Please, rotate your device

Mobile apps and games

AI will look for vulnerabilities before hackers find them

Palo Alto Networks has launched Unit 42 Continuous Frontier AI Defense, an enterprise service designed to continuously identify security weaknesses across corporate environments.

The service uses specialized Anthropic Claude Mythos 5 and OpenAI GPT-5.6-Cyber models alongside open-weight models. It examines web applications, APIs, cloud infrastructure, source-code repositories and network assets.

Its central purpose is to discover and validate dangerous exposures before attackers can exploit them.

How Continuous Frontier AI Defense works

The service begins with a baseline assessment of the customer’s environment and then continues testing as applications, code and infrastructure change.

The process includes:

  • discovering vulnerabilities and configuration errors;

  • checking whether the identified weakness can actually be exploited;

  • mapping possible attack paths across multiple systems;

  • prioritizing the most dangerous exposures;

  • preparing remediation recommendations;

  • retesting systems after changes are made.

Instead of examining every weakness in isolation, the system attempts to determine how multiple issues could be combined. A relatively minor web application problem, for example, might provide the first step toward compromising an API, cloud account or internal network.

Why the service uses multiple AI models

Palo Alto Networks has developed a proprietary multi-model harness that sends each task to the model considered best suited to handle it.

The service combines:

  • Anthropic Claude Mythos 5;

  • OpenAI GPT-5.6-Cyber;

  • open-weight models;

  • Unit 42 threat intelligence;

  • offensive security expertise.

One model may be more effective at source-code analysis, while another may perform better when evaluating cloud configurations or simulating a multistage attack. The approach is intended to improve coverage while controlling the cost of using frontier models at scale.

The findings are not used without oversight. Unit 42 specialists review the results and verify whether an identified attack path is genuinely exploitable in a real environment.

How it differs from a conventional scanner

Traditional vulnerability scanners often rely on databases of known CVEs and run at scheduled intervals. A new vulnerability or configuration error may therefore remain undetected until the next scan.

Continuous Frontier AI Defense is designed to test changing environments on an ongoing basis. It also attempts to demonstrate practical exploitability rather than simply reporting that a possible weakness exists.

Customers receive:

  • a prioritized list of validated risks;

  • descriptions of possible attack paths;

  • source-code remediation guidance;

  • configuration recommendations;

  • virtual-patch options;

  • integration with enterprise ticketing systems.

A virtual patch does not modify the vulnerable source code. Instead, it can temporarily block a dangerous request or attack route while developers prepare a permanent fix.

What Palo Alto Networks found during testing

Palo Alto Networks says it developed and validated the approach over six months and more than 100 Unit 42 customer engagements.

According to the company, exposures were identified in every assessed customer environment, with 37% classified as high or critical severity.

Palo Alto Networks also reports that more than two-thirds of the exposures found in third-party applications had no known CVE. Conventional scanners focused exclusively on published vulnerability databases might therefore have missed them.

These figures were provided by Palo Alto Networks. The company has not published an independent audit of the reported results.

Does the AI automatically fix vulnerabilities?

The service can recommend changes to source code, configurations and security controls. That does not mean an AI model receives unrestricted permission to modify a company’s systems.

The customer’s security and development teams retain control over whether recommended changes are implemented. Human review remains important because an incorrect automated change could disrupt a critical application or network service.

Availability and pricing

Unit 42 Continuous Frontier AI Defense is available worldwide through an annual subscription. Palo Alto Networks has not published standard pricing.

The cost depends on the customer’s environment and the combination of Anthropic, OpenAI and open-weight models used for its assessments.

This is an enterprise security service, not a consumer antivirus product or downloadable application. It is aimed at organizations with complex cloud environments, proprietary applications, APIs and dedicated security teams.

Why this matters

Artificial intelligence is accelerating not only software development but also the discovery of weaknesses in software. Advanced models can examine large amounts of code, connect several minor flaws into a usable attack path and produce possible exploitation scenarios faster than a human team.

Continuous Frontier AI Defense shows how the same capabilities can be used defensively: continuously examining infrastructure, separating practical risks from theoretical findings and delivering validated problems to developers more quickly.

Cybersecurity is consequently moving from occasional assessments toward a continuous contest between automated systems, with artificial intelligence being used by both attackers and defenders.

Sources: Palo Alto Networks announcement, Continuous Frontier AI Defense product page.