and a stronger foundation to support the future of security.

Cybersecurity partnerships are operating in a more demanding environment. As customers consolidate vendors, modernize security architectures and adopt artificial intelligence (AI) across the enterprise, they’re placing greater expectations on partners to help guide decisions across network, cloud and security operations. They also want clearer evidence that their selected partners have invested in growing the skills and expertise needed to support more integrated and fast-changing security priorities.

The Palo Alto Networks NextWave Partner Program has evolved to help partners meet these heightened expectations. As security delivery becomes broader and more strategic, customers are placing more weight on what a partner’s credentials actually represent. That’s why stronger performance and enablement requirements are part of our reimagined program. The new requirements help partners better understand what they need to build real capability and advance within our program. They also give more substance to the designations customers see when choosing a partner.

Our objective was never simply to raise the standards for engagement in our program. It was to inspire partners at all levels – Registered, Innovator, Platinum and Diamond – to invest deliberately and continuously in learning, so they can deepen their proficiency and earn specializations that will help them stay competitive and build and deliver the future of security.

Why Requirements and Incentives Had to Evolve Together

Raising performance expectations was only part of the work in evolving the NextWave program. We also wanted to give our partners compelling reasons to invest in the capabilities Palo Alto Networks wants to see scale. That meant looking more closely at how standards, specializations and incentives fit together, and how we can help accelerate mutual success.

We are providing our partners with better access, better visibility and better support for learning and enablement. In turn, we are recognizing and rewarding partners for their efforts to develop and maintain the competency, capability and capacity needed to go to market successfully with Palo Alto Networks.

This approach, shaped largely by partner feedback, is designed to make incentives easier to access while still directing partner investment toward deeper specialization and next-gen security capabilities. Program levels and product specializations help define what partners need to do to grow within our program and to excel at selling, supporting or delivering Palo Alto Networks products and services.

The program’s Partner Development Fund adds another dimension to this evolved model. It gives all partners a more deliberate way to reinvest a portion of their earned incentives into the capabilities they need to stay competitive and innovate, including training, certification, workshops, demos and other strategic activities that help strengthen their team’s overall readiness over time. In that sense, the program is both rewarding current performance and driving mutual growth.

Training and Enablement that Move with the Market

As we continue to strengthen our partner program, Palo Alto Networks is refreshing courses, updating certification paths and redesigning training to better reflect the customer needs that partners are helping to address today, including emerging areas like AI security.

Notable improvements:

  • Introduced more online, on-demand learning experiences across all products and across all roles, including sales, technical presales and post-sales professionals.
  • Expanded access to lab environments for hands-on experiences, as well as access to perform demos for customers.
  • Injected AI roleplay into learning experiences to help sales and presales teams improve their ability to educate customers about our products and services while addressing questions or concerns.
  • Instituted a continuous education component that encourages partners to stay current with certifications and other program requirements, so they don’t need to be tested annually.

Our aim with these changes is to keep learning options relevant, practical and easier to engage in and apply in practice. We believe product and services training should help partners deepen expertise, validate skills and stay current as technologies, customer expectations and threats shift. It should also recognize the experience many professionals already bring to the table, with learning paths that are rigorous without being repetitive or unnecessarily burdensome.

Ultimately, the impact of providing more effective enablement for our partners (and outlining clear requirements for advanced specializations and total certified staff for specific partner paths) positively impacts the customer experience through more informed conversations, stronger design guidance and more consistent support across the entire security lifecycle.

A More Focused Program to Help Accelerate Next-Generation Security

Part of what makes the current evolution of the NextWave program so significant is its focus on helping partners build the bench strength they will need to stay competitive as security becomes more platform-driven, AI-influenced and interconnected across domains. The program also encourages bookings tied to next-generation security priorities, helping direct partner investment toward the areas customers are prioritizing most. That focus is especially visible in areas such as Idira®Prisma® SASE, Cortex® Cloud™ and Cortex, where customer demand and program priorities are increasingly aligned.

The benefits of that alignment extend beyond the partner organization. Customers gain access to partners that are better prepared to support more connected security strategies without adding unnecessary complexity. They can work with partners that are building expertise around the technologies and use cases becoming more central to modern enterprise security programs.

This kind of alignment also strengthens the broader ecosystem. It creates a clearer connection between customer needs, partner capabilities and Palo Alto Networks platform strategy. It’s the value exchange in cybersecurity in action: Ongoing investment in knowledge, skills and services that helps partners grow while giving customers faster time-to-value realization.

What Stronger Program Requirements Mean for Customers

For customers, stronger requirements for our Nextwave program can make partner distinctions more meaningful. A specialization or program level should point to something real, such as training completed, certifications maintained and expertise developed. While those accomplishments don’t guarantee security outcomes, they do provide evidence that a partner has built the depth needed to support more complex environments.

Partner distinctions are also reinforced through an active compliance framework rather than treated as a one-time achievement. Partners have ongoing visibility into their progress and can be recognized immediately throughout the year as they meet requirements. Reviews take place on a defined cycle, and status changes are subject to oversight. Taken together, these elements add credibility to the designations customers see and give them more weight in the partner selection process.

This becomes increasingly important as customers look for security partners that can do more than support a single transaction or product decision. Many are seeking guidance at the architecture stage and during implementation, and expecting continuity as IT environments evolve and new risks emerge. It also raises the level of scrutiny that partner selection deserves:

  • Is a partner specialized in the areas most relevant to the customer’s priorities?
  • Do they have the certifications and technical expertise required to support the solutions being considered?
  • Can they provide the level of guidance, implementation support and ongoing engagement the relationship will require over time?

In a fast-moving security market, questions like these can help customers make more informed decisions about which partners are best equipped to deliver long-term value.

What Partners Should Do Now

Now that we’ve introduced our new program requirements, partners should take stock of whether their certifications, specializations and go-to-market priorities are aligned to where customer demand and the future of security are headed. Steps partners can take:

  • Evaluate your current book of business: Consider where you may be missing growth opportunities because the right specializations aren’t yet in place. Those gaps can affect both business momentum and the ability to earn incentives.
  • Reflect on the current direction of your practice: Which customer conversations are signaling the need for deeper expertise? Which areas of next-generation security are becoming more central to your future? These questions can help guide your next investments by clarifying where your practice needs to build more depth sooner rather than later.
  • Review certifications and specializations with growth in mind: Look at where new specializations could open the door to additional incentives and stronger alignment with customer demand, while ensuring your team’s existing certifications and specializations remain on track for the next compliance cycle.

Partners that take the time now to assess our new requirements and create a plan to meet them will be better positioned to advance within and benefit from our partner program, while developing the capabilities needed to help build the future of security.

Partners with a designated Palo Alto Networks Channel Business Manager can get detailed data and analysis now on their progress and performance in the Nextwave program, including the status of their certifications and which team members have engaged in training, demos and more. In the second half of 2026, we plan to make the same dashboard capabilities and insights directly available to all partners, so they can understand exactly what they need to do to excel in our program. These red-yellow-green dashboards are simple but powerful tools, and we are eager to put them in our partners’ hands soon.

Visit the NextWave Partner Portal to learn more.

The post The “Why” Behind NextWave’s New Requirements appeared first on Palo Alto Networks Blog.

  •  

Beyond the Frontier — Expanding the Ecosystem for Autonomous Defense

Over the past few weeks, we have reached a critical turning point in cybersecurity. Following the launch of our Frontier AI Defense initiative, we’ve continued testing the latest frontier models (including Anthropic’s Mythos and Claude Opus 4.7, as well as OpenAI’s GPT-5.5-Cyber) as part of the Trusted Access for Cyber program.

The urgency to innovate continues to ramp up. As Lee Klarich recently detailed in his Defender's Guide to the Frontier AI Impact on Cybersecurity, our current landscape is defined by a brief three-to-five-month window to gain a strategic advantage over attackers. To outsmart AI-based exploits, enterprises must decisively address vulnerabilities across their code and stand up the right security stack to enable real-time, automated defenses.

With such a ticking clock in front of us, acting rapidly and at-scale to support our customers is paramount. Today, we exponentially grow our scale of delivery by expanding our Frontier AI Alliance.

Since introducing this initiative, our collaboration with initial partners – Accenture, Deloitte, IBM, NTT DATA, and PwC – has already begun changing the defensive math for our customers. This is a moment that calls for radical collaboration across the entire security ecosystem, so today we are proud to welcome a new cohort of strategic partners – Cognizant, HCLTech, Kyndryl, TCS, Infosys, McKinsey & Company, Orange Cyberdefense, and Wipro – who will join us in delivering AI readiness at scale.

Frontier AI Alliance

While this expansion significantly increases our reach, this is only the beginning. We are committed to a continuous evolution of this alliance and will be adding more critical partners in the future across the globe to ensure our customers have the most robust defense network possible.

By combining our technology with these partners’ deep consulting expertise, we are delivering:

  • Machine-Speed Security: Natively integrating Frontier AI to provide real-time, automated defense against autonomous threats.
  • Intelligence-Led Resilience: Leveraging Unit 42® experts to fast-track the discovery and remediation of exposures at machine speed.
  • Hardened Defenses: Utilizing early access to frontier models from partners like OpenAI and Anthropic to simulate and block attack chains before they hit the mainstream.

The stakes are high. The attack cycle has compressed with the time from initial access to data exfiltration collapsing to just 39 seconds. Machine-speed MTTR (mean time to respond) is no longer an ambitious goal, it is a requirement.

This initiative underscores our commitment to providing every client with integrated, real-time protection.

Discover further details: Palo Alto Networks Frontier AI Defense.

Forward-Looking Statements

This blog contains forward-looking statements that involve risks, uncertainties and assumptions, including, without limitation, statements regarding the benefits, impact, or performance or potential benefits, impact or performance of our products and technologies or future products and technologies. These forward-looking statements are not guarantees of future performance, and there are a significant number of factors that could cause actual results to differ materially from statements made in this blog. We identify certain important risks and uncertainties that could affect our results and performance in our most recent Annual Report on Form 10-K, our most recent Quarterly Report on Form 10-Q, and our other filings with the U.S. Securities and Exchange Commission from time-to-time, each of which are available on our website at investors.paloaltonetworks.com and on the SEC's website at www.sec.gov.  All forward-looking statements in this blog are based on information available to us as of the date hereof, and we do not assume any obligation to update the forward-looking statements provided to reflect events that occur or circumstances that exist after the date on which they were made.

The post Beyond the Frontier — Expanding the Ecosystem for Autonomous Defense appeared first on Palo Alto Networks Blog.

  •  

Idira — Our Journey to Democratize Privilege Controls

Key Takeaways

  • Built on the Pioneers of PAM (privileged access management): Idira™ is Palo Alto Networks next-generation identity security platform, extending privileged access controls to every human, machine and AI agent identity in the AI enterprise.
  • Zero Standing Privilege by Default: Idira replaces static, always-on access with dynamic privilege, granted just-in-time on a single control plane.
  • AI-Driven Identity: AI runs natively inside Idira to surface hidden entitlements, unmanaged accounts, recommend least privilege, and remediate to close the gap between attackers who move in 72 minutes and defenders who historically took days.

Since Palo Alto Networks and CyberArk came together in February, customers have been asking me the same question: What does the future of identity security actually look like?

At IMPACT, I got to answer that question.

I am proud to introduce Idira™, the next-generation identity security platform from Palo Alto Networks. Idira secures every identity in the AI enterprise (human, machine, AI agent) on a single control plane that discovers risk, applies privilege dynamically, and governs the full lifecycle from first access to last session.

Idira begins with a belief shaped by more than 20 years of working on this problem. Privilege is the most challenging aspect of identity security. For a generation, the industry learned how to manage it well for a small population – administrators inside the most security-sensitive organizations in the world. That was necessary. But it is no longer enough.

The moment has come to extend that same rigor to every identity, because every identity today carries the power to move the business, or enable an attacker. That is the journey Idira takes us on. From privilege controls for administrators, to privilege controls for every identity.

Attackers Are Not Breaking In. They Are Logging In.

For most of the last two decades, identity security was built on a comfortable assumption: One can maintain a firm divide between a small number of powerful administrators and a much larger number of ordinary users; that is enough to secure the organization. That assumption no longer holds.

Our Chairman and CEO, Nikesh Arora, calls it the “IAM fallacy,” and the data in the 2026 Identity Security Landscape Report makes clear why it is time to retire this assumption.

Based on responses from 2,930 cybersecurity decision-makers worldwide:

  • Machine identities now outnumber humans by 109 to 1. Of those, 79 are AI agents.
  • 91% of organizations already run autonomous agents in production.
  • 90% of organizations suffered an identity-related breach in the past 12 months. 83% of organizations suffered two or more incidents.

The old model is not failing because identity became less important. It is failing because identity and privilege became universal and ubiquitous.

Every major breach I have studied over the last two years follows the same pattern. An attacker steals a credential. They move laterally using standing access that should have expired. They escalate privilege. They reach the data, the infrastructure or the business systems they came for: Okta, MGM, Microsoft. Different industries. Different scales. The same pattern.

One overprivileged identity unlocks the entire enterprise.

And when defenders have a chance to respond, they are already behind and disadvantaged. 97% of practitioners tell us that fragmented tools add 12 hours to every identity incident response time. All while Unit 42® has observed the fastest attackers move from a first foothold to exfiltration in as little as 72 minutes.

Identity is now the enterprise perimeter. And the perimeter was built for a threat model that no longer exists.

Every Identity Is Privileged — Idira’s First Fundamental Principle

The premise of Idira is simple. Every identity in your organization is privileged.

Every login, every token, every service account, every workload, every AI agent can trigger a workflow, call an API, or reach sensitive data. Some can create and destroy infrastructures, direct organizational spend, or create new identities. Privilege is no longer reserved for a small class of administrators. It is distributed across the enterprise, quietly and continuously, every second of the day.

The controls that protect privilege cannot be reserved for the few, either.

Idira changes three things from day one.

First, We Discover

Idira continuously finds every identity, every entitlement and every access path across your entire environment: humans, machines, workloads, secrets, certificates and AI agents everywhere – on the network, in the cloud, on servers and endpoints, in the browser. If someone or something can authenticate, Idira knows it is there, knows what it can reach, and evaluates how much of that access is actually necessary.

Second, We Control

Idira replaces static, always-on accounts attackers rely on with dynamic privileges that exist only in the moment of use. Zero standing privilege moves from aspiration to default, and it applies equally to the administrator logging into production, the developer deploying code, and the AI agent calling a tool. This is the shift to identity-centric active security.

Third, We Govern

Idira automates the identity lifecycle end-to-end. Governance stops being a quarterly compliance exercise and becomes a continuous enforcement loop. The 12-hour fragmentation tax closes.

This is what I mean when I say we are democratizing privilege controls. We are not loosening them. We are extending the strongest privilege controls the industry has ever built to every identity that now carries the weight of the business, without penalizing these identities for the powers they carry.

Already Better Together

Idira is not launching into an empty runway. We have been executing against this roadmap since the day we joined Palo Alto Networks, and the early results give us real confidence in what comes next.

Earlier this year at the RSA Conference, we launched Next-Generation Trust Security (NGTS), the first network-native platform to automate certificate lifecycle management and accelerate post-quantum readiness. That matters because 71% of organizations have not yet automated certificate renewal. As public TLS lifetimes compress to 47 days and manual workloads multiply, that gap becomes more than an operational burden. It becomes a business continuity risk.

NGTS closes it in the network itself.

As one of the core platforms of Palo Alto Networks along with Strata® and Cortex®, Idira is providing deep identity integrations across the entire portfolio to enhance platform value for customers. Prisma® Browser™ delivers privileged access directly in the place where enterprise users work. Prisma AIRS™ 3.0 natively integrates with Idira to extend deep identity security and privilege controls to AI agents. Cortex will receive first-party identity signals to sharpen detection and take automatic identity- and privilege-driven response actions when indicators of compromise are detected.

Customers are already seeing the impact. Northern Trust improved password compliance by 137 percent. Panasonic Information Systems rebuilt its security operations around identity. Healthfirst grounded its zero trust program in identity-first controls. PDS Health secured clinical access for more than 900 practices. They had different problems with the same answer.

Different challenges. One answer. One platform. Consistent privilege controls applied to every identity that matters.

AI Makes This Urgent. AI Makes This Possible.

AI has changed the speed, scale and economics of identity risk.

Frontier models have crossed a threshold. Anthropic's Claude Mythos Preview has already identified thousands of zero-day vulnerabilities across the operating systems and browsers that businesses rely on every day. Every exposed secret, every standing admin path, every forgotten service account can now be discovered, validated and weaponized faster than most security teams can respond. 55% of the decision-makers in our 2026 survey named AI-enabled threats as their top identity concern.

Our answer is clear: We fight AI with AI.

If frontier models are rewriting the economics of attack, the only credible response is to rewrite the economics of defense with the same technology.

Idira is how we do that in identity. AI is built into the platform to surface hidden entitlements, identify risky access combinations, recommend the least privilege automatically, and drive surgical remediation. That same intelligence lets attackers find the weakest link in 72 minutes and helps defenders close it in seconds.

When code cannot be patched fast enough, identity becomes the control plane that can still adapt at machine speed.

Same Mission, Stronger Together

For more than two decades, the pioneers of privileged access have management-built controls trusted to safeguard the world's most critical environments. That mission created a category and earned the trust that made today possible.

Idira carries that mission forward and expands it to match the scale of the problem we now face.

This is the first wave, not the last. The roadmap extends privilege controls to workforce identity, advances machine and agentic identity security, and unifies a fragmented market into one platform. We are building it in the open, shaped by the customers in the room with us at IMPACT and by the realities they face every day.

The future of identity security will not be defined by access alone. It will be defined by control. See what Idira is built to deliver.


Forward-Looking Statements

This blog contains forward-looking statements that involve risks, uncertainties and assumptions, including, without limitation, statements regarding the benefits, impact, or performance or potential benefits, impact or performance of our products and technologies or future products and technologies. Any unreleased services, integrations or features (and any services or features not generally available to customers) referenced in this or other press releases or public statements are not currently available (or are not yet generally available to customers) and may not be delivered when expected or at all. Customers who purchase Palo Alto Networks applications should make their purchase decisions based on services and features currently generally available.

The post Idira — Our Journey to Democratize Privilege Controls appeared first on Palo Alto Networks Blog.

  •  

A New Era of Security: Frontier AI Defense

For the last several months, we have had early, unbounded access to the latest frontier AI models. What we’ve seen from that vantage point has made it clear that the window for organizations to get ahead of what’s coming is shorter than most leaders realize.

We have moved past the era of incremental AI improvements into a threat landscape shift. Our testing has revealed a step-change in capability that demonstrates an intuitive understanding of software vulnerabilities. This is more than faster code generation, it is a shift from AI as an assistant to AI as an autonomous agent capable of discovering and chaining flaws at a scale that most defenders aren’t prepared for.

These capabilities will not stay confined to controlled environments for long. When Mythos first launched, we predicted a six-month window before attackers gained access. We now believe that timeline has accelerated significantly.

To meet this inflection point, defense must operate at the speed of the adversary. That is why Palo Alto Networks has introduced Frontier AI Defense. This initiative unites our AI-native security platforms with Unit 42® consulting and threat expertise with strategic partners to deliver continuous protection, prioritized risk mitigation and autonomous remediation.

What the Threat Looks Like Now

The latest frontier models, including OpenAI’s GPT-5.5-Cyber, Anthropic’s Mythos and Claude Opus 4.7, and the specialized variants emerging across major labs, represent roughly a 50% improvement in coding efficiency over their predecessors. That number sounds incremental, but in practice, it’s the threshold at which AI crosses from a helpful assistant into an autonomous operator.

Based on our testing and review, we found four key developments that, taken together, redefine the modern threat landscape:

  • Vulnerability Discovery at Scale: Frontier AI is exceptionally effective at identifying vulnerabilities across massive, complex codebases. In our testing, three weeks of model-assisted analysis matched a full year of manual penetration testing, with broader coverage.
  • Exploit Chaining & Synthesis: What is more consequential than individual discovery is the models’ ability to think like an attacker. They link multiple lower-severity issues into single, critical exploit paths, seeing full-stack logic, including SaaS and public-facing surfaces, in ways traditional scanners cannot.
  • Attack Cycle Compression: In AI-assisted scenarios, the time from initial access to exfiltration has collapsed to as little as 25 minutes. Detection and response measured in hours is no longer a viable standard; single-digit MTTR (Mean Time to Respond) is the new floor.
  • The Unsupervised Attack Surface: Rapid AI development and decentralized innovation are creating a massive, unsupervised attack surface in real-time. As local AI agents become commonplace, every desktop is now effectively a server, yet most organizations lack visibility into the code their own employees are generating and deploying.

Our Approach

These emerging threats form the foundation of how we have architected our platform response for the agentic era – Frontier AI Defense. Our approach moves beyond traditional, reactive defense to provide a comprehensive framework built to outpace frontier-AI-enabled attackers. This initiative is defined by:

  • Advanced Access: We leverage early access to frontier AI models to harden defenses and simulate attacks before they reach the mainstream.
  • Intelligence-Led Resilience: Unit 42 experts leverage frontier AI to fast-track discovery and remediation of exposures at machine speed through our Unit 42 Frontier AI Defense service.
  • Unified Global Ecosystem: We provide the scale required for global protection through our Frontier AI Alliance of elite partners, including Accenture, Armadin, Deloitte, IBM, NTT DATA, and PwC.
  • Machine Speed Security: By natively integrating Frontier AI across our platforms, we deliver the automated, real-time defense necessary to counter autonomous threats.

The Window Is Open. It Won’t Be for Long.

The capabilities we tested under early-access conditions are expected to become widely available over the next several months. Success in this new environment requires adapting your cybersecurity stack before these tools are in the hands of every adversary.

The threat has never been more sophisticated. The window to prepare for this shift is closing. And we're here to help secure your future at the edge of the frontier.

Visit Palo Alto Networks Frontier AI Defense to learn more.

The post A New Era of Security: Frontier AI Defense appeared first on Palo Alto Networks Blog.

  •  

The Dangerous Momentum of Autodownload Phishing

Modern phishing campaigns are no longer trying to convince users. They are trying to outrun them. By forcing an automatic progression from click to download, attackers eliminate the moment of hesitation entirely by forcing files to download instantly using trusted cloud platforms like Dropbox and Google Drive.

Detecting when these legitimate SaaS auto-download features are being weaponized is an immense challenge for traditional defenses. This is exactly where Cortex® Email Security steps in. By combining deep static analysis with advanced behavioral intelligence, the module can distinguish in this attack between a benign file share and a malicious, forced-momentum trigger.

This technical detection is vital because while the autodownload method is the primary cause of infection, its effectiveness relies on a clever strategy, using a wide range of changing social engineering lures. By alternating between lures like 'Invoices' or 'Quotes,' attackers rotate their themes to catch a wider variety of victims. This strategy allows attackers to convert trusted email links into rapid, dangerous file executions that effectively evade standard security measures.

How Forced Momentum Drives Auto-Downloads

The core of this attack leverages the infrastructure of real SaaS providers to eliminate the user's preview buffer. Typically, cloud sharing directs users to a webpage for file examination. In this campaign, however, forced-download parameters (such as ?dl=1 on Dropbox) are used instead. To ensure the victim executes the file once it lands on their machine, attackers hide the danger behind "visual anchors." By using double extensions like PDF and .EXE, the threat actor exploits default settings in certain operating systems that hide known extensions. The user's eyes stop at the familiar ".PDF" or ".ZIP," leading them to believe the file is a harmless document rather than a malicious executable.

When the targeted victim clicks the link in the email, it triggers an immediate file download in the browser, effectively bypassing any intermediary steps.

Attack Flow: From Email to Execution

  • The Bait: A highly personalized email arrives, using a trusted cloud link (like Dropbox) to lower the victim's guard.
  • The Trap: Clicking the link skips the usual "preview" screen and instantly drops a file onto the victim's computer.
  • The Disguise: The file is cleverly named to look like a safe PDF or document, hiding its true identity as a harmful program.
  • The Lock: In many cases, the attacker ensures only the intended victim can open the file, preventing security tools from scanning it first.
  • The Takeover: Once the victim opens the file, the attacker gains remote access to the system.
Attack flow chart, from email to execution.
Multi-step attack flow, starting from targeted phishing email, to bypass security and establish persistence.

The Library of Lures Strategy

To fuel the autodownload machine, attackers employ a flexible strategy by switching between various social engineering themes. This spear phishing campaign targets specific inboxes, such as "Orders," to exploit professional routines. Some common lures found in this campaign include:

  • Financial Urgency Fake "Invoices" or "Receipts" that induce anxiety. These often set close-day payment deadlines, pressuring recipients to click quickly.
  • Business Operations – "Quote Requests" or "Purchase Orders" that exploit professional habits.
  • Deceptive Naming – Concealing the download as a safe document, using display text like "invoice.pdf" in the email body to hide the underlying Dropbox URL.

Government Domain Impersonation

Attackers often leverage high-authority lures designed to paralyze a user's critical thinking. In one sophisticated wave, we observed threats impersonating a government entity by exploiting the high-reputation, official government domain. By borrowing the reputational authority associated with official infrastructure, the attacker successfully maneuvered an "Unidentified Payment Notice" past standard "Untrusted Sender" filters. To the recipient, the email carries the weight of a sanctioned document. Fearing legal or financial ramifications, they feel a heightened sense of urgency to click "View Invoice" to resolve the issue immediately.

Employee Impersonation

When government authority isn’t the angle, attackers shift to impersonating internal staff. In one case, the sender’s display name was spoofed to match a real employee in the target organization. Attackers rely on a “Momentum of Trust” tied to familiar names to overwhelm user judgment. Even when a generic Gmail address is used, users, especially those on mobile devices, rarely pause to check the underlying headers.

Internal Trust Amplification ("Human Relay")

The most effective aspect of this campaign occurs through Internal Laundering, where the threat shifts from external suspicion to a trusted internal message. This was observed when a Finance Department employee received a "Quote Analysis" file and, believing it to be a valid inquiry, mistakenly forwarded the link to the Procurement department.

At that stage, the attack no longer depended on deception, it propagated through trusted human workflows. These various tactics illustrate the sophistication and adaptability of phishing campaigns and highlight the importance of vigilance in email security.

How We Uncovered a Single Threat Actor

Although the lures appeared diverse, a deeper technical analysis revealed that they were all orchestrated by a single, coordinated threat actor.

By mapping the campaign, we uncovered a significant pattern: Each autodownload link pointed to a different file hash to evade signature detection, but all unique executables were ultimately associated with the same parent installer hash.

The file was identified as a specific Remote Monitoring and Management (RMM) executable, an administrative software used to manage computers remotely. Because RMM tools are legitimate, they often trigger fewer alerts than traditional Trojans. This allows the attacker to maintain persistent access under the guise of “authorized” system activity.

How Cortex Email Security Addresses the Threat

To defend against a campaign that emphasizes speed and rotation, behavioral analysis is essential.

The Cortex® Email Security Module addresses this threat:

  • Advanced URL Analysis – Detection of forced-download parameters, combined with delivery of high-risk files via URLs.
  • Deep Metadata Correlation Correlating sender identity with behavioral anomalies to flag threats that traditional scanners might overlook.
  • LLM-Based Intent Analysis Classifying phishing themes (invoice, payment, quote) despite variation.

The security engine triggers an alert by synthesizing LLM analysis with real-time email telemetry, global threat intelligence and behavioral signals.

Securing the Click

The combination of autodownload links and rotating lures is crafted to exploit user momentum and the "psychology of trust."

This campaign represents a shift from deception to acceleration. Attackers no longer need perfect lures, they only need to remove friction. Defenders must evolve accordingly, focusing not only on what a link is, but on what it forces a user to do.

Palo Alto Networks Cortex Advanced Email Security was built for this evolution. By moving beyond static file analysis to identify the behavioral "red flags" of autodownloads and forced-momentum URLs, we provide the visibility needed to stop these attacks before they reach the device.

The module examines email metadata, content, and behavior to uncover hidden malicious intent and sophisticated impersonation, including AI-crafted threats. By assigning precise risk scores to every detection, the system filters out the noise, allowing analysts to move past alert fatigue and focus on the most critical threats first.

Indicators of compromise discovered during this research are detailed on Unit 42’s GitHib instance.


FAQs

  1. Why is the "Auto-Download" parameter so effective? It removes the "moment of doubt." By bypassing the preview page, the attacker forces the file onto the computer instantly, prompting the user to "Open" it out of habit.
  2. How does the use of rotating lures benefit the attacker? It maximizes both psychological and technical success. People have different "blind spots" (e.g., finance professionals are likely to click on invoices), and variety increases the chances of finding a template that can bypass specific customers' security filters.
  3. Why might a sandbox fail to catch the malicious file? Because the link was "Identity-Bound." To the scanner, the link appeared to lead to a harmless error page (cloaking), resulting in a false negative.

Cloaking involves showing different content to security scanners than what is presented to the victim. By using Identity-Bound access, the file only reveals itself to the intended target.

The post The Dangerous Momentum of Autodownload Phishing appeared first on Palo Alto Networks Blog.

  •  

AI Threat Readiness: Defending Against Attacks Powered by Frontier AI Models

A new generation of frontier AI models is fundamentally changing how cyber attacks are created and executed, introducing a level of speed, scale, and accessibility the industry has not faced before. Early testing of advanced models, including Claude’s Mythos model, shows that they can identify vulnerabilities in code, connect them into viable attack paths, and generate working exploits with minimal effort. What once required deep expertise and significant time can now be executed rapidly, and at scale, across a wide range of environments. These are not simply AI-assisted attacks, they are attacks powered by frontier AI models. The new models […]

The post AI Threat Readiness: Defending Against Attacks Powered by Frontier AI Models appeared first on Check Point Blog.

  •  

Unit 42 Expands Frontier AI Defense with Armadin Partnership

Frontier AI is changing what is possible for attackers. To meet this escalating threat, Palo Alto Networks is teaming up with Armadin, the new offensive security company founded by Kevin Mandia. This partnership expands our newly introduced Unit 42 Frontier AI Defense service, scaling our ability to identify and remediate AI-driven exposures, and accelerating protection across the enterprise.

Over the past few weeks, we’ve spoken with hundreds of CISOs who universally feel the urgency on the frontlines. Security leaders need to know exactly where they stand against the AI-driven attacks happening right now, and the ones coming in the next six months.

Expanding Frontier AI Defense — The External AI Hyperattack Assessment

For organizations seeking to actively pressure-test their perimeter, this partnership introduces an autonomous, AI-driven offensive assessment of your external attack surface.

This added layer identifies real attack paths and proves exploitability across internet-facing assets. The platform begins with passive discovery, validating publicly exposed assets, cloud resources and secrets. Next, Armadin deploys a coordinated swarm of autonomous AI attack agents, operating at machine speed across your external footprint.

These agents execute active reconnaissance, launch attacks and exploit vulnerabilities in parallel, using over 50,000 templates. Upon initial access, the swarm simulates post-exploitation behavior to demonstrate impact, logging every attack chain as decision-grade evidence of exploitable risk.

Decision-Grade Proof of Exploitable Risk

With this added layer of autonomous simulation, Unit 42 Frontier AI Defense provides an even more rigorous, pressure-tested view of an organization's external attack surface. This allows our experts to accurately simulate the tradecraft of the most capable, AI-equipped threat actors, compressing complex attack lifecycles from days into minutes.

AI may change what is possible for attackers, but in the hands of defenders, it becomes a decisive advantage. This partnership is another important step in making sure that advantage stays with the defenders.

A member of Project Glasswing and OpenAI’s Trusted Access for Cyber (TAC) program, Palo Alto Networks remains the only company equipped to deliver this strategic level of partnership through Unit 42 Frontier AI Defense and the Frontier AI Alliance, driven to integrate cutting-edge technologies into our products and services.

Get started with Unit 42 Frontier AI Defense today.

The post Unit 42 Expands Frontier AI Defense with Armadin Partnership appeared first on Palo Alto Networks Blog.

  •  

Palo Alto Networks and Google Cloud

Expand Strategic Collaboration to Secure the AI Enterprise

The transition from generative AI to agentic AI represents one of the most significant shifts in the history of enterprise technology. As organizations move from simple chatbots to autonomous agents that can execute business processes, the attack surface isn't just changing, it's exploding.

At Google Cloud Next 2026 in Las Vegas, Palo Alto Networks is proud to announce a series of groundbreaking integrations with Google Cloud. These innovations are designed to do more than just monitor the new AI-driven landscape; they are built to secure it by design. AI deployment is currently outpacing AI governance. By embedding our security platform into Google Cloud’s infrastructure, we are giving today’s enterprises the foundation to become the autonomous organizations of tomorrow.

Here is a look at the four major milestones of our partnership being unveiled this week.

Secure AI Agents with Google Cloud + Prisma AIRS

As autonomous AI agents become the new enterprise standard, security can no longer be an afterthought; it must be architectural. By integrating Prisma AIRS™ natively with Google Cloud Gemini Enterprise Agent Platform, we provide the proactive defenses required to govern complex agentic workflows. This integration ensures that as you scale your autonomous workforce, your security scales with it, providing comprehensive operational integrity without hindering the speed of innovation.

We are delivering capabilities across three critical pillars:

  • Protecting Agent-Specific Runtime Risks: In an agentic ecosystem, the primary risk is unauthorized or a destructive action taken by the AI agents themselves. Prisma AIRS secures the "agent-to-tool" interface, preventing poisoned context from triggering malicious scripts or destructive actions. The solution monitors agent execution in real-time, so agents cannot leak sensitive credentials or tool schemas, maintaining the boundary between agents and their access to enterprise data.
  • Securing the GenAI Application Surface: Modern AI applications and agents require a secure-by-design approach. Prisma AIRS AI Runtime Security™ provides prevention of more than 30 adversarial prompt injection and jailbreak techniques, as well as malicious code and URLs within LLM outputs. Prisma AIRS utilizes over 1,000 predefined patterns out of the box and ML-powered Enterprise DLP to stop sensitive data leakage.
  • Enforcing Enterprise AI Safety and Grounding: Trust in AI is built on the consistency and safety of its output. Prisma AIRS allows organizations to define safety policies in natural language and filter toxic content across eight distinct categories to protect brand reputation. Using contextual grounding, Prisma AIRS can prevent misleading outputs that contradict internal RAG data, keeping agents tied to real facts.

This integration ensures that as you scale your autonomous workforce, your security posture scales with it, providing operational integrity without hindering the speed of innovation.

Security-as-Code for Prisma AIRS Integration with Application Design Center (ADC)

The traditional bolt-on approach to security is no longer viable in a cloud-first world. Google Cloud’s Application Design Center (ADC) is revolutionizing how applications are built, using an intuitive canvas and natural language via Gemini Code Assist.

Palo Alto Networks is announcing that it will be published as a template within the Application Design Center, providing more capabilities to engineering teams:

  • Drag-and-Drop Security – Visually "snap" VM-Series firewalls and Prisma AIRS AI protections directly into network flows.
  • AI-Driven Architecture – Use natural language prompts to generate secure-by-default, multiregion architectures.
  • Simultaneous Deployment – Deploy entire application stacks and security services in a single, unified workflow, ensuring protection is present from the very first minute of deployment.

Zero-Day Protection at Scale with Advanced Malware Sandboxing for Google Cloud NGFW Enterprise

The battle against malware has shifted to the cloud. Modern attacks are faster, more evasive and capable of bypassing traditional defenses.

That is why we are excited to announce Advanced WildFire®, powered by Palo Alto Networks, natively integrated into Google Cloud NGFW Enterprise, delivering AI-driven malware prevention directly within Google Cloud environments.

This integration embeds inline sandboxing and real-time threat intelligence directly into Google Cloud’s distributed firewall to stop advanced and unknown threats before they impact workloads, enabling:

  • Secure Detonation – Suspicious files are safely executed in a controlled sandbox environment to uncover hidden and unknown threats.
  • Inline Traffic Inspection – Inbound and outbound traffic is analyzed in real time to prevent lateral movement of malicious payloads across cloud environments.
  • AI-Driven Threat Prevention – Leverages global threat intelligence by Palo Alto Networks to block zero-day threats before they compromise workloads.

With Advanced WildFire embedded directly into Google Cloud NGFW Enterprise, organizations can extend consistent protection across their cloud infrastructure while maintaining operational simplicity.

Cloud NGFW Enterprise Advanced Malware Sandboxing will be available in Public Preview soon.

Defining the Future with the Google Cloud Marketplace

Palo Alto Networks has joined the Google Cloud Marketplace Agent-as-a-Service as a launch partner to introduce the Prisma AIRS Model Security agent. Operating as an Agent-as-a-Service, this solution scans AI models for vulnerabilities and policy noncompliance before they reach production.

Available in the Agent Gallery inside Gemini Enterprise, this marketplace offering runs entirely within the customer’s own Google Cloud environment, providing both new and existing Prisma AIRS users a seamless and simple deployment experience inside Gemini Enterprise.

Securing AI Innovation at Scale

The collaboration between Palo Alto Networks and Google Cloud is built on a shared vision: Security should be an accelerator for innovation, not a bottleneck. As we look toward the future of the AI-powered enterprise, our commitment remains to provide the most robust, platform-driven security for every workload, every agent and every interaction.

Want to see these integrations in action? Contact your Palo Alto Networks representative to learn more about how we are securing the future of the cloud together. If you’re attending Google Cloud Next 2026, join us at these sponsored sessions:

The post Palo Alto Networks and Google Cloud appeared first on Palo Alto Networks Blog.

  •  

Scaling AI Agents with Confidence

The Google Cloud and Palo Alto Networks Partnership

As AI agents move into business-critical environments, they are transforming everything from security operations to internal workflows. However, scaling these AI applications introduces unprecedented hurdles for security executives, from detecting "shadow AI" and unsanctioned usage to governing complex nonhuman identities across multimodel environments.

To overcome these challenges, organizations need more than just tools; they need a layered architecture built on a foundation of platformization. The long-standing partnership between Palo Alto Networks and Google Cloud provides this essential framework, offering customers:

  • Integrated Security Ecosystems: Seamlessly manage the full agent lifecycle with visibility and observability across your entire AI infrastructure.
  • Jointly Engineered Solutions: Leverage over 80 co-engineered integrations designed to eliminate the tradeoff between a cloud-native experience and best-in-class security.
  • Proven Scale and Performance: Benefit from a partnership that has already delivered impactful, AI-driven solutions to protect joint customers from evolving threats.

Google Cloud Marketplace enables customers to discover, try, buy and use industry-leading applications that have been validated to run on Google Cloud. Palo Alto Networks has closed $2.4 billion in GCP bookings, helping address evolving customer needs, such as simplified procurement and seamless deployment.

Kevin Ichhpurani, President, Global Partner Ecosystem at Google Cloud:

We’re pleased to celebrate Palo Alto Networks as our Global Technology Partner of the Year… Palo Alto Networks has consistently delivered impactful, AI-driven security solutions that help Google Cloud customers better protect their organizations from evolving threats.

The extensive, long-standing collaboration between Palo Alto Networks and Google Cloud includes jointly engineered offerings, built on 80 solution integrations that help customers build, run and secure AI-enhanced cloud infrastructure and applications with end-to-end protection.

Palo Alto Networks Wins 2026 Global Technology Google Cloud Partner of the Year Award

At Google Cloud Next, Palo Alto Networks has been recognized with four 2026 Google Cloud Partner of the Year awards. By partnering with Google Cloud, we help customers securely leverage the power of the cloud and AI-driven growth with comprehensive cloud-native security offerings. Wins included the following:

  • Global Technology
  • Marketplace: Technology
  • Marketplace: Security
  • Security: Artificial Intelligence

These Partner of the Year Awards underscore our expanding partnership with Google Cloud. We share a mutual dedication to improve cloud, network security and AI observability, as well as the progress we’ve made in protecting our joint customers from today’s and tomorrow’s cyberthreats.

By combining our industry-leading security engineering with Google Cloud’s industry-leading cloud infrastructure and services, we’re providing advanced protection for every stage of a customer’s digital journey. We want customers to feel secure from the formative steps of lifting workloads into the cloud, to expanding digital innovation across platforms, to reaching new levels of business scale and velocity.

Protecting these journeys requires alignment and modernization of infrastructure (lift and shift), applications (refactoring) and user access models (zero trust). It requires an advanced AI drive security operations transformation across all IT domains, leveraging machine learning and sophisticated models to minimize human interventions and unguarded sides.

Our relationship with Google Cloud is based on a deep engineering relationship, yielding integrated solutions that help customers achieve better digital outcomes. Our partnership can help your organization eliminate tradeoffs between a cloud-native experience and best-in-class security. We have more than 80 co-engineered integrations, helping to improve and protect hybrid workers, cloud migrations and application modernization efforts.

We remain committed to our goals of outpacing cyberthreats, helping customers at every stage of their cloud journey, and creating a world where tomorrow is more secure than today.

Whether you’re just beginning your cloud journey or managing complex transformational projects, our jointly engineered, AI-driven solutions are designed to deliver seamless, scalable security. Explore the dynamic partnership between Palo Alto Networks and Google Cloud. Join us at Google Cloud Next '26 in Las Vegas from April 22-24 to discover how to secure your development lifecycle from code to cloud.

The post Scaling AI Agents with Confidence appeared first on Palo Alto Networks Blog.

  •  

Defender's Guide to the Frontier AI Impact on Cybersecurity

The release of the newest frontier AI models marks a turning point for cybersecurity. Palo Alto Networks has conducted early testing of the latest frontier AI models, including Anthropic’s Mythos model as part of Project Glasswing and OpenAI’s latest models as part of Trusted Access for Cyber program. The conclusion is clear: They are extraordinarily capable at finding vulnerabilities and generating corresponding exploits.

This generational improvement in coding ability directly translates to a significant advance in vulnerability discovery and exploit generation. These capabilities, however guardrailed, will not stay contained. Similar advances will appear across other major AI labs, Chinese models, and open source models. Attackers will find the seams in those guardrails. They will use advanced AI to discover zero-day vulnerabilities at scale, generate exploits in near real time, and develop autonomous attack agents unlike anything the industry has faced.

Within six months, advanced AI models with deep cybersecurity capabilities will become commonplace. Organizations that have not put appropriate safeguards in place will face an entirely new class of risk across their enterprise and critical infrastructure.

Frontier AI: A Quantum Leap in Code Fluency

As you have probably already seen, the latest unbounded models like Mythos represent roughly a 50% improvement in coding efficiency over Anthropic’s previous leading model. Palo Alto Networks has had early access to unbounded models and we’ve been able to leverage this vast improvement in coding to a quantum leap in scanning and offensive capability.

Hundreds of our best security engineers have been assessing these capabilities and developing best practices for using it effectively. The results revealed several core truths:

  • Vulnerability discovery at scale: Frontier AI is exceptionally effective at identifying vulnerabilities in code. In less than three weeks, it accomplished the equivalent of a full year’s worth of penetration testing effort.
  • Attack path determination: Perhaps more impressive than finding individual vulnerabilities, Frontier AI excels at vulnerability chaining, combining multiple lower-severity issues into critical-level exploit paths. For example, linking two medium-severity and one low-severity vulnerability into a single critical exploit.
  • Full-stack logic analysis: Frontier AI can analyze the full exposure surface of applications, including SaaS and public-facing platforms, identifying logic-based vulnerabilities that traditional tools miss.

Impacts on the Cyber Landscape

Attackers have been using LLMs for years, but based on our testing of frontier AI models, there are three key areas where they will have a significant impact on the cybersecurity landscape:

  1. The Vulnerability Deluge: Frontier AI models will dramatically accelerate the rate at which vulnerabilities are discovered, by defenders and attackers alike. This will be particularly acute in open source and critically, the flood of patches that follows will itself create risk. Every patch that is not applied immediately becomes a known, targetable vulnerability. Organizations will need to accelerate and automate their patching programs, rethink how they prioritize and apply patches, and ensure best-in-class protections are in place to mitigate vulnerability until they can be remediated.
  2. Rise of Inside-Out Attacks: Recent supply chain attacks on tools like LiteLLM and Trivy demonstrate a growing pattern where attacks land adversaries inside an organization’s infrastructure, bypassing multiple conventional attack steps and reducing the number of prevention opportunities available to defenders. The rapid deployment of AI infrastructure has made this problem more acute as the AI supply chain, including runtime environments, communication infrastructure, and model dependencies, is often insufficiently protected. While open source usage and patching practices must become significantly more robust, organizations will need structural containment of potential attacks through zero trust, identity modernization, outbound connection restrictions and lateral movement protections.
  3. Faster AI-Assisted Attack Cycles: I expect the most consequential shift with frontier AI models is the move from AI-assisted to AI-driven attacks. Attackers will build autonomous attack agents that dramatically compress attack cycle times. What once took days or weeks of skilled manual effort will soon be executed in minutes. This democratization of advanced attack capabilities means that defenders must match that speed with near-real-time detection and response, which is only possible with extensive AI and automation throughout security operations. Organizations whose Mean Time to Detection and Mean Time to Response are not measured in low single-digit minutes will be outpaced.

The Defenders Guide: Assessment, Protection, Platformization

The framework for defending against AI-driven threats is not completely new, but the standard for execution must be absolute. Organizations that are “mostly protected” are effectively unprotected. What follows is a phased approach – assessment, protection and platformization – that organizations should pursue in parallel to close gaps before attackers exploit them.

Assessment: Every organization should use the latest AI models to assess its entire code and application landscape and build a comprehensive asset and exposure inventory.

Key priorities:

  • Leverage AI models to identify vulnerabilities across your codebase, applications and infrastructure before attackers do.
  • Evaluate exposure with full context, including how vulnerabilities chain together to form critical exploit paths.
  • Audit your open source supply chain, including AI infrastructure, runtime environments and model dependencies.
  • Map your current sensor coverage. Detection, prevention and telemetry gaps represent critical blind spots.

Protect & Remediation: Remediating and reducing exposure is table-stakes. What in the past may have been difficult due to cross-organizational friction of finding and fixing at pace should now be accelerated with the c-suite attention of these new AI models. But this must go further and extend to comprehensive deployment of best-in-class attack prevention capabilities where the new standard is 100% coverage and optimization.

  • XDR everywhere, with emphasis on real-time ML-based detection and prevention of attacks; all hosts on prem and cloud included.
  • Agentic endpoint security to secure wide-scale adoption of vibe coding and AI security across the enterprise (e.g. Prisma AIRS and our recent acquisition of Koi is now a necessity for securing the agentic endpoint).
  • With an average of 85% of work now happening in the browser, secure enterprise browsers with real-time security become a must-have for attack prevention.
  • Zero trust and identity security are foundational to securing every user and every connection.

Real-Time Security Operations: With attack cycle times shrinking rapidly, the legacy approach to security operations simply doesn’t work. Disparate tools analyzing data in silos overlaid with manual processes must be replaced with AI and automation throughout. Cortex XSIAM, our AI-driven SOC platform, is what I consider to be the gold standard for how to take a next-generation approach to deliver MTTD and MTTR in single digit minutes.

  • Attack detections must be AI/ML driven to detect even frequently-changing and novel attacks at scale.
  • These AI detections must operate against a wide range of 1st party and 3rd party data sources – a best in class AI SOC must operate on ALL relevant data sources.
  • Automation both natively integrated and throughout the SOC lifecycle is necessary to achieve single digit MTTR; this automation will increasingly be agentic.
  • This must be delivered as a platform to remove the seams and gaps between point solutions.

We’re Here to Help

Achieving this level of resilience requires the right platforms and the right expertise.

To help you navigate this shift, we are introducing Unit 42 Frontier AI Defense. This new offering is designed to discover and remediate your current exposure before attackers do, strengthen controls that reduce exposure and contain impact and modernize operations so teams can detect and respond at machine speed.

This is the moment we’ve been preparing for. The threat has never been more sophisticated, but the path forward has never been clearer, and we’re here to partner with you on what comes next.

The post Defender's Guide to the Frontier AI Impact on Cybersecurity appeared first on Palo Alto Networks Blog.

  •  
❌