Archive for Palo Alto Networks

NTT DATA and Palo Alto Networks Sign Global Strategic Alliance to Accelerate Secure AI Transformation

Posted in Commentary with tags , on August 20, 2026 by itnerd

NTT DATA and Palo Alto Networks today announced a multi-year strategic alliance designed to help organizations securely adopt AI, modernize cybersecurity, simplify complex technology environments and build cyber resilience for the AI era.

As Palo Alto Networks first strategic alliance of this kind with a global systems integrator, the agreement, which targets $1 billion in joint business by the end of three years (2029), combines Palo Alto Networks AI-powered cybersecurity platforms with NTT DATA’s consulting, engineering and managed services.

Leveraging joint engineering, co-innovation and coordinated global delivery, the alliance will help clients assess cyber risk, deploy AI securely and continuously optimize security. Through these joint solutions, clients will gain a unified approach that seamlessly spans cybersecurity strategy, implementation and managed services.

Building on the companies’ Frontier AI collaboration, the alliance brings together Palo Alto Networks Unit 42® threat intelligence with NTT DATA’s global cybersecurity expertise, AI governance and managed services. Backed by joint investments, more than 2,000 certified experts, as well as dedicated Forward Deployed Engineers, the alliance will deliver a seamless approach to streamline deployments and speed client outcomes. Through direct engineering collaboration, NTT DATA will gain early access to new platform features — further accelerating the delivery of AI security services to clients. 

Initial solutions will address the most pressing cybersecurity challenges facing clients in highly regulated and critical industries, including financial services, healthcare, manufacturing and the public sector, across six strategic transformation areas:

  • Autonomous Security Operations Center (SOC) – Modernize security operations with Agentic AI and managed services that help organizations detect, investigate and respond faster to increasingly sophisticated, machine-speed cyber threats while reducing operational complexity.
  • AI governance – Embed governance, security and risk management throughout the AI lifecycle, helping organizations manage emerging AI risks and confidently scale AI innovation with greater accountability, transparency and control.
  • Identity security –  Protect human, machine and AI agent identities, including workloads and devices, through an Identity Security Framework designed to discover, manage, secure and govern identities across the enterprise.
  • Zero Trust & SASE – Helps secure users, applications and data across an increasingly complex attack surface through a unified Zero trust and secure edge architecture, leveraging AI-driven threat detection and prevention.
  • Resilient cloud – Enables organizations to improve visibility, compliance and autonomous risk reduction across multi-cloud environments with AI-enabled security posture management and stronger governance.
  • Firewall modernization – Modernize firewall environments to reduce complexity, improve visibility and strengthen enterprise security.

NTT DATA brings world-class cybersecurity expertise to the collaboration, backed by over 7,500 cybersecurity professionals, 70+ delivery centers and 20+ Autonomous Cyber Defense Centers. Paired with Palo Alto Networks AI-powered platforms and Unit 42 threat intelligence, the alliance delivers the technology, expertise and global reach enterprise organizations need to securely deploy AI across complex environments.

Palo Alto Puts OpenAI Cyber Models to Work for Defenders

Posted in Commentary with tags on August 12, 2026 by itnerd

Today, Palo Alto Networks announced it will give defenders access to OpenAI’s leading cybersecurity-focused model, GPT-5.6 Daybreak, to help businesses find, test, and validate attack paths at machine speed. Until now, GPT-5.6 Daybreak has not been available for commercial use.

Frontier AI in cybersecurity has largely been seen as a threat defenders were racing against. Now, Palo Alto Networks’ Unit 42 is expanding its Frontier AI Defense service to bring advanced AI cyber models inside customer environments to actively simulate attacks and uncover hidden, previously unknown attack paths and create custom remediation plans before AI-enabled threat actors can exploit them.

What’s New 

Through our partnership with OpenAI, we’re expanding our Frontier AI Exposure Analysis capabilities to offer security teams: 

  • Leading cyber models: Apply the latest advanced cyber models to improve exposure discovery, testing and validation.
  • Multi-model harness: Use the right model for the right task to improve efficacy, expand coverage and optimize cost.
  • Exposure discovery: Find vulnerabilities, misconfigurations, leaked credentials, unmanaged attack surface and other posture gaps across applications and network assets.
  • Advanced adversary simulation: Actively test exploitability and validate end-to-end attack paths to understand how an attacker could compromise the environment.
  • Custom remediation plan: Prioritize the fixes that break the most important attack paths and feed those findings into existing IT, development and security workflows.

Focusing on known vulnerabilities and exploits doesn’t work anymore. Our Frontier AI Defense data found that 36% of exposures lacked known CVEs. Security teams must now match AI-powered attacks with machine-speed defense.

There’s also the blog post from Sam Rubin, SVP of Unit 42, with more details.

Researchers find hacker using DeepSeek AI to automate cyberattacks 

Posted in Commentary with tags on August 3, 2026 by itnerd

Palo Alto Networks’ Unit 42 researchers have identified a Chinese-speaking threat actor using the DeepSeek AI model with the open-source Hermes Agent framework to autonomously scan, exploit and compromise vulnerable internet-facing servers with limited human involvement.

The activity was uncovered after the attacker’s AI agent accidentally exposed its own infrastructure, revealing API keys, exploit scripts, target lists and attack logs.

According to the researchers, the AI agent operated in an autonomous “Yolo” mode that allowed it to execute commands without requiring operator approval. The system was used to identify vulnerable targets, launch exploits and automate post-exploitation tasks.

Jacob Krell, Senior Director: Secure AI Solutions & Cybersecurity, Suzu Labs Had This To Say:

“Unit 42 caught this campaign because the AI agent accidentally started a file server from the attacker’s home directory and exposed everything. API keys, exploit scripts, target lists, session logs. The competent campaigns don’t self-expose.

“This was an unsophisticated operator with poor operational security. No zero-day discovery, no zero-day deployment. Every exploit was a public proof-of-concept pulled from GitHub for known Common Vulnerabilities and Exposures (CVEs).

“The entire stack was off-the-shelf, with DeepSeek as the reasoning engine, Hermes Agent for orchestration, and FOFA, a Chinese internet asset search engine similar to Shodan, connected through a Model Context Protocol (MCP) server. In one session with no further human input, the agent surveyed deployment counts across ten product families, selected the highest-value CVE by severity score and target volume, downloaded the exploit code, and started scanning.

“A single operator in Zhuhai attempted exploitation against over 460 systems across seven CVEs. The autonomous portion failed because target-side configurations happened to block the exploit chain. Happened to. A slightly less secure default on those n8n workflow automation instances and this would be a breach disclosure, not a research paper.

“That’s the unsophisticated version with commodity tooling and public exploits. A more capable threat actor running this same workflow discovers and deploys zero-days autonomously, without a human ever reviewing the exploit chain. When that capability intersects with ICS environments, the consequences shift from data theft to physical damage.

“I’ve built a Shodan MCP integration in about 30 minutes with an AI coding agent, and industrial control system (ICS) protocol MCP servers in a couple of hours. The attacker used a jailbroken DeepSeek instance, but they didn’t need to. I run Opus 4.6 for offensive security work, and it doesn’t stop you. The older and even open-source models are plenty strong with a solid harness around them. The barrier to autonomous hacking at scale is an afternoon and an API key or a decent GPU.


“This campaign burned through public CVEs with off-the-shelf tooling and still nearly succeeded. The next iteration finds zero-days on its own. Every quarter these models get more capable and cheaper to run. Organizations that aren’t aggressively shrinking their external attack surface and investing in detection and incident response now are going to learn that from an autonomous agent instead of a research paper.”

If I were you, I would look to see if you are a potential target. Because if you don’t, your adversaries will.

Palo Alto warns of actively exploited PAN-OS firewall flaw

Posted in Commentary with tags on May 7, 2026 by itnerd

Palo Alto Networks has disclosed a critical vulnerability in multiple PAN-OS versions, tracked as CVE-2026-0300 (CVSS 9.3), that allows unauthenticated remote attackers to execute arbitrary code with root privileges on affected firewalls. The flaw is a buffer overflow vulnerability impacting the User-ID Authentication Portal service on PA-Series and VM-Series firewalls.

Palo Alto confirmed the vulnerability is being actively exploited in limited attacks, specifically targeting systems where the Authentication Portal is exposed to untrusted IP addresses or the public internet. 

Palo Alto said fixes will begin rolling out starting May 13, with additional patches planned later in the month. Until patches are available, the company is advising organizations to restrict Authentication Portal access to trusted internal networks or disable the feature entirely if not required. Prisma Access, Cloud NGFW, and Panorama are not affected.

Underscoring how critical this is, the CISA has added the vulnerability to its KEV catalog May 6th.

Jacob Warner, Director of IT, Xcape, Inc.:

   “The disclosure of CVE-2026-0300 is a sobering reminder that the network edge remains the highest-value target for state-sponsored espionage. By the time Palo Alto Networks released this advisory, the suspected threat actor CL-STA-1132 had already spent nearly a month refining their exploit, moving from failed attempts on April 9 to successful root RCE by mid-April. This is not a theoretical vulnerability; it is an active, surgical operation where attackers are using the firewall’s own nginx processes to drop tunneling tools like EarthWorm and ReverseSocks5.

   “For leadership, the takeaway is that a “critical” CVSS score on a firewall often means the attacker is already behind your lines before the alert even fires. With patches not arriving until May 13, the only viable defense is immediate exposure reduction. If your User-ID Authentication Portal is reachable from the public Internet, you are essentially providing an unauthenticated root shell to anyone with the right packet sequence. You must audit your Interface Management Profiles now: restrict portal access to trusted internal zones and ensure that “Response Pages” are disabled on all Internet-facing interfaces. In 2026, if you aren’t actively shrinking your edge attack surface, you’re just waiting for the next zero-day to do it for you.

   “This bug was a zero-day for 26 days before we even gave it a name. In the time it took us to get an advisory, the bad guys were already halfway through the Active Directory.”

Denis Calderone, CTO, Suzu Labs:

   “This one is a little different from the management interface exposures we’ve been warning about with other edge devices like Fortinet, SonicWall, and Cisco. This vulnerability is in the User-ID Authentication Portal, which is the page users hit to authenticate through the firewall. In a lot of deployments, that portal is internet-exposed on purpose because that’s how it’s designed to work. That makes the mitigation more complicated than just “take it off the internet,” because for some organizations, it’s there for a reason.

   “That said, there are a lot of environments where the exposure isn’t necessary. If your Authentication Portal is used for local captive portal authentication, guest WiFi, or BYOD segments, it only needs to be reachable from those specific interfaces. Restrict it to those zones and block everything else. If the portal serves branch offices or remote sites over SD-WAN or site-to-site tunnels, you can restrict access to known source IP ranges for those branches. You don’t need to open it to the entire internet just because some of your traffic originates externally.

   “The harder scenario is organizations using the portal for VPN-less remote authentication, where users could be connecting from anywhere. You can’t restrict by source IP in that case. Those organizations need to look at migrating remote users to GlobalProtect or Prisma Access, both of which are not affected by this CVE. If that’s not possible before May 13, enable Threat ID 510019 if you have a Threat Prevention subscription on PAN-OS, and understand that you’re carrying real risk until the patch drops.

   “Nation-state actors have had nearly a month with this one. They’ve been deploying tunneling tools and cleaning logs immediately after compromise. If your Authentication Portal has been internet-exposed, don’t just apply the workaround and move on. Assume compromise and hunt for it.”

Rajeev Raghunarayan, Head of GTM, Averlon:

   “CVE-2026-0300 is an unusual situation: active exploitation confirmed, added to KEV, and for many systems there is no patch available yet. The only immediate option is to restrict the Authentication Portal to trusted internal zones or disable it entirely. The silver lining is that the vulnerable service is not enabled by default, and organizations following best practice by keeping the Authentication Portal restricted to trusted internal networks are at much lower risk.

   “A perimeter firewall is a gateway into the environment. When the gateway is owned, access is owned. With root-level access on a perimeter control point, the concern is no longer just the vulnerable service itself, but the visibility, access, and control that position can provide into the systems behind it.

   “Even for organizations that have already applied the workaround, the important question is what was potentially exposed during that window and what activity should now be treated as suspicious.”

Given how long this has been out there, and the fact that it is being exploited, this is a drop everything and patch now sort if thing. Which is of course the worst kind of situation to be in.

Unit 42 Expands Frontier AI Defense with Armadin Partnership

Posted in Commentary with tags on May 1, 2026 by itnerd

Palo Alto Networks Unit 42 announced a partnership with Kevin Mandia‘s new offensive security company Armadin, to scale ability to identify and remediate AI-driven exposures and better protect organizations.

You can read all the details here: Unit 42 Expands Frontier AI Defense with Armadin Partnership

Unit 42 Research: Fully Autonomous AI Attacks Closer Than Ever

Posted in Commentary with tags on April 23, 2026 by itnerd

Palo Alto Networks has shared new research regarding how effective autonomous AI offensive capabilities are against cloud environments. While Unit 42 did not use frontier AI models in testing, this research is a crucial look at how powerful AI models may ultimately be weaponized in cyberspace.

Building on the November 2025 Anthropic disclosure that showed AI acting as the operator in an espionage campaign, Unit 42 answers the question: Can AI systems operate autonomously end-to-end to attack cloud environments, or do they still require human guidance?

Unit 42’s research & findings include:

  • Unit 42 created “Zealot,” a multi-agent penetration testing proof-of-concept designed to see if AI could independently take down a hardened cloud environment without any human oversight.
  • In sandboxed GCP tests, the multi-agent system autonomously executed a full attack chain, including: Server-Side Request Forgery (SSRF) exploitation, Metadata service credential theft, service account impersonation and privilege escalation and BigQuery data exfiltration.
  • AI-driven attacks have reached functional maturity and current LLMs can chain attacks with minimal human guidance. The window between initial access and data loss is shrinking as tools like Zealot leverage misconfigurations faster and more consistently than a human attacker. 
  • However, creating a purely autonomous multi-agent cyber attack was not entirely possible (manual oversight was needed to prevent the AI from irrelevant rabbit-holing).
  • Current security detection models optimized for human attack patterns will struggle to catch agent-based operations that chain actions across services in seconds.

You can read the research here: https://unit42.paloaltonetworks.com/autonomous-ai-cloud-attacks/

Unit 42 has a new service to defend against frontier AI attacks

Posted in Commentary with tags on April 20, 2026 by itnerd

The release of the newest frontier AI models marks a turning point for cybersecurity. Late last week, Palo Alto Networks chief product & technology officer Lee Klarich published a stark warning about what this means for the industry. 

Some additional context:

  • Palo Alto Networks conducted early testing of the latest frontier AI models, including Anthropic’s Mythos model as part of Project Glasswing and OpenAI’s latest models as part of the Trusted Access for Cyber program. 
  • As a result of that testing, Lee contends we are officially moving from AI-assisted threats to autonomous, AI-driven attacks. The resulting “vulnerability deluge” means human-speed security is no longer enough.
  • Palo Alto Networks launched Unit 42 Frontier AI Defense. Instead of waiting for an AI-driven attack, this new service proactively finds and validates an organization’s exposures using the latest frontier AI models before adversaries do, transforming security in the process.

You can read more here: https://www.paloaltonetworks.com/blog/2026/04/defenders-guide-frontier-ai-impact-cybersecurity/

Unit 42 researchers discover security flag in Google Vertex AI Engine

Posted in Commentary with tags on March 31, 2026 by itnerd

Palo Alto Networks Unit 42 published new research on a security flaw in Google’s Vertex AI Engine,

Unit 42 researchers found that Google Cloud’s Vertex AI Engine is giving AI agents far too much access by default. This critical discovery highlights the challenges of applying foundational security standards in the AI era.

Key Takeaways:

  • Significant Insider Threat: The research details how Google Cloud’s Vertex AI Engine is giving AI agents far too much access, by default. The report reveals that a misconfigured or compromised AI agent deployed via Google Cloud Platform’s (GCP) Vertex AI Agent Engine can be weaponized to compromise an organization’s cloud environment. This level of access constitutes a significant security risk, transforming the AI agent from a helpful tool into a potential insider threat.
  • The Big Picture: The rapid deployment of AI agents introduces a whole new class of overprivileged insiders. This comes as 90% of organizations are already facing pressure to loosen access control to support AI-driven automation.

You can read the research here:http://unit42.paloaltonetworks.com/double-agents-vertex-ai 

Unit 42 Analyzes The Use of AI in Malware

Posted in Commentary with tags on March 19, 2026 by itnerd

While less sophisticated attackers are using LLMs to help write functional malware, we’re still seeing attackers having challenges deploying local models to a target environment or embedding into a malware sample for local decision making. This research analyzes two samples of malware leveraging AI for remote decision making

  1. AI Theater: An Infostealer’s Illusory LLM Features: A trio of highly similar .NET information stealer samples that incorporate the OpenAI GPT-3.5-Turbo model via HTTP API. We will explore the implementation and assess the practical impact of its AI integration.
  2. AI-Gated Execution: Malware Dropper’s LLM-Based Environment Assessment: A malware dropper written in Golang that leverages an LLM to evaluate a system and provide a decision on whether to proceed with an infection. The sample was initially highlighted on X as a dropper for Sliver malware.

Some key takeaways:  

  • The current state of AI in malware is characterized by experimentation and uneven integration, but the potential for AI to aid in malware creation highlights a concerning issue of lowering the barrier to entry for less-skilled threat actors. 
  • Unit 42 anticipates a future where AI plays a greater role in both malware creation and execution. As local model deployment becomes more feasible, we may see malware samples with embedded AI capabilities (especially code generation) that can more dynamically adapt to their environment, evade detection and optimize malicious activities in real-time.
  • The rise of AI-assisted malware could manifest in the form of increased feature cadence and reliability. It will be crucial to monitor these advancements and develop defenses that can effectively counter an evolving AI-driven threat landscape.

You can read the research here: https://unit42.paloaltonetworks.com/ai-use-in-malware

New 2026 Global Incident Response Report from Unit 42

Posted in Commentary with tags on February 17, 2026 by itnerd

Unit 42 has published its annual Global Incident Response Report (full report available here).The report spotlights key trends from over 750 major cyber incidents managed by Unit 42 across 50 countries, and provides actionable guidance to defend against emerging and notable attack techniques.

Key data from this year’s report: 

  • AI has become a force multiplier for threat actors – Attackers moved from AI experimentation to operationalization. Unit 42 saw that with AI, exfiltration speeds for the fastest attacks increased from nearly 5 hours to just 72 minutes (a 4x increase).
  • Identity drives initial access –Identity weaknesses played a material role in nearly 90% of our investigations. Agentic identity management makes this challenge even more complex as non-human identities are often over-privileged and inconsistently monitored.  65% of initial access is driven by identity-based techniques such as social engineering, while vulnerabilities account for 22% of initial access in all attacks. 
  • Software supply chain risk has expanded to include the misuse of trusted connectivity. Attacks involving third-party SaaS applications have surged 3.8x since 2022, accounting for 23% of all attacks, as threat actors abuse OAuth tokens and API keys for lateral movement.
  • Attack complexity is increasing – 87% of intrusions span multiple attack surfaces, with as many as 10 in some complex investigations. Threats are rarely confined to a single environment, and attackers often coordinate actions across endpoints, networks, cloud services, SaaS platforms, and identity systems. This creates complexity by forcing defenders to keep visibility across all of these areas simultaneously.
  • The browser is a primary battleground – Nearly 48% of incidents included browser-based activity. That reflects how often modern attacks intersect with routine workflows like email, web access, and day-to-day SaaS use, turning normal user behavior into an attack vector.
  • Extortion is moving beyond encryption – Encryption-based extortion declined to 78% of incidents, down from 92% the year before, as more attackers skip encryption and move straight to data theft and disruption. From the attacker’s perspective, it’s faster, quieter, and creates immediate pressure without the signals defenders once relied on to detect ransomware attacks.

Additionally, Palo Alto Networks announced Managed XSIAM 2.0 (MSIAM) the managed evolution of Cortex XSIAM SOC transformation platform. As the Incident Response Report highlights, attacks can now unfold in under an hour, and MSIAM delivers 24/7 AI-driven SOC operations with continuous and high-speed threat hunting, response, and remediation.