
Palo Alto Networks is launching a subscription service that puts Anthropic and OpenAI models to work hunting for weaknesses in customers’ systems around the clock.
The service is built on models whose access is tightly controlled: Anthropic’s Claude Mythos 5 and OpenAI’s GPT-5.6-Cyber, both designed for cybersecurity work, plus open-weight models.
“Claude Mythos found flaws that survived decades of human review, and more than ten thousand high-severity vulnerabilities across the software the world runs on,” said Michael Moore, Cybersecurity Lead, Anthropic.
Unit 42’s own software decides which model handles each task, which the company says improves results and keeps costs down.
“AI has created an asymmetric advantage for threat actors against organizations trying to defend at human speed. Modern cybersecurity requires machine-speed defense.
We’re combining Unit 42’s offensive testing and threat intelligence expertise with industry-leading AI harnesses and exclusive access to gated capability models to give defenders back the upper hand,” said Sam Rubin, Senior Vice President of Unit 42 at Palo Alto Networks.
After an initial scan of a customer’s whole estate, the service keeps attacking web apps, APIs, cloud infrastructure, code repositories, and networks as they change.
It then tries to prove that each weakness can really be exploited, maps where an attacker could go next, and suggests code fixes or temporary “virtual” patches.
It extends a one-off assessment Unit 42 introduced in April, which it began running on the two cyber models in August. According to Palo Alto Networks, that assessment found exposures at every customer it tested, and 37% of those were rated high or critical severity.
The company says it spent six months and $17m developing the approach, across more than 100 customer engagements. When it ran the service on its own systems, it says three weeks of testing surfaced as many exposures as it would normally expect to find in a year.
Attackers using AI have cut the time from finding a flaw to exploiting it by almost 97% in some cases, from weeks to hours, Palo Alto Networks says.
“Modern cybersecurity requires machine-speed defense,” said Sam Rubin, who leads Unit 42.
Anthropic, for its part, says Mythos has found more than 10,000 high-severity vulnerabilities in widely used software. Access to the model has been restricted: Anthropic briefly suspended access to its Mythos models in June to comply with US export controls, restoring it on 1 July after the controls were lifted.