❌

Reading view

Using a VM to Contain an AI Agent

It won’t work:

My suspicion was that GPT 5.6-Cyber would succeed, but the frequency and manner of its success removed all doubt. We have to reassess sandboxing quality for capable AI agents, and in general the software stack with which they interact.

An off-the-shelf VM is not enough to contain a modern, cyber-capable AI agent. There is simply too much attack surface. Even innocuous features (like running with a display) add extra, exploitable attack surface.

  •  

Leaked Russian Cyber-Operations Training Materials

This is interesting:

The records describe a force-generation mechanism for several General Staff components, including the GRU, Main Operational Directorate, and 8th Directorate, which is associated with protected communications, cryptography, and information security.

[…]

The reporting also linked a 2024 Department No. 4 graduate, Aleksei Kondrashov, to Military Unit 74455, widely known as Sandworm.

That unit has been associated with destructive cyber activity against Ukraine and other targets, including the 2017 NotPetya attack.

The reports do not establish that every listed graduate participated in a named operation; assignments should therefore be described as reported unit placements, not proof of individual operational involvement.

The Bauman material reframes Russia’s cyber capability as an institutional system, not merely a collection of well-known threat groups.

It suggests that Moscow has formalized a recurring pathway from university recruitment to military service, where students receive supervised technical and ideological preparation before entering intelligence, cyber, and security roles.

For defenders, the leak reinforces the need to track Russian operations as a combined threat: espionage, destructive activity, military reconnaissance, technical surveillance, and influence campaigns may draw on related personnel pipelines and overlapping doctrine.

The exposure of Department No. 4 also provides researchers with a clearer lens for understanding how the GRU sustains cyber capacity beyond the familiar APT28 and Sandworm brand names.

  •  

Unit 42 Defends Organizations Against Next-Gen Frontier AI Risks with Anthropic’s Mythos 5

Frontier AI has compressed attack timelines from weeks to minutes.Β 

For defenders to gain the upper hand, they need to fight back at machine speed. That’s why Palo Alto Networks Unit 42 launched Frontier AI Defense, our comprehensive service that pairs advanced frontier AI models with leading threat intelligence to uncover hidden risks, validate real attack paths, and accelerate remediation before adversaries strike.Β 

Today, in a major milestone for organizations to defend themselves against AI-powered attacks, Unit 42 is expanding its Frontier AI Exposure Analysis capabilities with Anthropic’s Claude Mythos 5, giving organizations access to its advanced cyber capabilities.

Unlocking High-Fidelity Security with the Right Models, Harness and Expertise

While incredibly powerful, achieving high-fidelity results with frontier AI requires three things: the right models, an advanced harness, and the expertise to run it. With Unit 42 Frontier AI Exposure Analysis, guided and reviewed by Unit 42 experts, Claude Mythos 5 goes beyond identifying exposures. It tests whether those exposures can actually be exploited, connects weaknesses into attack paths, and helps prioritize the most urgently needed fixes. That answers the questions conventional scanners alone cannot: Is this exploitable? What can an attacker reach from here? And what should we fix first?

Further, our research shows models have different strengths. Unit 42’s multi-model approach applies the model best suited for the task, improving coverage and results while allowing us to continuously incorporate the strongest new capabilities as models advance.Β 

Human expertise remains at the center. Unit 42 combines these models with our offensive security experts, global Palo Alto Networks telemetry, and Unit 42 Threat Intelligence to turn model output into validated attack paths, prioritized remediation, and clear defensive action.

How It Works

Our Frontier AI Defense service uses the most advanced AI models to discover exposures, test whether they are exploitable, validate attack paths and help customers prioritize what to fix first, including:Β 

  • Leading Cyber Models: Advanced AI applied to discovery, testing, and validation.
  • Multi-Model Harness: Dynamic routing for stronger results, wider coverage, and managed costs.
  • Exposure Discovery: Identification of vulnerabilities, misconfigurations, exposed credentials, and unmanaged attack surfaces across apps and networks.
  • Advanced Adversary Simulation: Live exploitability testing and end-to-end attack path validation.
  • Custom Remediation Plans: Prioritized fixes delivered directly into existing IT, development, and security workflows.

Security teams do not need more findings. They need to know which weaknesses lead to a viable attack path. Attackers do not think about applications, identity, cloud, and infrastructure in isolation. They look for ways to move across them to reach their objective.

By putting frontier models to work with Unit 42 experts, we can identify and validate those attack paths before attackers do, and help organizations close them first.

Visit Palo Alto Networks Frontier AI Defense to learn more.

The post Unit 42 Defends Organizations Against Next-Gen Frontier AI Risks with Anthropic’s Mythos 5 appeared first on Palo Alto Networks Blog.

  •  

Prisma AIRS - Unified Data Protection for Claude

As AI adoption shifts from experimental tools to the business core, enterprises are deploying AI agents and assistants across every department. Developers are accelerating software delivery with Claude Code and business functions are collaborating in Claude.ai, Claude Cowork, and Claude Design, using Anthropic's Claude to fundamentally rewire how they operate and drive complex, autonomous workflows across their most critical tasks.

Broad AI adoption has forced enterprise security into a difficult paradox: secure the business without stalling innovation. Today, security teams must answer three critical questions: How do we prevent sensitive data from leaking into AI models? How do we intercept runtime attacks, like prompt injection, before they execute? And how do we enforce these guardrails consistently across every AI interaction, in real-time?

We are thrilled to announce that Palo Alto Networks Prisma AIRS API now directly integrates with Claude Enterprise via inference hooks.

Key Takeaways:

  • Synchronous Governance at the Speed of AI: Enforce critical runtime policy guardrails instantly before model inference occurs. By evaluating every Claude interaction in real-time, security teams can confidently enable high-speed AI innovation without introducing unacceptable risk or operational bottlenecks.
  • Extending Proven DLP to AI Workflows: Safeguard PII, intellectual property, and proprietary code across all Claude environments (Claude Code, Claude.ai, Claude Cowork) seamlessly. By directly leveraging your organization’s existing enterprise DLP policies, you get consistent, unified data protection without the friction of managing disparate rule sets.
  • Neutralizing AI-Specific Threats Proactively: Deploy enterprise AI with confidence by intercepting malicious activity before it executes. Proactively block sophisticated runtime threats, including prompt injections, jailbreaks, and toxic inputs, enabling your AI workflows to remain secure and your business operations uninterrupted.

How It Works

Setting up zero-trust governance for your Claude Enterprise environment takes just a few clicks:

  • Configure Claude Enterprise: In your Claude Enterprise organization settings, navigate to inference hooks, set the hook endpoint URL to your designated Prisma AIRS webhook URL, and include your custom Prisma AIRS API key in the custom headers (x-pan-token).
  • Activate Cryptographic Verification in Prisma AIRS: Claude generates a unique, one-time signing secret. You simply drop this signing secret into the Prisma AIRS UI.

Prisma AIRS securely stores the signing secret in an encrypted edge Key-Value Map (KVM) to cryptographically verify the authenticity of every incoming request before processing.

Unified Governance Across All Claude Surfaces

Before Claude reads a prompt, Claude POSTs the payload to Prisma AIRS, which evaluates the input against the configured security profile and returns a synchronous allow or deny verdict back to Claude.

Removing the Data Inspection Blind Spot

This Prisma AIRS integration natively leverages the Palo Alto Networks Enterprise DLP engine your organization already runs. Your current policies, custom definitions of "confidential," and compliance dashboards now instantly govern Claude. No redundant rule creation, and no new management overhead. Every prompt is classified in real-time, before anything reaches the model. Data Policy updates reach Claude the moment they reach everything else, and Claude events land in the same dashboards and audit reporting as every other channel. AI stops being the exception to your data protection strategy and becomes just another channel that is covered.

In practice, this helps prevent:

  • Accidental exposure of PII and regulated data: a Social Security number, card number, or patient record pasted into a prompt is detectedΒ  on the spot by advanced RegEx patterns and ML classifiers,Β  with Exact Data Matching (EDM) recognizing your actual customer records. Β  When policy requires, Prisma AIRS enforces a deny policy to help keep Claude usage stays aligned with GDPR, HIPAA, and PCI-DSS requirements.
  • Misuse of credentials in code: Developers working in Claude Code can't inadvertently submit hardcoded API keys, private tokens, or environment credentials into prompt context.
  • Disclosure of confidential business matters. Document classifiers flag prompts touching M&A, legal, or HR material β€” even when they contain no identifier a pattern could match.

AI Safety & Runtime Threat Protection

Simultaneously, Prisma AIRS inspects payloads for operational risks specific to large language models:

  • Prompt Injection & Jailbreak Attacks: Intercepts malicious attempts to manipulate model context or bypass system instructions.
  • Malicious Code & Malicious URLs: Prevents execution or processing of untrusted scripts and risky links embedded within prompts.
  • Toxic Content & Topic Guardrails: Enforces compliance with corporate policies and custom business topics.

If a prompt violates your security policy, Prisma AIRS issues a deny verdict. Claude immediately blocks the prompt, optionally presenting a user-facing explanation while returning a unique audit correlation code to your security telemetry dashboards.

Deploy Claude Without the Risk

The Prisma AIRS integration with Claude transforms security from a deployment bottleneck into a business enabler. You no longer have to choose between the operational control of Palo Alto Networks and the cognitive velocity of Claude.

Choose Your Path Forward:

Β 


Forward-Looking Statements

This blog contains forward-looking statements that involve risks, uncertainties and assumptions, including, without limitation, statements regarding the benefits, impact, or performance or potential benefits, impact or performance of our products and technologies or future products and technologies. These forward-looking statements are not guarantees of future performance, and there are a significant number of factors that could cause actual results to differ materially from statements made in this blog. We identify certain important risks and uncertainties that could affect our results and performance in our most recent Annual Report on Form 10-K, our most recent Quarterly Report on Form 10-Q, and our other filings with the U.S. Securities and Exchange Commission from time-to-time, each of which are available on our website at investors.paloaltonetworks.com and on the SEC's website at www.sec.gov.Β  All forward-looking statements in this blog are based on information available to us as of the date hereof, and we do not assume any obligation to update the forward-looking statements provided to reflect events that occur or circumstances that exist after the date on which they were made.

The post Prisma AIRS - Unified Data Protection for Claude appeared first on Palo Alto Networks Blog.

  •  
❌