Palo Alto Networks has launched Unit 42 Continuous Frontier AI Defense, an expert-led offensive-security service that uses models from Anthropic and OpenAI alongside open-weight systems to search for exploitable weaknesses.

The service is designed to test web applications, APIs and cloud infrastructure repeatedly as enterprise environments change. Palo Alto Networks says its multi-model approach can discover exposures, validate whether attack paths are genuinely exploitable and recommend code changes or virtual patches. Human Unit 42 specialists remain involved in confirming findings and prioritising remediation.

The commercial proposition is as significant as the technology. Traditional penetration testing captures a moment in time, while software, permissions and dependencies continue changing after the report is delivered. Frontier models can revisit an estate more frequently and explore combinations of weaknesses at greater scale. The obvious counter-risk is that organisations must define the scope, permissions and evidence standards for an offensive agent that is deliberately attempting to break things.

For security buyers, the useful question is not whether AI found more issues in a demonstration. It is whether the service can prove exploitability, control false positives, protect sensitive data and integrate remediation into existing workflows without creating a new privileged attack surface.


Agentic Exploits- Deterministic gates for a probabilistic problem
David Girvin, CEO and co-founder of Assury, joins Stewart Tinson to dig into what’s actually happening when agentic AI goes wrong, and why he thinks most of the industry is solving the wrong layer of the problem. David explains the difference between prompt-level exploits and execution-level ones, arguing that the real danger starts the moment an agent moves from generating text to calling tools: deleting databases, reading files, sending emails. He walks through real-world incidents, including a Mexican government breach chain that escalated from just over a thousand prompts to over five thousand AI-executed actions across multiple agencies before detection, and the UK AI Security Institute’s recent cyber evaluation, in which agents took unsanctioned action including fabricating identities to socially engineer a real GitHub maintainer. The conversation covers why David is sceptical of “guardrails” language and AI-governing-AI approaches, arguing that only deterministic, architectural controls can reliably constrain agent behaviour, alongside human review reserved for genuinely high-stakes actions rather than blanket approval fatigue. He breaks down credential starvation, session risk accumulation, and why classifier-based tools keep failing inconsistently on identical actions, pointing to a named frontier lab’s own zero trust paper as an example of the industry misjudging what actually works. Elsewhere, David discusses the exposed MCP server problem, the widening trust gap between small specialist security vendors and platform incumbents, and why he believes regulation, not product quality alone, is what finally drives enterprise security spend. He closes with the exploit that concerns him most for the year ahead: session-level, goal-directed deception with no attacker involved at all.
Share this post
The link has been copied!