Observed Signal · May 13, 2026 · Security Advisory · Source: CNBC Technology · Impact: 4/5 · Sentiment: Negative

Palo Alto: AI-driven cyberattacks to become new norm

Executive Signal Summary

Palo Alto Networks tech chief Lee Klarich warned that AI-driven cyberattacks will likely become the "new norm" within a narrow three-to-five-month window, urging organizations to urgently strengthen software defenses. Klarich cited advanced models — including Anthropic’s Mythos and OpenAI’s GPT-5.5-Cyber — as making it easier for attackers to discover and exploit previously unknown vulnerabilities. Palo Alto said it will roll out initial defensive capabilities, including virtual patching, "very soon." The article notes Anthropic limited Mythos access to a select group of companies (including Palo Alto Networks, CrowdStrike, Amazon, Apple and JPMorgan) and that Google recently said it blocked an attempt to use AI in a mass-exploitation event. The piece was published May 13, 2026.

Polaris7 AgentPolaris7 Strategic Assessment
High Confidence

Major cybersecurity vendor warning that frontier LLMs materially lower the bar for exploiting unknown vulnerabilities creates urgent, cross-industry operational risk and signals near-term need for defensive innovations.

SIGNAL RADAR

Track Palo Alto Networks Signals & Market Shifts in Real-Time

Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.

Start Free in Explorer
Free Explorer tierNo credit card requiredInstant watchlist setup

Key Takeaways & Evidence Grounding

  • Lee Klarich, tech chief at Palo Alto Networks, said there is a three-to-five-month window to outpace AI-driven exploits.
  • Palo Alto Networks plans to roll out initial defensive capabilities, including virtual patching, "very soon."
  • Anthropic’s Mythos and OpenAI’s GPT-5.5-Cyber are cited as models that make discovering software vulnerabilities easier for attackers.
  • Anthropic limited Mythos access to select companies including Palo Alto Networks, CrowdStrike, Amazon, Apple and JPMorgan.
  • Google said it stopped an attempt to use AI for a "mass exploitation event."
Primary Source Grounding & Direct Attribution
Direct Origin Attribution
Primary Reporting: CNBC Technology•Published: May 13, 2026
Original Coverage Title: “AI-driven cyberattacks will start to be the 'new norm' in months, Palo Alto warns”

Related Market Signals & Shifts

Recent verified developments and strategic activity across this market segment.

InfrastructureSep 1, 2026

Palo Alto CEO says $1 trillion cybersecurity infrastructure isn't AI-ready

Palo Alto Networks CEO Nikesh Arora said that AI is forcing companies to modernize roughly $1 trillion of aging cybersecurity infrastructure that is not equipped to handle attacks at machine speed. Speaking to CNBC's Jim Cramer, Arora noted that nothing deployed 7-10 years ago can handle AI, and that companies must rethink their cyber architecture. The comments came after Palo Alto Networks beat fiscal fourth-quarter estimates and gave a strong outlook. Arora highlighted the emergence of Anthropic's Mythos model as a turning point that made companies take AI security threats seriously. He said Palo Alto has engaged with about 2,000 companies on its Frontier AI Critical Defense Program, which uses advanced AI to test defenses. Arora believes the AI threat extends the growth runway for the entire cybersecurity industry, though spending will not materialize all at once.

Read assessment
Cybersecurity / Large Language ModelsMay 8, 2026

Anthropic Mythos Sparks Cybersecurity Alarm

Anthropic’s purpose-built vulnerability model Mythos, run by Mozilla against Firefox, produced a substantially larger set of security findings than an earlier general-purpose model — surfacing 271 security-sensitive bugs in a later run versus 22 previously. The episode was published by Nate on May 8, 2026. The author frames the result as a possible inflection point: machine-driven generation, attack, repair and verification of software may overtake humans as the primary trust anchor. The piece argues teams must prepare for a new risk model where code is cheap to produce but expensive to trust, and that code comprehensibility will become a core security property. This reporting aligns with broader industry alarm about Mythos’ capabilities and concerns that defenders may have uneven access compared with offensive uses.

Read assessment
Large Language Models (LLM) & AIApr 7, 2026

Anthropic Limits Mythos AI Rollout Over Cyberattack Fears

Anthropic released a preview of its frontier model, Mythos, and is deploying it selectively under a new security initiative called Project Glasswing. Twelve partner organizations — including Amazon, Apple, Broadcom, Cisco, CrowdStrike, the Linux Foundation, Microsoft and Palo Alto Networks — will pilot Mythos for defensive cybersecurity work; Anthropic said an additional 40 organizations will gain preview access beyond the partner cohort. Although Mythos was not explicitly trained for security, Anthropic says the model identified “thousands of zero-day vulnerabilities,” many decades old, when scanning first‑party and open‑source code. The rollout follows a prior leak of drafts (the model was previously referenced as “Capybara”) and an accidental exposure of source code tied to a Claude Code release. Anthropic said it is in discussions with federal officials even as it faces legal and supply‑chain disputes with the U.S. government.

Read assessment

Track Real-Time Market Signals & Shifts

Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.