
What happened
Palo Alto Networks CEO Nikesh Arora said AI vulnerability-finding models have driven talks with roughly 2,000 companies, and its own first test surfaced about 1,200 potential vulnerabilities.
Why it matters
Arora said about 60% of vulnerabilities found in testing came through Mythos, about 30% through OpenAI models, with the rest from others — evidence he says supports a multi-model approach.
What to watch
He said consolidation favors incumbents with integrated platforms and may lead customers to cut vendors over time, with changes tied to contract renewals. Watch Palo Alto's $100 million in Prisma AIRS revenue.
WHO IT HITSEnterprise security leaders and CISOs at companies running dozens of security vendors are the ones weighing consolidation and SIEM rollouts, while incumbent platform providers such as Palo Alto Networks stand to gain share as contracts come up for renewal.
Ask the AI about this article →
Summaries like this, in your inbox every morning.
Arora's remarks at a company news event center on a shift he says he is already seeing in customer conversations. After the emergence of the model he referred to as "Mythos," Palo Alto Networks tested its own environment and found about 1,200 potential vulnerabilities, then spent three to four months sorting out which findings were valid and fixing them. He said that work would previously have taken weeks or months, or been skipped entirely, and that about 2,000 companies have now been drawn into discussions involving CEOs, CIOs and chief security officers.
The internal testing also produced a claim about how models compare. Arora said about 60% of vulnerabilities identified came through Mythos, about 30% through OpenAI models, and the remainder through other models — results he said argue for using multiple models, because different ones surface different flaws. He framed those assessments as a gateway to broader talks about consolidating security products, improving response times and deploying SIEM capabilities.
What the outcome hinges on, by Arora's account, is timing and architecture. He described security operations center transformations as shorter-term projects, potentially six-month engagements, while network-security consolidation plays out as existing vendor contracts come up for renewal. He also said AI agents could help address threats "in flight," but that this becomes harder when agents from multiple suppliers must communicate — a dynamic he said favors incumbents with integrated platforms and may lead customers to reduce vendor counts over time.
For example, today's edition would include:
AI-summarized, only the topics you pick — one digest a day via Email, Slack, or Discord.
Free · 30 seconds with Google · unsubscribe anytimeWhat is AIToday? →
Ask AI anything about this article. Q&As are published on this page for other readers too.
A Digitimes piece argues corporate cybersecurity's perimeter model — firewalls at network entry points, email…

Much of the attention on AI infrastructure buildouts is now tied to sheer compute power, with dominance define…

Barron's reported September 10 that Kepler Computing emerged from stealth with a memory architecture using fer…

Dynatrace acquired Arize AI, adding AI observability, evaluation and agent monitoring to its application obser…
Reuters reported September 10 that inference-chip startup d-Matrix will use Nvidia's NVLink Fusion to connect…

A report by Spencer Kitts, Thomas Larsen and Sydney Von Arx says an OpenAI agent swarm very likely ran an atta…
