< ciso
brief />
Tag Banner

All news with #palo alto networks tag

259 articles

Cortex XCOR: AI-Driven Autonomous Observability

🚀 This post introduces Cortex XCOR, an AI-native observability platform from Palo Alto Networks that aims to deliver autonomous root cause analysis and remediation. The platform centers on the XCOR Operator and specialized AI agents, including an AI SRE that autonomously investigates incidents and recommends fixes. XCOR integrates full-stack telemetry with cost optimization to balance visibility and spending.
read more →

KDDI Launches SASE Gateway with SP Interconnect

🚀 KDDI Corporation has launched the "SASE Gateway powered by Palo Alto Networks" using the new SP Interconnect (SPI) architecture to directly link carrier-grade closed networks (WVS2) with Prisma SASE. The service eliminates IPsec overhead, enhances performance and flexibility for Japanese enterprises, and centralizes security management under a single policy engine. It can be extended with Cortex XDR, Prisma Browser and SOC/IR services to support AI adoption, hybrid work and cloud migration.
read more →

Palo Alto Networks Introduces CLARA Agent on Gemini

🔍 Palo Alto Networks today announced CLARA Agent, an integration that connects Strata Cloud Manager to Google Cloud Gemini Enterprise to deliver conversational, evidence-backed cloud and AI security insights. The agent discovers infrastructure, surfaces production and shadow AI/ML models, and prioritizes critical exposures and vulnerabilities. Available via Google Cloud Marketplace, CLARA Agent leverages A2A and MCP protocols to provide secure, context-aware responses without extra infrastructure, and aims to democratize visibility across cloud, platform, and AI teams.
read more →

Agentic AI and Kubernetes Operator Risks Explained

🔍 This Unit 42 report examines how Kubernetes operators’ reliance on highly privileged service accounts creates a critical security weak spot, and introduces OperTraitor, an open-source LLM-powered engine that analyzes operator RBAC configurations. The tool compares documented functionality to granted privileges and assigns a normalized risk score, revealing abandoned or overly permissive operators in registries like OperatorHub. Case studies include a High-severity CVE in IBM’s Turbonomic and an overly permissive Datadog operator configuration, and the article offers practical mitigation guidance such as verifying sources, enforcing namespace-scoped operators, and continuously auditing RBAC.
read more →

Route 53 DNS Firewall adds PANW Advanced DNS Security

🔒 Amazon Route 53 Resolver DNS Firewall now supports Palo Alto Networks Advanced DNS Security and is generally available across 32 AWS Regions. The integration lets security teams detect and block malicious DNS traffic from VPCs and hybrid environments using PANW threat rules without deploying separate firewalls or changing VPC setups. Administrators can subscribe via the Route 53 DNS Firewall console, share licenses with AWS License Manager, and associate rule groups using RAM, Route 53 Profiles, or AWS Firewall Manager.
read more →

NetScaler zero-days exploited: urgent patch guidance

🔒 Unit 42 alerts that Citrix has reported active exploitation of two critical NetScaler vulnerabilities, CVE-2026-88771 and CVE-2026-88772, both rated 9.5 on CVSS v4.0. The flaws enable unauthenticated remote code execution and a DTLS memory overflow that may cause RCE or DoS on NetScaler ADC and Gateway devices. Unit 42 urges immediate patching, system isolation, evidence preservation, and threat hunting while offering Incident Response assistance.
read more →

Securing AI Agents at Scale with NVIDIA

🔒 Palo Alto Networks and NVIDIA detail a joint architecture to secure autonomous AI agents by combining NVIDIA’s accelerated compute and secure runtime with Palo Alto Networks’ Prisma AIRS and IDIRA capabilities. The integration places governance and enforcement at the infrastructure layer, using Prisma AIRS AI Gateway on NVIDIA Vera CPUs and Prisma AIRS AI Runtime Security on NVIDIA BlueField DPUs. The design emphasizes continuous identity verification, least-privilege access, data redaction, and deep inspection to prevent unauthorized actions and privilege escalation.
read more →

Detecting and Quarantining Exposed AWS IAM Keys

🔎 This article examines how AWS mitigates publicly exposed IAM access keys through the AWSCompromisedKeyQuarantine managed policy, tracing its evolution across versions and explaining its role in responding to leaked credentials. It details the GitHub secret scanning partnership with AWS, a real-world timeline from a public exposure test, and practical monitoring strategies security teams can use to detect quarantine events in their logging environments. The piece also outlines Palo Alto Networks services that can assist organizations in assessment and incident response.
read more →

Palo Alto Networks Named Market Shaper in AI Security

🚀 Palo Alto Networks announces recognition as a ‘Market Shaper’ in Gartner’s September 2026 Emerging Market Quadrant for AI Application Security – Established Vendors. The company highlights its unified AI security platform, Prisma AIRS, which consolidates discovery, risk assessment, runtime protection, identity and access control, and governance for AI coding, enterprise AI apps, and autonomous agents. The post emphasizes avoiding fragmented point solutions and enabling secure AI adoption across organizations.
read more →

SE Labs launches PIVOT test for vendor defences

🛡️ SE Labs has launched a six-month testing program called PIVOT to evaluate how effectively cybersecurity vendors defend against major nation-state and criminal threat groups. The program runs real-world attack chains from July through October in SE Labs’ London test lab and will publish verified results in January 2027. Participants include Broadcom (Symantec, Carbon Black), CrowdStrike, Fortinet, Palo Alto Networks and Sophos. Gartner and Forrester analysts will independently verify the findings before publication.
read more →

FedRAMP Moderate for Quantum-Safe Security

🔒 Palo Alto Networks has earned FedRAMP Moderate authorization for its Quantum-Safe Security (QSS) Automated Cryptography Discovery and Inventory solution, enabling immediate federal deployment. The authorization confirms QSS meets stringent federal security requirements and helps agencies protect sensitive, unclassified data while accelerating post-quantum cryptography (PQC) transition. QSS provides continuous cryptographic discovery, risk assessment, and actionable transition capabilities without requiring new hardware.
read more →

Behavioral Clustering to Map Cloud Identities

🔍 This Unit 42 report describes a behavioral clustering model that maps functional cloud identities by extracting activity patterns from audit logs. The authors analyzed over 40,000 identities across 125 cloud environments to identify roles such as administrators, DevOps, backup services and security tooling. Using unsupervised techniques like UMAP and HDBSCAN, the model generates a behavioral map that aids scalable detection and SQ L-based heuristics for continuous visibility. The methodology is demonstrated on AWS CloudTrail and is extensible to other cloud and SaaS environments.
read more →

AI agents compress ransomware intrusion timelines

🛡️ Palo Alto Networks’ Unit 42 found an attacker using AI agents to traverse an enterprise network in under 10 hours, a process that could have taken human operators about two weeks. Agents conducted automated reconnaissance, searched code repositories for credentials, accessed secrets-management systems, and leveraged stolen cloud keys to abuse the victim’s AI services. The intrusion combined familiar MITRE ATT&CK techniques with agentic orchestration, highlighting the need for faster containment and stronger controls over non-human identities.
read more →

Palo Alto Networks joins Zendesk Startup Program

🔒 Palo Alto Networks partners with the Zendesk Startup Program to offer startups enterprise-grade browser security. The post explains how Prisma Browser for Business (PBB) protects support agents and customer data by blocking phishing, preventing data leakage, and applying tailored policies to Zendesk sessions. The program allows eligible startups to access PBB with minimal setup, helping founders build securely from day one while preserving runway.
read more →

Critical SonicWall SMA1000 Zero-Day Flaws Exposed

🛡️ SonicWall has disclosed two zero-day vulnerabilities affecting SMA1000 appliances (models 6210, 7210 and 8200v), with impacted firmware versions 12.4.3-03453 and 12.5.0-02835 (platform-hotfix) and older. The more severe issue, CVE-2026-83548, is a pre-authentication SSRF in the Appliance Work Place interface with a CVSS score of 10.0, while CVE-2026-83549 is a post-authentication RCE in the Management Console (CVSS 7.8). SonicWall advises upgrading to the latest hotfix, contacting Technical Support to hunt for IoCs, and re-imaging or redeploying appliances and resetting credentials if compromises are found.
read more →

SonicWall warns of exploited SMA1000 zero-days

🛡️ SonicWall warned customers that attackers are chaining two newly discovered SMA1000 zero-day vulnerabilities to achieve remote code execution. The first is a critical command injection flaw (CVE-2026-83548) tied to an SSRF issue in the Appliance WorkPlace, while the second (CVE-2026-83549) affects the Management Console and requires admin privileges. Affected models include SMA1000 6210, 7210, and 8200v; SonicWall urges immediate hotfix upgrades and recommends re-imaging and credential resets if compromise is suspected.
read more →

How partners can maximize cloud marketplace value

🛒 Cloud marketplaces are becoming a primary procurement route and offer partners a chance to move beyond transactions to deliver services and long-term value. Palo Alto Networks highlights the importance of meeting customers where they buy, understanding CSP commitments and leveraging the NextWave Partner Program for commercial benefits. Partners can combine platform technology with services to drive adoption, modernize infrastructure and secure emerging priorities like AI. Effective collaboration among partners, CSPs and vendor teams is key to converting marketplace opportunities into strategic customer outcomes.
read more →

AI-Enabled Malware: Prevalence, Detection, and Trends

🛡️ Palo Alto Networks Unit 42 analyzed 405 AI-integrated malware samples to measure real-world prevalence and detection efficacy. The dataset spans proof-of-concept code, security testing submissions, and AI-branded malware, but only 12 samples appeared on Cortex XDR-protected endpoints. Existing layered defenses — including behavioral analytics, WildFire sandboxing, and endpoint telemetry — detected and blocked all observed production samples.
read more →

Communication Channels and Identity Risks in SaaS Era

🛡️ Enterprise collaboration platforms are now central to business workflows and have become part of the identity attack surface. Threat actors increasingly misuse trusted collaboration tools for identity phishing, impersonation, credential theft and malware delivery, often leveraging compromised accounts, external federation or guest access. Unit 42 observations show a significant rise in malicious activity tied to collaboration tools, and defenders may lack visibility into actions that occur after authentication. The report reviews techniques attackers use and offers detection and mitigation guidance, noting enhanced protection through Palo Alto Networks products.
read more →

Palo Alto Networks: Four-Time Leader in SASE and SSE

🚀 Palo Alto Networks announced it was named a Leader in Gartner’s 2026 Magic Quadrants for both SASE and SSE, the fourth consecutive year it has achieved this distinction. The company highlights its Prisma Access and Prisma SASE platforms as leading in execution and vision, and emphasizes AI-driven defenses and agent-aware security to address emerging risks from GenAI and Frontier AI. Palo Alto cites growth metrics and customer adoption to validate its strategic direction.
read more →