Reading view

Building Securely From Day One: Palo Alto Networks Partners with the Zendesk Startup Program

A secure workspace for your team - so you can focus on building, not on what could go wrong.

Every customer support agent starts their day the same way: opening a browser, logging into Zendesk, and handling sensitive customer interactions. For most early-stage teams, that workspace is completely unprotected. The browser is where your people work, where your customer data lives, and where most security incidents begin - yet it's the layer that gets secured last, if at all.

AI is now part of everyday work. Your team is using agents and AI-powered workflows to move faster. But as your AI usage scales, so does your exposure: sensitive customer data, keys, source code, credentials, and proprietary information can flow into unvetted AI tools without anyone noticing - including you. And the browser is where all of it happens.

The startup ecosystem thrives when founders can focus on building. That's why Palo Alto Networks partners with the Zendesk Startup Program to provide early-stage teams access to the same browser security used by large enterprises - so startups are not forced to choose between preserving runway and protecting their customers' data.

A secure workspace, not just a secure browser.

Picture this: a support agent on your team gets a convincing phishing email that looks like a familiar notification. They click the link, land on a spoofed login page, and enter their credentials. Within hours, an attacker has access to your support system, and every customer conversation, ticket, and piece of sensitive data inside it. You find out when a customer calls to ask why your support team reached out, asking for payment details.

This isn't a hypothetical. It's how many small business breaches actually play out - and it's exactly what Prisma Browser for Business stops. We use Palo Alto Networks’s Precision AI-powered security to recognize the destination as malicious and block it before the page ever loads. No credentials entered. The agent sees a warning and moves on with their day.

That's the core idea behind Prisma Browser for Business (PBB): a secure workspace that sits at the intersection of work, AI use and threats - the browser. PBB wraps your entire browser session in enterprise-grade security, protecting every app, every tab, and every interaction, without requiring your team to change how they work.

For Zendesk users specifically, PBB can be configured with Zendesk as a dedicated workspace app - automatically applying the right security policies to everything Zendesk-related the moment your team opens it. Phishing attempts are blocked. Data leakage from support conversations is prevented. And your agents work inside a protected environment without any extra steps on their end.

The result: your team gets a seamless experience, and you get end-to-end visibility and control over how Zendesk is accessed across every device on your team.

The security gap startups can't afford to ignore.

When you're building a company, security can feel like something to tackle later - after the product ships, after the team grows, after the next funding round. But phishing, malware, and data leakage are not enterprise problems. They're startup problems too - and they can be significantly more damaging when you don't have a dedicated security team to catch them.

Three risks in particular are growing fast for early-stage teams:

  • AI tools without guardrails. Your team is almost certainly using AI tools - Claude, ChatGPT, Copilot, and others - to move faster. But without controls in place, sensitive customer data, internal documents, and proprietary information can flow into these tools without anyone noticing. PBB lets you set guardrails around how AI tools are used in the browser, so your team can stay productive without inadvertently exposing data they shouldn't.
  • Unvetted browser extensions. Extensions are one of the most overlooked attack surfaces in any organization. A single malicious or compromised extension can silently capture credentials, intercept data, or give an attacker persistent access to your environment. PBB gives you control over which extensions can be installed across your team's browsers, and alerts you when a suspicious or malicious extension is detected - before it can do damage.
  • Phishing and malware. The browser is the primary delivery mechanism for both. PBB blocks malicious sites and stops malware downloads in real time, protecting your team and your customer data at the point of risk.

PBB brings all of this together in a way that is simple to deploy and easy to manage - no security expertise required, no complex infrastructure to stand up.

Built for where startups actually are.

The Zendesk Startup Program is designed to support founders from their earliest stages through scale - including when security becomes a core business priority. Startups eligible for the program can access PBB as a practical way to evaluate enterprise-grade workspace security without a large upfront commitment. It's a way to build securely from the start, preserve runway, and scale your operations with confidence.

As a rapidly growing startup, you shouldn't have to choose between moving fast and staying secure.

  • The browser is your biggest security gap - and it's where startups get hit first. Phishing, credential theft, malicious extensions: these aren't enterprise problems. They're startup problems, and they land in the browser before you even have a security team to respond.
  • Security doesn't have to slow your team down. PBB applies enterprise-grade protection automatically - no behavior change required from agents, no complex infrastructure to stand up. Your team works exactly as they do today, just inside a protected environment.
  • Build securely from day one, without the day-one security budget. Leverage protection large enterprises rely on - so you don't have to choose between your runway and your customers' trust.

Ready to get started?

Startups participating in the Zendesk Startup Program are eligible to apply for PBB as part of their program benefits. Visit the Prisma Browser for Business dedicated landing page for Zendesk to take advantage of our partner’s promotion.

The post Building Securely From Day One: Palo Alto Networks Partners with the Zendesk Startup Program appeared first on Palo Alto Networks Blog.

  •  

Making the Most of the Cloud Marketplace Opportunity

How Partners Can Turn Marketplace Momentum into Customer Value.

Cloud marketplaces have become an increasingly important way for customers to buy technology. They can offer a familiar route to procurement, help organizations use their precommitted cloud budgets for eligible purchases and support goals such as consolidating IT spend and simplifying governance.

For partners, though, the opportunity goes well beyond the transaction. A recent report from Canalys (now Omdia) predicts that by 2027, more than half of all hyperscaler marketplace business will flow through partners. That points to an important shift in how technology is bought and sold – and creates an opportunity for partners to bring much more than purchasing convenience to the table.

Partners know their customers. They understand their environments, priorities and cloud investments. Many also bring the services and technical expertise needed to migrate, integrate, deploy, and manage technology after it’s purchased. When we combine that customer intimacy with the reach and capabilities of leading cloud service providers (CSPs) and the Palo Alto Networks platform, marketplaces can become a powerful vehicle for creating value across the ecosystem.

Meeting Customers Where They Want to Buy.

One of the most important principles in any marketplace strategy is also one of the simplest: Meet customers where they want to buy.

Organizations have established relationships with CSPs and, in many cases, significant cloud commitments. They may also have specific pricing arrangements, governance requirements and procurement processes tied to those relationships. A marketplace purchase can allow them to work within that existing framework rather than introduce an entirely separate buying motion.

The opportunity for partners is to understand those dynamics early. Does the customer have a cloud commitment? Is there a marketplace budget available? Are there CSP programs that could support the opportunity? Would purchasing through the marketplace make the process easier or provide a commercial advantage?

Palo Alto Networks works across the four major CSP ecosystems – AWS, Google Cloud, Microsoft Azure and Oracle Cloud Infrastructure (OCI) – giving partners the flexibility to follow customers to the cloud environments and marketplaces that make sense for them. Through Palo Alto Networks agreements with CSPs and benefits available through the reimagined NextWave Partner Program, marketplace transactions can also carry relevant pricing advantages for eligible partners and customers.

The goal is to understand how and where the customer wants to buy, then build the opportunity from there. 

Bringing More Value to the Transaction.

Of course, procurement is only the beginning. A marketplace can make technology easier to purchase, but partners can help customers turn that purchase into adoption and value.

Say a customer is looking to secure AI adoption, migrate infrastructure to the cloud, modernize on-premises infrastructure or transform its network. Addressing any of those priorities takes more than selecting technology. The customer may also need help assessing their IT environment, deploying and integrating new capabilities, and connecting their investment to a broader security strategy.

Partners are often closest to those needs because they already have trusted relationships with customers. Many are also managed security services providers (MSSPs) or have other services capabilities they can provide around a marketplace transaction.

That creates an opportunity to do more than facilitate a sale. Partners can combine Palo Alto Networks technology with their own services and expertise to develop a more complete offer for the customer. In turn, that can expand the value of the engagement, support technology adoption and create opportunities to develop and expand more strategic customer relationships.

Palo Alto Networks has long recognized this role for partners. The newly evolved NextWave Partner Program includes marketplace, resale, managed security services, support and delivery models, reflecting the different ways partners contribute throughout the customer lifecycle.

Turning a Customer Need into a Broader Platform Conversation.

Marketplace opportunities can also open the door to platform discussions. Customers rarely look for “platformization” from the outset. Most often, they just want to solve a specific problem. They may need to protect an AI initiative, secure a cloud migration, modernize infrastructure or improve connectivity for a cloud-first environment. But those priorities often intersect with other cybersecurity needs.

That gives partners an opportunity to start with the customer’s immediate need and identify how a more integrated, consolidated approach can deliver additional value. This is where complementary capabilities across the ecosystem can come together. CSPs provide the cloud platforms and services customers use. Palo Alto Networks extends security across those environments. And partners bring the technical expertise, services and customer context needed to connect those capabilities to specific needs.

Rather than viewing each technology purchase in isolation, partners can help customers consider how it contributes to a broader security strategy. And as we develop marketplace sales motions in additional areas, including identity, partners will have even more opportunities to connect capabilities around customers’ evolving needs.

Collaboration: The Key to Unlocking Marketplace Opportunities.

For all the attention cloud marketplaces receive as a digital route to market, much of the opportunity today is still deeply relationship-based. It starts with identifying the customer need, understanding that customer’s cloud strategy and commitments, bringing the right value proposition and then getting the right people around the table.

Success hinges on effective collaboration between the partner, the customer, the CSP, and our dedicated Palo Alto Networks account and alliance teams. Through early qualification and joint account planning, we can collectively pinpoint customer challenges, determine the best purchasing route, and define how each stakeholder can contribute to the solution.

This is also where marketplace strategy connects directly to the value exchange in cybersecurity I’ve discussed previously. Partners, vendors and other members of the ecosystem invest in different capabilities – technology, knowledge, skills, services and customer relationships – and create greater value when those investments are aligned around the customer. Public cloud marketplaces give us another way to put that model into action.

We Are Only Scratching the Surface of What’s Possible.

Cloud marketplaces are already changing how customers purchase technology; however, I believe we have only scratched the surface of what partners, CSPs and technology providers can accomplish together as these marketplaces evolve.

For partners, the next step is to understand the CSP initiatives and marketplace programs relevant to their customers, identify where their own services and expertise can add value, and be ready to act when the right opportunity emerges. 

Ready to Make the Most of Cloud Marketplaces? 

Reach out to your Palo Alto Networks team to schedule a sales enablement session, learn the relevant CSP sales motions, identify opportunities within your customer base and understand how to submit deal registrations through the NextWave Partner Program.

Key Takeaways:

  • Meet customers where they want to buy. Cloud marketplaces can align purchases with existing cloud relationships, commitments and procurement preferences.
  • Partners add value beyond the transaction. Customer knowledge, services and technical expertise can help turn purchases into adoption and lasting business value.
  • Collaboration expands the opportunity. Early coordination among partners, Palo Alto Networks and CSPs can uncover opportunities and support a broader platformization strategy.

The post Making the Most of the Cloud Marketplace Opportunity appeared first on Palo Alto Networks Blog.

  •  

Celebrating excellence: Palo Alto Networks announces the 2026 North America Partner of the Year Awards

At the 2026 Executive Partner Summit, Palo Alto Networks President BJ Jenkins made one thing clear: the AI era is the platform era — and above all, the AI era is the partner era. Palo Alto Networks tightly integrates its platforms to work seamlessly together and give customers full end-to-end protection. 

But securing the world’s largest organizations requires both advanced AI security technology and the combined power of our ecosystem, spanning resellers, service providers, cloud providers, distributors, and strategic advisors, to drive success at every stage. From initial architecture and deployment to 24/7 managed services, our partners ensure complex environments stay protected at scale.

As organizations navigate unprecedented technological transformation, partners are more critical than ever before in helping our customers modernize by adopting AI-powered platform security.

Anar Desai
North America Channel Sales at Palo Alto Networks

 

Together, Palo Alto Networks and our partner community are redefining what it means to secure the enterprise. As we continue to deepen our commitment to our partner ecosystem, we're proud to announce the winners of the Palo Alto Networks 2026 North America Partner of the Year Awards

This year’s award winners have demonstrated exceptional performance, deep expertise, and an unwavering commitment to our joint customers. Together, they reflect what is possible when Palo Alto Networks and our partners align around a shared goal: helping customers secure today while preparing for what’s next.

Congratulations to our:

  • North America Cloud Provider of the Year: Amazon Web Services
  • North America Distributor of the Year: TD SYNNEX
  • North America Managed Security Services Provider of the Year: Norlem
  • North America Service Provider of the Year: AT&T Business
  • North America Solution Provider of the Year: World Wide Technology 
  • North America System Integrator Partner of the Year: Deloitte
  • North America Frontier AI Partner of the Year: NTT DATA
  • North America Idira Advisory Partner of the Year: Accenture
  • North America Idira Partner of the Year: Optiv
  • North America Network Security Partner of the Year: Sycomp
  • North America Prisma AIRS Partner of the Year: Cognizant
  • North America SASE Partner of the Year: Trace3
  • North America Cortex Partner of the Year: Presidio
  • North America Software Firewall Partner of the Year: AHEAD
  • North America Commercial Select Partner of the Year: GuidePoint Security
  • North America Federal Growth Partner of the Year: Vibrint
  • North America Federal Partner of the Year: ThunderCat Technology
  • North America Growth Partner of the Year: Insight Enterprises
  • North America Small-Medium Business Partner of the Year: CDW
  • North America State, Local & Education Partner of the Year: NWN
  • Canada Partner of the Year: Kyndryl

Building a more secure future, together. 

Our awards honor a shared commitment to customers. Our partners bring their expertise, capabilities and perspective to the table, and that collaboration helps turn our technology into outcomes. 

For our partners, this award celebrates the shared effort that keeps our customers safer every single day. As trusted advisors, they bring the strategic guidance and domain experience clients rely on to navigate an ever-changing threat landscape. Together, we help customers turn complex security challenges into lasting confidence and trust. 

To our 2026 North America partner award winners: thank you for your relentless commitment to protecting our customers and setting the standard for excellence across our ecosystem. We look forward to deepening our alignment and driving the next wave of platform innovation together.

Join us in securing the frontier and protecting our digital world. Learn more about our Palo Alto Networks Partner Program and how to become a partner today.

The post Celebrating excellence: Palo Alto Networks announces the 2026 North America Partner of the Year Awards appeared first on Palo Alto Networks Blog.

  •  

Unit 42 Defends Organizations Against Next-Gen Frontier AI Risks with Anthropic’s Mythos 5

Frontier AI has compressed attack timelines from weeks to minutes. 

For defenders to gain the upper hand, they need to fight back at machine speed. That’s why Palo Alto Networks Unit 42 launched Frontier AI Defense, our comprehensive service that pairs advanced frontier AI models with leading threat intelligence to uncover hidden risks, validate real attack paths, and accelerate remediation before adversaries strike. 

Today, in a major milestone for organizations to defend themselves against AI-powered attacks, Unit 42 is expanding its Frontier AI Exposure Analysis capabilities with Anthropic’s Claude Mythos 5, giving organizations access to its advanced cyber capabilities.

Unlocking High-Fidelity Security with the Right Models, Harness and Expertise

While incredibly powerful, achieving high-fidelity results with frontier AI requires three things: the right models, an advanced harness, and the expertise to run it. With Unit 42 Frontier AI Exposure Analysis, guided and reviewed by Unit 42 experts, Claude Mythos 5 goes beyond identifying exposures. It tests whether those exposures can actually be exploited, connects weaknesses into attack paths, and helps prioritize the most urgently needed fixes. That answers the questions conventional scanners alone cannot: Is this exploitable? What can an attacker reach from here? And what should we fix first?

Further, our research shows models have different strengths. Unit 42’s multi-model approach applies the model best suited for the task, improving coverage and results while allowing us to continuously incorporate the strongest new capabilities as models advance. 

Human expertise remains at the center. Unit 42 combines these models with our offensive security experts, global Palo Alto Networks telemetry, and Unit 42 Threat Intelligence to turn model output into validated attack paths, prioritized remediation, and clear defensive action.

How It Works

Our Frontier AI Defense service uses the most advanced AI models to discover exposures, test whether they are exploitable, validate attack paths and help customers prioritize what to fix first, including: 

  • Leading Cyber Models: Advanced AI applied to discovery, testing, and validation.
  • Multi-Model Harness: Dynamic routing for stronger results, wider coverage, and managed costs.
  • Exposure Discovery: Identification of vulnerabilities, misconfigurations, exposed credentials, and unmanaged attack surfaces across apps and networks.
  • Advanced Adversary Simulation: Live exploitability testing and end-to-end attack path validation.
  • Custom Remediation Plans: Prioritized fixes delivered directly into existing IT, development, and security workflows.

Security teams do not need more findings. They need to know which weaknesses lead to a viable attack path. Attackers do not think about applications, identity, cloud, and infrastructure in isolation. They look for ways to move across them to reach their objective.

By putting frontier models to work with Unit 42 experts, we can identify and validate those attack paths before attackers do, and help organizations close them first.

Visit Palo Alto Networks Frontier AI Defense to learn more.

The post Unit 42 Defends Organizations Against Next-Gen Frontier AI Risks with Anthropic’s Mythos 5 appeared first on Palo Alto Networks Blog.

  •  

Putting OpenAI Cyber Models to Work for Defenders

Unit 42 is putting the latest frontier cyber models to work across customer environments to find, validate and help remediate the attack paths that matter most.

In May, we introduced Frontier AI Defense with a warning: the window to get ahead of AI-enabled attacks was shorter than most people realized. Since then, we have briefed more than 1,000 security teams around the world and introduced our Frontier AI Defense service to hundreds of customers.

Today, through our partnership with OpenAI, we are expanding Unit 42 Frontier AI Exposure Analysis to put advanced frontier cyber models directly to work in customer environments. Under Unit 42 direction, these models can find exposures, test whether they are exploitable, validate attack paths and help customers prioritize what to fix first.

Our early work shows why this approach matters: 36% of the exposures we identified map to no known CVE, often because they involve multiple gaps that have to be discovered, chained and tested together.

Bringing the Latest Frontier Cyber Capabilities to Defenders

Palo Alto Networks has been among a limited group of organizations with early access to advanced cyber capabilities from the leading frontier AI labs. Through our partnership with OpenAI, Unit 42 can now bring its latest advanced cyber capabilities, including GPT-5.6 Daybreak, to security testing and validation for our customers. Until now, GPT-5.6 Daybreak has not been available for commercial use.

Frontier models have helped inform the work of our experts. Now they can increasingly perform complex offensive security tasks directly, at machine speed and under Unit 42 direction. That allows us to go deeper than traditional vulnerability discovery by testing exploitability, reasoning across multiple weaknesses and determining how an attacker could use them to achieve an objective.

There is no single best model for every cyber task. Our research has shown that different models have different strengths and find vulnerabilities others miss. A multi-model harness routes work to the model best suited for the task, improving efficacy and coverage while managing the cost of frontier AI at scale. As stronger models emerge, we can incorporate them without rebuilding the offering around a single model or provider.

Unit 42 experts remain central to the process. We combine frontier models with our offensive security expertise, Palo Alto Networks telemetry and Unit 42 Threat Intelligence to validate findings, connect exposures into attack paths and understand what an attacker could ultimately achieve.

Built to Find What Attackers Can Exploit

The expanded service brings five capabilities together:

  • Leading cyber models: Apply the latest advanced cyber models to improve exposure discovery, testing and validation.
  • Multi-model harness: Use the right model for the right task to improve efficacy, expand coverage and optimize cost.
  • Exposure discovery: Find vulnerabilities, misconfigurations, leaked credentials, unmanaged attack surface and other posture gaps across applications and network assets.
  • Advanced adversary simulation: Actively test exploitability and validate end-to-end attack paths to understand how an attacker could compromise the environment.
  • Custom remediation plan: Prioritize the fixes that break the most important attack paths and feed those findings into existing IT, development and security workflows.

Most security teams already have more findings than they can act on. The harder problem is knowing which ones create a real path to compromise. Attackers look across applications, infrastructure, identity and cloud for weaknesses they can combine to achieve an objective. Frontier AI Exposure Analysis applies that same adversarial perspective, helping defenders understand which paths matter and what to fix first.

The Asymmetry Runs Both Ways Now

For the past several months, frontier AI has been a story about what is coming for defenders: vulnerability discovery at scale, exploit chaining that sees full-stack logic no scanner catches, and attack cycles compressed to seconds from initial access to exfiltration.

All of that is still true. Our answer has been to put everything we learn testing these frontier models into the hands of defenders. Today, that gets more direct: not just what frontier models have taught us, but the models themselves, working in your environment for your defenders before those same capabilities are working for the attacker.

The window is still closing. We intend to spend it building on the side of the defenders.

Visit Palo Alto Networks Frontier AI Defense to learn more.

The post Putting OpenAI Cyber Models to Work for Defenders appeared first on Palo Alto Networks Blog.

  •  

Palo Alto Networks Recognized as the Only Vendor to be Named a 4X Leader in SASE and SSE Gartner Magic Quadrant Reports

As organizations race to deploy agentic AI, legacy network security solutions are ill-equipped to keep up, forcing productivity tradeoffs while exposing coverage gaps. At the same time, Frontier AI is proving capable of discovering vulnerabilities and creating exploits in real-time. Navigating this shift requires more than incremental feature enhancements; it requires a bold, market-defining vision backed by relentless customer focused execution. 

Today, we’re proud to announce that Gartner® has once again recognized Palo Alto Networks as a Leader in the 2026 Magic Quadrant™ reports for both Security Service Edge and SASE Platforms. This marks the fourth consecutive year that Palo Alto Networks has been recognized, making us the only security vendor to be recognized as a Leader in both reports for four years in a row.

In this year’s Magic Quadrant for SSE, Palo Alto Networks was placed highest in ability to execute and furthest in completeness of vision for Prisma Access.

Every day we focus relentlessly on understanding the needs of our customers and channeling that back into products and services that create real value for them. Our product strategy centers on where our customers' environments and security needs are heading, not just where it sits today.

Vision Matters More than Ever in the AI Era

The AI landscape is changing daily - in this new reality, we strive to be the visionary leaders to serve our customers. GenAI and Agentic AI are exposing enterprises to novel categories of risks like prompt injection, over-privileged agents, and poisoned models. At the same time, Frontier AI is accelerating vulnerability discovery and attack speed resulting in attack timelines being compressed by over 95%.

Gartner projects that by the end of this year, 40% of enterprise applications will feature embedded agents, up from less than 5% today. And by 2028, 60% of brands will use agentic AI to facilitate streamlined one-to-one interactions. Operating a business in this new reality requires security architecture engineered to anticipate threats that haven't yet emerged. Success cannot be achieved by retrofitting legacy products with support for AI infrastructure. It demands a unified future-ready foundation that natively secures users, applications, sensitive data, and non-human identities across every touchpoint. The platform enterprises use today determines whether they'll be prepared for tomorrow's threats.

As the cybersecurity landscape undergoes its biggest shift in decades, to us, the Gartner recognition as a Leader on vision and execution across both reports means more than ever before. In our opinion, it not only validates Palo Alto Network’s ability to serve the world’s largest enterprises but also celebrates our strategic product capabilities as shaping the future of cybersecurity through industry leading innovation such as securing AI traffic flows and agents that simplify manageability of SASE operations.

Vision Backed by Relentless Execution

We believe being placed highest in execution and furthest in vision is only as valuable as the ability to execute on it, and Palo Alto Networks has a proven record of creating value for our customers. Our recent milestone of crossing the $1.6 billion ARR mark while growing 40% year over year for Prisma SASE reflects the trust customers have placed in us. Over 6,800 organizations, including over one third of the fortune 500, trust us because we consistently turn market-defining innovation into enterprise-grade reality. Our execution leadership is built on a strong foundation:

  • Security powered by Precision AI: Our platform delivers universal zero trust through distributed and flexible enforcement points. We inspect traffic as close to the user as possible to ensure that whether your teams are at the corporate HQ, a remote branch, a coffee shop or working from home, they receive the same protection at their precise point of interaction.
  • Unmatched performance and resilience: By leveraging global hyperscalers, we provide the massive scale and reach that modern organizations require. For specialized, high-performance and sensitive needs, SASE Private Location brings that same cloud-delivered resilience directly to private campuses.
  • Unified platform: With a truly unified policy engine, data platform and operations, we ensure that as enterprises adapt to the future, our architecture remains an accelerator for secure productivity rather than a bottleneck. We accelerate vendor consolidation for enterprise customers, replacing fragmented legacy point products with a single platform that slashes operational overhead and reduces total cost of ownership (TCO) by up to 50%.

Building for the Future 

As the rules of cybersecurity are rewritten in real time, leading the market requires more than following past trends, it requires setting the trajectory. Our aim is to continuously be at the forefront of defining the future of cybersecurity to power the agentic enterprise of tomorrow.

Protecting with AI

Palo Alto Networks continues to innovate to keep enterprises safe at the speed of AI. Our Precision AI security service blocks over 30B threats every single day defeating sophisticated and highly evasive tactics. When combined with our virtual patching and IP defense security services, organizations receive proactive defense that secures at the speed of Frontier AI with flexible enforcement that provides consistent protection everywhere. We are delivering comprehensive security across network, edge, and cloud infrastructure to stop hidden threats that are invisible to traditional networks security solutions. 

This AI-powered defense in depth strategy operates across the entire attack lifecycle to enable proactive protection that shifts enterprise security postures from reactive incident response to preemptive defense. 

Securing AI 

Safely enabling employee adoption of AI tools and agents requires special considerations to mitigate risks around data leaks, intellectual property exposure, and compliance. Prisma SASE and Prisma Access solve these challenges by discovering all AI usage and agentic actions, enforcing granular least privilege access for human and non-human identities, and preventing exposure of risky data to AI and agents. Through AI Access Security™, Prisma SASE provides unified data security across the AI lifecycle by integrating GenAI app visibility and control, real-time prompt analysis, shadow data discovery, and  protection on endpoint. Prisma Browser provides a secure AI workspace that safeguards both human and autonomous agent workflows across any LLM by defending against data leaks, prompt injections, and agent hijacking. 

To secure the rapid adoption of AI agents by enterprises, Prisma Access will natively integrate with Prisma AIRS AI Gateway to provide a unified LLM, MCP, and A2A gateway giving security teams a single pane of glass for AI observability, cost governance, and runtime inspection.

This innovative approach represents an evolution away from traditional device and user centric fabrics towards an agent-aware platform capable of securing AI for the enterprise of tomorrow, today. 

Operating with AI

We continue to invest in capabilities that make our platforms proactive, efficient and easier to use. Our new deployment agents enable customers to onboard their SSE or SASE environment more efficiently, reducing their time to value while increasing productivity. Once onboarded, autonomous AI agents within Strata Cloud Manager continuously evaluate network and security posture to proactively identify configuration drift, performance degradation, and security policy gaps. By uncovering potential disruptions before they impact users or expose the organization to risk we’ve created automated systems capable of finding issues and automatically remediating them, with human-in-the-loop oversight calibrated to the administrator's comfort level, from guided recommendations to full autonomy.

The practical outcome is a dramatic reduction in mean time to resolution (MTTR) and a measurable reduction in total cost of ownership (TCO) while significantly reducing administrative burdens and making Palo Alto Networks products easier to maintain and operate.

Learn More

Download your complimentary copies of the 2026 Gartner® Magic Quadrant™ reports to learn why Palo Alto Networks has been recognized as a Leader in both SASE and SSE for the fourth consecutive year.


 

Gartner, Magic Quadrant for Security Service Edge, 29 July 2026, John Watts Et Al.
Gartner, Magic Quadrant for SASE Platforms, 28 July 2026, By Jonathan Forest Et Al.
Gartner does not endorse any company, vendor, product or service depicted in its publications, and does not advise technology users to select only those vendors with the highest ratings or other designation. Gartner publications consist of the opinions of Gartner’s business and technology insights organization and should not be construed as statements of fact. Gartner disclaims all warranties, expressed or implied, with respect to this publication, including any warranties of merchantability or fitness for a particular purpose.
Gartner and Magic Quadrant are a trademark of Gartner, Inc., and/or its affiliates.
This graphic was published by Gartner, Inc. as part of a larger research document and should be evaluated in the context of the entire document. The Gartner document is available upon request from Palo Alto Networks.

The post Palo Alto Networks Recognized as the Only Vendor to be Named a 4X Leader in SASE and SSE Gartner Magic Quadrant Reports appeared first on Palo Alto Networks Blog.

  •  

Strengthening Security of AI Coding: Prisma AIRS API Integration with OpenAI Codex

Palo Alto Networks works closely with OpenAI across our product platform and Unit 42, leveraging advanced frontier model capabilities. Furthermore, we are a partner in the OpenAI Daybreak Cyber Partner Program, working with OpenAI to bring trusted, AI-powered cyber defense to more organizations. Today, we’re announcing native integration of Prisma AIRS Runtime API with OpenAI Codex. This milestone deepens our partnership and drives our shared mission forward: equipping defenders with the industry's most advanced tools.

AI coding assistants have transformed software development, accelerating shipping velocity and changing how engineers solve problems. But as integration of AI coding assistants deepens across development teams, security and compliance teams constantly struggle with enabling developer productivity while helping protect proprietary source code and credentials, and reducing the risk of runtime threats entering the codebase.

Streamlined Security in Minutes

We designed this integration to eliminate complex traffic steering and heavy client-side hooks. Securing your entire developer organization takes just a few clicks inside Codex Enterprise Management UI. Here is how you can enable it:

  1. Retrieve Credentials: Generate your API key and endpoint from the Prisma AIRS management console.
  2. Configure Codex: Paste the Prisma AIRS API key and endpoint directly into your Global Admin Console.
  3. Activate Org-Wide Scanning: Once saved, all user prompts across your entire organization in Codex are automatically routed through the Prisma AIRS Runtime API for real-time inspection.

What Prisma AIRS Brings to OpenAI Codex

By connecting the Codex in ChatGPT for Enterprise workspace to the Prisma AIRS Runtime API, security teams gain comprehensive, automated security controls across two critical vectors:

1. Enterprise Data Loss Prevention (DLP)

Developers frequently paste context – logs, config snippets, or functions – into AI coding assistants. Prisma AIRS scans inputs to help identify sensitive data before it is submitted.

  • Secrets & Credentials: Intercept API keys, hardcoded passwords, tokens, and private keys.
  • PII & Financial Data: Automatically detect personally identifiable information and regulated data patterns.
  • Proprietary Code & IP: Enforce custom pattern rules to help prevent sensitive internal code, architecture details, or trade secrets from being submitted.

2. Advanced Threat & Malicious Code Detection

AI prompts and contextual inputs can contain content that introduces security risks into development workflows. Prisma AIRS Runtime API inspects incoming developer inputs for:

  • Malicious Code Patterns: Detect obfuscated scripts, dangerous command executions, or known exploit patterns within developer prompts.
  • Malicious URLs & Links: Flag unverified, phishing, or malicious domain references before they influence generated code or enter internal repos.
  • Prompt Manipulation Attacks: Detect adversarial inputs that may attempt to bypass system controls or alter model behavior.

Built for DevSecOps Alignment

Security controls only work if developers actually use them. Because the inspection happens at the platform administrative level via API, developers continue working natively in Codex without changing their IDE setup or downloading local hooks. SecOps gain centralized visibility, consistent policy enforcement, and audit-ready logging capabilities across the entire engineering organization, while developers keep the speed and experience they expect.

Key Takeaways

  • Security as Invisible Infrastructure: Prisma AIRS integrates at the Codex administrative layer, applying security and DLP controls without requiring additional developer workflow changes. Developers can continue working in Codex while security teams maintain centralized policy controls.
  • Unified Governance for Frontier Models: Prisma AIRS acts as an inline security layer that scans AI traffic in real-time before prompts ever reach the destination model. This architecture can help organizations identify sensitive information moving outward while detecting prompt manipulation and potentially malicious content moving into development workflows. If Prisma AIRS API detects a threat, a block verdict is sent to OpenAI Codex, and the prompt does not reach the destination model or MCP server.
  • Organization-Wide Compliance: Deployment speed is a strategic advantage, not just an IT convenience. By configuring the Prisma AIRS API within the Global Admin Console, organizations can achieve org-wide governance without complex traffic steering. This can help development teams shift from unmanaged AI use toward more consistent, auditable security practices.

Getting Started

The Prisma AIRS integration helps organizations maintain consistent security controls while preserving the speed and productivity gains of Codex. Organizations can combine Palo Alto Networks’ security capabilities with OpenAI Codex to maintain centralized security and governance controls.

Choose your path forward:


Forward-Looking Statements

This blog contains forward-looking statements that involve risks, uncertainties and assumptions, including, without limitation, statements regarding the benefits, impact, or performance or potential benefits, impact or performance of our products and technologies or future products and technologies. These forward-looking statements are not guarantees of future performance, and there are a significant number of factors that could cause actual results to differ materially from statements made in this blog. We identify certain important risks and uncertainties that could affect our results and performance in our most recent Annual Report on Form 10-K, our most recent Quarterly Report on Form 10-Q, and our other filings with the U.S. Securities and Exchange Commission from time-to-time, each of which are available on our website at investors.paloaltonetworks.com and on the SEC's website at www.sec.gov. All forward-looking statements in this blog are based on information available to us as of the date hereof, and we do not assume any obligation to update the forward-looking statements provided to reflect events that occur or circumstances that exist after the date on which they were made.

The post Strengthening Security of AI Coding: Prisma AIRS API Integration with OpenAI Codex appeared first on Palo Alto Networks Blog.

  •  

Bridging the Gap: An Unprecedented Approach to Browser and Endpoint Security

The enterprise workforce now operates almost entirely within the web browser. In fact, employees do roughly 85% of their daily work inside it, turning the browser into the sole operating system of the modern organization that connects every application, data interaction, and identity. Yet, for modern Security Operations Center (SOC) teams, the browser remains a frustrating and dangerous "black box."

While traditional Extended Detection and Response (XDR) platforms excel at monitoring endpoint hosts and processes, they treat the browser as a single, opaque process. This creates a critical visibility gap. According to research from Unit 42, over 90% of breaches are preventable by solving for factors such as visibility gaps. Because modern AI tools are predominantly accessed directly through the browser, it is now critical that SOCs get visibility into what’s happening within the browser. Leaving browser activity unmonitored forces your SOC to fight today's AI-driven workflows in the dark.

The Operational Fallout of Browser Blind Spots

SOC analysts frequently see alerts for malicious endpoint processes but lack the granular telemetry to pinpoint the exact web tab, malicious script, or user interaction that initiated the threat. This leaves incident responders blind to sophisticated tactics like rogue extensions and cross-origin attack chains, making it nearly impossible to reconstruct the full attack narrative.

When a security team operates with a fragmented view, a dangerous domino effect triggers the moment an attack strikes.

  • The root cause is hidden as analysts frequently see alerts for malicious endpoint processes but do not have enough context. Lacking the necessary telemetry, the SOC is forced to take extreme containment measures and completely isolate the entire endpoint machine.
  • In some cases, SOCs use third party investigation tools which create problems with disconnected context and long investigation times.
  • What starts as a simple browser blind spot ultimately leads to an aggressive response that unnecessarily halts daily operations, disrupts user productivity, and floods the help desk with tickets.

Recent research on Palo Alto Networks customer incidents highlights the sheer scale of this problem, revealing massive monthly volume of Cortex threat detections stemming from siloed browser activity.

To eliminate this vulnerability, Palo Alto Networks is thrilled to announce the native integration of Prisma Browser and Cortex XDR.

Cortex XDR and Prisma Browser Better Together

By unifying deep browser-level telemetry with industry-leading endpoint detection, we are providing SOC teams with visibility into the user’s primary workspace, transforming the browser from an unmonitored process into an active security sensor.

Prisma Browser and Cortex XDR Better Together
Figure1: Prisma Browser and Cortex XDR Better Together

Organizations can achieve the full benefits of this integration without complex APIs or heavy deployment overhead. Prisma Browser events including DLP violations, browser tampering, and unauthorized configuration updates are automatically fed directly into your Cortex tenant, making it incredibly easy to adopt this joint offering.

Moreover, when Cortex XDR raises an issue, browser-based events are correlated with the user’s malicious activity on the same endpoint, to add browser-based context and adding visibility to the possible starting point of the attack when it is initiated from the browser context.

What Makes Our Approach Different?

Many legacy vendors attempt to solve this problem using brittle, easily bypassed browser extensions that provide basic, surface-level visibility especially providing poor visibility into unmanaged devices. Palo Alto Networks takes a fundamentally different approach. Cortex XDR now integrates natively with Prisma Browser under the hood. This ensures both layers "speak the same language," turning a massive blind spot into a rich engine of security telemetry and visibility into everything from each user action to specific activities into their device posture while executing a particular activity..

True workspace security requires a unified defense system that understands exactly how web activity can impact the host device. This first-of-its-kind integration achieves this through three fundamental pillars:

1. Find the Root Source of Attacks in Seconds

Integrating Prisma Browser with Cortex XDR connects comprehensive endpoint visibility with deep web context. By seamlessly linking endpoint process execution directly to browser events and host execution, Cortex XDR provides an unprecedented unified data foundation that allows SOC teams to analyze complete attack narratives rather than isolated, disjointed issues.

SOC Teams Get Insights Into Attack Scenarios with Prisma Browser Investigation Panel
Figure 2: SOC Teams Get Insights Into Attack Scenarios with Prisma Browser Investigation Panel

SOC Teams Get Insights Into Attack Scenarios with Prisma Browser Investigation Panel

Scenario: Unmasking Phishing and Malware Narratives

When a malicious payload executes on an endpoint, traditional tools show the threat on the host but leave analysts guessing the source of the attack. By correlating Prisma Browser events directly with Cortex XDR eliminates this guesswork. Analysts can effortlessly trace a malware alert back to the exact phishing URL, original download source, or hidden iFrame metadata, uncovering the precise forensic root cause in seconds while easily dismissing false positives.

Connecting the Dots: Instantly correlate browser activity with endpoint execution for faster response and zero false positives.
Figure 3: Connecting the Dots: Instantly correlate browser activity with endpoint execution for faster response and zero false positives.

2. Respond Without Disrupting Business

Traditional XDR tools often need to disconnect a device to mitigate a threat. While effective at stopping lateral movement, it severely disrupts user productivity and halts business operations. The integration of Prisma Browser and Cortex XDR introduces granular, precision control.

Prisma Browser detects a malicious file download, blocks the action and sends a detailed report to the SOC
Figure 4: Prisma Browser detects a malicious file download, blocks the action and sends a detailed report to the SOC

For example, when a rogue browser extension attempts to compromise a web session, traditional tools are forced to isolate the device, forcing the employee offline, and disrupting daily operations. The integration of Prisma Browser and Cortex XDR introduces surgical containment instead. The threat is instantly neutralized and terminated only at the browser layer while simultaneously alerting Cortex, allowing the employee's laptop to stay completely online and productive.

3. Detect Evasive Threats in Real Time

Prisma Browser uses a pioneering approach to analyze activity in real time, detecting threats as they happen. This ensures that even the most sophisticated, evasive threats, such as rogue extension behavior or malicious script execution, are identified and flagged in real-time within your Cortex dashboard.

Prisma Browser detects an evasive threat in real time and shows in the Cortex dashboard
Figure 5: Prisma Browser detects an evasive threat in real time and shows in the Cortex dashboard

4. Securing GenAI Use Cases:

As employees rush to adopt GenAI tools, critical risks emerge, such as an engineer copying proprietary source code and pasting it into an unapproved, public AI model to fix a bug. To traditional XDR, this looks like safe, standard web traffic. Prisma Browser solves this by monitoring user behavior inside the workspace to automatically detect and block data loss prevention (DLP) violations in real time. Because it connects natively to the Cortex tenant without complex APIs, shadow AI risks are instantly flagged in the SOC dashboard before they turn into major compliance issues.

Future-Proof Your Workspace Security

Security operations can no longer afford to leave the browser unmonitored. By bridging the gap between what happens in the browser and activities on the endpoint, the integration of Prisma Browser and Cortex XDR accelerates investigation times, exposes hidden threats, and allows your SOC to respond with unprecedented precision.

New to Prisma Browser? Talk to your account team

The post Bridging the Gap: An Unprecedented Approach to Browser and Endpoint Security appeared first on Palo Alto Networks Blog.

  •  

Prisma AIRS - Unified Data Protection for Claude

As AI adoption shifts from experimental tools to the business core, enterprises are deploying AI agents and assistants across every department. Developers are accelerating software delivery with Claude Code and business functions are collaborating in Claude.ai, Claude Cowork, and Claude Design, using Anthropic's Claude to fundamentally rewire how they operate and drive complex, autonomous workflows across their most critical tasks.

Broad AI adoption has forced enterprise security into a difficult paradox: secure the business without stalling innovation. Today, security teams must answer three critical questions: How do we prevent sensitive data from leaking into AI models? How do we intercept runtime attacks, like prompt injection, before they execute? And how do we enforce these guardrails consistently across every AI interaction, in real-time?

We are thrilled to announce that Palo Alto Networks Prisma AIRS API now directly integrates with Claude Enterprise via inference hooks.

Key Takeaways:

  • Synchronous Governance at the Speed of AI: Enforce critical runtime policy guardrails instantly before model inference occurs. By evaluating every Claude interaction in real-time, security teams can confidently enable high-speed AI innovation without introducing unacceptable risk or operational bottlenecks.
  • Extending Proven DLP to AI Workflows: Safeguard PII, intellectual property, and proprietary code across all Claude environments (Claude Code, Claude.ai, Claude Cowork) seamlessly. By directly leveraging your organization’s existing enterprise DLP policies, you get consistent, unified data protection without the friction of managing disparate rule sets.
  • Neutralizing AI-Specific Threats Proactively: Deploy enterprise AI with confidence by intercepting malicious activity before it executes. Proactively block sophisticated runtime threats, including prompt injections, jailbreaks, and toxic inputs, enabling your AI workflows to remain secure and your business operations uninterrupted.

How It Works

Setting up zero-trust governance for your Claude Enterprise environment takes just a few clicks:

  • Configure Claude Enterprise: In your Claude Enterprise organization settings, navigate to inference hooks, set the hook endpoint URL to your designated Prisma AIRS webhook URL, and include your custom Prisma AIRS API key in the custom headers (x-pan-token).
  • Activate Cryptographic Verification in Prisma AIRS: Claude generates a unique, one-time signing secret. You simply drop this signing secret into the Prisma AIRS UI.

Prisma AIRS securely stores the signing secret in an encrypted edge Key-Value Map (KVM) to cryptographically verify the authenticity of every incoming request before processing.

Unified Governance Across All Claude Surfaces

Before Claude reads a prompt, Claude POSTs the payload to Prisma AIRS, which evaluates the input against the configured security profile and returns a synchronous allow or deny verdict back to Claude.

Removing the Data Inspection Blind Spot

This Prisma AIRS integration natively leverages the Palo Alto Networks Enterprise DLP engine your organization already runs. Your current policies, custom definitions of "confidential," and compliance dashboards now instantly govern Claude. No redundant rule creation, and no new management overhead. Every prompt is classified in real-time, before anything reaches the model. Data Policy updates reach Claude the moment they reach everything else, and Claude events land in the same dashboards and audit reporting as every other channel. AI stops being the exception to your data protection strategy and becomes just another channel that is covered.

In practice, this helps prevent:

  • Accidental exposure of PII and regulated data: a Social Security number, card number, or patient record pasted into a prompt is detected  on the spot by advanced RegEx patterns and ML classifiers,  with Exact Data Matching (EDM) recognizing your actual customer records.   When policy requires, Prisma AIRS enforces a deny policy to help keep Claude usage stays aligned with GDPR, HIPAA, and PCI-DSS requirements.
  • Misuse of credentials in code: Developers working in Claude Code can't inadvertently submit hardcoded API keys, private tokens, or environment credentials into prompt context.
  • Disclosure of confidential business matters. Document classifiers flag prompts touching M&A, legal, or HR material — even when they contain no identifier a pattern could match.

AI Safety & Runtime Threat Protection

Simultaneously, Prisma AIRS inspects payloads for operational risks specific to large language models:

  • Prompt Injection & Jailbreak Attacks: Intercepts malicious attempts to manipulate model context or bypass system instructions.
  • Malicious Code & Malicious URLs: Prevents execution or processing of untrusted scripts and risky links embedded within prompts.
  • Toxic Content & Topic Guardrails: Enforces compliance with corporate policies and custom business topics.

If a prompt violates your security policy, Prisma AIRS issues a deny verdict. Claude immediately blocks the prompt, optionally presenting a user-facing explanation while returning a unique audit correlation code to your security telemetry dashboards.

Deploy Claude Without the Risk

The Prisma AIRS integration with Claude transforms security from a deployment bottleneck into a business enabler. You no longer have to choose between the operational control of Palo Alto Networks and the cognitive velocity of Claude.

Choose Your Path Forward:

 


Forward-Looking Statements

This blog contains forward-looking statements that involve risks, uncertainties and assumptions, including, without limitation, statements regarding the benefits, impact, or performance or potential benefits, impact or performance of our products and technologies or future products and technologies. These forward-looking statements are not guarantees of future performance, and there are a significant number of factors that could cause actual results to differ materially from statements made in this blog. We identify certain important risks and uncertainties that could affect our results and performance in our most recent Annual Report on Form 10-K, our most recent Quarterly Report on Form 10-Q, and our other filings with the U.S. Securities and Exchange Commission from time-to-time, each of which are available on our website at investors.paloaltonetworks.com and on the SEC's website at www.sec.gov.  All forward-looking statements in this blog are based on information available to us as of the date hereof, and we do not assume any obligation to update the forward-looking statements provided to reflect events that occur or circumstances that exist after the date on which they were made.

The post Prisma AIRS - Unified Data Protection for Claude appeared first on Palo Alto Networks Blog.

  •  

Redefining Network Security for the Frontier AI Era

Modern enterprise security is at a pivotal moment where CIOs and CISOs have a clear opportunity to build a cybersecurity architecture for both today’s environment, and for the future. Doing so requires redefining enterprise resilience across three critical dimensions. 

First, Frontier AI driven threat velocity and novelty. Frontier AI models have automated the entire attack lifecycle. Adversaries aren’t just compressing exploit windows to near-zero timelines, they are also generating novel, highly evasive threats at machine speed, bypassing traditional signatures and often before patches are generated. 

Second, surging network traffic is overwhelming traditional defenses. Driven by AI workloads, inter-datacenter traffic will nearly triple1 over the next decade dramatically expanding the volume of data teams must inspect and secure. 

Finally, major shifts are forcing a “cryptographic reset.” Shrinking certificate lifecycles, internet-scale distrust events, and quantum computers powerful enough to crack public key cryptography are combining to shake the foundation of all digital communications. 

Meeting these challenges requires more than incremental fixes. Today, we are proud to introduce PAN-OS 12.2 Ceres, a landmark release representing a major leap forward in network security. 

Ceres brings to market 55+ innovations, including three flagship, core capabilities, designed to shift the balance of power back to defenders.

Introducing Frontier Virtual Patching: Preemptive Defense Against Frontier AI Exploits

Today, Palo Alto Networks is giving defenders the ultimate advantage with the launch of Frontier Virtual Patching. By harnessing Frontier AI to discover unknown vulnerabilities, and deploying protections in hours, we are collapsing the exposure window from the industry-average 55 days2 it takes to deploy a traditional patch down into a near-zero window of exposure. This isn’t just about faster patching; it’s about eliminating the attacker’s chance by neutralizing exploits before they ever reach your network.

Frontier AI models - Collapse the patch window

The new reality: Exploitation far outpaces patch deployment

We’ve built this capability as a collaborative, force-multiplying ecosystem, with our industry partnerships across the enterprise software and OT vendor landscape to accelerate vulnerability disclosure, remediation and customer protection. This includes our collaboration with Project Lightwell, which combines our rapid network-level protection with software remediation to help organizations reduce exposure to emerging threats. We’re also partnering with vulnerability clearinghouses, software maintainers, and industry initiatives to continuously expand a real-time pool of protected vulnerabilities.

This approach builds on recent Unit 42 research, where the autonomous AI system NOVA identified more than 14,000 previously unknown vulnerabilities in just two months – a clear signal that defenders must pair AI-powered discovery with equally fast, coordinated protection. We have built an all-new detection engine, “vaulted protection," that enables us to deliver these rapid protections in a safe and responsible manner. When one participant identifies a threat, the entire ecosystem is protected instantly. Individual discovery becomes global protection. 

This is especially valuable for operational technology (OT), critical infrastructure, healthcare, and IoT: environments where systems can’t be taken offline to patch, where patch cycles can stretch for months, and where a single unpatched device can expose an entire network. Frontier Virtual Patching closes that gap in the network, blocking the exploit without applying a patch, rebooting a system, or causing any downtime to critical operations.

Bad actors will lean into Frontier AI to reduce the attack lifecycle from months to minutes. To keep pace, organizations require security partners to match that machine speed. To this end, Palo Alto Networks is raising the bar with its Frontier Virtual Patching, moving beyond compensating controls. By safely and efficiently discovering undisclosed vulnerabilities and deploying protection long before traditional patches can be rolled out, Palo Alto Networks deep security capabilities are flipping network defense from a reactive to proactive operational model.


Will Townsend
Chief Analyst, LoneStar Advisory & Research

And for existing Palo Alto Networks network security customers, getting started is effortless.  Frontier Virtual Patching is available as a PAN-OS software upgrade with persistent, automatic content updates, so protections keep arriving as new threats emerge, with no new hardware and no manual intervention. 

Clearly, Network Security is evolving quickly. Frontier Virtual Patching is part of a huge set of innovations that the team at Palo Alto Networks is delivering in PAN-OS Ceres 12.2 to enable you to stay protected.

Advanced IP Defense: Blocking attacker infrastructure before they can strike

Modern threat actors continuously work to hide their attacks and evade existing controls. Adversaries are increasingly evading traditional perimeter detection of their command-and-control traffic by leveraging direct-to-IP connection techniques that bypass DNS and URL inspection entirely. Attackers are also weaponizing massive proxy networks and hundreds of thousands of residential IP addresses to conduct stealthy, large-scale scanning, brute-force attacks, and exploitation that bypass traditional defenses such as IP reputation and blocklists.

To counter this, Palo Alto Networks is introducing a new preventative solution, Advanced IP Defense, with three powerful new capabilities:

  • Real-time IP-layer intelligence. We leverage global telemetry from over 70,000 customers to track and block attacker infrastructure inline across the entire attack lifecycle. Our researchers track these threats 24/7, so your team doesn’t have to.
  • Zero-Trust IP enforcement. We don’t just look at an IP’s past reputation. We verify the intent of the connection itself. By validating that every network connection maps to a legitimate DNS resolution, we provide a critical guardrail against attackers attempting to evade detection.
  • Powerful IP-layer context. We continuously monitor every connection across more than 40 distinct security attributes, letting you proactively shrink your attack surface and block high-risk traffic from the internet’s “bad neighborhoods” with confidence.

The transition to the Frontier AI era isn't a distant future. It’s happening right now. The organizations that thrive won't be those trying to run old, reactive playbooks faster; they have to scale their defenses to match a whole new velocity of risk. When threats occur at machine speed, relying on human-scale operations is no longer an option. That is why AI and automation are becoming essential tools to meet these challenges head-on.

Varinder Singh
CIO, NXP Semiconductors

Network Security Agents: Making admins superhuman

When threats execute in minutes, human-only operations become a bottleneck. To reduce fatigue and accelerate response, we’re launching an elite suite of AI agents for every major role a network administrator performs.

These six specialized AI-powered Network Security Agents, available through Strata Cloud Manager, are trained on your enterprise context and operational workflows. From onboarding and configuration to threat assessment and troubleshooting, they automate the hundreds of routine, repetitive tasks that consume an admin’s day. And you stay in control: for each workflow, you choose the level of oversight that matches your risk tolerance — human-in-the-loop, human-on-the-loop, or human-out-of-the-loop.

Expanding platform protection across every edge

Securing the modern enterprise means extending these AI-powered capabilities across every surface, from data center cores to remote industrial sites, and from custom AI applications to the web browser.

Today we’re introducing PAN-OS Ceres 12.2, which, in addition to the innovations above, expands our platform across five more areas:

  • Quantum-safe & next-generation trust security. Automates digital certificate lifecycle management and accelerates post-quantum cryptographic readiness, including a cryptographic inventory spanning network security, endpoint, SIEM, and vulnerability management integrations for a complete view of enterprise readiness.
  • 5th-generation ML-optimized hardware. New high-performance PA-Series firewalls equipped with 400G interfaces, and 300 Gbps of threat inspection, and active clustering, these platforms eliminate capacity limits for AI-era data centers. These firewalls also  scale to 1.4Tbps of throughput while delivering 5-microsecond latency ensuring peak performance. 
  • Modernized OT & critical infrastructure defense. Purpose-built PA-50R ruggedized 5G firewalls that extend real-time, AI-powered threat prevention to remote, extreme-environment OT networks and critical infrastructure.
  • AI and agent security. Prisma AIRS is now delivered as a scalable, cloud-native service explicitly engineered to secure AI models, applications, and autonomous agent workflows. The same platform on which we built CloudNGFW has now been extended to provide security for AI with the addition of Prisma AIRS.
  • Browser-to-firewall integration. Imagine the browser as a secure fast-lane that doesn’t just protect users, it empowers them. By integrating Prisma Browser with our NGFWs, we’ve eliminated the need to decrypt on the endpoint while delivering full Layer 7 protection. This is proactive security that neutralizes threats before they can even touch your network. For security admins, policy is fully unified from device to network, delivering a streamlined, automated experience.

Pan-OS 12.2 Ceres

The path forward

We are investing heavily in the innovations you need to defeat today’s threats while future-proofing your enterprise for tomorrow.

The transition to the Frontier AI era demands a bold strategy. The winners will be the organizations that adopt a prevention-first architecture capable of stopping threats long before weaponization occurs. With PAN-OS Ceres 12.2, Palo Alto Networks is giving defenders the speed, scale, and platform foundation to turn the tables on modern adversaries.

 

Forward-Looking Statements 

This blog contains forward-looking statements that involve risks, uncertainties and assumptions, including, without limitation, statements regarding the benefits, impact, or performance or potential benefits, impact or performance of our products and technologies or future products and technologies. Any unreleased services or features (and any services or features not generally available to customers) referenced in this or other press releases or public statements are not currently available (or are not yet generally available to customers) and may not be delivered when expected or at all. Customers who purchase Palo Alto Networks applications should make their purchase decisions based on services and features currently generally available.

 

​​Sources
1 https://www.nokia.com/artificial-intelligence/explainer-network-traffic-is-fundamentally-changing-in-the-ai-supercycle/
2 According to the Verizon 2024 Data Breach Investigations Report

 

The future of Frontier AI network security

Join Palo Alto Networks virtual InterSECt 2026 event on Aug. 19–20 
to see PAN-OS 12.2 Ceres and learn how to preempt AI-driven network attacks.
Secure your spot

Secure your future at the edge of the frontier

Explore our leading Frontier AI Ecosystem and essential resources
Learn more

The Future of Vulnerability Discovery Is Here

4,000 projects. 14,000 previously unknown vulnerabilities. Two months. Read Unit 42's latest research on why defenders must prepare for a dramatically faster threat landscape.
Read the report

The post Redefining Network Security for the Frontier AI Era appeared first on Palo Alto Networks Blog.

  •  
❌