- Palo Alto Networks built NOVA, an agentic AI research system, that found 14,090 unreported vulnerabilities across 3,915 open-source projects in about two months
- Palo Alto argues the traditional patch window has already collapsed, citing an average 55-day enterprise patch lag
- The vendor introduced Advanced Virtual Patching for its firewall software, PAN-OS 12.2 Ceres , which pushes network protections before a software vendor's patch exists
Palo Alto Networks said an agentic AI system built by its Unit 42 research arm found 14,090 previously unreported software vulnerabilities across 3,915 open-source projects in two months. To fight back, the vendor is now shipping firewall software designed for a world where that kind of thing is normal.
Machines can now find and prove exploitable bugs at a scale no human team could approach, according to research from Palo Alto released Tuesday. To help security teams keep up, the vendor introduced PAN-OS 12.2 Ceres firewall software supporting Advanced Virtual Patching.
AI is slamming the patch window closed. Network operators have historically operated on the assumption that there is a usable gap between the moment a flaw becomes public and the moment attackers can weaponize it, giving operators time to patch the vulnerability. Palo Alto argues frontier AI is compressing that gap toward zero on the offensive side while leaving enterprise patch cycles roughly where they were, Palo Alto says.
"It takes anywhere from 30 to 90 days after a vulnerability is disclosed before a patch is available, and then an average of about 55 days before an enterprise typically patches," said Rich Campagna, SVP of products at Palo Alto Networks, in an interview with Fierce at the company's Palo Alto offices.
Facing that two-to-five-month defensive cycle is an attacker who can produce a working exploit the moment a flaw is public, he said. The vulnerability is even greater for factory floors and critical business applications, which can't be patched outside of scheduled maintenance windows. Often, embedded firmware cannot be patched at all.
Concern is close to universal among the customers Campagna speaks with, he said.
"There's not a CISO on the planet that is not interested in solving this problem. To this point in time, there has been no real way," Campagna said.
The theoretical case got a demonstration last month. Hugging Face said that on July 16 that an autonomous agent system had broken into part of its production infrastructure. Five days later OpenAI identified the attacker as its own models.
Unit 42 is the security consulting, threat intelligence and incident response organization Palo Alto Networks operates. It built a pipeline called the Network and Open-Source Vulnerability Analyzer, or NOVA. Across 3,915 projects in six ecosystems it produced 14,090 confirmed findings.
What Advanced Virtual Patching does that virtual patching didn't
Conventional virtual patching writes a signature after a vulnerability is disclosed. Palo Alto says its Advanced Virtual Patching is designed to deploy protection before disclosure, using vulnerabilities Palo Alto Networks discovers itself through NOVA and vulnerabilities that partner software vendors pre-disclose to the company ahead of public release. The company said it built a new detection engine, which it calls "vaulted protection," to distribute those protections without leaking the underlying flaw.
The company said protection can be in place within hours, against an industry-average 55 days to deploy a traditional patch, and that it arrives as a PAN-OS software upgrade with automatic content updates. The update requires no new hardware, no reboot, no maintenance window, Palo Alto said.
Palo Alto's direction aligns with industry trends. As AI becomes the engine of cybercrime, defenders must deploy AI-powered security to protect against attackers operating at industrial scale.
When attackers skip the domain name
Another new Ceres capability, Advanced IP Defense, targets a shift in how attackers move traffic. Most enterprise network controls were built to inspect domains and URLs, the addressing layer of the web. Attackers have started bypassing that layer entirely and connecting straight to IP addresses, where there is no domain for a domain-based control to catch. Inbound traffic often arrives from compromised consumer devices sitting on residential ISP connections that no blocklist flags as malicious, Campagna said. Outbound, malware that once called home to a known bad domain — and then to rapidly rotating domains — now simply calls an IP address directly.
Palo Alto Networks said Advanced IP Defense draws real-time intelligence on attacker infrastructure from telemetry across more than 70,000 customers and blocks that infrastructure inline. Additionally, the protection applies a zero-trust test to each connection, validating that the destination maps to a legitimate DNS resolution rather than trusting an IP address's past reputation. And it scores traffic against more than 40 security attributes, letting administrators cut off what the company calls the internet's "bad neighborhoods."
AI agents never sleep
Also included in Ceres are six AI agents covering covering major network-administration functions, including onboarding, configuration, threat assessment and troubleshooting. The agents are trained on enterprise context and operational workflows and are meant to absorb the routine, repetitive work that fills an admin's day, the company said. Network operators can configure the agents to provide human oversight.
Agents keep going where humans need to take breaks, Anupam Upadhyaya, Palo Alto SVP, products, SASE and network security, told Fierce.
"Humans sleep. Agents do not," Upadhyaya said. "I can fire up an agent, go home, and it's going at it, going at it, going at it."
Q-Day protection
Ceres also beefs up quantum encryption protection. Palo Alto Networks expects Q-Day, the date when quantum computing grows advanced enough to break conventional encryption, within three to four years. In April, Cloudflare predicted Q-Day will arrive by 2029.
For protecting against Q-Day, the harder problem is inventory, not algorithms, Campagna said. Quantum-proof encryption algorithms are attainable; the more difficult problem is protecting all the assets on the network. For assets that will never be upgraded, such as such as embedded devices, OT systems and internally developed applications, the company built what he called a cipher translation proxy: isolate the device on a segment where it can only talk to a Palo Alto Networks firewall, let it speak pre-quantum crypto to that firewall, and have the firewall present post-quantum ciphers to everything else in real time.
AT&T Business is working with Palo Alto Networks on quantum security. The two companies have built what they call a Quantum-Resilient SASE Fabric, pairing Palo Alto's Prisma SD-WAN with AT&T's global network, the companies said in a July blog post.
Learn more about security
Q-Day just got closer — you need to be ready by 2029, Cloudflare says
AI vs. AI is the new security battleground
Spontaneous AI is about to upend security
Zero trust for AI agents: SASE vendors race to secure non human users