Palo Alto Networks Uses AI to Find Flaws and Shield Them With Virtual Patches

Palo Alto Networks has introduced the Frontier AI Critical Defense Program, an initiative to shorten the time between finding a vulnerability and putting effective protection in place, especially in critical infrastructure where deploying a software update can take days or weeks of testing. The company plans to use advanced AI models to spot flaws and roll out “virtual patches” in the network that block exploitation until the final fix is ready.

Frontier AI Critical Defense in 20 seconds

  • Palo Alto Networks will coordinate manufacturers, researchers, and AI providers to get ahead of new vulnerabilities.
  • The company says it used Frontier AI models to find more than 14,000 previously unknown flaws in open-source software.
  • “Virtual patches” block exploitation attempts from the network without immediately changing the vulnerable software.
  • Participants include OpenAI, Anthropic, Microsoft, IBM, Red Hat, Siemens, Mitsubishi, Axis Communications, and various sector-specific groups.
  • The focus is especially on critical infrastructure, where stopping systems for updates is hard.

The initiative comes from a less visible side effect of AI models getting more capable. The same tools that help a security researcher analyze code and find bugs could also automate vulnerability searches at scales that are hard to reach by hand.

Palo Alto Networks says it has already used frontier AI models to find more than 14,000 previously unknown vulnerabilities in open-source projects. That number comes from the company’s own research and doesn’t mean the flaws have been exploited or are equally severe.

What matters most is the speed AI brings to a process that traditionally takes a lot of specialized effort. That creates a problem: finding vulnerabilities faster doesn’t mean organizations can fix them just as fast.

AI can find vulnerabilities faster than they can be patched

On paper, the traditional security process is simple: discover a vulnerability, the manufacturer builds a fix, test it, then users install the update.

In practice, it can be much messier.

Updating a browser or an ordinary application might take a few minutes. Changing software running in a factory, hospital, power plant, or industrial site is a whole different story.

Operational Technology (OT) systems may be tied directly to physical processes. A bad update can make applications fail, disrupt a production line, or hit systems that have to stay available all the time.

So updates often need validation procedures, compatibility tests, and maintenance windows.

AI threatens to widen the gap between these two speeds.

If ever more capable models can scan large amounts of code and automatically flag potential vulnerabilities, both researchers and attackers get tools to speed up that work.

But the vulnerable software still needs time to be fixed and updated.

The Frontier AI Critical Defense Program aims to bridge that gap.

A “virtual patch” doesn’t change the vulnerable program

Palo Alto Networks’ plan is to temporarily move some of the defense into the network with Frontier Virtual Patching.

A virtual patch isn’t the same as installing an update from the manufacturer.

Instead of changing the code where the vulnerability lives, security systems identify traffic or behavior tied to a possible exploit and block the attack before it reaches the vulnerable component.

That provides protection while the responsible teams prepare, test, and deploy the final patch.

The approach matters most in environments where immediate updates aren’t possible.

A virtual patch doesn’t remove the need to fix the software. The vulnerability is still there, and the protection relies on network mechanisms correctly spotting and blocking exploit attempts.

Its main value is shrinking the exposure window.

Palo Alto Networks’ plan also adds another element: combining insights from advanced models with traditional vulnerability data to produce protections faster.

OpenAI and Anthropic join a broader cybersecurity alliance

The program brings together companies and organizations from different corners of technology.

Participants include OpenAI and Anthropic, two leading developers of advanced AI models.

Also involved are Microsoft, IBM, Red Hat, and Siemens.

They’re joined by Mitsubishi, Axis Communications, and groups focused on sectors where system continuity is especially critical, plus initiatives tied to open-source software.

The mix of players reflects a basic feature of the problem: no single company controls the whole chain from finding a vulnerability to protecting affected systems.

Model developers can bring analysis capabilities. Software makers know their products. Researchers can assess flaws. Cybersecurity providers have points to block attacks, and critical-infrastructure operators understand their systems’ real constraints.

Palo Alto Networks wants to use the program to coordinate among these parties.

The 14,000 vulnerabilities show the dark side of advanced models

The most striking figure in the announcement is finding more than 14,000 previously unknown vulnerabilities in open-source software using Frontier AI models.

The company doesn’t present that only as a demonstration of defensive capability.

It also shows what could happen if similar tools are used offensively.

Finding vulnerabilities has historically taken specialized knowledge and time. A researcher has to analyze code, spot unexpected behavior, reproduce the flaw, and work out whether it can be exploited to compromise a system.

AI automation can take some of that workload off.

That doesn’t automatically turn a model into a tool that can run any cyberattack, nor does it mean all 14,000 vulnerabilities can be used to compromise critical systems. But it points to lower cost and less time to analyze huge amounts of software.

For defenders, a different race begins.

The goal is no longer just finding a vulnerability before an attacker does, but making sure knowledge of the flaw can quickly become effective protection.

Critical infrastructure can’t be updated like a laptop

The program pays special attention to operational technology, healthcare, and other critical environments, because they’re among the hardest systems to update quickly.

A typical organization might accept some downtime to install updates. Critical infrastructure that controls industrial processes or provides essential services may not have that flexibility.

Many OT environments also use equipment with much longer lifecycles than ordinary software.

That produces a tough challenge: systems that need to run for years, against tools that can find vulnerabilities ever faster.

Virtual patches try to buy time in that race.

They don’t replace proper vulnerability management, network segmentation, updates, and access controls. And they don’t remove the need for manufacturers to develop fixes.

But they can be a useful intermediate layer when a vulnerability is known and the patch can’t be deployed yet.

Advanced models are speeding up both attack and defense. The Frontier AI Critical Defense Program shows one consequence: if AI cuts the weeks needed to find certain flaws down to hours, the industry also has to cut the time from discovery to effective protection.

Frequently Asked Questions

What is the Frontier AI Critical Defense Program?

It’s a Palo Alto Networks initiative bringing together tech companies, research organizations, and critical-infrastructure stakeholders to speed up protection against vulnerabilities found with AI.

What is a virtual patch?

It’s protection usually applied through network security systems to prevent exploitation of a vulnerability without immediately changing the affected software. It doesn’t replace the manufacturer’s final patch.

Has Palo Alto Networks’ AI really found 14,000 vulnerabilities?

Palo Alto Networks says its research with Frontier AI models has uncovered more than 14,000 previously unknown vulnerabilities in open-source software. That doesn’t mean all are equally severe or exploitable the same way.

Why does this matter so much for critical infrastructure?

Because hospitals, industrial sites, and essential systems can’t always stop or update their equipment right away. Virtual patches can give temporary protection while a final fix is validated and deployed.

Scroll to Top