Invest2 publishers3 min readPublished
Palo Alto Networks built a service on the Anthropic model that found 75 flaws in its own products
Palo Alto Networks pointed Anthropic's unreleased Mythos at its own systems and found 75 vulnerabilities in a month, against a usual rate below five. The defense business it built on that result depends on Anthropic's model and on customers choosing a security vendor over the lab.
The Investor · Invest desk

What happened
- Palo Alto's Unit 42 team shipped 26 CVE fixes in direct response to the vulnerabilities Mythos surfaced.
- Anthropic had given early access through Project Glasswing to roughly 40 organizations from around April 7, with CrowdStrike a partner alongside Palo Alto.
- US export controls imposed around June 12 forced Anthropic to disable Mythos for all users until a partial lifting for approved entities around June 26.
- By September 22 Palo Alto had launched Unit 42 Continuous Frontier AI Defense, a service pairing Claude Mythos 5 with its own threat intelligence.
Compiled by The InvestorSomething wrong?How this is made
Why it matters
- exposure A service sold as continuous depends on a model Washington cut off for about two weeks in June, so a repeat of that action would reach Palo Alto's clients as well as Anthropic's.
- constraint CrowdStrike had the same preview in the same weeks, so any edge Palo Alto keeps has to come from its own threat intelligence and customer base.
- decision Enterprise buyers now pick between buying Mythos-grade testing through a vendor or from labs that want to sell it directly, and Palo Alto's pitch rests on Klarich's bet that they pick the vendor.
- contradiction Arora's manual-time estimate implies a baseline near one flaw a month, so the claimed speed-up runs anywhere from 15 times to 84 times depending on which figure a buyer trusts.
The record gives two figures for the same speed-up, and they differ in size. According to Crypto Briefing, the model found 75 vulnerabilities across more than 130 products in roughly a month, against a usual rate of fewer than five a month [3]. That puts the new pace at 15 times the old one or more [1]. Arora's own estimate is that the gaps would have taken five to seven years to find manually [4]. Spread 75 findings over 60 to 84 months and the manual rate comes out near one a month [2], with a speed-up of 60 to 84 times [3]. The two figures agree only if the company's usual rate was about one a month.
Unit 42 shipped 26 CVE fixes against those 75 findings, about 35% [4]. In Palo Alto's internal evaluations the model also produced working exploits more than 70% of the time [5].
Arora also saw a commercial opening. He called it "the best marketing moment for the cybersecurity industry in history" [11]. He said that before Mythos, a call about security got an answer that might as well have been "Sure, stand right by the insurance guy." Now, he said, "for the first time, CEOs want to see Mythos, they want to talk about it" [12]. For a $300 billion company whose customers include some 95% of the Fortune 500 [2][16], that attention lands on buyers it already serves. The service went from preview access to launch in about 168 days [6]. The reporting does not include what Palo Alto pays Anthropic, what the service costs clients or how many have signed.
The labs have spotted the same opening. Leading AI companies are looking to sell their own models directly as cyber defense [13]. "I don't believe companies will trust the big AI labs to provide their cybersecurity," said Lee Klarich, Palo Alto's chief product and technology officer [14]. Sam Altman, who runs OpenAI, said: "I think it's going to be hard to patch every bug on the internet. We need a new model of cybersecurity here." [15] Fortune reports that Arora is trying to build exactly that at Palo Alto [17].
From here the business can go one of three ways. Buyers can side with Klarich and pay Palo Alto to combine the model with its threat intelligence [10]. They can go to the labs and cut the vendor out. Or Washington can narrow access again, as it did in June [7], and settle the question for everyone. I think the first is the most likely in the near term. The parts of the service Palo Alto owns outright are its threat intelligence and its customer list. The model underneath is rented from Anthropic and was also offered to CrowdStrike [9]. The view is wrong if Anthropic or OpenAI start signing large enterprises to direct defense contracts [13], or if a second export action cuts Palo Alto's clients off from Mythos [8].
What to watch
- Whether Anthropic or OpenAI sign direct cyber-defense contracts with Fortune 500 companies that already buy from Palo Alto.
- Any new US export action on Mythos or Fable, or access widened beyond the 15 countries, which sets how many Palo Alto clients the service can reach.
- Pricing, uptake or Anthropic cost figures for Continuous Frontier AI Defense in Palo Alto's next results.