Palo Alto Networks said on Aug. 20 it is launching a new cooperation program, the Frontier AI Critical Defense Program, to respond to vulnerabilities in the frontier AI era.
The company said frontier AI models are finding large numbers of previously unknown vulnerabilities, pushing defenders into a race against time. Vulnerabilities are being discovered faster, but applying permanent patches still takes anywhere from hours to weeks. Palo Alto Networks is focusing on virtual patching to narrow that gap.
The program uses Palo Alto Networks' Frontier Virtual Patching feature launched earlier this month and its new detection engine, Volted Protection. It supports organisations in operational technology, healthcare, commercial software and open-source fields in sharing vulnerability information and rapidly deploying virtual patches before attackers can exploit them.
Virtual patches aim to block attack attempts at the network level instead of directly modifying software or devices. They are particularly useful in infrastructure that is difficult to take offline quickly, such as medical devices. Palo Alto Networks said its virtual patching technology can stop attacks without reboots or downtime.
Palo Alto Networks said Volted Protection enables a vulnerability found by one participating institution to be extended to defensive capabilities for other organisations and customers.
Participants include OpenAI and Anthropic, as well as OT companies such as Mitsubishi and Axis Communications, and Health-ISAC, the Center for Threat-Informed Defense, the Electric Power Research Institute and the Linux Foundation's Open Source Security Foundation. Palo Alto Networks is also expanding existing cooperation with IBM and Red Hat, Microsoft, and Siemens and Idaho National Laboratory.
Palo Alto Networks' threat intelligence team, Unit 42, has developed an autonomous research tool called NOVA. NOVA identifies potential software flaws and verifies whether they can be reproduced with proof-of-concept code. The company said it used NOVA to analyse 3,915 open-source projects over two months and confirmed 14,090 vulnerabilities.