












Modern enterprise security is at a pivotal moment where CIOs and CISOs have a clear opportunity to build a cybersecurity architecture for both today’s environment, and for the future. Doing so requires redefining enterprise resilience across three critical dimensions.
First, Frontier AI driven threat velocity and novelty. Frontier AI models have automated the entire attack lifecycle. Adversaries aren’t just compressing exploit windows to near-zero timelines, they are also generating novel, highly evasive threats at machine speed, bypassing traditional signatures and often before patches are generated.
Second, surging network traffic is overwhelming traditional defenses. Driven by AI workloads, inter-datacenter traffic will nearly triple1 over the next decade dramatically expanding the volume of data teams must inspect and secure.
Finally, major shifts are forcing a “cryptographic reset.” Shrinking certificate lifecycles, internet-scale distrust events, and quantum computers powerful enough to crack public key cryptography are combining to shake the foundation of all digital communications.
Meeting these challenges requires more than incremental fixes. Today, we are proud to introduce PAN-OS 12.2 Ceres, a landmark release representing a major leap forward in network security.
Ceres brings to market 55+ innovations, including three flagship, core capabilities, designed to shift the balance of power back to defenders.
Today, Palo Alto Networks is giving defenders the ultimate advantage with the launch of Advanced Virtual Patching. By harnessing Frontier AI to discover unknown vulnerabilities, and deploying protections in hours, we are collapsing the exposure window from the industry-average 55 days2 it takes to deploy a traditional patch down into a near-zero window of exposure. This isn’t just about faster patching; it’s about eliminating the attacker’s chance by neutralizing exploits before they ever reach your network.

The new reality: Exploitation far outpaces patch deployment
We’ve built this capability as a collaborative, force-multiplying ecosystem, with our industry partnerships across the enterprise software and OT vendor landscape to accelerate vulnerability disclosure, remediation and customer protection. This includes our collaboration with Project Lightwell, which combines our rapid network-level protection with software remediation to help organizations reduce exposure to emerging threats. We’re also partnering with vulnerability clearinghouses, software maintainers, and industry initiatives to continuously expand a real-time pool of protected vulnerabilities.
This approach builds on recent Unit 42 research, where the autonomous AI system NOVA identified more than 14,000 previously unknown vulnerabilities in just two months – a clear signal that defenders must pair AI-powered discovery with equally fast, coordinated protection. We have built an all-new detection engine, “vaulted protection," that enables us to deliver these rapid protections in a safe and responsible manner. When one participant identifies a threat, the entire ecosystem is protected instantly. Individual discovery becomes global protection.
This is especially valuable for operational technology (OT), critical infrastructure, healthcare, and IoT: environments where systems can’t be taken offline to patch, where patch cycles can stretch for months, and where a single unpatched device can expose an entire network. Advanced Virtual Patching closes that gap in the network, blocking the exploit without applying a patch, rebooting a system, or causing any downtime to critical operations.
Bad actors will lean into Frontier AI to reduce the attack lifecycle from months to minutes. To keep pace, organizations require security partners to match that machine speed. To this end, Palo Alto Networks is raising the bar with its Advanced Virtual Patching, moving beyond compensating controls. By safely and efficiently discovering undisclosed vulnerabilities and deploying protection long before traditional patches can be rolled out, Palo Alto Networks deep security capabilities are flipping network defense from a reactive to proactive operational model.
Will Townsend
Chief Analyst, LoneStar Advisory & Research
And for existing Palo Alto Networks network security customers, getting started is effortless. Advanced Virtual Patching is available as a PAN-OS software upgrade with persistent, automatic content updates, so protections keep arriving as new threats emerge, with no new hardware and no manual intervention.
Clearly, Network Security is evolving quickly. Advanced Virtual Patching is part of a huge set of innovations that the team at Palo Alto Networks is delivering in PAN-OS Ceres 12.2 to enable you to stay protected.
Modern threat actors continuously work to hide their attacks and evade existing controls. Adversaries are increasingly evading traditional perimeter detection of their command-and-control traffic by leveraging direct-to-IP connection techniques that bypass DNS and URL inspection entirely. Attackers are also weaponizing massive proxy networks and hundreds of thousands of residential IP addresses to conduct stealthy, large-scale scanning, brute-force attacks, and exploitation that bypass traditional defenses such as IP reputation and blocklists.
To counter this, Palo Alto Networks is introducing a new preventative solution, Advanced IP Defense , with three powerful new capabilities:
The transition to the Frontier AI era isn't a distant future. It’s happening right now. The organizations that thrive won't be those trying to run old, reactive playbooks faster; they have to scale their defenses to match a whole new velocity of risk. When threats occur at machine speed, relying on human-scale operations is no longer an option. That is why AI and automation are becoming essential tools to meet these challenges head-on.
Varinder Singh
CIO, NXP Semiconductors
When threats execute in minutes, human-only operations become a bottleneck. To reduce fatigue and accelerate response, we’re launching an elite suite of AI agents for every major role a network administrator performs.
These six specialized AI-powered Network Security Agents, available through Strata Cloud Manager, are trained on your enterprise context and operational workflows. From onboarding and configuration to threat assessment and troubleshooting, they automate the hundreds of routine, repetitive tasks that consume an admin’s day. And you stay in control: for each workflow, you choose the level of oversight that matches your risk tolerance — human-in-the-loop, human-on-the-loop, or human-out-of-the-loop.
Securing the modern enterprise means extending these AI-powered capabilities across every surface, from data center cores to remote industrial sites, and from custom AI applications to the web browser.
Today we’re introducing PAN-OS Ceres 12.2, which, in addition to the innovations above, expands our platform across five more areas:

We are investing heavily in the innovations you need to defeat today’s threats while future-proofing your enterprise for tomorrow.
The transition to the Frontier AI era demands a bold strategy. The winners will be the organizations that adopt a prevention-first architecture capable of stopping threats long before weaponization occurs. With PAN-OS Ceres 12.2, Palo Alto Networks is giving defenders the speed, scale, and platform foundation to turn the tables on modern adversaries.
Forward-Looking Statements
This blog contains forward-looking statements that involve risks, uncertainties and assumptions, including, without limitation, statements regarding the benefits, impact, or performance or potential benefits, impact or performance of our products and technologies or future products and technologies. Any unreleased services or features (and any services or features not generally available to customers) referenced in this or other press releases or public statements are not currently available (or are not yet generally available to customers) and may not be delivered when expected or at all. Customers who purchase Palo Alto Networks applications should make their purchase decisions based on services and features currently generally available.
Sources:
1 https://www.nokia.com/artificial-intelligence/explainer-network-traffic-is-fundamentally-changing-in-the-ai-supercycle/
2 According to the Verizon 2024 Data Breach Investigations Report
此内容由惯性聚合(RSS阅读器)自动聚合整理,仅供阅读参考。 原文来自 — 版权归原作者所有。