< ciso
brief />
Tag Banner

All news with #palo alto networks tag

242 articles

AI-Enabled Malware: Prevalence, Detection, and Trends

🛡️ Palo Alto Networks Unit 42 analyzed 405 AI-integrated malware samples to measure real-world prevalence and detection efficacy. The dataset spans proof-of-concept code, security testing submissions, and AI-branded malware, but only 12 samples appeared on Cortex XDR-protected endpoints. Existing layered defenses — including behavioral analytics, WildFire sandboxing, and endpoint telemetry — detected and blocked all observed production samples.
read more →

Communication Channels and Identity Risks in SaaS Era

🛡️ Enterprise collaboration platforms are now central to business workflows and have become part of the identity attack surface. Threat actors increasingly misuse trusted collaboration tools for identity phishing, impersonation, credential theft and malware delivery, often leveraging compromised accounts, external federation or guest access. Unit 42 observations show a significant rise in malicious activity tied to collaboration tools, and defenders may lack visibility into actions that occur after authentication. The report reviews techniques attackers use and offers detection and mitigation guidance, noting enhanced protection through Palo Alto Networks products.
read more →

Palo Alto Networks: Four-Time Leader in SASE and SSE

🚀 Palo Alto Networks announced it was named a Leader in Gartner’s 2026 Magic Quadrants for both SASE and SSE, the fourth consecutive year it has achieved this distinction. The company highlights its Prisma Access and Prisma SASE platforms as leading in execution and vision, and emphasizes AI-driven defenses and agent-aware security to address emerging risks from GenAI and Frontier AI. Palo Alto cites growth metrics and customer adoption to validate its strategic direction.
read more →

Prisma AIRS Integrates with OpenAI Codex

🔒 Palo Alto Networks announces native integration of Prisma AIRS Runtime API with OpenAI Codex, enabling centralized, API-level security controls for developer workflows. The integration inspects developer inputs and prevents sensitive data leakage without requiring client-side hooks, preserving developer productivity in Codex. SecOps benefit from consistent policy enforcement, audit-ready logging, and organization-wide visibility through the Codex Enterprise Management UI.
read more →

Unified Browser and Endpoint Security Integration

🛡️ Palo Alto Networks announces native integration between Prisma Browser and Cortex XDR, closing critical SOC visibility gaps by turning the browser into an active security sensor. This integration feeds browser telemetry—DLP violations, tampering, and configuration changes—directly into Cortex, enabling correlated alerts and precise, surgical containment without disrupting user productivity. The approach avoids brittle extensions and provides deep, real-time context for investigations.
read more →

Report: Passkey weaknesses expose account takeover risks

🔒 A Palo Alto Networks Unit 42 report details how attackers can exploit onboarding, recovery and device-trust workflows to bypass passkey protections after compromising an endpoint. Analysts stress the underlying cryptography remains intact but warn implementations, synced passkeys and support processes create practical risks. Experts advise enforcing user verification, preferring device-bound authenticators and improving incident response.
read more →

Enterprise passkey risks from malware and weak processes

🔒 A Palo Alto Networks Unit 42 report details how malware on compromised endpoints can abuse onboarding, recovery and device-trust workflows to defeat passkey protections. The research outlines three attack categories—Pass-ta-key, Silver Pass-ta-key and Golden Pass-ta-key—that enable account takeover or mass extraction of synced passkeys. Experts emphasize these are post-compromise attacks that exploit implementation and procedural weaknesses rather than breaking the underlying cryptography. CISOs are advised to enforce user verification, prefer device-bound authenticators for sensitive accounts and tighten enrollment, recovery and sync policies.
read more →

Prisma AIRS Brings Unified Data Protection for Claude

🔒 Palo Alto Networks announces Prisma AIRS integration with Claude Enterprise to enforce zero-trust, real-time data protection and runtime threat inspection across Claude surfaces. The integration leverages existing Enterprise DLP policies, using an encrypted KVM to verify requests and returning synchronous allow or deny verdicts before prompts reach the model. This enables consistent governance, immediate policy updates, and consolidated auditing within existing dashboards.
read more →

XCSSET v40 Targets macOS Developers via Xcode

🛡️ Researchers at Unit 42 have uncovered a resurgence of the XCSSET macOS malware, now in version 40, which infects developers by injecting downloader scripts into compromised Xcode projects and GitHub repositories. The campaign was observed in two waves in mid-April and early May and introduces two new modules: a Chrome hijacker and a Telegram trojanizer. The malware employs enhanced evasion techniques, aggressively disables macOS protections, and propagates across Xcode projects when developers build infected code.
read more →

Redefining Network Security for the Frontier AI Era

🔒 PAN-OS 12.2 Ceres introduces Advanced Virtual Patching, Advanced IP Defense, and AI-powered Network Security Agents to confront Frontier AI–driven threats, surging traffic, and cryptographic upheaval. The release emphasizes near-zero exposure windows by using AI to discover vulnerabilities and deploy network-level protections instantly, while integrating with industry partners and Project Lightwell. These innovations aim to protect critical OT, healthcare, and IoT environments without downtime and to automate routine admin tasks via Strata Cloud Manager.
read more →

New Pass-ta-key attacks target Google synced passkeys

🔒 Security researchers from Palo Alto Networks' Unit 42 disclosed three related attacks, collectively dubbed "Pass-ta-key," that let malware on compromised Windows devices abuse Google Password Manager's synced passkeys in Chrome on TPM-equipped machines. The techniques — Pass-ta-key, Silver Pass-ta-key, and Golden Pass-ta-key — exploit weaknesses in device trust, onboarding, recovery, and synced credential handling rather than breaking passkey cryptography. While the attacks require existing malware on the victim's device, they can bypass or subvert user verification and even extract the master key that encrypts synced passkeys, enabling account takeover and future key decryption. Unit 42 reported findings to Google and affected services; some issues, such as eBay's validation, have been fixed.
read more →

Unit 42 Threat Intelligence: Contextualized Defense

🔍 Security teams need intelligence that identifies what matters, when it matters, and what to do next. Unit 42 Threat Intelligence integrates proprietary research into the Cortex platform and offers analyst-driven services to deliver contextual, actionable insights. By correlating global visibility with each customer’s environment, it converts signals into prioritized detections, hunts and response actions. This approach addresses accelerated adversary behavior amplified by AI and shortens defenders’ reaction window.
read more →

Risks and Attacks Targeting Passkey Authentication

🔒 This Unit 42 analysis examines novel attack classes against passwordless authentication, focusing on Google’s synced passkey ecosystem and the Cloud Authenticator used by desktop clients. The research demonstrates how malware on a compromised endpoint can misuse onboarding, recovery and device trust workflows to authenticate without user interaction, bypass user verification, and extract synced passkey private keys. The article outlines three attack variants—Pass-ta-key, Silver Pass-ta-key, and Golden Pass-ta-key—showing practical exploit paths on Windows Chrome with TPM-equipped devices and emphasizing mitigation via Palo Alto Networks products.
read more →

Palo Alto Networks Earns Global CBPR and PRP Certifications

🔒 Palo Alto Networks announces attainment of the Global Cross-Border Privacy Rules (CBPR) and the Global Privacy Recognition for Processors (PRP) certifications following independent third-party audits. These credentials, rooted in the APEC Privacy Framework and expanded by the Global CBPR Forum, validate that the company's data privacy practices meet international standards. This achievement supplements its existing privacy and security certifications and underscores an ongoing commitment to responsible cross-border data protection.
read more →

Qilin ransomware leverages PAN‑OS VPN flaw

🛡️ Arctic Wolf Labs investigated June 2026 intrusions where actors exploited CVE-2026-0257, a patched authentication bypass in Palo Alto Networks PAN-OS, to establish SSL VPN sessions and deploy Qilin (aka Agenda) ransomware. Post-exploitation activity varied from rapid encryption to full double-extortion, but shared tactics included staging payloads in C:\PerfLogs\, using PsExec for lateral movement, harvesting credentials, disabling Defender real-time protection, and clearing event logs.
read more →

Critical GlobalProtect VPN Bug Now Used in Ransomware

🔒 Palo Alto Networks patched a critical PAN-OS GlobalProtect authentication bypass (CVE-2026-0257) on May 13 after Rapid7 observed active exploitation from May 17. Arctic Wolf reports the Qilin ransomware gang is leveraging the flaw to gain unauthorized VPN access and deploy ransomware, with incidents in June resulting in domain-wide encryption. CISA added the vulnerability to its Known Exploited Vulnerability catalog and ordered federal agencies to remediate within three days.
read more →

Chained Zero-Day Flaws in Siemens ROX II Switches

🛡️ This Unit 42 advisory, developed in partnership with Siemens, describes a chained exploit of three zero-day vulnerabilities in Siemens ROX II OT switches. The chain (CVE-2025-40948, CVE-2025-40947, CVE-2025-40949) enables arbitrary file disclosure, root privilege escalation and persistent root execution, risking full device compromise. Siemens has issued advisories and a firmware update V2.17.1; Palo Alto Networks provides virtual patching and OT device protections.
read more →

Prisma AIRS AI Gateway Now Generally Available

🔒 Palo Alto Networks has announced the general availability of Prisma AIRS AI Gateway, an AI control plane designed to provide unified governance, identity, and runtime controls for enterprise AI interactions. The gateway sits inline between agents, AI apps, and model providers to deliver observability, policy enforcement, credential scoping, and runtime inspection. Built from Portkey innovations, it targets scale and security gaps as AI usage and outbound data volumes surge across enterprises.
read more →

Fake Microsoft Teams support call scam targets files

📢 Palo Alto Networks’ Unit 42 warns of a new campaign targeting Microsoft Teams users that begins with a survey email and a malicious PDF. If opened, victims soon receive a voice call claiming to be Microsoft Support; the fake agent requests permission to install a remote access tool and additionally deploys Ether RAT. The Trojan gives attackers full access to the compromised machine, enabling theft of sensitive information and files. Users should be cautious of unsolicited surveys and support calls.
read more →

Phantom squatting: AI-hallucinated domains abused

🛡️ Palo Alto Networks' Unit 42 warns attackers are registering AI-hallucinated domains and using them for phishing and malware distribution. The report shows models invent millions of links, many unregistered, and attackers are preemptively purchasing and cloning brand sites. Because new domains lack reputation data, they evade blocklists until damage is done. Unit 42 documents several real-world cases and offers mitigation steps for defenders and users.
read more →