Palo Alto Networks CEO: "AI Found 5 Years of Bugs in 6 Weeks"
Palo Alto Networks CEO Nikesh Arora discusses how AI is transforming cybersecurity, revealing that Claude (Mythos) found 5-7 years worth of code vulnerabilities in just 6 weeks. He also shares his views on the death of analytical SaaS, the future of enterprise software, and the race between AI-powered cyber defenders and attackers.
Summary
In this wide-ranging interview, Palo Alto Networks CEO Nikesh Arora discusses the transformative impact of AI on cybersecurity and enterprise software. The conversation opens with context on his tenure: he joined when the company was valued at $17 billion and it now sits at $238 billion market cap.
On AI and cybersecurity, Arora reveals a landmark finding: using Anthropic's Claude model (referred to as 'Mythos'), Palo Alto Networks discovered vulnerabilities in their own codebase in 6 weeks that would have normally taken 5 to 7 years to find. He notes the model's 'ultra mode' (persistent thinking) can even daisy-chain vulnerabilities to find novel attack paths. However, he tempers this with a critical caveat: Claude had a 30% false positive rate, making it powerful for offense but problematic for defense without additional refinement and harnesses.
Arora warns that similar capabilities are likely available or soon to be available in open-source and Chinese models — perhaps within 3 months — creating an urgent race between defenders and attackers. He expresses less concern about attacks on critical national infrastructure (which is well-funded and defended) and more concern about small businesses and mid-market companies running legacy or open-source software, citing the Change Healthcare ransomware attack as an example of the real economic chaos such breaches can cause.
On enterprise software and SaaS, Arora is direct: analytical SaaS is dead. Companies that collect and analyze data on behalf of customers are being made obsolete because AI models can run directly against raw data. He argues that the middle tier — 'systems of work' or 'systems of record' — will be reinvented over the next 5 years, with agent-driven workflows replacing human-facing UIs. He also predicts enterprises will need 10x more stored data to train AI systems to distinguish normal from anomalous behavior.
On the model vs. application layer debate, Arora believes models will commoditize into a utility layer where intelligence is purchased on demand at varying capability levels. He argues the real profit pools are in the application layer, which is why OpenAI and Anthropic are pushing into coding tools and vertical applications. However, he believes this application layer is still largely unformed and represents a major opportunity for new companies.
Arora also touches on hardware (still essential for low-latency use cases like financial services), M&A strategy (Palo Alto recently acquired a $25 billion identity security company), and workforce impact (he believes AI is actually increasing headcount on the technical side at Palo Alto, not reducing it).
Key Insights
- Arora reveals that using Claude (Mythos), Palo Alto Networks found vulnerabilities in their own codebase in 6 weeks that would have taken 5 to 7 years to find through conventional means, and that Claude's 'ultra mode' can daisy-chain vulnerabilities to discover novel attack paths.
- Arora discloses that Claude had a 30% false positive rate during their security testing — meaning it flagged non-existent vulnerabilities nearly a third of the time — making it powerful for offensive use but unreliable for defense without significant additional tuning and harnesses.
- Arora argues that analytical SaaS is definitively 'over' because AI models can run directly against raw enterprise data, eliminating the need for third-party software that collects and analyzes data on a company's behalf.
- Arora states that 89% of breaches happen due to simple credential theft (stolen usernames and passwords), not sophisticated model-based attacks, and that the real systemic risk is economic chaos from attacks on under-resourced small and mid-market businesses — not cracking hardened national infrastructure.
- Arora reveals that the CEO of a major AI model company told him the entire model weights of their newest model fit on a USB stick, and that all training data can be distilled into a new model in under 24 to 48 hours — undermining the idea that frontier model IP can be meaningfully protected or export-controlled for more than a few months.
Topics
Transcript
[0:00] It's one of the biggest winners right now. The big daddy of the cyber security space. >> Palo Alto Networks is an outer performer in the space. >> CEO Nesh Aurora. >> This might come as news to you, but humans have been writing bad code for a very long time. >> I spent 10 years at Google and you know Google search was democratizing information. If you take that analogy and think about what AI is doing, AI is democratizing intelligence. Money is a way to keep track. It's not the goal. You've been the CEO of Palo Alto [0:30] Networks for eight years. >> Coming up on eight years this week. >> Eight years. And I think…
Full transcript available for MurmurCast members
Sign Up to AccessMore from All-In Podcast
How Robots Learn: Much Slower Than Humans At First, Then Infinitely Scalable
The speaker discusses the evolution of learning in robots compared to humans, emphasizing that while humans learn efficiently with minimal data, robots require significantly more data to learn effectively. However, once a robot learns a task, that knowledge can be shared across all robots of that type, leading to infinite scalability.
Former Navy Seal Details First Autonomous Rescue Mission Near the Strait of Hormuz
A former Navy SEAL discusses a significant autonomous rescue mission involving a fully autonomous speedboat named Corsair, tasked with rescuing downed American pilots in the Strait of Hormuz. This mission represents a critical milestone in military operations, showcasing the ability to conduct rescues without further endangering soldiers.
GameStop CEO: “Why Does Everyone Want Us to Fail?”
GameStop CEO argues that the media and management are biased against GameStop's success, despite his financial commitment to the company. He highlights the disparity between overpaid management teams and those willing to risk their own capital.
Friedberg: Elon’s $17B Terafab Could Be the Greatest Chip Fab on Earth
The discussion highlights Elon Musk's ambitious vision for a semiconductor fabrication site, which could reduce U.S. dependence on Taiwan and China for chips. The potential success of this venture is tied to profits from Starlink and Musk's investment strategies.
Google’s AI Brain Drain, SpaceX's Huge Quarter, Airtable’s 90% Collapse, US Data Fuels China AI
The All-In podcast discusses Google's AI leadership exodus and restructuring, SpaceX's spectacular earnings with $7.8B revenue (up 92% YoY) and $2.6B in AI compute rental revenue, Airtable's acquisition by Bending Spoons for $1.28B (90% below peak valuation), and concerns about U.S. training data being sold to Chinese AI companies.