Cybersecurity

Unit 42 Unveils Subscription for Continuous AI-Powered Offensive Security

mm
Add Unite.AI to your preferred sources on Google

Palo Alto Networks announced Unit 42 Continuous Frontier AI Defense on September 22, 2026, an agentic offensive security subscription service built on gated frontier AI models, including Anthropic’s Claude Mythos and OpenAI’s GPT, that continuously identifies, validates, and remediates enterprise exposures.

The Santa Clara, California-based company positioned the service for enterprises that want to apply gated capability models to their own estates so exposures are found and fixed before attackers can weaponize them. The company said threat actors are deploying AI to find and exploit vulnerabilities, compressing breach cycles by almost 97% in some cases, from weeks to hours. Unit 42, the company’s threat intelligence, incident response, and security consulting arm, is now offering continuous offensive testing to identify and validate vulnerabilities, map exposures and attack paths, and accelerate remediation.

How the Service Works

A Continuous Testing Engine runs a full-estate baseline scan and then keeps testing as an organization’s environment changes. Underneath it sits a proprietary multi-model harness, software architecture that routes each task to the model best suited for it and integrates cyber-specialized frontier AI models with Unit 42 threat intelligence and offensive security expertise. The company said the harness improves efficacy and coverage while managing the cost of frontier AI at scale.

The harness is built around gated capability models, including Anthropic’s Claude Mythos 5 and OpenAI’s GPT-5.6-Cyber, alongside open-weight models. An Advanced Adversary Simulation component checks end-to-end attack paths across first- and third-party web applications, APIs, cloud infrastructure, source code repositories, and network assets, with the goal of proving real-world exploitability. An Accelerated Remediation component delivers prioritized fixes, code-level guidance, and virtual patch recommendations, and organizations can pair the service with Frontier Virtual Patching to apply virtual patches before a vulnerability is publicly disclosed or an official patch exists.

The service’s product page describes the offering as an expert-led service with exclusive access to gated capability models, and lays out a five-step delivery methodology: scope, discover, validate, remediate, and improve. Under that methodology, offensive security experts verify frontier AI findings and chain end-to-end attack paths, remediations integrate with customer ticketing systems, and re-testing triggers automatically as environments or applications change. The page frames delivery in three phases, continuous discovery, ongoing validation, and remediation acceleration, and its FAQ defines frontier AI as the most advanced AI models, naming Anthropic Mythos and OpenAI GPT-Cyber, and describes them as capable of reasoning across complex tasks, generating code, and autonomously executing multistep workflows.

Reported Efficacy and the Frontier AI Defense Line

Palo Alto Networks said it developed and validated the approach over six months of in-house testing and across more than 100 Unit 42 customer engagements, backed by a $17 million investment in research and development and methodology optimization. During internal deployment, the company reported, the approach surfaced a year’s worth of exposures in three weeks.

The company also reported results from customer assessments run through the Frontier AI Exposure Analysis: exposures were found in 100% of customers, 37% of which rated high or critical in severity. Most exposures stemmed from first-party applications, and more than two in three exposures found in third-party applications had no known CVE, according to the company.

The subscription builds on Unit 42’s Frontier AI Defense, which launched in April 2026 with a point-in-time exposure analysis and a subsequent security blueprint that benchmarks current capabilities. The April 17, 2026 launch post, written by Sam Rubin, described three components delivered by expert consultants: Frontier AI Exposure Analysis, which identifies and validates the exposures most likely to be chained into real attacks; Autonomous Security Blueprint, which benchmarks current capabilities and defines the changes required for machine-speed defense; and Agentic Defense Transformation, which implements the prioritized architecture, control, and operating changes. That launch included six months of complimentary access to Cortex XDR, Cortex Xpanse, and Koi Agentic Security, with a stated exclusion for public sector customers and current customers of those products.

In August 2026, Unit 42 announced it would expand the Frontier AI Exposure Analysis with OpenAI’s GPT-5.6-Cyber and Anthropic’s Claude Mythos 5, giving organizations access to those models’ advanced cyber capabilities.

Executive Statements and Availability

“AI has created an asymmetric advantage for threat actors against organizations trying to defend at human speed,” said Sam Rubin, Senior Vice President of Unit 42 at Palo Alto Networks. “Modern cybersecurity requires machine-speed defense.” Rubin said the service combines Unit 42’s offensive testing and threat intelligence expertise with AI harnesses and exclusive access to gated capability models.

McCall McIntyre, Head of Global Cyber Partnerships at OpenAI, pointed to the Daybreak program and said OpenAI is pairing its GPT Cyber Models with Unit 42’s security expertise, governance, and human judgment to help organizations validate the attack paths that matter and move from discovery to remediation at machine speed. Michael Moore, Cybersecurity Lead at Anthropic, said Claude Mythos found flaws that survived decades of human review and more than ten thousand high-severity vulnerabilities across widely used software, and that Unit 42 tests whether those findings can actually be exploited, maps what an attacker could reach from them, and gets the fix in front of the right team first.

Continuous Frontier AI Defense is available worldwide on an annual subscription, with options that vary based on the specific OpenAI, Anthropic, and open-source models used. The company said every subscription uses the multi-model harness to match the optimal AI model to each security task. Palo Alto Networks is directing prospective customers to register for an upcoming Virtual Threat Briefing on the service.

Miles Okada is an AI-generated analyst at Unite.AI, covering artificial intelligence and cybersecurity with a focus on emerging threats, defensive architectures, and the evolving dynamics between attackers and automated systems. His work examines how AI is reshaping security operations, from autonomous threat detection and response to the rise of adversarial AI techniques.

With a technical and investigative perspective, Miles analyzes security research, incident disclosures, and real-world deployments to understand where AI strengthens defenses—and where it introduces new vulnerabilities. He pays particular attention to model exploitation, data poisoning, attack automation, and the operational realities of securing AI-powered systems at scale.

Articles authored by Miles Okada are AI-generated and reviewed by Unite.AI’s editorial team to ensure accuracy, rigor, and responsible coverage of the rapidly changing AI security landscape.