<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
    xmlns:content="http://purl.org/rss/1.0/modules/content/"
    xmlns:wfw="http://wellformedweb.org/CommentAPI/"
    xmlns:dc="http://purl.org/dc/elements/1.1/"
    xmlns:dcterms="http://purl.org/dc/terms/"
    xmlns:atom="http://www.w3.org/2005/Atom"
    xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
    xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
        >

<channel>
    <title>Palo Alto Networks Blog</title>
    <atom:link href="https://www.paloaltonetworks.com/blog/feed/" rel="self" type="application/rss+xml" />
    <link>https://www.paloaltonetworks.com/blog/</link>
    <description>Palo Alto Networks Blog</description>
    <lastBuildDate>Thu, 04 Jun 2026 18:23:19 +0000</lastBuildDate>
    <language>en-US</language>
    <sy:updatePeriod>
	hourly    </sy:updatePeriod>
    <sy:updateFrequency>
	1    </sy:updateFrequency>
    <generator>https://wordpress.org/?v=6.9.4</generator>
    <item>
	<title>How AI and Evasion Demand a Radical Shift in Network Threat Prevention</title>
	<link>https://www.paloaltonetworks.com/blog/2026/06/ai-and-evasion-demand-radical-shift-in-threat-prevention/</link>
	    		<comments>https://www.paloaltonetworks.com/blog/2026/06/ai-and-evasion-demand-radical-shift-in-threat-prevention/#respond</comments>
	    
	<dc:creator><![CDATA[Anand Oswal and Srinivas Avasarala]]></dc:creator>
	<pubDate>Thu, 04 Jun 2026 15:55:08 +0000</pubDate>
		<dcterms:extent>5</dcterms:extent>
	<enclosure url="https://www.paloaltonetworks.com/blog/wp-content/uploads/2026/06/AdobeStock_624078692-2-scaled.jpeg" type="image/jpeg"  length="326896"/>
	    		<category><![CDATA[CIO/CISO]]></category>
		<category><![CDATA[Network Perimeter]]></category>
		<category><![CDATA[Reports]]></category>
		<category><![CDATA[Secure the Enterprise]]></category>
		<category><![CDATA[Threat Brief]]></category>
		<category><![CDATA[Threat Prevention]]></category>
		<category><![CDATA[Threat Research]]></category>
		<category><![CDATA[Unit 42]]></category>
	<guid isPermaLink="false">https://www.paloaltonetworks.com/blog/?p=359937</guid>

	    		<description><![CDATA[<p>The Future of Threat Defense Resides at the IP Layer For years, network security operated on a relatively predictable premise: inspect traffic, identify malicious content, and block it. Because deep content inspection &#8230;</p>
<p>The post <a href="https://www.paloaltonetworks.com/blog/2026/06/ai-and-evasion-demand-radical-shift-in-threat-prevention/">How AI and Evasion Demand a Radical Shift in Network Threat Prevention</a> appeared first on <a href="https://www.paloaltonetworks.com/blog">Palo Alto Networks Blog</a>.</p>
]]></description>
						<content:encoded><![CDATA[<h1><b>The Future of Threat Defense Resides at the IP Layer</b></h1>
<p><span style="font-weight: 400;">For years, network security operated on a relatively predictable premise: inspect traffic, identify malicious content, and block it. Because deep content inspection created a seemingly robust defense in depth, relatively static legacy approaches—like reliance on threat intelligence feeds—were allowed to simply persist in the background.</span></p>
<p><span style="font-weight: 400;">The weaponization of agentic AI and highly evasive techniques has fundamentally shattered that model. Attackers are no longer just iterating on old threats. They are launching attacks at staggering velocity, completely outpacing threat feeds, and employing evasion tactics that actively starve legacy prevention solutions of the content they rely on to inspect.</span></p>
<p><span style="font-weight: 400;">Our new research report from Unit 42, </span><a href="/resources/research/attackers-are-evading-threat-prevention-at-internet-edge"><i><span style="font-weight: 400;">Attackers Are Evading Threat Prevention at the Internet Edge</span></i></a><span style="font-weight: 400;">, reveals how adversaries are actively exploiting the contextual vacuum at the IP layer to bypass standard security controls. For security leaders, understanding this shift is no longer optional. As the nature of the threat fundamentally changes, our strategic approach to network security must definitively change with it.</span></p>
<h1><b>The AI-Accelerated, Evasive Attack Lifecycle</b></h1>
<p><span style="font-weight: 400;">To understand why legacy defenses are failing, we must look at how adversaries are accelerating and obfuscating every stage of the attack lifecycle. As these threats progress, the commonly used network indicators we have long relied upon are vanishing, collapsing traditional defenses and leaving defenders with little to act on.</span></p>
<p><span style="font-weight: 400;">Powered by frontier AI, adversaries now automate reconnaissance and exploitation at huge scale and speed, while using anonymizers to mask their intent. Once an intrusion is launched, orchestration shifts to highly evasive command and control (C2). Attackers hide communications using advanced encryption and AI-built malware-less techniques. They’re also bypassing traditional web and DNS inspection entirely by routing traffic directly to IP addresses—a tactic Unit 42 found in 23% of modern malware</span></p>
<p><span style="font-weight: 400;">Ultimately, the takeaway is clear: network threat prevention can no longer rely solely on detecting malicious payloads. As AI-driven attacks continue to minimize their footprint, security strategies must augment content inspection with real-time IP layer monitoring to left-shift threat detection and counter these rapid, machine-speed threats at the network foundation.</span></p>
<h1><b>Existing Approaches Aren’t Working</b></h1>
<p><span style="font-weight: 400;">Where content-based detection falls short, many security vendors and organizations still rely on IP threat intelligence feeds to pick up the slack in an attempt to filter out malicious connections on the network layer. However, after years of operating under this model, the results are in—the traditional feed is showing its age.</span></p>
<p><span style="font-weight: 400;">Attackers have long relied on proxies, anonymizers, residential routers and public cloud providers as a tactic to evade detection. However, agentic AI morphs this process, enabling rapid infrastructure rotation and stealth at an unprecedented scale. As this autonomous evasion accelerates, experienced network defenders continue to run into the well-known limitations of classic IP blocklists:</span></p>
<ul>
<li style="font-weight: 400;" aria-level="1"><b>Too slow to keep pace: </b><span style="font-weight: 400;">Unit 42 found an average 20-day lag time before new threats hit popular feeds. Because agentic AI enables adversaries to autonomously rotate proxy IPs in hours, these lists are obsolete at the moment of delivery.</span></li>
<li style="font-weight: 400;" aria-level="1"><b>Fundamentally incomplete: </b><span style="font-weight: 400;">IP feeds are unable to see a massive portion of the modern attack surface. Unit 42 research indicates that 52% of malicious IPs used for direct-to-IP connections are completely absent from these lists.</span></li>
<li style="font-weight: 400;" aria-level="1"><b>Unactionable on shared infrastructure: </b><span style="font-weight: 400;">Even known threats are often impossible to block. The Unit 42 team reports that 37% of direct-to-IP traffic uses reputable CDNs and cloud providers. IP feeds cannot distinguish malicious connections from legitimate ones, making blocking too risky for business continuity.</span></li>
<li style="font-weight: 400;" aria-level="1"><b>A management nightmare: </b><span style="font-weight: 400;">Among the security teams that Unit 42 polled, 30% indicate resource-intensive vetting and false-positive triage as their top pain point. To avoid breaking legitimate traffic, feeds are frequently relegated to an alert-only mode, defeating the entire purpose of prevention</span><b>.</b></li>
</ul>
<p><span style="font-weight: 400;">If modern and agentic AI-enabled attacks can outrun traditional network payload-based detections, we need a new weapon in the network defender’s arsenal. We can no longer depend on yesterday’s IP feeds to secure such an extremely agile threat environment.</span></p>
<h1><b>The Blueprint for Modernizing the Internet Edge</b></h1>
<p><span style="font-weight: 400;">To outpace the impact of agentic AI and advanced evasion on network threat prevention, security leaders must redefine their defense strategy and shift-left to track the attacker infrastructure itself—monitoring the exact IP layer locations where adversaries build and control their campaigns. Deep content inspection remains essential, but securing the modern edge requires establishing the context and intent of a connection before a session is established.</span></p>
<p><span style="font-weight: 400;">To achieve this goal, organizations must move beyond the limitations of static defense and adopt a modern security blueprint:</span></p>
<ul>
<li style="font-weight: 400;" aria-level="1"><b>Proactive protection against attacker infrastructure:</b><span style="font-weight: 400;"> While high-quality threat feeds remain essential for SOC investigations and incident response, relying on them for frontline, real-time prevention creates major blind spots. Instead, security teams must use real-world, global telemetry to proactively identify and block connections to attacker-controlled hosts before requesting a URL or file.</span></li>
<li style="font-weight: 400;" aria-level="1"><b>Zero trust principles applied to the network layer:</b><span style="font-weight: 400;"> An IP address without a negative reputation does not equal a safe connection. Continuous verification requires extending zero trust down to the network foundation. It validates the real-time behavior and intent of every single session to ensure attackers cannot hide in the contextual vacuum of the IP layer.  </span></li>
<li style="font-weight: 400;" aria-level="1"><b>Reducing the attack surface with rich contextual attributes:</b><span style="font-weight: 400;"> Traditional IP blocking is like a blunt instrument that creates unacceptable false positives and alert fatigue. To modernize the edge, security teams need deep, attribute-based visibility across the entire Internet address space to reduce noise and replace legacy IP feeds entirely.  </span></li>
</ul>
<p><span style="font-weight: 400;">By moving away from point-in-time assumptions and embracing real-time, inline protection, security leaders can reclaim the advantage at the network foundation.</span></p>
<p><span style="font-weight: 400;">To see how these evasion tactics operate in the wild, read the latest Unit 42 report, </span><a href="/resources/research/attackers-are-evading-threat-prevention-at-internet-edge"><i><span style="font-weight: 400;">Attackers Are Evading Threat Prevention at the Internet Edge</span></i></a><span style="font-weight: 400;">. You’ll find this report valuable in understanding the systemic gaps in legacy risk models and learning why continuous verification must be our new mandate.</span></p>
<p>The post <a href="https://www.paloaltonetworks.com/blog/2026/06/ai-and-evasion-demand-radical-shift-in-threat-prevention/">How AI and Evasion Demand a Radical Shift in Network Threat Prevention</a> appeared first on <a href="https://www.paloaltonetworks.com/blog">Palo Alto Networks Blog</a>.</p>
]]></content:encoded>
			    
	    		<wfw:commentRss>https://www.paloaltonetworks.com/blog/2026/06/ai-and-evasion-demand-radical-shift-in-threat-prevention/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	    
	    
	    <post-id xmlns="com-wordpress:feed-additions:1">359937</post-id>    </item>
        <item>
	<title>Reinventing Security for the Agentic NVIDIA AI Factory</title>
	<link>https://www.paloaltonetworks.com/blog/2026/06/reinventing-security-for-the-agentic-nvidia-ai-factory/</link>
	    		<comments>https://www.paloaltonetworks.com/blog/2026/06/reinventing-security-for-the-agentic-nvidia-ai-factory/#respond</comments>
	    
	<dc:creator><![CDATA[Shrikant Brahmbhatt, Lee Space and Nadav Shai Kanon]]></dc:creator>
	<pubDate>Mon, 01 Jun 2026 12:00:57 +0000</pubDate>
		<dcterms:extent>7</dcterms:extent>
	<enclosure url="https://www.paloaltonetworks.com/blog/wp-content/uploads/2026/06/AdobeStock_628395867-scaled.jpeg" type="image/jpeg"  length="551978"/>
	    		<category><![CDATA[Announcement]]></category>
	<guid isPermaLink="false">https://www.paloaltonetworks.com/blog/?p=359841</guid>

	    		<description><![CDATA[<p>Building on the momentum of NVIDIA GTC Taipei at COMPUTEX  2026, the conversation has moved beyond AI experimentation to the industrialization of intelligence. Organizations are rapidly deploying AI Factories – high-performance, purpose-built &#8230;</p>
<p>The post <a href="https://www.paloaltonetworks.com/blog/2026/06/reinventing-security-for-the-agentic-nvidia-ai-factory/">Reinventing Security for the Agentic NVIDIA AI Factory</a> appeared first on <a href="https://www.paloaltonetworks.com/blog">Palo Alto Networks Blog</a>.</p>
]]></description>
						<content:encoded><![CDATA[<p><span style="font-weight: 400;">Building on the momentum of </span><a href="https://www.nvidia.com/en-tw/gtc/taipei/computex/" rel="nofollow,noopener" ><span style="font-weight: 400;">NVIDIA GTC Taipei at COMPUTEX  2026</span></a><span style="font-weight: 400;">, the conversation has moved beyond AI experimentation to the industrialization of intelligence. Organizations are rapidly deploying AI Factories – high-performance, purpose-built computing infrastructures designed to manufacture intelligence at an unprecedented scale. AI’s next phase is agentic. Autonomous AI agents are reshaping enterprise operations—and demand security architectures that can keep pace with the speed and scale of innovation.  We are proud to announce the integration of </span><a href="https://cortex.marketplace.pan.dev/marketplace/details/NVIDIA_DOCA_Argus/" rel="nofollow,noopener" ><span style="font-weight: 400;">Palo Alto Networks Cortex XSIAM</span></a> <span style="font-weight: 400;">with the </span><a href="https://catalog.ngc.nvidia.com/orgs/nvidia/teams/doca/containers/doca_argus" rel="nofollow,noopener" ><span style="font-weight: 400;">NVIDIA DOCA Argus framework</span></a><span style="font-weight: 400;">, a breakthrough that brings real-time, AI-powered security operations directly into the heart of the NVIDIA AI factory. </span></p>
<p><span style="font-weight: 400;">By operating on the </span><a href="https://www.nvidia.com/en-us/networking/products/data-processing-unit/" rel="nofollow,noopener" ><b>NVIDIA BlueField</b></a> <span style="font-weight: 400;">data processor</span><b>,</b><span style="font-weight: 400;"> DOCA Argus provides situational awareness through real-time memory analysis at the silicon level. This allows Cortex XSIAM to detect kernel-level rootkits and "living-off-the-land" attacks without installing security agents on the host system.</span></p>
<p><span style="font-weight: 400;">This innovation builds upon our proven foundation with </span><a href="https://technologypartners.paloaltonetworks.com/English/integration/Secure-AI-Factory-3DPU-Prisma-AIRS-NVIDIA-BlueField"><span style="font-weight: 400;">Palo Alto Networks Prisma AIRS</span></a><span style="font-weight: 400;">, where AI Runtime Security is deployed natively on NVIDIA BlueField, and powered by </span><a href="https://resources.nvidia.com/en-us-accelerated-networking-resource-library/powering-the-next-frontier-of-networking-for-ai-platforms-with-nvidia-doca-3-0" rel="nofollow,noopener" ><span style="font-weight: 400;">NVIDIA DOCA</span></a><span style="font-weight: 400;">, bringing defense in depth. This integration enables offload , isolation and acceleration of security in AI factories.  </span></p>
<h2><span style="font-weight: 400;">Purpose-Built Observability for the AI Factory</span></h2>
<p><span style="font-weight: 400;">Deployed consistently across the AI factory,</span> <span style="font-weight: 400;">DOCA Argus monitors and correlates AI application processes, network telemetry, and data access to detect sophisticated anomalies that traditional tools miss. With this integration, Cortex XSIAM recognizes the high-fidelity data from DOCA Argus as a native Palo Alto Networks sensor, allowing for better decisions with the new intelligence gathered directly from the host.</span></p>
<p><span style="font-weight: 400;">By integrating Cortex XSIAM with the NVIDIA DOCA Argus framework, we leverage the innovations of two industry leaders to deliver a seamless, high-performance SecOps ecosystem for your most valuable AI assets.</span></p>
<h4><b>Why This Integration Is a Game-Changer for SecOps</b></h4>
<ul>
<li style="font-weight: 400;" aria-level="1"><b>Process Introspection:</b><span style="font-weight: 400;"> Residing on NVIDIA BlueField, DOCA Argus has the unique ability to correlate network telemetry with deep process inspection.</span></li>
<li style="font-weight: 400;" aria-level="1"><b>Anomaly Detection:</b><span style="font-weight: 400;"> By analyzing traffic and host behavior simultaneously, XSIAM can detect sophisticated anomalies (e.g., lateral movement or data exfiltration) that traditional tools miss.</span></li>
<li style="font-weight: 400;" aria-level="1"><b>Unified Intelligence:</b><span style="font-weight: 400;"> Cortex XSIAM recognizes the security and alert information in this high-fidelity data, providing security teams with end-to-end visibility and dedicated security dashboards specifically for their AI infrastructure.</span></li>
</ul>
<p>&nbsp;</p>
<p><img fetchpriority="high" decoding="async" class="alignnone size-full wp-image-359902" src="/blog/wp-content/uploads/2026/06/image2-2.png" alt="" width="1613" height="965" srcset="https://www.paloaltonetworks.com/blog/wp-content/uploads/2026/06/image2-2.png 1613w, https://www.paloaltonetworks.com/blog/wp-content/uploads/2026/06/image2-2-230x138.png 230w, https://www.paloaltonetworks.com/blog/wp-content/uploads/2026/06/image2-2-500x299.png 500w, https://www.paloaltonetworks.com/blog/wp-content/uploads/2026/06/image2-2-768x459.png 768w, https://www.paloaltonetworks.com/blog/wp-content/uploads/2026/06/image2-2-1536x919.png 1536w, https://www.paloaltonetworks.com/blog/wp-content/uploads/2026/06/image2-2-501x300.png 501w, https://www.paloaltonetworks.com/blog/wp-content/uploads/2026/06/image2-2-67x40.png 67w" sizes="(max-width: 1613px) 100vw, 1613px" /></p>
<h6 style="text-align: center;"><span style="font-weight: 400;">Native integration of DOCA Argus with XSIAM</span></h6>
<p>&nbsp;</p>
<h2><b>Palo Alto Networks Prisma AIRS Across the NVIDIA AI Factory</b></h2>
<p><span style="font-weight: 400;">The inclusion of Prisma AIRS in </span><a href="/blog/2026/01/support-nvidia-enterprise-ai-factory/#:~:text=By%20isolating%20security%20functions%20on,organizations%20gain%20a%20comprehensive%20defense."><span style="font-weight: 400;">NVIDIA AI Factory validated design</span></a><span style="font-weight: 400;"> delivers a unified security platform, providing proactive, defense-in-depth security across critical layers of the AI ecosystem. </span></p>
<p><span style="font-weight: 400;">Serving as the network enforcement engine for this architecture, Prisma AIRS secures the infrastructure of the modern AI Factory. By unifying protection and visibility into a single automated fabric, it eliminates the traditional trade-off between security and agility, allowing organizations to innovate at machine speed without compromising performance or governance. </span></p>
<p><span style="font-weight: 400;">Beyond enforcement, the broader Prisma AIRS platform acts as the security blueprint for the entire enterprise AI ecosystem—consolidating fragmented point-tools to slash total cost of ownership while providing end-to-end observability from the data plane to the model layer. The platform scales dynamically alongside your AI clusters to safeguard raw datasets, build Layer 7 micro-perimeters around autonomous agents, and protect proprietary model weights from external threats—all without throttling mission-critical performance.</span></p>
<p><span style="font-weight: 400;">By deploying the AI Runtime Firewall directly on NVIDIA BlueField, we establish a foundational network security layer that is fully offloaded, isolated, and accelerated. This provides pervasive protection across the Enterprise AI Factory without sacrificing critical compute resources.</span></p>
<p><span style="font-weight: 400;">Securing the </span><a href="https://www.nvidia.com/en-us/solutions/ai-factories/" rel="nofollow,noopener" ><span style="font-weight: 400;">NVIDIA AI factory</span></a><span style="font-weight: 400;"> requires the entire Prisma AIRS suite, which secures the AI lifecycle through five specialized pillars:</span></p>
<ul>
<li aria-level="1"><b>AI Model Security</b><span style="font-weight: 400;">: Protects against model tampering, malicious scripts and data exfiltration attacks before deployment.</span></li>
<li aria-level="1"><b>AI Red Teaming</b><span style="font-weight: 400;">: Advanced threat simulation and vulnerability discovery to enable the safety, security and integrity of your AI and Agents deployments.</span></li>
<li aria-level="1"><b>AI Runtime Security Firewall</b><span style="font-weight: 400;">: Protects against prompt injection, data leakage, abuse and AI-specific runtime threats across distributed inference flows.</span></li>
<li aria-level="1"><b>AI Agent Gateway</b> acts as the control plane for the AI enterprise – governing tool calls, model access and external connections. Every agent interaction is enforced through centralized policies.</li>
</ul>
<ul>
<li aria-level="1"><b>Agent Identity Security</b><span style="font-weight: 400;"> assigns each agent a governed identity with precise permissions and full traceability, ensuring actions are attributable and enforceable.</span></li>
</ul>
<p>&nbsp;</p>
<h2><b>A Forward-Looking Architecture: Embracing Vera NVIDIA BlueField-4 STX</b></h2>
<p><span style="font-weight: 400;">Looking ahead to the next frontier of enterprise-scale agentic AI, Palo Alto Networks is closely aligning its platform approach with the </span><a href="https://nvidianews.nvidia.com/news/nvidia-vera-bluefield-4-stx-brings-agentic-ai-storage-processing-with-in-silicon-security" rel="nofollow,noopener" ><b>NVIDIA Vera BlueField-4 STX architecture</b></a><span style="font-weight: 400;">, extending protections to AI data storage infrastructure. As AI data demands surge, high-throughput, large-scale environments require a move toward hardware-isolated, performance-neutral protection to support the rapid growth of critical AI applications.</span></p>
<p><span style="font-weight: 400;">Operating within an isolated trust domain on future </span><b>BlueField-4 silicon</b><span style="font-weight: 400;">, our inline security capabilities will maintain strict, policy-driven controls independently of the host operating system and storage systems. This co-design enables critical forward-looking innovations for data, agents, and context memory, ensuring security is </span><i><span style="font-weight: 400;">offloaded, isolated and accelerated</span></i><span style="font-weight: 400;"> to support the next generation of the AI Factory.</span></p>
<p><span style="font-weight: 400;">                        </span></p>
<p><img decoding="async" class="alignnone size-large wp-image-359859" src="/blog/wp-content/uploads/2026/06/image2-500x357.png" alt="" width="500" height="357" srcset="https://www.paloaltonetworks.com/blog/wp-content/uploads/2026/06/image2-500x357.png 500w, https://www.paloaltonetworks.com/blog/wp-content/uploads/2026/06/image2-230x164.png 230w, https://www.paloaltonetworks.com/blog/wp-content/uploads/2026/06/image2-768x549.png 768w, https://www.paloaltonetworks.com/blog/wp-content/uploads/2026/06/image2-1536x1097.png 1536w, https://www.paloaltonetworks.com/blog/wp-content/uploads/2026/06/image2-420x300.png 420w, https://www.paloaltonetworks.com/blog/wp-content/uploads/2026/06/image2-56x40.png 56w, https://www.paloaltonetworks.com/blog/wp-content/uploads/2026/06/image2.png 1716w" sizes="(max-width: 500px) 100vw, 500px" /></p>
<h6 style="text-align: center;"><span style="font-weight: 400;">NVIDIA BlueField-4</span></h6>
<p>&nbsp;</p>
<h2><b>Key Takeaways</b></h2>
<p><span style="font-weight: 400;">Our ongoing collaboration with NVIDIA focuses on these essential pillars for reimagining AI security:</span></p>
<ul>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Deliver the industry-leading security platform reinvented for the unique demands of the AI factory. High-throughput, large-scale environments require a move toward hardware-isolated and performance-neutral protection to support the rapid growth of critical AI applications. By offloading </span><b>AI Runtime Firewall</b><span style="font-weight: 400;"> directly to the </span><b>NVIDIA BlueField</b><span style="font-weight: 400;">, we enable zero-latency protection and strict data governance that neutralizes threats (like model theft) while maintaining peak performance and the integrity of your proprietary models.This architecture embeds security directly into the infrastructure, out of the way of app developers.</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Transform the SOC and achieve deep visibility across AI environments by leveraging </span><b>Cortex XSIAM</b><span style="font-weight: 400;"> to provide real-time detections and automated response. By connecting infrastructure protection with this centralized intelligence, you can secure the AI journey, from development in the factory to operations at the secure industrial edge.</span></li>
<li style="font-weight: 400;" aria-level="1"><b>Zero-Trust for AI Infrastructure:</b><span style="font-weight: 400;"> This helps ensure that as your operations scale toward multi-agent architectures, your security footprint is fully offloaded, isolated, and accelerated to protect advanced inference flows, autonomous agents, and data pipelines without throttling performance.</span></li>
<li style="font-weight: 400;" aria-level="1"><b>Unified Platform Architecture:</b><span style="font-weight: 400;"> Beyond standalone point tools, the Prisma AIRS platform serves as a unified security fabric that spans the entire AI lifecycle—from safeguarding raw data to autonomous agents.</span></li>
</ul>
<h2><b>Deploy Bravely</b></h2>
<p><span style="font-weight: 400;">The Palo Alto Networks platform approach delivers a comprehensive solution to secure an enterprise's entire AI ecosystem. By integrating </span><b>Cortex XSIAM with the NVIDIA DOCA Argus framework</b><span style="font-weight: 400;">, we are extending this comprehensive, deep visibility and protection to the very heart of the AI Factory. With this integration, security teams can leverage an agentless approach via </span><b>DOCA Argus</b><span style="font-weight: 400;"> to gain deep visibility into AI systems hosts by simply downloading the content pack from the </span><a href="https://cortex.marketplace.pan.dev/marketplace/details/NVIDIA_DOCA_Argus/" rel="nofollow,noopener" ><span style="font-weight: 400;">Cortex Marketplace</span></a><span style="font-weight: 400;">.</span></p>
<p><span style="font-weight: 400;">The Palo Alto Networks platform secures the entire AI journey, protecting the infrastructure, intelligent applications, agents and data it produces. With the inclusion of </span><b>Prisma AIRS</b><span style="font-weight: 400;"> in </span><b>NVIDIA Enterprise AI Factory Validated Design</b><span style="font-weight: 400;">, we have delivered the blueprint for secure AI. </span></p>
<p><span style="font-weight: 400;">Palo Alto Networks and NVIDIA are redefining security for the AI factory. Together, we are ensuring your security architecture is as fast, scalable and innovative as the intelligence it protects, empowering you to scale AI production with reduced latency and stronger governance. </span><span style="font-weight: 400;"><br />
</span><span style="font-weight: 400;"><br />
</span><span style="font-weight: 400;">Discover more through the </span><a href="https://technologypartners.paloaltonetworks.com/English/listing/nvidia"><span style="font-weight: 400;">Palo Alto Networks partner directory</span></a><span style="font-weight: 400;">, or read the official </span><a href="https://nvidianews.nvidia.com/news/nvidia-vera-bluefield-4-stx-brings-agentic-ai-storage-processing-with-in-silicon-security" rel="nofollow,noopener" ><span style="font-weight: 400;">press release</span></a><span style="font-weight: 400;"> from NVIDIA for more details.</span></p>
<p>The post <a href="https://www.paloaltonetworks.com/blog/2026/06/reinventing-security-for-the-agentic-nvidia-ai-factory/">Reinventing Security for the Agentic NVIDIA AI Factory</a> appeared first on <a href="https://www.paloaltonetworks.com/blog">Palo Alto Networks Blog</a>.</p>
]]></content:encoded>
			    
	    		<wfw:commentRss>https://www.paloaltonetworks.com/blog/2026/06/reinventing-security-for-the-agentic-nvidia-ai-factory/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	    
	    
	    <post-id xmlns="com-wordpress:feed-additions:1">359841</post-id>    </item>
        <item>
	<title>A 4X Gartner Magic Quadrant for EPP Leader. Built for the Agentic Era.</title>
	<link>https://www.paloaltonetworks.com/blog/2026/05/a-4x-gartner-magic-quadrant-for-epp-leader-built-for-the-agentic-era/</link>
	    		<comments>https://www.paloaltonetworks.com/blog/2026/05/a-4x-gartner-magic-quadrant-for-epp-leader-built-for-the-agentic-era/#respond</comments>
	    
	<dc:creator><![CDATA[Hadar Oren]]></dc:creator>
	<pubDate>Fri, 29 May 2026 13:16:32 +0000</pubDate>
		<dcterms:extent>3</dcterms:extent>
	<enclosure url="https://www.paloaltonetworks.com/blog/wp-content/uploads/2026/05/gartner-epp-leader.jpg" type="image/jpeg"  length="901460"/>
	    		<category><![CDATA[Announcement]]></category>
		<category><![CDATA[Agentic AI]]></category>
		<category><![CDATA[agentic endpoint security]]></category>
		<category><![CDATA[agentic era]]></category>
		<category><![CDATA[Cloud detection and response]]></category>
		<category><![CDATA[cybersecurity endpoint]]></category>
		<category><![CDATA[detection and response]]></category>
		<category><![CDATA[digital forensics]]></category>
		<category><![CDATA[EDR]]></category>
		<category><![CDATA[endpoint forensics]]></category>
		<category><![CDATA[endpoint protection]]></category>
		<category><![CDATA[endpoint security]]></category>
		<category><![CDATA[Extended Detection and Response]]></category>
		<category><![CDATA[Gartner Magic Quadrant]]></category>
		<category><![CDATA[Identity]]></category>
		<category><![CDATA[incident causality]]></category>
		<category><![CDATA[incident response tool]]></category>
		<category><![CDATA[network detection and response]]></category>
		<category><![CDATA[ransomware protection]]></category>
		<category><![CDATA[Threat Detection and Response]]></category>
		<category><![CDATA[Threat Hunting]]></category>
		<category><![CDATA[XDR]]></category>
	<guid isPermaLink="false">https://www.paloaltonetworks.com/blog/?p=359609</guid>

	    		<description><![CDATA[<p>I am incredibly proud to share that Palo Alto Networks has been named a Leader in the 2026 Gartner® Magic Quadrant&#x2122; for Endpoint Protection Platforms for the fourth consecutive year. For us, &#8230;</p>
<p>The post <a href="https://www.paloaltonetworks.com/blog/2026/05/a-4x-gartner-magic-quadrant-for-epp-leader-built-for-the-agentic-era/">A 4X Gartner Magic Quadrant for EPP Leader. Built for the Agentic Era.</a> appeared first on <a href="https://www.paloaltonetworks.com/blog">Palo Alto Networks Blog</a>.</p>
]]></description>
						<content:encoded><![CDATA[<p><span style="font-weight: 400;">I am incredibly proud to share that Palo Alto Networks has been named a Leader in the 2026 Gartner<sup>®</sup> Magic Quadrant<sup><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/2122.png" alt="™" class="wp-smiley" style="height: 1em; max-height: 1em;" /></sup> for Endpoint Protection Platforms for the fourth consecutive year. For us, this recognition is a testament to our team's relentless vision as we continue to define endpoint defense—from the pioneer days of XDR to the new frontier of agentic AI.</span></p>
<p><img decoding="async" class="alignnone size-large wp-image-359825" src="/blog/wp-content/uploads/2026/05/Figure1-500x553.png" alt="" width="500" height="553" srcset="https://www.paloaltonetworks.com/blog/wp-content/uploads/2026/05/Figure1-500x553.png 500w, https://www.paloaltonetworks.com/blog/wp-content/uploads/2026/05/Figure1-230x254.png 230w, https://www.paloaltonetworks.com/blog/wp-content/uploads/2026/05/Figure1-768x849.png 768w, https://www.paloaltonetworks.com/blog/wp-content/uploads/2026/05/Figure1-1389x1536.png 1389w, https://www.paloaltonetworks.com/blog/wp-content/uploads/2026/05/Figure1-1852x2048.png 1852w, https://www.paloaltonetworks.com/blog/wp-content/uploads/2026/05/Figure1-271x300.png 271w, https://www.paloaltonetworks.com/blog/wp-content/uploads/2026/05/Figure1-36x40.png 36w" sizes="(max-width: 500px) 100vw, 500px" /></p>
<p><span style="font-weight: 400;">We believe our repeated recognition as a Leader is built on a single, uncompromising commitment to our customers and partners: empowering organizations with reduced overhead, rapid threat response, a strengthened security posture, and the resilient protection required to close the most critical security gaps. We are now leading the shift into the agentic era. While AI agents significantly boost enterprise productivity, they also introduce novel attack surfaces that legacy EDR tools are unable to protect. As the pioneer of XDR, we are committed to defining the next generation of cybersecurity by securing this new frontier.</span></p>
<p><span style="font-weight: 400;">Cortex<sup>®</sup> XDR is helping customers:</span></p>
<ul>
<li style="font-weight: 400;" aria-level="1"><b>Secure Agentic AI with Koi:</b><span style="font-weight: 400;"> Gain unprecedented visibility, guardrails, and control over AI agents and agentic tools before they become a liability.</span></li>
<li style="font-weight: 400;" aria-level="1"><b>Stop the Unseen: </b><span style="font-weight: 400;">Leverage battle-tested prevention powered by behavioral analytics, and industry-leading automation and response.</span></li>
<li style="font-weight: 400;" aria-level="1"><b>Unify Your Defense:</b> Consolidate your endpoint and workspace security with a proven, four-time industry Leader.</li>
</ul>
<p><span style="font-weight: 400;">We are incredibly proud to be recognized as a Leader once again, an acknowledgement that belongs just as much to our customers and partners as it does to us. Your trust, feedback, and real-world challenges keep us sharp and dictate our roadmap. At the end of the day, our continued leadership is built on one core promise: make each day more secure than the day before.</span></p>
<p><span style="font-weight: 400;">To get the full story and a comprehensive analysis of the endpoint security market, I invite you to read the 2026 Gartner Magic Quadrant report.</span></p>
<p><a href="/cortex/cortex-xdr-gartner-mq-epp-report"><b>Get Your Complimentary Copy of the Report</b></a></p>
<p><span style="font-weight: 400; font-size: 10pt;">Gartner, Magic Quadrant for Endpoint Protection Platforms, By Deepak Mishra, Evgeny Mirolyubov, Nikul Patel, May 29, 2026</span></p>
<p><span style="font-size: 10pt;"><i><span style="font-weight: 400;">Gartner and Magic Quadrant are trademarks of Gartner, Inc. and/or its affiliates. Gartner does not endorse any company, vendor, product or service depicted in its publications, and does not advise technology users to select only those vendors with the highest ratings or other designation. Gartner publications consist of the opinions of Gartner’s business and technology insights organization and should not be construed as statements of fact. Gartner disclaims all warranties, expressed or implied, with respect to this publication, including any warranties of merchantability or fitness for a particular purpose.</span></i></span></p>
<p>The post <a href="https://www.paloaltonetworks.com/blog/2026/05/a-4x-gartner-magic-quadrant-for-epp-leader-built-for-the-agentic-era/">A 4X Gartner Magic Quadrant for EPP Leader. Built for the Agentic Era.</a> appeared first on <a href="https://www.paloaltonetworks.com/blog">Palo Alto Networks Blog</a>.</p>
]]></content:encoded>
			    
	    		<wfw:commentRss>https://www.paloaltonetworks.com/blog/2026/05/a-4x-gartner-magic-quadrant-for-epp-leader-built-for-the-agentic-era/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	    
	    
	    <post-id xmlns="com-wordpress:feed-additions:1">359609</post-id>    </item>
        <item>
	<title>Securing and Governing AI Agents At Scale Through A Unified AI Gateway</title>
	<link>https://www.paloaltonetworks.com/blog/2026/05/securing-and-governing-ai-agents-at-scale-through-a-unified-ai-gateway/</link>
	    		<comments>https://www.paloaltonetworks.com/blog/2026/05/securing-and-governing-ai-agents-at-scale-through-a-unified-ai-gateway/#respond</comments>
	    
	<dc:creator><![CDATA[Anand Oswal]]></dc:creator>
	<pubDate>Fri, 29 May 2026 08:00:33 +0000</pubDate>
		<dcterms:extent>7</dcterms:extent>
	<enclosure url="https://www.paloaltonetworks.com/blog/wp-content/uploads/2026/03/AdobeStock_1246251272_800x600.png" type="image/png"  length="555759"/>
	    		<category><![CDATA[AI Security]]></category>
		<category><![CDATA[Prisma AIRS]]></category>
		<category><![CDATA[Secure AI]]></category>
	<guid isPermaLink="false">https://www.paloaltonetworks.com/blog/?p=358187</guid>

	    		<description><![CDATA[<p>Palo Alto Networks acquires Portkey, integrating its AI Gateway into Prisma AIRS. Get the unified control plane to securely govern and operationalize autonomous AI agents.</p>
<p>The post <a href="https://www.paloaltonetworks.com/blog/2026/05/securing-and-governing-ai-agents-at-scale-through-a-unified-ai-gateway/">Securing and Governing AI Agents At Scale Through A Unified AI Gateway</a> appeared first on <a href="https://www.paloaltonetworks.com/blog">Palo Alto Networks Blog</a>.</p>
]]></description>
						<content:encoded><![CDATA[<h2>Palo Alto Networks Completes Acquisition of Portkey</h2>
<p><span style="font-weight: 400;">We are pleased to announce that Palo Alto Networks has officially completed the acquisition of Portkey. </span></p>
<p><span style="font-weight: 400;">We are moving from vision to reality by integrating Portkey’s pioneering AI Gateway directly into the fabric of the Palo Alto Networks product portfolio. Prisma AIRS AI Gateway will provide a unified vantage point to secure and govern AI agents at scale, offering a mission-critical control plane to identify, authenticate and authorize every agentic interaction in real time.  </span></p>
<p><span style="font-weight: 400;">We are delivering the industry’s most comprehensive security and unified control framework for the agentic enterprise, enabling our customers to scale autonomous AI workloads with complete confidence.</span></p>
<p><span style="font-weight: 400;">The era of the AI Enterprise has arrived. Today, </span><a href="https://www.gartner.com/en/newsroom/press-releases/2025-10-29-gartner-survey-finds-45-percent-of-martech-leaders-say-existing-vendor-offered-ai-agents-fail-to-meet-their-expectations-of-promised-business-performance#:~:text=The%20survey%20revealed%20that%20AI%20agent%20adoption%20is%20now%20widespread%2C%20with%2081%25%20either%20piloting%20or%20fully%20implementing%20these%20solutions.%20Just%201%25%20of%20respondents%20neither%20have%20AI%20agent%20initiatives%20currently%20nor%20have%20any%20plans%20to%20invest%20in%20GenAI%20initiatives%2C%20highlighting%20the%20technology%E2%80%99s%20near%2Duniversal%20appeal" rel="nofollow,noopener" ><span style="font-weight: 400;">81%</span></a><span style="font-weight: 400;"> of enterprises are piloting the use of AI agents or have fully implemented AI agent solutions. We aren't just talking about smart chatbots. We are talking about autonomous agents that execute.</span></p>
<p><span style="font-weight: 400;">By leveraging APIs and MCP servers, these agents navigate complex workflows, access sensitive data and make real-time, business-critical decisions. The question is no longer </span><i><span style="font-weight: 400;">if</span></i><span style="font-weight: 400;"> companies will adopt AI agents, but </span><i><span style="font-weight: 400;">how</span></i><span style="font-weight: 400;"> to securely operationalize them without putting the brakes on innovation. </span></p>
<h3>The Challenge: Expanding Attack Surfaces</h3>
<p><span style="font-weight: 400;">AI agents are creating a new and largely invisible attack surface. The risk is not just their independence, but the lack of visibility and accountability. Without a centralized enforcement layer for operational and security controls, every team that deploys an agent may unintentionally expose the enterprise to unauthorized data access and heightened security risks.</span></p>
<p><span style="font-weight: 400;">To solve this, Palo Alto Networks</span><span style="font-weight: 400;"> is redefining security for the agentic era. We recently introduced </span><a href="/prisma/agent-security"><b>Prisma</b><b> AIRS<sup><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/2122.png" alt="™" class="wp-smiley" style="height: 1em; max-height: 1em;" /></sup> 3.0</b></a><span style="font-weight: 400;">, the industry’s first platform to secure the entire agentic AI lifecycle. Portkey's acquisition accelerates that momentum.</span></p>
<h3>The Prisma AIRS AI Gateway: From Chaos to Control<i> </i></h3>
<p><span style="font-weight: 400;">Portkey's AI Gateway will be integrated into Prisma AIRS to deliver the unified control plane that enterprises need to operationalise and secure AI apps and agents at scale.</span></p>
<p><span style="font-weight: 400;">Moving from “chaos to control” requires a centralized approach to governance. Currently, many AI initiatives are hindered by fragmented security and a lack of oversight. The AI Gateway solves this by providing a unified vantage point where organizations can enforce consistent policies across all models and agents, ensuring every interaction is identified, authenticated and authorized in real time within a single governing framework.</span></p>
<p><span style="font-weight: 400;">The Prisma AIRS AI Gateway will establish a mission-critical control plane for the agentic enterprise, enabling teams to move autonomous workloads from development into at-scale production with confidence. With operational features like a unified API to LLMs, an agent registry, semantic routing and caching, the AI Gateway equips enterprises with complete control in one platform. By serving as a centralized enforcement point at the center of Prisma AIRS for all agent traffic, the AI Gateway will provide critical security functions, including Agent Artifact scanning, automated Red Teaming and Runtime Security needed to monitor behavior, route requests and mitigate risks in real time. Crucially, the AI Gateway will reinforce Agent Identity Security via Idira (formerly CyberArk), applying strict protocols to ensure every autonomous action is authenticated and governed by least-privilege controls.</span></p>
<p><span style="font-weight: 400;">Our vision is for the Prisma AIRS AI Gateway to serve as the industry blueprint for enterprises in the agentic era. By making security a foundational component of the operational lifecycle, we are empowering enterprises to build and govern an AI ecosystem that is secure by design.</span></p>
<p>&nbsp;</p>
<p><img loading="lazy" decoding="async" class="aligncenter wp-image-357885" src="/blog/wp-content/uploads/2026/04/Prisma-AIRS-500x500.jpg" alt="Secure All Agents with the Prisma AIRS AI Gateway" width="600" height="600" /></p>
<p>&nbsp;</p>
<h3>Why Portkey? The Pioneer in AI Gateways</h3>
<ul>
<li style="font-weight: 400;" aria-level="1"><b>Battle-Tested:</b><span style="font-weight: 400;"> Portkey’s AI Gateway is already supporting the demands of the modern enterprise, at scale, with several Fortune 500 customers, processing trillions of tokens per month with the low latency that is required for agent-to-agent communication. This ensures that agentic security does not come at the cost of developer speed or application performance. </span></li>
<li style="font-weight: 400;" aria-level="1"><b>Architectural Simplicity: </b><span style="font-weight: 400;">Portkey offers plug-and-play capabilities with just </span><em>three</em><span style="font-weight: 400;"> lines of code required to implement the AI Gateway. The AI Gateway, powered by unified APIs, also provides </span><span style="font-weight: 400;">secure access to over 3,000 LLMs, MCP servers and agents, giving enterprises a flying start to building and executing with AI agents. </span></li>
<li style="font-weight: 400;" aria-level="1"><b>Better Together: </b><span style="font-weight: 400;">Palo Alto Networks and Portkey’s joint vision is to make Prisma AIRS the most ubiquitous platform for AI security. With exceptional AI security by Palo Alto Networks combined with Portkey’s AI Gateway, we will offer a comprehensive AI Security platform.</span></li>
</ul>
<p><img loading="lazy" decoding="async" class="aligncenter wp-image-357989 size-full" src="/blog/wp-content/uploads/2026/04/Project-Potter-Infographic-v2.jpg" alt="Prisma AIRS comprehensive AI App and agent security platform." width="1920" height="1080" srcset="https://www.paloaltonetworks.com/blog/wp-content/uploads/2026/04/Project-Potter-Infographic-v2.jpg 1920w, https://www.paloaltonetworks.com/blog/wp-content/uploads/2026/04/Project-Potter-Infographic-v2-230x129.jpg 230w, https://www.paloaltonetworks.com/blog/wp-content/uploads/2026/04/Project-Potter-Infographic-v2-500x281.jpg 500w, https://www.paloaltonetworks.com/blog/wp-content/uploads/2026/04/Project-Potter-Infographic-v2-768x432.jpg 768w, https://www.paloaltonetworks.com/blog/wp-content/uploads/2026/04/Project-Potter-Infographic-v2-1536x864.jpg 1536w, https://www.paloaltonetworks.com/blog/wp-content/uploads/2026/04/Project-Potter-Infographic-v2-510x287.jpg 510w, https://www.paloaltonetworks.com/blog/wp-content/uploads/2026/04/Project-Potter-Infographic-v2-71x40.jpg 71w, https://www.paloaltonetworks.com/blog/wp-content/uploads/2026/04/Project-Potter-Infographic-v2-533x300.jpg 533w" sizes="auto, (max-width: 1920px) 100vw, 1920px" /></p>
<h2>What’s Next?</h2>
<p><span style="font-weight: 400;">The era of AI Enterprises is here. We’re making sure it is secure by design. The complexity of managing agents and securing them has long created friction in enterprises. With the integration of Portkey into Prisma AIRS, we will remove the trade-off between agent autonomy and authority. We are ensuring that as businesses accelerate into the era of autonomous agents, the security architecture isn’t just keeping up, it is setting the pace. </span></p>
<p><a href="/prisma/prisma-ai-runtime-security"><span style="font-weight: 400;">Learn more about Prisma AIRS</span></a><span style="font-weight: 400;"> - the world’s most comprehensive AI security platform. </span></p>
<p><b>Forward-Looking Statements</b></p>
<p><i><span style="font-weight: 400;">This blog contains forward-looking statements that involve risks, uncertainties, and assumptions, including, but not limited to, statements regarding the anticipated benefits and impact of the acquisition of Portkey on Palo Alto Networks, Portkey and their customers. There are a significant number of factors that could cause actual results to differ materially from statements made in this blog, including, but not limited to: risks related to disruption of management time from ongoing business operations due to the acquisition and the integration of Portkey and other recent acquisitions; our ability to effectively operate Portkey's operations and business, integrate Portkey’s business and products into our products, and realize the anticipated synergies in the transaction in a timely manner or at all; changes in the fair value of our contingent consideration liability associated with acquisitions; developments and changes in general market, political, economic and business conditions; failure of our platformization product offerings; risks associated with managing our growth; risks associated with new product, subscription and support offerings; shifts in priorities or delays in the development or release of new product or subscription or other offerings or the failure to timely develop and achieve market acceptance of new products and subscriptions, as well as existing products, subscriptions and support offerings; failure of our product offerings or business strategies in general; defects, errors, or vulnerabilities in our products, subscriptions or support offerings; our customers’ purchasing decisions and the length of sales cycles; our ability to attract and retain new customers; developments and changes in general market, political, economic, and business conditions; our competition; our ability to acquire and integrate other companies, products, or technologies in a successful manner; our debt repayment obligations; and our share repurchase program, which may not be fully consummated or enhance shareholder value, and any share repurchases which could affect the price of our common stock.</span></i></p>
<p><i><span style="font-weight: 400;">Additional risks and uncertainties that could affect our financial results are included under the captions "Risk Factors" and "Management's Discussion and Analysis of Financial Condition and Results of Operations" in our Quarterly Report on Form 10-Q filed with the SEC on February 18, 2026, which is available on our website at investors.paloaltonetworks.com and on the SEC's website at www.sec.gov. Additional information will also be set forth in other filings that we make with the SEC from time to time. All forward-looking statements in this blog are based on information available to us as of the date hereof, and we do not assume any obligation to update the forward-looking statements provided to reflect events that occur or circumstances that exist after the date on which they were made.</span></i></p>
<p>The post <a href="https://www.paloaltonetworks.com/blog/2026/05/securing-and-governing-ai-agents-at-scale-through-a-unified-ai-gateway/">Securing and Governing AI Agents At Scale Through A Unified AI Gateway</a> appeared first on <a href="https://www.paloaltonetworks.com/blog">Palo Alto Networks Blog</a>.</p>
]]></content:encoded>
			    
	    		<wfw:commentRss>https://www.paloaltonetworks.com/blog/2026/05/securing-and-governing-ai-agents-at-scale-through-a-unified-ai-gateway/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	    
	    
	    <post-id xmlns="com-wordpress:feed-additions:1">358187</post-id>    </item>
        <item>
	<title>The “Why” Behind NextWave’s New Requirements</title>
	<link>https://www.paloaltonetworks.com/blog/2026/05/why-behind-nextwaves-new-requirements/</link>
	    		<comments>https://www.paloaltonetworks.com/blog/2026/05/why-behind-nextwaves-new-requirements/#respond</comments>
	    
	<dc:creator><![CDATA[Michael Khoury]]></dc:creator>
	<pubDate>Thu, 14 May 2026 13:00:54 +0000</pubDate>
		<dcterms:extent>8</dcterms:extent>
	<enclosure url="https://www.paloaltonetworks.com/blog/wp-content/uploads/2026/05/GettyImages-1138450812-edit-scaled.jpg" type="image/jpeg"  length="397549"/>
	    		<category><![CDATA[Announcement]]></category>
		<category><![CDATA[Partners]]></category>
		<category><![CDATA[Products and Services]]></category>
		<category><![CDATA[NextWave Partner Program]]></category>
	<guid isPermaLink="false">https://www.paloaltonetworks.com/blog/?p=358795</guid>

	    		<description><![CDATA[<p>Learn the NextWave Partner Program new requirements designed to boost partner capabilities, accelerate next-gen security specialization, and deliver greater customer value.</p>
<p>The post <a href="https://www.paloaltonetworks.com/blog/2026/05/why-behind-nextwaves-new-requirements/">The “Why” Behind NextWave’s New Requirements</a> appeared first on <a href="https://www.paloaltonetworks.com/blog">Palo Alto Networks Blog</a>.</p>
]]></description>
						<content:encoded><![CDATA[<h1><strong>Helping Partners Stay Competitive for the Future</strong></h1>
<h4>Key Takeaways</h4>
<ul>
<li>The evolved NextWave Partner Program raises expectations while strengthening enablement, incentives and the Partner Development Fund to support partner growth and reinvestment.</li>
<li>Levels and specializations are more closely aligned to next-generation security priorities, helping partners deepen expertise and making partner distinctions more meaningful for customers.</li>
<li>These changes help create a more capable partner ecosystem, with deeper capabilities, greater alignment with customer needs, and a stronger foundation to support the future of security.</li>
</ul>
<hr />
<p>Cybersecurity partnerships are operating in a more demanding environment. As customers consolidate vendors, modernize security architectures and adopt artificial intelligence (AI) across the enterprise, they’re placing greater expectations on partners to help guide decisions across network, cloud and security operations. They also want clearer evidence that their selected partners have invested in growing the skills and expertise needed to support more integrated and fast-changing security priorities.</p>
<p>The Palo Alto Networks NextWave Partner Program <a href="/blog/2026/02/new-year-new-program-new-opportunities/">has evolved</a> to help partners meet these heightened expectations. As security delivery becomes broader and more strategic, customers are placing more weight on what a partner’s credentials actually represent. That’s why stronger performance and enablement requirements are part of our reimagined program. The new requirements help partners better understand what they need to build real capability and advance within our program. They also give more substance to the designations customers see when choosing a partner.</p>
<p>Our objective was never simply to raise the standards for engagement in our program. It was to inspire partners at all levels – Registered, Innovator, Platinum and Diamond – to invest deliberately and continuously in learning, so they can deepen their proficiency and earn specializations that will help them stay competitive and build and deliver the future of security.</p>
<h2>Why Requirements and Incentives Had to Evolve Together</h2>
<p>Raising performance expectations was only part of the work in evolving the NextWave program. We also wanted to give our partners compelling reasons to invest in the capabilities Palo Alto Networks wants to see scale. That meant looking more closely at how standards, specializations and incentives fit together, and how we can <a href="/blog/2026/03/nextwaves-evolution-drives-shared-success/">help accelerate mutual success</a>.</p>
<p>We are providing our partners with better access, better visibility and better support for learning and enablement. In turn, we are recognizing and rewarding partners for their efforts to develop and maintain the competency, capability and capacity needed to go to market successfully with Palo Alto Networks.</p>
<p>This approach, shaped largely by partner feedback, is designed to make incentives easier to access while still directing partner investment toward deeper specialization and next-gen security capabilities. Program levels and product specializations help define what partners need to do to grow within our program and to excel at selling, supporting or delivering Palo Alto Networks products and services.</p>
<p>The program’s Partner Development Fund adds another dimension to this evolved model. It gives all partners a more deliberate way to reinvest a portion of their earned incentives into the capabilities they need to stay competitive and innovate, including training, certification, workshops, demos and other strategic activities that help strengthen their team’s overall readiness over time. In that sense, the program is both rewarding current performance and driving mutual growth.</p>
<h2>Training and Enablement that Move with the Market</h2>
<p>As we continue to strengthen our partner program, Palo Alto Networks is refreshing courses, updating certification paths and redesigning training to better reflect the customer needs that partners are helping to address today, including emerging areas like <a href="/blog/2025/09/securing-the-future-of-ai/">AI security</a>.</p>
<p>Notable improvements:</p>
<ul>
<li>Introduced more online, on-demand learning experiences across all products and across all roles, including sales, technical presales and post-sales professionals.</li>
<li>Expanded access to lab environments for hands-on experiences, as well as access to perform demos for customers.</li>
<li>Injected AI roleplay into learning experiences to help sales and presales teams improve their ability to educate customers about our products and services while addressing questions or concerns.</li>
<li>Instituted a continuous education component that encourages partners to stay current with certifications and other program requirements, so they don’t need to be tested annually.</li>
</ul>
<p>Our aim with these changes is to keep learning options relevant, practical and easier to engage in and apply in practice. We believe product and services training should help partners deepen expertise, validate skills and stay current as technologies, customer expectations and threats shift. It should also recognize the experience many professionals already bring to the table, with learning paths that are rigorous without being repetitive or unnecessarily burdensome.</p>
<p>Ultimately, the impact of providing more effective enablement for our partners (and outlining clear requirements for advanced specializations and total certified staff for specific partner paths) positively impacts the customer experience through more informed conversations, stronger design guidance and more consistent support across the entire security lifecycle.</p>
<h2>A More Focused Program to Help Accelerate Next-Generation Security</h2>
<p>Part of what makes the current evolution of the NextWave program so significant is its focus on helping partners build the bench strength they will need to stay competitive as security becomes more <a href="/resources/ebooks/platformization-in-action">platform-driven</a>, <a href="/precision-ai-security">AI-influenced</a> and interconnected across domains. The program also encourages bookings tied to next-generation security priorities, helping direct partner investment toward the areas customers are prioritizing most. That focus is especially visible in areas such as <a href="/idira">Idira<sup>®</sup></a>, <a href="/sase">Prisma<sup>®</sup> SASE</a>, <a href="/cortex/cloud">Cortex<sup>®</sup> Cloud<img src="https://s.w.org/images/core/emoji/17.0.2/72x72/2122.png" alt="™" class="wp-smiley" style="height: 1em; max-height: 1em;" /></a> and <a href="/cortex">Cortex</a>, where customer demand and program priorities are increasingly aligned.</p>
<p>The benefits of that alignment extend beyond the partner organization. Customers gain access to partners that are better prepared to support more connected security strategies without adding unnecessary complexity. They can work with partners that are building expertise around the technologies and use cases becoming more central to modern enterprise security programs.</p>
<p>This kind of alignment also strengthens the broader ecosystem. It creates a clearer connection between customer needs, partner capabilities and <a href="/why-paloaltonetworks/platformization">Palo Alto Networks platform strategy</a>. It’s <a href="/blog/2025/08/value-exchange-in-cybersecurity/">the value exchange in cybersecurity</a> in action: Ongoing investment in knowledge, skills and services that helps partners grow while giving customers faster time-to-value realization.</p>
<h2>What Stronger Program Requirements Mean for Customers</h2>
<p>For customers, stronger requirements for our Nextwave program can make partner distinctions more meaningful. A specialization or program level should point to something real, such as training completed, certifications maintained and expertise developed. While those accomplishments don’t guarantee security outcomes, they do provide evidence that a partner has built the depth needed to support more complex environments.</p>
<p>Partner distinctions are also reinforced through an active compliance framework rather than treated as a one-time achievement. Partners have ongoing visibility into their progress and can be recognized immediately throughout the year as they meet requirements. Reviews take place on a defined cycle, and status changes are subject to oversight. Taken together, these elements add credibility to the designations customers see and give them more weight in the partner selection process.</p>
<p>This becomes increasingly important as customers look for security partners that can do more than support a single transaction or product decision. Many are seeking guidance at the architecture stage and during implementation, and expecting continuity as IT environments evolve and <a href="/blog/2025/10/ai-quantum-computing-emerging-risks/">new risks emerge</a>. It also raises the level of scrutiny that partner selection deserves:</p>
<ul>
<li>Is a partner specialized in the areas most relevant to the customer’s priorities?</li>
<li>Do they have the certifications and technical expertise required to support the solutions being considered?</li>
<li>Can they provide the level of guidance, implementation support and ongoing engagement the relationship will require over time?</li>
</ul>
<p>In a fast-moving security market, questions like these can help customers make more informed decisions about which partners are best equipped to deliver long-term value.</p>
<h2>What Partners Should Do Now</h2>
<p>Now that we’ve introduced our new program requirements, partners should take stock of whether their certifications, specializations and go-to-market priorities are aligned to where customer demand and the future of security are headed. Steps partners can take:</p>
<ul>
<li><strong>Evaluate your current book of business:</strong> Consider where you may be missing growth opportunities because the right specializations aren’t yet in place. Those gaps can affect both business momentum and the ability to earn incentives.</li>
<li><strong>Reflect on the current direction of your practice:</strong> Which customer conversations are signaling the need for deeper expertise? Which areas of next-generation security are becoming more central to your future? These questions can help guide your next investments by clarifying where your practice needs to build more depth sooner rather than later.</li>
<li><strong>Review certifications and specializations with growth in mind: </strong>Look at where new specializations could open the door to additional incentives and stronger alignment with customer demand, while ensuring your team’s existing certifications and specializations remain on track for the next compliance cycle.</li>
</ul>
<p>Partners that take the time now to assess our new requirements and create a plan to meet them will be better positioned to advance within and benefit from <a href="/partners">our partner program</a>, while developing the capabilities needed to help build the future of security.</p>
<p>Partners with a designated Palo Alto Networks Channel Business Manager can get detailed data and analysis now on their progress and performance in the Nextwave program, including the status of their certifications and which team members have engaged in training, demos and more. In the second half of 2026, we plan to make the same dashboard capabilities and insights directly available to all partners, so they can understand exactly what they need to do to excel in our program. These red-yellow-green dashboards are simple but powerful tools, and we are eager to put them in our partners’ hands soon.</p>
<p>Visit the <a href="/partners">NextWave Partner Portal</a> to learn more.</p>
<p>The post <a href="https://www.paloaltonetworks.com/blog/2026/05/why-behind-nextwaves-new-requirements/">The “Why” Behind NextWave’s New Requirements</a> appeared first on <a href="https://www.paloaltonetworks.com/blog">Palo Alto Networks Blog</a>.</p>
]]></content:encoded>
			    
	    		<wfw:commentRss>https://www.paloaltonetworks.com/blog/2026/05/why-behind-nextwaves-new-requirements/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	    
	    
	    <post-id xmlns="com-wordpress:feed-additions:1">358795</post-id>    </item>
        <item>
	<title>Beyond the Frontier — Expanding the Ecosystem for Autonomous Defense</title>
	<link>https://www.paloaltonetworks.com/blog/2026/05/expanding-ecosystem-autonomous-defense/</link>
	    		<comments>https://www.paloaltonetworks.com/blog/2026/05/expanding-ecosystem-autonomous-defense/#respond</comments>
	    
	<dc:creator><![CDATA[Simone Gammeri]]></dc:creator>
	<pubDate>Wed, 13 May 2026 19:00:19 +0000</pubDate>
		<dcterms:extent>3</dcterms:extent>
	<enclosure url="https://www.paloaltonetworks.com/blog/wp-content/uploads/2026/05/frontier-AI-defense_blog@2x-1.jpg" type="image/jpeg"  length="435881"/>
	    		<category><![CDATA[Announcement]]></category>
		<category><![CDATA[Products and Services]]></category>
		<category><![CDATA[Research]]></category>
		<category><![CDATA[Frontier AI Alliance]]></category>
	<guid isPermaLink="false">https://www.paloaltonetworks.com/blog/?p=358767</guid>

	    		<description><![CDATA[<p>Palo Alto Networks expands the Frontier AI Alliance with top partners to deliver autonomous, machine-speed defense against frontier AI threats and exploits.</p>
<p>The post <a href="https://www.paloaltonetworks.com/blog/2026/05/expanding-ecosystem-autonomous-defense/">Beyond the Frontier — Expanding the Ecosystem for Autonomous Defense</a> appeared first on <a href="https://www.paloaltonetworks.com/blog">Palo Alto Networks Blog</a>.</p>
]]></description>
						<content:encoded><![CDATA[<p>Over the past few weeks, we have reached a critical turning point in cybersecurity. Following the launch of our <a href="/frontier">Frontier AI Defense</a> initiative, we’ve continued testing the latest frontier models (including Anthropic’s <strong>Mythos</strong> and <strong>Claude Opus 4.7</strong>, as well as OpenAI’s <strong>GPT-5.5-Cyber</strong>) as part of the <strong>Trusted Access for Cyber</strong> program.</p>
<p>The urgency to innovate continues to ramp up. As Lee Klarich recently detailed in his <a href="/blog/2026/05/defenders-guide-frontier-ai-impact-cybersecurity-may-2026-update/">Defender's Guide to the Frontier AI Impact on Cybersecurity</a>, our current landscape is defined by a brief <em>three-to-five-month window </em>to gain a strategic advantage over attackers. To outsmart AI-based exploits, enterprises must decisively address vulnerabilities across their code and stand up the right security stack to enable real-time, automated defenses.</p>
<p>With such a ticking clock in front of us, acting rapidly and at-scale to support our customers is paramount. Today, we exponentially grow our scale of delivery by expanding our <a href="/blog/2026/04/ai-ecosystem-edge-introducing-frontier-ai-alliance/">Frontier AI Alliance.</a></p>
<p>Since introducing this initiative, our collaboration with initial partners – <strong>Accenture, Deloitte, IBM, NTT DATA, </strong>and<strong> PwC</strong> – has already begun changing the defensive math for our customers. This is a moment that calls for radical collaboration across the entire security ecosystem, so today we are proud to welcome a new cohort of strategic partners – <strong>Cognizant, HCLTech, Kyndryl, TCS, Infosys, McKinsey &amp; Company, Orange Cyberdefense, </strong>and<strong> Wipro</strong> – who will join us in delivering AI readiness at scale.</p>
<p><img loading="lazy" decoding="async" class="wp-image-358852 aligncenter" src="/blog/wp-content/uploads/2026/05/image-45-230x229.png" alt="Frontier AI Alliance" width="437" height="435" srcset="https://www.paloaltonetworks.com/blog/wp-content/uploads/2026/05/image-45-230x229.png 230w, https://www.paloaltonetworks.com/blog/wp-content/uploads/2026/05/image-45-500x498.png 500w, https://www.paloaltonetworks.com/blog/wp-content/uploads/2026/05/image-45-100x100.png 100w, https://www.paloaltonetworks.com/blog/wp-content/uploads/2026/05/image-45-768x766.png 768w, https://www.paloaltonetworks.com/blog/wp-content/uploads/2026/05/image-45-301x300.png 301w, https://www.paloaltonetworks.com/blog/wp-content/uploads/2026/05/image-45-40x40.png 40w, https://www.paloaltonetworks.com/blog/wp-content/uploads/2026/05/image-45.png 1298w" sizes="auto, (max-width: 437px) 100vw, 437px" /></p>
<p>While this expansion significantly increases our reach, <em>this is only the beginning</em>. We are committed to a continuous evolution of this alliance and will be adding more critical partners in the future across the globe to ensure our customers have the most robust defense network possible.</p>
<p>By combining our technology with these partners’ deep consulting expertise, we are delivering:</p>
<ul>
<li><strong>Machine-Speed Security:</strong> Natively integrating Frontier AI to provide real-time, automated defense against autonomous threats.</li>
<li><strong>Intelligence-Led Resilience:</strong> Leveraging Unit 42<sup>®</sup> experts to fast-track the discovery and remediation of exposures at machine speed.</li>
<li><strong>Hardened Defenses:</strong> Utilizing early access to frontier models from partners like OpenAI and Anthropic to simulate and block attack chains before they hit the mainstream.</li>
</ul>
<p>The stakes are high. The attack cycle has compressed with the time from initial access to data exfiltration collapsing to <a href="/blog/2026/05/how-long-it-takes-to-lose-data/">just 39 seconds</a>. Machine-speed MTTR (mean time to respond) is no longer an ambitious goal, it is a requirement.</p>
<p>This initiative underscores our commitment to providing every client with integrated, real-time protection.</p>
<h5>Discover further details: <a href="/frontier">Palo Alto Networks Frontier AI Defense.</a></h5>
<p dir="ltr">
<p dir="ltr"><em>Forward-Looking Statements</em></p>
<p dir="ltr"><em>This blog contains forward-looking statements that involve risks, uncertainties and assumptions, including, without limitation, statements regarding the benefits, impact, or performance or potential benefits, impact or performance of our products and technologies or future products and technologies. These forward-looking statements are not guarantees of future performance, and there are a significant number of factors that could cause actual results to differ materially from statements made in this blog. We identify certain important risks and uncertainties that could affect our results and performance in our most recent Annual Report on Form 10-K, our most recent Quarterly Report on Form 10-Q, and our other filings with the U.S. Securities and Exchange Commission from time-to-time, each of which are available on our website at <a href="http://investors.paloaltonetworks.com/" target="_blank" rel="noopener" data-saferedirecturl="https://www.google.com/url?q=http://investors.paloaltonetworks.com&amp;source=gmail&amp;ust=1778868530825000&amp;usg=AOvVaw1bQuLbWF716MSHmsHQ_vsL">investors.paloaltonetworks.com</a> and on the SEC's website at <a href="http://www.sec.gov/" target="_blank" rel="noopener" data-saferedirecturl="https://www.google.com/url?q=http://www.sec.gov&amp;source=gmail&amp;ust=1778868530825000&amp;usg=AOvVaw3zEOC78IkcAa80oMPaPDUo">www.sec.gov</a>.  All forward-looking statements in this blog are based on information available to us as of the date hereof, and we do not assume any obligation to update the forward-looking statements provided to reflect events that occur or circumstances that exist after the date on which they were made.</em></p>
<p>The post <a href="https://www.paloaltonetworks.com/blog/2026/05/expanding-ecosystem-autonomous-defense/">Beyond the Frontier — Expanding the Ecosystem for Autonomous Defense</a> appeared first on <a href="https://www.paloaltonetworks.com/blog">Palo Alto Networks Blog</a>.</p>
]]></content:encoded>
			    
	    		<wfw:commentRss>https://www.paloaltonetworks.com/blog/2026/05/expanding-ecosystem-autonomous-defense/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	    
	    
	    <post-id xmlns="com-wordpress:feed-additions:1">358767</post-id>    </item>
        <item>
	<title>Defender&#039;s Guide to the Frontier AI Impact on Cybersecurity: May 2026 Update</title>
	<link>https://www.paloaltonetworks.com/blog/2026/05/defenders-guide-frontier-ai-impact-cybersecurity-may-2026-update/</link>
	    		<comments>https://www.paloaltonetworks.com/blog/2026/05/defenders-guide-frontier-ai-impact-cybersecurity-may-2026-update/#respond</comments>
	    
	<dc:creator><![CDATA[Lee Klarich]]></dc:creator>
	<pubDate>Wed, 13 May 2026 16:00:04 +0000</pubDate>
		<dcterms:extent>8</dcterms:extent>
	<enclosure url="https://www.paloaltonetworks.com/blog/wp-content/uploads/2026/05/PANW-DefendersGuide-Blog-e1778683382914.jpg" type="image/jpeg"  length="164514"/>
	    		<category><![CDATA[AI Security]]></category>
		<category><![CDATA[Announcement]]></category>
		<category><![CDATA[Points of View]]></category>
		<category><![CDATA[frontier AI]]></category>
		<category><![CDATA[Updates]]></category>
	<guid isPermaLink="false">https://www.paloaltonetworks.com/blog/?p=358811</guid>

	    		<description><![CDATA[<p>Get the May 2026 update on Frontier AI-driven exploits. Learn the 4 immediate steps for agentic defense, vulnerability finding and security operations to outpace the adversary.</p>
<p>The post <a href="https://www.paloaltonetworks.com/blog/2026/05/defenders-guide-frontier-ai-impact-cybersecurity-may-2026-update/">Defender&#039;s Guide to the Frontier AI Impact on Cybersecurity: May 2026 Update</a> appeared first on <a href="https://www.paloaltonetworks.com/blog">Palo Alto Networks Blog</a>.</p>
]]></description>
						<content:encoded><![CDATA[<p>By now, you’ve heard about the latest frontier AI models that are remarkably good at finding vulnerabilities in code and creating potential exploits. So good, in fact, that these models have been significantly limited from general use in an attempt to give defenders time to find and fix vulnerabilities before attackers find and exploit them.</p>
<p>For context, on April 7, 2026, we began testing Anthropic’s Claude Mythos model as a launch partner for <a href="https://www.anthropic.com/glasswing" target="_blank" rel="noopener">Project Glasswing</a>. Our conclusion was clear: The latest models are extraordinarily capable at finding vulnerabilities and changing them into critical exploit paths in near-real-time. In <a href="/blog/2026/04/defenders-guide-frontier-ai-impact-cybersecurity/" target="_blank" rel="noopener">Defender's Guide to the Frontier AI Impact on Cybersecurity</a>, I shared our early findings and recommendations.</p>
<p>Since then, we’ve continued testing the latest frontier AI models, including Anthropic’s Mythos and Claude Opus 4.7 and OpenAI’s GPT-5.5-Cyber as part of the Trusted Access for Cyber program. The big question just a few weeks ago was: “Are we overstating the model capabilities?” With more testing, I can confidently say we weren’t. In fact, these models are likely even better at finding vulnerabilities than we initially realized. Today, we’re providing an update on our ongoing research, our learnings uncovered in the process, and the approach we’re taking to protect our customers.</p>
<h2><a id="post-358811-_1sfk3nkmeifw"></a>Find and Fix Before Attackers Find and Exploit</h2>
<p>Today, we released our May “Patch Wednesday” security advisories, our monthly cadence of transparent vulnerability disclosure and remediation. This is the first time where the majority of findings were the result of frontier AI models scanning our code.</p>
<ul>
<li>These are the results of the full, initial scan of over 130 products across all three platforms.</li>
<li>As of today, we’ve patched all important vulnerabilities in our SaaS delivered products, and all customer-operated products now have patches available.</li>
<li>Today’s advisory covers 26 CVEs (representing 75 issues) versus our usual volume (typically less than 5 CVEs in a month); none of which are being exploited in the wild. Note, this excludes CyberArk vulnerabilities, which are disclosed in their normal process.</li>
</ul>
<p>It's important to understand this isn’t a one-and-done situation. We’re now rescanning, applying all our learnings about how to provide the right context and threat intelligence to the models. We intend to fix every vulnerability we find before advanced AI capabilities become widely available to adversaries.</p>
<p>While incredibly powerful, AI models aren’t simply magic. To achieve high-fidelity results, you need to build AI scanning harnesses, leverage context, guardrails and threat intelligence. We’ve also discovered a variance across models, due to variations in their training. A multimodel approach is required to identify the superset of vulnerabilities. And finally, while the immediate priority is finding and fixing the vulnerabilities that organizations currently have, the longer-term shift is incorporating these models directly into the software development lifecycle. This is the light at the end of the tunnel: A future where software is secure by design.</p>
<h2><a id="post-358811-_6q553nnp0gm1"></a>Four Steps Every Organization Needs to Take Immediately</h2>
<p>Regardless of the current restricted access, we believe these capabilities will flow more broadly to other models. We now estimate a narrow three-to-five-month window for organizations to outpace the adversary before AI-driven exploits start to become the new norm. This impending vulnerability deluge demands urgency. Organizations that haven’t put appropriate safeguards in place will face an entirely new class of risk. Here’s what we recommend:</p>
<ol>
<li><strong>Find and Fix Vulnerabilities In Your Applications, Products and Code </strong><br />
Find and fix before attackers find and exploit.</p>
<ul>
<li>Leverage AI models to identify vulnerabilities across all codebase.</li>
<li>Apply the same AI scanning to your open-source supply chain, and remediate or mitigate findings.</li>
<li>Run accelerated patching tightly coordinated with product and development teams.</li>
</ul>
</li>
<li><strong>Assess, Reduce and Remediate Your Exposure</strong><br />
Reduce what is reachable by attackers, secure what must be accessible, such as customer-facing applications.</p>
<ul>
<li>Attack surface management products, like <a href="http://paloaltonetworks.com/cortex/cortex-xpanse">Cortex Xpanse<sup>®</sup></a>, have never been more critical for finding and reducing exposure.</li>
<li>The latest frontier AI models are very adept (with the right AI scanning harness) at evaluating exposures, understanding security misconfigurations and prioritizing attack-path reachability.</li>
<li>Audit your supply chain, including AI infrastructure, runtime environments and model dependencies.</li>
</ul>
</li>
<li><strong>Ensure Attack Protections</strong><br />
Vulnerability exploits are typically just one step of a multi-step attack lifecycle. Ensuring best-in-class protections is now even more important for preventing breaches.</p>
<ul>
<li>Map current sensor coverage to identify critical blind spots in detection, prevention and telemetry.</li>
<li>Deploy best-in-class XDR everywhere with an emphasis on real-time ML-based detection and prevention of attacks with all hosts on-premises and cloud included.</li>
<li>Deploy Agentic Endpoint Security to secure wide-scale adoption of vibe coding and AI security across the enterprise (e.g. <a href="https://start.paloaltonetworks.com/prisma-airs-demo.html" target="_blank" rel="noopener">Prisma AIRS<sup>®</sup></a> and our recent <a href="/blog/2026/02/securing-the-agentic-endpoint/" target="_blank" rel="noopener">acquisition of Koi</a> are now a necessity for securing the agentic endpoint).</li>
<li>Secure enterprise browsers with AI-based security are a must have for securing where users now do their work.</li>
<li>Zero trust and Identity Security are foundational to securing every user and connection, extending to internal segmentation and outbound application connections.</li>
</ul>
</li>
<li><strong>Deploy Real-Time Security Operations</strong><br />
Autonomous AI-driven attacks will drive attack lifecycles to minutes requiring every SOC to achieve single-digit mean time to detect (MTTD) and mean time to respond (MTTR).</p>
<ul>
<li>Attack detections must be AI/ML-driven to detect even frequently changing and novel attacks at scale.</li>
<li>These AI detections must operate against a wide range of first party and third party data sources. A best in class AI SOC must operate on ALL relevant data sources.</li>
<li>Automation, both natively integrated and throughout the SOC lifecycle, is necessary to achieve single-digit MTTR. This automation will increasingly be agentic.</li>
<li>This must be delivered as a platform to remove seams and gaps created by point solutions.</li>
<li>Assess and act as quickly as possible.</li>
</ul>
</li>
</ol>
<h2><a id="post-358811-_53ig1yx9ennr"></a>Fighting AI with AI — AI Frontier Security Innovations Coming Soon</h2>
<p>So far, frontier AI models only find new attacks, not new attack techniques. This means that with the right innovations, we can expand our use of AI to solve the security challenges that organizations are facing, and deliver what our customers need to stay ahead of the ever-evolving threat landscape, including:</p>
<ul>
<li><strong>Reimagining virtual patching with proactive, high-fidelity content updates across network, endpoint and cloud security</strong> – We expect that across open source and technology suppliers there will be a deluge of patches, and virtual patching will provide a mitigation layer necessary to give your teams time to update. We expect to roll out the first phase of capabilities very soon.</li>
<li><strong>Enhanced attack preventions, including cyber-LLM trained ML and small language models (SML) and behavior protections</strong> – Early testing with <a href="/cortex/cortex-xdr" target="_blank" rel="noopener">Cortex XDR<sup>®</sup></a> and our network security security services, such as WildFire<sup>®</sup> malware prevention, indicate high protection coverage from the types of attacks created using these new frontier AI models.</li>
<li><strong>Using these models to scan our code, applications and even security configurations</strong> – Our intention is to productize these capabilities and incorporate them into our platforms.</li>
</ul>
<h2><a id="post-358811-_q05rzlriw5dj"></a>Unit 42 — We’re Here to Help</h2>
<p>We recognize that not everyone has the capacity and/or expertise to action all of the recommendations to effectively counter frontier AI-driven risks in the short timeframe mandated by AI innovation. Our <a href="/blog/2026/04/introducing-unit-42-frontier-ai-defense/" target="_blank" rel="noopener">Unit 42 Frontier AI Defense</a> service is designed to discover and remediate your current exposure before attackers do, strengthen controls that reduce exposure and contain impact and modernize security operations so teams can detect and respond at machine speed.</p>
<p>This is a pivotal moment for our industry. While the scale of the challenge presented is real, I’m confident in our ability to solve it. We’re here to help our customers navigate this transition and ensure that as the landscape continues to evolve, the advantage remains with the defender.</p>
<p><strong><em>Forward-Looking Statements</em></strong></p>
<p><em>This blog contains forward-looking statements that involve risks, uncertainties and assumptions, including, without limitation, statements regarding the benefits, impact, or performance or potential benefits, impact or performance of our products and technologies or future products and technologies. These forward-looking statements are not guarantees of future performance, and there are a significant number of factors that could cause actual results to differ materially from statements made in this blog. We identify certain important risks and uncertainties that could affect our results and performance in our most recent Annual Report on Form 10-K, our most recent Quarterly Report on Form 10-Q, and our other filings with the U.S. Securities and Exchange Commission from time-to-time, each of which are available on our website at investors.paloaltonetworks.com and on the SEC's website at www.sec.gov. All forward-looking statements in this blog are based on information available to us as of the date hereof, and we do not assume any obligation to update the forward-looking statements provided to reflect events that occur or circumstances that exist after the date on which they were made.</em></p>
<p>The post <a href="https://www.paloaltonetworks.com/blog/2026/05/defenders-guide-frontier-ai-impact-cybersecurity-may-2026-update/">Defender&#039;s Guide to the Frontier AI Impact on Cybersecurity: May 2026 Update</a> appeared first on <a href="https://www.paloaltonetworks.com/blog">Palo Alto Networks Blog</a>.</p>
]]></content:encoded>
			    
	    		<wfw:commentRss>https://www.paloaltonetworks.com/blog/2026/05/defenders-guide-frontier-ai-impact-cybersecurity-may-2026-update/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	    
	    
	    <post-id xmlns="com-wordpress:feed-additions:1">358811</post-id>    </item>
        <item>
	<title>From WarGames to Cyberwar</title>
	<link>https://www.paloaltonetworks.com/blog/2026/05/from-wargames-to-cyberwar/</link>
	    		<comments>https://www.paloaltonetworks.com/blog/2026/05/from-wargames-to-cyberwar/#respond</comments>
	    
	<dc:creator><![CDATA[Dena De Angelo]]></dc:creator>
	<pubDate>Wed, 13 May 2026 13:00:16 +0000</pubDate>
		<dcterms:extent>6</dcterms:extent>
	<enclosure url="https://www.paloaltonetworks.com/blog/wp-content/uploads/2026/05/threat-vector-rsa_Allie_blog.jpg" type="image/jpeg"  length="604517"/>
	    		<category><![CDATA[AI Security]]></category>
		<category><![CDATA[Points of View]]></category>
		<category><![CDATA[national security]]></category>
		<category><![CDATA[podcast]]></category>
		<category><![CDATA[Threat Vector]]></category>
	<guid isPermaLink="false">https://www.paloaltonetworks.com/blog/?p=358730</guid>

	    		<description><![CDATA[<p>Code War author Allie Mellen explains how nations hack, why attribution fails, and what AI changes in cyberwarfare. Learn why "Fighting AI with AI" is the only effective defense.</p>
<p>The post <a href="https://www.paloaltonetworks.com/blog/2026/05/from-wargames-to-cyberwar/">From WarGames to Cyberwar</a> appeared first on <a href="https://www.paloaltonetworks.com/blog">Palo Alto Networks Blog</a>.</p>
]]></description>
						<content:encoded><![CDATA[<h1><a id="post-358730-_vu7eu1f8k3an"></a><em>How Nations Hack, Why Attribution Fails, and What AI Changes</em></h1>
<h4><a id="post-358730-_xhow1xbkz669"></a>Executive Summary:<br />
<em>Code War</em> author Allie Mellen, argues that cyberwarfare must be understood through a human and geopolitical lens to close the knowledge gap between the security community and the public.</h4>
<p><em>Disclaimer:<br />
This post reflects the perspectives shared in the book Code War: How Nations Hack, Spy, and Shape the Digital Battlefield, and does not represent the views of the publisher of this blog.</em></p>
<hr />
<p>The summer of 1983, President Reagan watched <em>WarGames</em> at Camp David and couldn't get it out of his head. A week later, he walked into a White House meeting with cabinet members and Congress and launched into a detailed plot summary of a Matthew Broderick movie about a teenager who nearly hacks the world into nuclear war. The room full of defense experts sat uncomfortably, suppressing smirks. Then Reagan turned to General John Vessey, Chairman of the Joint Chiefs, and asked if something like that could actually happen.</p>
<p>Vessey came back a week later with an answer: "Mr. President, the problem is much worse than you think."</p>
<p>Fifteen months after that, Reagan signed a classified presidential directive titled "National Policy on Telecommunications and Automated Information Systems Security" – the first federal policy of its kind. A movie had done what years of expert warnings hadn't: It made the most powerful person in the world stop and ask the right question.</p>
<p>Allie Mellen, author of <em>Code War: How Nations Hack, Spy, and Shape the Digital Battlefield</em>, loves to tell this story, and it captures exactly why she wrote the book. In a <a href="https://thecyberwire.com/podcasts/threat-vector/113/notes" rel="nofollow,noopener" >conversation recorded at RSA 2025</a>, Mellen joined Threat Vector host, David Moulton, to talk about nation-state threats, attribution pitfalls, and why the security industry's biggest problem isn't technical.</p>
<blockquote>
<p style="text-align: center;">"They're human stories, and if we can communicate them that way to the general public, then we'll get more people interested in cybersecurity, invested in cybersecurity, and invested in protecting their data."</p>
</blockquote>
<p>That gap, between what the security community understands and what everyone else grasps, is the core problem Mellen set out to solve. And in today's geopolitical moment, closing it has never been more urgent.</p>
<h2><a id="post-358730-_z3eldi81of1q"></a>Every Nation Hacks Differently</h2>
<p>One of the central arguments in <em>Code War</em> is that you can't understand a nation's cyber behavior without understanding its history, doctrine and social contract. China, Russia, Iran, North Korea and the U.S. each approach offensive and defensive cyber operations from completely different starting points, and those differences matter enormously to defenders.</p>
<p>China operates with patience. Its attacks tend to be low and slow, focused on long-term espionage rather than loud disruption. But that changes sharply in its own region, where operations targeting Taiwan are aggressive and relentless. Russia, by contrast, is bombastic; they want you to know it was Russia. Its influence operations have been some of the most effective in modern history, studied and imitated by Iran and others.</p>
<p>Interestingly, the very system China built to protect itself has become a liability in one specific domain. Because Chinese operators live behind the Great Firewall, without access to western social media, they lack the cultural fluency that makes Russian disinformation so effective. "They try to use memes, but it's like ‘uncanny valley’," Mellen explains. "They just slightly miss every time and so it doesn't go viral." The walled garden that gives China control over its own population makes it harder to manipulate everyone else's.</p>
<h2><a id="post-358730-_ewfic8pqtjp5"></a> Attribution Is a Geopolitical Tool, Not Just a Technical One</h2>
<p>Mellen is careful about attribution, and she wants defenders to be too. The standard technical signals (coding language, infrastructure patterns, operational hours) are necessary but not sufficient. Nation-states, especially the U.S., have developed tools specifically designed to mimic other actors' signatures. AI will make that problem significantly worse.</p>
<p>But the bigger issue is motivation. Mellen walks through a case from the Olympics where an attack was initially attributed to North Korea, even though North Korea was actively trying to normalize relations at the time by sending Kim Jong Un's sister to the games. The actual perpetrator was Russian, using a false flag to obscure its involvement. The lesson: Attribution requires asking not just "who has the technical capability?" but "who has the motive right now, given everything happening geopolitically?"</p>
<p>The pitfalls are real:</p>
<ul>
<li>Tools once used exclusively by intelligence agencies are now publicly available, making code signatures unreliable.</li>
<li>Working-hours analysis is easy to spoof, especially for sophisticated actors.</li>
<li>Government-controlled research in adversarial nations can deliberately skew attribution findings.</li>
<li>False flag operations are increasingly sophisticated and harder to disentangle.</li>
</ul>
<h2><a id="post-358730-_h94xjz6hb2x0"></a> Why Your Data Is a Geopolitical Asset</h2>
<p>One of the more powerful sections of the conversation centers on a question Mellen hears constantly: why would China care about my data?</p>
<p>Her answer cuts through the dismissiveness. These nations aren't collecting data out of idle curiosity. They're willing to constrain companies for it, invest billions in infrastructure for it, and in some cases, far worse. "Whether you wanna be involved in that system or not, you are involved in that system," she says. "And so you can either choose to take control of your information in that environment, or you can just pretend like it's not your problem."</p>
<p>The historical context she offers is striking. One of the driving forces behind GDPR in the EU was the collective memory of how Nazi Germany used data to target Jewish people during the Holocaust. Europe built privacy protections into law because it had seen what happens when governments gain unrestricted access to population data. That's not an abstract concern. It's a lesson written in history that the rest of the world is still catching up to.</p>
<h2><a id="post-358730-_xzkd4xi3c6if"></a> AI Makes Everything Harder</h2>
<p>Mellen isn't optimistic about the trajectory. Attribution is about to get much harder. Attacks are about to get much more dynamic. And AI is the reason for both.</p>
<p>She points to research on Chinese state-sponsored actors using AI to orchestrate attacks across the full kill chain, with only a couple of human checkpoints in the loop. The implication isn't just faster attacks. It's more adaptive malware that can adjust to different operating environments, more convincing disinformation that clears the cultural context bar, and reconnaissance-to-exploitation cycles that move faster than most defenders can process.</p>
<p>The constraints that have always slowed sophisticated attackers – understanding the operating system, identifying vulnerabilities, crafting exploits, mimicking attribution – all get easier with AI. All of that becomes more dynamic. And most enterprises, Mellen acknowledges, are not yet equipped to respond effectively.</p>
<p>The investment required is in the basics the industry has always struggled to get right, executed now at a pace and scale that demands automation and AI on the defensive side. <a href="/blog/2026/05/how-long-it-takes-to-lose-data/">Fighting AI with AI</a> isn't a vendor talking point. It's the only math that works.</p>
<h3><a id="post-358730-_xqqlon8tws8n"></a> More to Explore</h3>
<p>The nation-state threats Mellen describes aren't theoretical. Unit 42 responded to more than 750 major incidents in 2025. See what they found. <a href="/resources/research/unit-42-incident-response-report">Download the 2026 Global Incident Response Report.</a></p>
<p><em>Listen to the full conversation with Allie Mellen, author of Code War, on </em><a href="https://thecyberwire.com/podcasts/threat-vector/113/notes" rel="nofollow,noopener" ><em>the Threat Vector podcast</em></a></p>
<p>The post <a href="https://www.paloaltonetworks.com/blog/2026/05/from-wargames-to-cyberwar/">From WarGames to Cyberwar</a> appeared first on <a href="https://www.paloaltonetworks.com/blog">Palo Alto Networks Blog</a>.</p>
]]></content:encoded>
			    
	    		<wfw:commentRss>https://www.paloaltonetworks.com/blog/2026/05/from-wargames-to-cyberwar/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	    
	    
	    <post-id xmlns="com-wordpress:feed-additions:1">358730</post-id>    </item>
        <item>
	<title>Idira — Our Journey to Democratize Privilege Controls</title>
	<link>https://www.paloaltonetworks.com/blog/2026/05/idira-journey-democratize-privilege-controls/</link>
	    		<comments>https://www.paloaltonetworks.com/blog/2026/05/idira-journey-democratize-privilege-controls/#respond</comments>
	    
	<dc:creator><![CDATA[Peretz Regev]]></dc:creator>
	<pubDate>Tue, 12 May 2026 13:55:39 +0000</pubDate>
		<dcterms:extent>8</dcterms:extent>
	<enclosure url="https://www.paloaltonetworks.com/blog/wp-content/uploads/2026/05/idira-blog-2.jpg" type="image/jpeg"  length="294611"/>
	    		<category><![CDATA[AI Governance]]></category>
		<category><![CDATA[AI Security]]></category>
		<category><![CDATA[Announcement]]></category>
		<category><![CDATA[Products and Services]]></category>
		<category><![CDATA[Idira]]></category>
		<category><![CDATA[Next-Generation Trust Security]]></category>
	<guid isPermaLink="false">https://www.paloaltonetworks.com/blog/?p=358271</guid>

	    		<description><![CDATA[<p>Introducing Idira: The AI-Driven Identity security platform. Extend Zero Standing Privilege to every human, machine, and AI agent identity in your enterprise.</p>
<p>The post <a href="https://www.paloaltonetworks.com/blog/2026/05/idira-journey-democratize-privilege-controls/">Idira — Our Journey to Democratize Privilege Controls</a> appeared first on <a href="https://www.paloaltonetworks.com/blog">Palo Alto Networks Blog</a>.</p>
]]></description>
						<content:encoded><![CDATA[<h4>Key Takeaways</h4>
<ul>
<li>Built on the Pioneers of PAM (privileged access management): Idira<img src="https://s.w.org/images/core/emoji/17.0.2/72x72/2122.png" alt="™" class="wp-smiley" style="height: 1em; max-height: 1em;" /> is Palo Alto Networks next-generation identity security platform, extending privileged access controls to every human, machine and AI agent identity in the AI enterprise.</li>
<li>Zero Standing Privilege by Default: Idira replaces static, always-on access with dynamic privilege, granted just-in-time on a single control plane.</li>
<li>AI-Driven Identity: AI runs natively inside Idira to surface hidden entitlements, unmanaged accounts, recommend least privilege, and remediate to close the gap between attackers who move in 72 minutes and defenders who historically took days.</li>
</ul>
<hr />
<p>Since Palo Alto Networks and CyberArk came together in February, customers have been asking me the same question: What does the future of identity security actually look like?</p>
<p>At <a href="https://www.youtube.com/watch?v=mX-fSV7vMEw" rel="nofollow,noopener" >IMPACT</a>, I got to answer that question.</p>
<p>I am proud to introduce <strong>Idira<img src="https://s.w.org/images/core/emoji/17.0.2/72x72/2122.png" alt="™" class="wp-smiley" style="height: 1em; max-height: 1em;" /></strong>, the next-generation <a href="/idira">identity security platform</a> from Palo Alto Networks. Idira secures every identity in the AI enterprise (human, machine, AI agent) on a single control plane that discovers risk, applies privilege dynamically, and governs the full lifecycle from first access to last session.</p>
<p>Idira begins with a belief shaped by more than 20 years of working on this problem. <em>Privilege is the most challenging aspect of identity security.</em> For a generation, the industry learned how to manage it well for a small population – administrators inside the most security-sensitive organizations in the world. That was necessary. But it is no longer enough.</p>
<p>The moment has come to extend that same rigor to every identity, because every identity today carries the power to move the business, or enable an attacker. That is the journey Idira takes us on. From privilege controls for administrators, to privilege controls for every identity.</p>
<h2><a id="post-358271-_yrul2ovum90s"></a><strong>Attackers Are Not Breaking In. They Are Logging In.</strong></h2>
<p>For most of the last two decades, identity security was built on a comfortable assumption: One can maintain a firm divide between a small number of powerful administrators and a much larger number of ordinary users; that is enough to secure the organization. That assumption no longer holds.</p>
<p>Our Chairman and CEO, Nikesh Arora, calls it the “IAM fallacy,” and the data in the 2026 Identity Security Landscape Report makes clear why it is time to retire this assumption.</p>
<p>Based on <a href="http://paloaltonetworks.com/idira/identity-security-landscape-report">responses from 2,930 cybersecurity decision-makers</a> worldwide:</p>
<ul>
<li>Machine identities now outnumber humans by 109 to 1. Of those, 79 are AI agents.</li>
<li>91% of organizations already run autonomous agents in production.</li>
<li>90% of organizations suffered an identity-related breach in the past 12 months. 83% of organizations suffered two or more incidents.</li>
</ul>
<p>The old model is not failing because identity became less important. It is failing because identity and privilege became universal and ubiquitous.</p>
<p>Every major breach I have studied over the last two years follows the same pattern. An attacker steals a credential. They move laterally using standing access that should have expired. They escalate privilege. They reach the data, the infrastructure or the business systems they came for: Okta, MGM, Microsoft. Different industries. Different scales. The same pattern.</p>
<p>One overprivileged identity unlocks the entire enterprise.</p>
<p>And when defenders have a chance to respond, they are already behind and disadvantaged. 97% of practitioners tell us that fragmented tools add 12 hours to every identity incident response time. All while <a href="https://unit42.paloaltonetworks.com/">Unit 42<sup>®</sup></a> has observed the fastest attackers move from a first foothold to exfiltration in as little as 72 minutes.</p>
<p>Identity is now the enterprise perimeter. And the perimeter was built for a threat model that no longer exists.</p>
<h2><a id="post-358271-_3bdncp70fkb4"></a><strong>Every Identity Is Privileged — Idira’s First Fundamental Principle</strong></h2>
<p><strong>The premise of Idira is simple. Every identity in your organization is privileged. </strong></p>
<p>Every login, every token, every service account, every workload, every AI agent can trigger a workflow, call an API, or reach sensitive data. Some can create and destroy infrastructures, direct organizational spend, or create new identities. Privilege is no longer reserved for a small class of administrators. It is distributed across the enterprise, quietly and continuously, every second of the day.</p>
<p>The controls that protect privilege cannot be reserved for the few, either.</p>
<p>Idira changes three things from day one.</p>
<h3><a id="post-358271-_84ltj7le11rf"></a>First, We Discover</h3>
<p>Idira continuously finds every identity, every entitlement and every access path across your entire environment: humans, machines, workloads, secrets, certificates and AI agents everywhere – on the network, in the cloud, on servers and endpoints, in the browser. If someone or something can authenticate, Idira knows it is there, knows what it can reach, and evaluates how much of that access is actually necessary.</p>
<h3><a id="post-358271-_hy3udyg1l2i3"></a>Second, We Control</h3>
<p>Idira replaces static, always-on accounts attackers rely on with dynamic privileges that exist only in the moment of use. Zero standing privilege moves from aspiration to default, and it applies equally to the administrator logging into production, the developer deploying code, and the AI agent calling a tool. This is the shift to identity-centric active security.</p>
<h3><a id="post-358271-_24p45dclw5d0"></a>Third, We Govern</h3>
<p>Idira automates the identity lifecycle end-to-end. Governance stops being a quarterly compliance exercise and becomes a continuous enforcement loop. The 12-hour fragmentation tax closes.</p>
<p>This is what I mean when I say we are democratizing privilege controls. We are not loosening them. We are extending the strongest privilege controls the industry has ever built to every identity that now carries the weight of the business, without penalizing these identities for the powers they carry.</p>
<h2><a id="post-358271-_31nuceqiza1z"></a><strong>Already Better Together</strong></h2>
<p>Idira is not launching into an empty runway. We have been executing against this roadmap since the day we joined Palo Alto Networks, and the early results give us real confidence in what comes next.</p>
<p>Earlier this year at the RSA Conference, we launched <a href="/network-security/next-gen-trust-security">Next-Generation Trust Security</a> (NGTS), the first network-native platform to automate certificate lifecycle management and accelerate post-quantum readiness. That matters because 71% of organizations have not yet automated certificate renewal. As public TLS lifetimes compress to 47 days and manual workloads multiply, that gap becomes more than an operational burden. It becomes a business continuity risk.</p>
<p>NGTS closes it in the network itself.</p>
<p>As one of the core platforms of Palo Alto Networks along with Strata<sup>®</sup> and Cortex<sup>®</sup>, Idira is providing deep identity integrations across the entire portfolio to enhance platform value for customers. Prisma<sup>®</sup> Browser<img src="https://s.w.org/images/core/emoji/17.0.2/72x72/2122.png" alt="™" class="wp-smiley" style="height: 1em; max-height: 1em;" /> delivers privileged access directly in the place where enterprise users work. Prisma AIRS<img src="https://s.w.org/images/core/emoji/17.0.2/72x72/2122.png" alt="™" class="wp-smiley" style="height: 1em; max-height: 1em;" /> 3.0 natively <a href="/prisma/agent-security">integrates with Idira</a> to extend deep identity security and privilege controls to AI agents. <a href="/cortex">Cortex</a> will receive first-party identity signals to sharpen detection and take automatic identity- and privilege-driven response actions when indicators of compromise are detected.</p>
<p>Customers are already seeing the impact. <a href="/customers/northern-trust">Northern Trust</a> improved password compliance by 137 percent. <a href="/customers/panasonic-information-systems">Panasonic Information Systems</a> rebuilt its security operations around identity. <a href="/customers/healthfirst">Healthfirst</a> grounded its zero trust program in identity-first controls. PDS Health secured clinical access for more than 900 practices. They had different problems with the same answer.</p>
<p>Different challenges. One answer. One platform. Consistent privilege controls applied to every identity that matters.</p>
<h2><a id="post-358271-_xpvev5cfn7sf"></a><strong>AI Makes This Urgent. AI Makes This Possible.</strong></h2>
<p>AI has changed the speed, scale and economics of identity risk.</p>
<p>Frontier models have crossed a threshold. Anthropic's Claude Mythos Preview has already identified thousands of zero-day vulnerabilities across the operating systems and browsers that businesses rely on every day. Every exposed secret, every standing admin path, every forgotten service account can now be discovered, validated and weaponized faster than most security teams can respond. 55% of the decision-makers in our 2026 survey named AI-enabled threats as their top identity concern.</p>
<p>Our answer is clear: <a href="/perspectives/weaponized-intelligence/">We fight AI with AI</a>.</p>
<p>If frontier models are rewriting the economics of attack, the only credible response is to rewrite the economics of defense with the same technology.</p>
<p>Idira is how we do that in identity. AI is built into the platform to surface hidden entitlements, identify risky access combinations, recommend the least privilege automatically, and drive surgical remediation. That same intelligence lets attackers find the weakest link in 72 minutes and helps defenders close it in seconds.</p>
<p>When code cannot be patched fast enough, identity becomes the control plane that can still adapt at machine speed.</p>
<h2><a id="post-358271-_nc5u9idnbov3"></a><strong>Same Mission, Stronger Together</strong></h2>
<p>For more than two decades, the pioneers of privileged access have management-built controls trusted to safeguard the world's most critical environments. That mission created a category and earned the trust that made today possible.</p>
<p>Idira carries that mission forward and expands it to match the scale of the problem we now face.</p>
<p>This is the first wave, not the last. The roadmap extends privilege controls to workforce identity, advances machine and agentic identity security, and unifies a fragmented market into one platform. We are building it in the open, shaped by the customers in the room with us at IMPACT and by the realities they face every day.</p>
<p>The future of identity security will not be defined by access alone. It will be defined by control. See what <a href="/idira">Idira</a> is built to deliver.</p>
<p><div class="styleIt" style="width:560px;height:315px;"><lite-youtube videoid="mX-fSV7vMEw" ></lite-youtube></div><br />
<strong><em>Forward-Looking Statements </em></strong></p>
<p><em>This blog contains forward-looking statements that involve risks, uncertainties and assumptions, including, without limitation, statements regarding the benefits, impact, or performance or potential benefits, impact or performance of our products and technologies or future products and technologies. Any unreleased services, integrations or features (and any services or features not generally available to customers) referenced in this or other press releases or public statements are not currently available (or are not yet generally available to customers) and may not be delivered when expected or at all. Customers who purchase Palo Alto Networks applications should make their purchase decisions based on services and features currently generally available.</em></p>
<p>The post <a href="https://www.paloaltonetworks.com/blog/2026/05/idira-journey-democratize-privilege-controls/">Idira — Our Journey to Democratize Privilege Controls</a> appeared first on <a href="https://www.paloaltonetworks.com/blog">Palo Alto Networks Blog</a>.</p>
]]></content:encoded>
			    
	    		<wfw:commentRss>https://www.paloaltonetworks.com/blog/2026/05/idira-journey-democratize-privilege-controls/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	    
	    
	    <post-id xmlns="com-wordpress:feed-additions:1">358271</post-id>    </item>
        <item>
	<title>A New Era of Security: Frontier AI Defense</title>
	<link>https://www.paloaltonetworks.com/blog/2026/05/frontier-ai-defense/</link>
	    		<comments>https://www.paloaltonetworks.com/blog/2026/05/frontier-ai-defense/#respond</comments>
	    
	<dc:creator><![CDATA[Sam Rubin]]></dc:creator>
	<pubDate>Thu, 07 May 2026 21:45:24 +0000</pubDate>
		<dcterms:extent>4</dcterms:extent>
	<enclosure url="https://www.paloaltonetworks.com/blog/wp-content/uploads/2026/05/PANW-Blog-FrontierAIDefense-1-e1778178721523.jpg" type="image/jpeg"  length="154153"/>
	    		<category><![CDATA[AI Security]]></category>
		<category><![CDATA[Announcement]]></category>
		<category><![CDATA[Products and Services]]></category>
		<category><![CDATA[Unit 42]]></category>
		<category><![CDATA[Unit 42 Frontier AI Defense]]></category>
	<guid isPermaLink="false">https://www.paloaltonetworks.com/blog/?p=358502</guid>

	    		<description><![CDATA[<p>Palo Alto Networks introduces Frontier AI Defense to counter autonomous AI cyber threats. Get continuous protection and autonomous remediation against machine-speed attacks.</p>
<p>The post <a href="https://www.paloaltonetworks.com/blog/2026/05/frontier-ai-defense/">A New Era of Security: Frontier AI Defense</a> appeared first on <a href="https://www.paloaltonetworks.com/blog">Palo Alto Networks Blog</a>.</p>
]]></description>
						<content:encoded><![CDATA[<p>For the last several months, we have had early, unbounded access to the latest frontier AI models. What we’ve seen from that vantage point has made it clear that the window for organizations to get ahead of what’s coming is shorter than most leaders realize.</p>
<p>We have moved past the era of incremental AI improvements into a threat landscape shift. Our testing has revealed a step-change in capability that demonstrates an intuitive understanding of software vulnerabilities. This is more than faster code generation, it is a shift from AI as an assistant to AI as an autonomous agent capable of discovering and chaining flaws at a scale that most defenders aren’t prepared for.</p>
<p>These capabilities will not stay confined to controlled environments for long. When Mythos first launched, we <a href="/blog/2026/04/defenders-guide-frontier-ai-impact-cybersecurity/">predicted</a> a six-month window before attackers gained access. We now believe that timeline has accelerated significantly.</p>
<p>To meet this inflection point, defense must operate at the speed of the adversary. That is why Palo Alto Networks has introduced <a href="/frontier">Frontier AI Defense</a>. This initiative unites our AI-native security platforms with Unit 42<sup>®</sup> consulting and threat expertise with strategic partners to deliver continuous protection, prioritized risk mitigation and autonomous remediation.</p>
<h2><a id="post-358502-_bepmclrs8qzq"></a>What the Threat Looks Like Now</h2>
<p>The latest frontier models, including <a href="https://openai.com/index/gpt-5-5-with-trusted-access-for-cyber/" rel="nofollow,noopener" >OpenAI’s GPT-5.5-Cyber</a>, Anthropic’s <a href="https://www.anthropic.com/glasswing" rel="nofollow,noopener" >Mythos</a> and <a href="/blog/2026/04/ai-driven-defense-anthropics-claude-opus/">Claude Opus 4.7</a>, and the specialized variants emerging across major labs, represent roughly a 50% improvement in coding efficiency over their predecessors. That number sounds incremental, but in practice, it’s the threshold at which AI crosses from a helpful assistant into an autonomous operator.</p>
<p>Based on our testing and review, we found four key developments that, taken together, redefine the modern threat landscape:</p>
<ul>
<li><strong>Vulnerability Discovery at Scale</strong>: Frontier AI is exceptionally effective at identifying vulnerabilities across massive, complex codebases. In our testing, three weeks of model-assisted analysis matched a full year of manual penetration testing, with broader coverage.</li>
<li><strong>Exploit Chaining &amp; Synthesis</strong>: What is more consequential than individual discovery is the models’ ability to think like an attacker. They link multiple lower-severity issues into single, critical exploit paths, seeing full-stack logic, including SaaS and public-facing surfaces, in ways traditional scanners cannot.</li>
<li><strong>Attack Cycle Compression</strong>: In AI-assisted scenarios, the time from initial access to exfiltration has collapsed to as little as 25 minutes. Detection and response measured in hours is no longer a viable standard; single-digit MTTR (Mean Time to Respond) is the new floor.</li>
<li><strong>The Unsupervised Attack Surface: </strong>Rapid AI development and decentralized innovation are creating a massive, unsupervised attack surface in real-time. As local AI agents become commonplace, every desktop is now effectively a server, yet most organizations lack visibility into the code their own employees are generating and deploying.</li>
</ul>
<h2><a id="post-358502-_g8v0405s8q7f"></a>Our Approach</h2>
<p>These emerging threats form the foundation of how we have architected our platform response for the agentic era – Frontier AI Defense. Our approach moves beyond traditional, reactive defense to provide a comprehensive framework built to outpace frontier-AI-enabled attackers. This initiative is defined by:</p>
<ul>
<li><a href="https://stage.paloaltonetworks.com/blog/2026/04/defenders-guide-frontier-ai-impact-cybersecurity/"><em>Advanced Access</em></a><em>: </em>We leverage early access to frontier AI models to harden defenses and simulate attacks before they reach the mainstream.</li>
<li><a href="/unit42/ai-advantage"><em>Intelligence-Led Resilience</em></a><em>: </em>Unit 42 experts leverage frontier AI to fast-track discovery and remediation of exposures at machine speed through our Unit 42 Frontier AI Defense service.</li>
<li><a href="https://stage.paloaltonetworks.com/blog/2026/04/defenders-guide-frontier-ai-impact-cybersecurity/"><em>Unified Global Ecosystem</em></a><em>: </em>We provide the scale required for global protection through our Frontier AI Alliance of elite partners, including Accenture, Armadin, Deloitte, IBM, NTT DATA, and PwC.</li>
<li><a href="/cortex/fight-ai-with-ai"><em>Machine Speed Security</em></a><em>: </em>By natively integrating Frontier AI across our platforms, we deliver the automated, real-time defense necessary to counter autonomous threats.</li>
</ul>
<h2><a id="post-358502-_fl3mhnxjqmxe"></a>The Window Is Open. It Won’t Be for Long.</h2>
<p>The capabilities we tested under early-access conditions are expected to become widely available over the next several months. Success in this new environment requires adapting your cybersecurity stack before these tools are in the hands of every adversary.</p>
<p>The threat has never been more sophisticated. The window to prepare for this shift is closing. And we're here to help secure your future at the edge of the frontier.</p>
<p>Visit <a href="/frontier">Palo Alto Networks Frontier AI Defense</a> to learn more.</p>
<p>The post <a href="https://www.paloaltonetworks.com/blog/2026/05/frontier-ai-defense/">A New Era of Security: Frontier AI Defense</a> appeared first on <a href="https://www.paloaltonetworks.com/blog">Palo Alto Networks Blog</a>.</p>
]]></content:encoded>
			    
	    		<wfw:commentRss>https://www.paloaltonetworks.com/blog/2026/05/frontier-ai-defense/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	    
	    
	    <post-id xmlns="com-wordpress:feed-additions:1">358502</post-id>    </item>
    </channel>
</rss>
