May 10, 2025

Palo Alto Networks Introduces Key AI Security and Cloud Innovations

AI Security Developments

Acquisition of Protect AI
On April 28, 2025, Palo Alto Networks announced its intent to acquire Protect AI, a company focused on addressing risks specific to AI systems. The integration is expected to support security teams in identifying and mitigating vulnerabilities within AI development and runtime environments.

Prisma AIRS Launch
Palo Alto Networks introduced Prisma AIRS, a platform designed to monitor and secure applications, models, agents, and data throughout the AI workflow. Prisma AIRS is positioned to help security teams oversee policy enforcement and threat detection in both training and deployment phases of AI systems.

Cortex Platform Enhancements

Cortex XSIAM
The company launched Cortex XSIAM, a platform built to integrate threat detection and incident response using AI and automation. It centralizes data, correlation, and workflows to assist security operations teams in managing threats across environments with reduced manual effort.

Cortex XDR Updates – April 2025
New detection analytics were added to Cortex XDR, including:

  • Webshell Analytics to flag installation and execution activity.
  • Microsoft SCCM Analytics for monitoring administrative behavior anomalies.
  • Active Directory Certificate Services Analytics to identify deviations in certificate service usage.

Graph Search in Cortex XDR
The Query Builder in Cortex XDR now includes Graph Search, a visual feature that maps relationships between entities, events, and risks. This supports investigations and provides structure to incident analysis and response.

Cloud Security Tools

Strata Copilot Expansion
Strata Copilot is now available within Strata Cloud Manager for broader use in cloud environments. It delivers AI-generated configuration insights and recommendations intended to support multi-cloud security posture management.

New Dashboards for Cortex and Cortex Cloud
Dashboards have been introduced for the Data, Identity, and AI Security Posture modules. These updates provide visibility into sensitive data, identity-related risk, and AI asset exposure for both operational and reporting purposes.

SASE and Infrastructure Updates

Prisma Access Browser 2.0
Palo Alto Networks released Prisma Access Browser 2.0, a browser-based access solution built into its SASE framework. It enables policy enforcement and threat prevention directly at the browser layer, designed to support distributed workforces with secure access control.

Oracle Cloud Infrastructure Integration
An expanded partnership with Oracle Cloud Infrastructure adds Prisma SASE support in additional OCI compute regions. This aims to improve regional availability and redundancy across hybrid and multicloud deployments.

IoT and Ecosystem Integration

Cortex XSOAR IoT Polling Enhancements
Cortex XSOAR now supports additional protocols for IoT Security polling, including Axis Communications, FTP Banner, and reverse DNS lookups. These updates enhance device discovery and improve threat context within operational technology environments.