Archive for Palo Alto Networks

Palo Alto Networks NextWave Program

Posted in Commentary with tags on February 5, 2026 by itnerd

Palo Alto Networks today announced the next generation of its NextWave Partner Program, fundamentally redefining partner profitability for the AI era. As the industry moves toward AI-driven security, NextWave moves beyond transactional volume to reward partners who deliver platform-centric security outcomes.

The evolved program enables the entire partner ecosystem to move away from the ‘point-product’ trap. By focusing on platformization, Palo Alto Networks enables partners to integrate their customers’ security stacks across the network, cloud, and SOC—reducing complexity while increasing high-margin, partner-led service opportunities.

Available to partners now, the new NextWave Partner Program is built on direct feedback from the global partner community, focusing on three transformative benefits:

  • Enhancing Partner Margins: Streamlined rebates focus on Next-Generation Firewalls (NGFW), Next-Generation Security (NGS) and platformization to reward technical expertise and maximize profitability.
  • Accelerating Deal Velocity: Enhanced Configure, Price, Quote (CPQ) and new automated deal registrations, combined with improved service delivery tools, to reduce friction and speed up time to close.
  • Reinvesting For Growth: A new Partner Development Fund (PDF) reinvests earned rebates directly into partner-led demand generation, training, and solution development to drive differentiation and accelerate joint customer success.

With Tailored Paths for Every Partner:

  • Managed Security Service Providers (MSSPs): Predictable, tiered pricing to build high-margin managed services to ensure accelerated outcomes.
  • Distributors: Enhanced capabilities, governance and support for Distributor Managed Partner growth.
  • Global System Integrators (GSIs): A “Global Path” rewarding multi-theater influence and strategic consulting with a white glove experience, coming later this year.
  • Authorized Services (ASC & APS): Real-time deployment assistance to ensure “first-time-right” customer implementations.

Palo Alto Networks Completes Chronosphere Acquisition

Posted in Commentary with tags on January 29, 2026 by itnerd

As enterprises increasingly rely on AI to run digital operations, protect assets, and drive growth, success depends on one critical factor: trusted, high-quality, real-time data. Palo Alto Networks® (NASDAQ: PANW), the global cybersecurity leader, today announced it has completed its acquisition of Chronosphere addressing a core challenge of the AI era: the inability to see and secure the massive data volumes running modern businesses.

Chronosphere, a Leader in the 2025 Gartner® Magic Quadrant™ for Observability Platforms,1 was purpose-built to handle this scale. While legacy tools break down in cloud-native environments, Chronosphere gives customers deep visibility across their entire digital estate. With this acquisition, Palo Alto Networks is redefining how organizations run at the speed of AI — by enabling customers to gain deep, real-time visibility into their applications, infrastructure, and AI systems — while maintaining strict control over data cost and value.

The planned integration of Palo Alto Networks Cortex® AgentiX™ with Chronosphere’s cloud-native observability platform will allow customers to apply AI agents that can now find and fix security and IT issues automatically — before they impact the customer or the bottom line. AI security without deep observability is blind; this acquisition delivers the essential context across models, prompts, users, and performance to move from manual guessing to autonomous remediation.

The Chronosphere Telemetry Pipeline remains available as a standalone solution, enabling organizations to eliminate the ‘data tax’ associated with modern security operations. By acting as an intelligent control layer, the pipeline can filter low-value noise to reduce data volumes by 30% or more and has been shown to require 20x less infrastructure than legacy alternatives. This will be key to Palo Alto Networks Cortex XSIAM® strategy, ensuring customers can scale their security posture—not their spending—as they transition to autonomous, AI-driven operations.

New LLM Runtime Phishing Exploit – Proof of Concept from Unit 42

Posted in Commentary with tags on January 22, 2026 by itnerd

 Unit 42 has published research that raises flags on what could be the next big shift in cybercriminals leveraging LLMs for more effective phishing attacks and the next frontier of web attacks. 

Unit 42’s latest research, The Next Frontier of Runtime Assembly Attacks: Leveraging LLMs to Generate Phishing JavaScript in Real Time, details a novel technique where attackers could use LLMs to assemble phishing attacks in the browser at the moment of execution.

Why this is a game-changer for attackers:

  • Prompt-Based Obfuscation: Malicious code is hidden within text prompts to bypass network analysis, only “translating” into an attack once it reaches the browser.
  • Unique Victim Payloads: The LLM generates a unique, polymorphic variant for every individual victim, making static signatures and blocklists useless.
  • Trusted Domain Delivery: Malicious code is transmitted over legitimate LLM service domains, allowing malicious traffic to blend in with trusted API calls.
  • Bypassing Guardrails: Attackers can “jailbreak” LLM APIs to deliver malicious snippets under the guise of legitimate code.

The most effective defense against this new class of threat is runtime behavioral analysis that can detect and block malicious activity at the point of execution, directly within the browser. 

Read the blog for more details: http://unit42.paloaltonetworks.com/real-time-malicious-javascript-through-llms

Unit 42 Puts Out A Report on Cyber Threats To Watch Out For At The Winter Olympics

Posted in Commentary with tags on January 15, 2026 by itnerd

To help defenders protect their infrastructure, venues, suppliers, athletes and more, Unit 42 is releasing a new report, “Defending the 2026 Milan-Cortina Winter Games, that details the top attackers, motives and tactics to prepare for ahead of the event, including steps organizations and local governments can take to protect themselves and the games.

The report builds on Unit 42’s prior work monitoring and preparing defenders for major events – including the 2024 Paris Olympics where authorities reported 140+ cyber incidents. The embargoed report (attached) shares highlights including:

  • Threat actor types: Ransomware gangs, nation-state actors, and hacktivist groups
  • Threat actors to watch: Muddled Libra, Insidious Taurus, and Salt Typhoon
  • Tactics to guard against: Social engineering attacks, DDoS attacks, API vulnerabilities and more.
  • Tips for defenders: Zero trust, runtime security, AI-driven automation and more.

You can read the report here: https://www.paloaltonetworks.com/resources/research/unit-42-cyber-vigilance-program/2026-winter-games-milano-cortina

VVS Discord Stealer Using Pyarmor for Obfuscation and Detection Evasion

Posted in Commentary with tags on January 15, 2026 by itnerd

VS Stealer, a Python-based information-stealing malware, is targeting Discord users to steal their data, including exfiltrating sensitive information like credentials and tokens stored in their accounts.

Unit 42 has more details here: https://unit42.paloaltonetworks.com/vvs-stealer/

Martin Jartelius, AI Product Director at Outpost24, provided the following comments:

“This is in line with the “malware as a service” elements we have seen over the years. The scope is relatively slim, and the Windows-based persistence mechanisms, such as copying itself to the Start Menu autostart locations, are very noisy and not indicative of a highly sophisticated actor. That said, the analysis is still interesting, as it shows an actor making malware commercially available while using commercially available security tools themselves. While everything the malware does is mainstream, and the techniques used are somewhat dated, it once again offers a glimpse into an established and growing criminal ecosystem.”

The Unit 42 report makes for interesting reading as it gives a lot of detail as to how a campaign like this works. It’s worth your time to have a look.

The Vibe Coding Security Gap & The New SHIELD Framework From Unit 42

Posted in Commentary with tags on January 8, 2026 by itnerd

Today, Unit 42 released new analysis on vibe coding’s hidden security risks and threats. AI-assisted “vibe coding” has officially gone mainstream with 99% of organizations now using AI agents in software development (State of Cloud Security Report 2025). But while AI-assisted coding dramatically boosts speed and productivity, it is also generating insecure code faster than security teams can review or remediate it – introducing vulnerabilities, technical debt, and real-world breach risks at an unprecedented scale.

This is a serious problem and too many organizations are ignoring long-standing industry principles such as “least privilege,” sacrificing secure development standards for speed and functionality. To compound this, the rise of Citizen Developers who lack code review literacy is accelerating the deployment of insecure code and supply chain weaknesses are being introduced at worrying rates. 

To address this, Unit 42 is introducing the SHIELD framework to reintroduce secure design into AI-assisted coding.

Read the full analysis for more details.

Threat Actors Target Global Retailers with Cloud-Based Gift Card Campaign 

Posted in Commentary with tags on October 22, 2025 by itnerd

Palo Alto Networks Unit 42 has posted new research called “Jingle Thief“—a campaign in which Morocco-based threat actors are exploiting Microsoft 365 environments to conduct large-scale gift card fraud against global retail enterprises. With the holiday shopping season approaching, these operations are expected to intensify in scale and frequency.

The research details a multi-stage campaign where attackers use phishing and smishing to infiltrate retail organizations, identify and compromise those with gift card administration privileges, and ultimately issue themselves massive quantities of gift cards. These actors employ sophisticated evasion techniques—including configuring inbox rules for silent exfiltration and deletion of sent messages—that have not been publicly detailed until now.

Key insights from the research include:

  • A shift from endpoint-based intrusions to cloud-native, identity-driven attacks that leverage Microsoft 365 services.
  • How these attackers exploit trusted environments such as SharePoint, OneDrive, and Entra ID to execute large-scale gift card fraud, and evade detection for months.
  • Broader context on how financially motivated groups are adopting APT-level tactics, mirroring the persistence and stealth of nation-state actors.

You can read the research here.

Unit 42 Identifies New Major Chinese APT Group Targeting Global Diplomats & Telecoms

Posted in Commentary with tags on October 1, 2025 by itnerd

After a nearly three-year investigation, Unit 42 has identified a previously unknown Chinese state-sponsored threat actor we’ve named Phantom Taurus. This isn’t just another threat actor; their methods, tools, and relentless persistence place them in a new top tier of global threats.

What makes Phantom Taurus significant?

  • Unique and Sophisticated: They operate with entirely unique tactics and a custom arsenal of previously undocumented malware, setting them apart from all other known Chinese APTs. 
  • Dual-Mission Focus: They are surgically targeting both high-level geopolitical intelligence and entities (embassies, foreign ministries, diplomats) and critical telecommunications infrastructure. 
  • Unprecedented Persistence: This is what truly sets them apart. When most threat actors are discovered, they retreat for weeks or months. Phantom Taurus regroups and re-enters target networks within hours or days. Their mission is so critical they are willing to risk exposure to maintain access.
  • They Go for the Jugular: Instead of common phishing attacks, they meticulously research their targets and bypass users to directly compromise critical infrastructure to steal entire mailboxes or gain a persistent foothold for data collection.

This group is well-resourced, geopolitically aware, and poses a formidable, ongoing threat with a primary geographic focus on Africa, the Middle East, and Asia.

Here is the full, in-depth report detailing their custom tools, malware, and tactics: http://unit42.paloaltonetworks.com/phantom-taurus

Hackers Distribute Malicious AI Tools Through Chrome Extensions 

Posted in Commentary with tags on September 30, 2025 by itnerd

According to researchers, threat actors are distributing fake Chrome extensions posing as AI tools to hijack prompts in the Chrome search bar and then redirect queries to attacker-controlled domains and track search activity.

More info via this Github link from Palo Alto Networks:  https://github.com/PaloAltoNetworks/Unit42-timely-threat-intel/blob/main/2025-09-24-IOCs-for-AI-prompt-hijacker-extensions.txt

Davit Asatryan, VP of Research at Spin.AI, commented:

“Malicious AI-themed extensions show how attackers are quick to exploit hype to bypass user trust and enterprise defenses. What many don’t realize is that browser extensions can act like shadow IT, silently harvesting sensitive data. Organizations should treat extensions as part of their attack surface and implement continuous risk monitoring to prevent these threats before they spread.”

This underlines the fact that there are dangers with anything that gets onto your computer. Which means that you should always be wary of what you install regardless of what it is.

Palo Alto Networks Unveils Protection for Highly Evasive Threats with Prisma Browser, Extending SASE Leadership

Posted in Commentary with tags on September 4, 2025 by itnerd

Today, Palo Alto Networks announced Prisma® SASE 4.0, the industry’s most advanced AI-driven secure access service edge (SASE) solution. It sets a new standard with innovations in Prisma Browser that neutralize sophisticated web threats in real-time directly within the browser, where legacy solutions have critical blind spots. It’s designed to intercept and neutralize encrypted, evasive attacks that assemble inside the browser and bypass traditional secure web gateways.

The browser is becoming the new operating system for the enterprise, the primary interface for AI and cloud applications. Securing it is not optional. As more critical applications and data reside within the browser, traditional consumer-grade browsers are no longer sufficient for businesses as they lack the necessary security controls to protect against the increasing number of cyberattacks. With Prisma SASE 4.0, Prisma Browser’s new in-browser advanced web protection identifies and neutralizes malware in real-time before it can do harm. This provides a critical layer of defense that other solutions miss.

In addition, Prisma SASE 4.0 delivers new capabilities designed to secure the modern workforce, including:

  • Unprecedented Data Security powered by AI: Prisma SASE 4.0 offers a unified, frictionless data security approach, essential for protecting against the growing risks posed by AI agents, copilots, and plugins directly accessing corporate data. It uses AI-augmented classification to automatically and precisely classify sensitive information across all formats, including unstructured content and data in use – achieving 10x fewer false positives than traditional methods. It includes over 140 pre-trained machine learning classifiers and customizable models to secure critical assets like patents, contracts and source code.
  • Smarter, Faster Protection with Private App Security: Private applications are the engine of many businesses and are prime targets for cyberattacks. Older static rule-based web application firewalls (WAF) are simply no match for threats custom-built for dynamic applications. Palo Alto Networks’ new Private App Security automatically adapts to shield these essential applications and constantly updates security policies for applications.

Palo Alto Networks continues to demonstrate market leadership and disruptive innovation in SASE, with SASE ARR reaching $1.3 billion in fiscal year 2025, growing 35% year-over-year—more than twice the rate of the overall market. For three consecutive years, Palo Alto Networks has been named a Leader in the Gartner® Magic Quadrant™ for SASE Platforms for Prisma SASE. In addition, Palo Alto Networks has been named a Leader for three consecutive years in the Magic Quadrant for Security Service Edge, and five times in the Magic Quadrant for SD-WAN. With over 6,300 SASE customers, including one-third of the Fortune 500, this single-vendor platform simplifies operations and provides a clear path to scale, with adoption of the Prisma Browser surpassing 6 million licensed seats.

These innovations and other key SASE features will be generally available later this year. To learn more, read the blog.