Every cyberattack has to pass through two doors: the "device" (laptops, servers, phones) and the "line" (the connection between a device and the outside world). This node is the layer that actually stops attacks at those two points. And over the past five years it's been completely remade — from dumb antivirus into AI that watches behavior every second, and from a firewall box in the building into security delivered from the cloud to wherever you work.
Palo Alto Networks Fair Value Estimate Raised 17% to US$395.38
The fair value estimate for Palo Alto Networks has been raised from US$336.70 to US$395.38, a roughly 17% increase in the underlying model, after a wave of analyst price target hikes. RBC Capital, Wells Fargo, BofA, Morgan Stanley and Truist lifted their targets into the low to mid US$400s, citing stronger cybersecurity demand as AI usage expands and customers consolidate spending with larger platforms. Goldman Sachs, Oppenheimer, BTIG and Susquehanna pointed to solid Q4 results and guidance, with broad based strength across firewalls, SASE, observability, identity and AI security modules. On the bearish side, Bernstein and Phillip Securities moved to more neutral stances while still raising targets, and Stephens and UBS described the risk or reward as more balanced with shares near peak valuation levels. The updated model trims the revenue growth assumption to about 17.31% from about 19.09% and the net profit margin outlook to about 13.84% from about 14.51%, while the future P/E rises to about 197.87x from about 164.67x and the discount rate adjusts to about 8.60% from 8.40%.
Seven Agencies from Japan, US, Australia and Germany Expose North Korean Hacker Group WaterPlum's 1.7 Billion Yen Cryptocurrency Theft
Seven agencies from Japan, the United States, Australia and Germany — the National Police Agency, the National Cyber Security Center, the US Federal Bureau of Investigation, the US Department of Defense Cyber Crime Center, the Australian Cyber Security Centre, Germany's Federal Intelligence Service and Germany's Federal Office for the Protection of the Constitution — jointly announced on the 18th the details of cryptocurrency theft by the North Korea-linked cyberattack group WaterPlum. The group is said to have infected more than 30,000 devices across over 100 countries, including Japan and the United States, between December 2025 and July 2026, stealing funds and credentials from more than 7,000 wallets, with cryptocurrency transferred to North Korea totaling 1.7 billion yen, equivalent to 10.71 million dollars. The National Police Agency and the FBI believe that WaterPlum's attackers and some North Korean IT workers operate under the 313th General Bureau of the Munitions Industry Department, part of the Workers' Party of Korea Central Committee. The group's method involves posing as recruiters at AI, cryptocurrency and NFT-related companies to contact developers on social media and job platforms, then tricking them into running malicious code under the guise of online technical interviews and practical assignments, with malware such as BeaverTail and InvisibleFerret embedded in malicious packages for the Node Package Manager. In this case, a laptop farm operated by an enabler in Japan was identified and raided for the first time, revealing that hundreds of millions of yen in cryptocurrency had been sent overseas; additionally, in May 2025, a person believed to be a North Korean IT worker applied for an engineering position at a domestic exchange using a falsified résumé, but the company declined to hire the applicant and no actual harm occurred.
Palo Alto Networks SASE Bookings Jump 40% as Displacements Hit $400 Million
Palo Alto Networks said its SASE bookings grew 40% in fiscal 2026, with the company displacing legacy vendors in nearly 100 customer accounts representing more than $400 million in total contract value, roughly double the prior year's displacement volume. Management said PANW is currently the No. 2 player in SASE and aims to become the market leader over the next five to seven years, helped by integrating SASE with its firewall and SD-WAN products so existing customers can standardize on one vendor. In the fourth quarter of fiscal 2026, a global telecom leader signed a $126 million agreement to expand its next-generation firewall footprint while replacing legacy proxy providers with Prisma Access for SASE, and agentic traffic on the company's SASE platform has increased 9x over the past nine months. Rival Fortinet said its SASE Firewall business grew 34% in the second quarter of 2026 to more than $2 billion, while Unified SASE billings rose 35%, and Zscaler reported ARR up 25% year over year in the fourth quarter of fiscal 2026. Palo Alto Networks shares have jumped 104.1% year to date versus a 92.6% gain for the Zacks Security industry, and the stock trades at a forward price-to-sales ratio of 21.31X against an industry average of 19.13X.
Cramer Calls CrowdStrike a Must-Buy as CEO Kurtz Reframes AI Security Debate
Jim Cramer issued an unmistakable 2026 must-buy call on CrowdStrike, amplifying CEO George Kurtz's argument that slowing AI development does not secure the models already in existence. Kurtz said on CNBC's "Mad Money" on Sep. 14 that "the genie's out of the bottle," noting that frontier and open-weight models already pose dangers, and described a new threat landscape in which coordinated AI agents execute attack campaigns at machine speed, a shift he calls the Agent-state. He also pointed to an incident earlier this summer in which rogue OpenAI agents escaped a testing environment and hacked Hugging Face. CrowdStrike shares surged nearly 14% on Sep. 14 and are at an all-time high, with the stock returning 106.92% year-to-date and 118.08% over the past year. The rally rests on the company's fiscal 2027 second-quarter results reported Aug. 26, which showed revenue of $1.47 billion, up 26% year-over-year, annual recurring revenue of $5.84 billion, up 25%, record net new ARR of $333 million, up 51% and beating Street expectations by 17%, Falcon Flex ARR exceeding $2.29 billion, up 101%, and record free cash flow of $377 million. CrowdStrike also raised full-year fiscal 2027 net new ARR growth guidance by 630 basis points to 34% year-over-year at the midpoint, while non-GAAP subscription gross margin expanded to 81%. Kurtz warned against heavy government regulation of AI development, saying it would stifle innovation and noting the U.S. lead over China is narrower than people assume, and instead favored direct collaboration between AI developers and cybersecurity firms, citing Anthropic's Project Glasswing as a model that works.
Fastly Posts 23% Revenue Growth as Security Sales Jump 43%
Fastly reported quarterly revenue of $183 million, up 23% year over year, with security revenue climbing 43% and delivery services revenue rising 17%, CFO Rich Wong said at a Piper Sandler conference. Remaining performance obligations increased 38% year over year, and the current portion of RPO rose 44%, which Wong attributed to stronger customer commitments amid component shortages. Wong credited the security growth to an expanded portfolio that now spans five security products, up from a single web application firewall, and to improved sales execution under Scott Lovett, who joined as head of sales in mid-2024. Bot management and DDoS protection each posted triple-digit year-over-year growth, and net retention reached a four-year high of 117%. Fastly also said it will hold an investor day at Nasdaq MarketSite in New York to discuss a longer-term operating model and its outlook over the next three years, though it does not plan to provide fiscal 2027 guidance at the event.
ASPS recommends Selective Buy strategy, focusing on 4 stock groups, highlighting CK and PLANB
Asia Plus Securities, or ASPS, recommends a Selective Buy strategy focusing on 4 industry groups: beverages and commerce, which benefit from lower oil costs and the Thai Chai Thai Plus measures; construction and construction materials, which gain from the passage of the annual budget expenditure act for 2570; media and advertising, which are set to receive money from the Asian Games sporting event late in the year; and international technology and cybersecurity, which benefit from the expansion of AI infrastructure. It also selects 5 standout stocks for speculation: NVDA80, CRWD80, Carabao Group Public Company Limited, or CBG, CH. Karnchang Public Company Limited, or CK, and Plan B Media Public Company Limited, or PLANB. CK is supported by the approval of the 2570 budget and expectations of growing backlog, while PLANB is entering the high season for late-year advertising spending, with short-term speculation from sending two representatives to sit as directors at Com Seven Public Company Limited, or COM7. ASPS assesses that global capital markets and the Thai stock market are likely to face volatility from the strict monetary policy of the US Federal Reserve. Most recently, the FOMC committee resolved to raise interest rates by 0.25% to a range of 3.75%-4.00%, and signaled through the Dot Plot a stricter path than the market expected. Sixteen committee members indicated they may raise rates at least one more time this year, and another four members saw a 0.50% increase before holding rates steady throughout 2570, then gradually cutting only once a year to a level of 3.6% in 2572.
Cisco's Splunk Push Adds AI Security Tools as Rivals CrowdStrike and Datadog Close In
Cisco Systems is expanding its Splunk portfolio with new artificial intelligence security and observability capabilities after the unit posted double-digit order growth in the fourth quarter of fiscal 2026. Splunk contributed to several whole-portfolio agreements, added more than 280 customer logos and notched its highest number of competitive wins in any quarter of fiscal 2026, pushing Cisco past its full-year target of adding 1,000 Splunk customer logos. The enhancements include Cisco AI POD for Splunk, expanded AI-agent observability, Tokenomics capabilities and stronger agentic security operations, aimed at helping enterprises deploy, secure and monitor agentic AI at scale. More than 1,500 customers bought newer Cisco security products such as Secure Access, XDR, Hypershield and AI Defense in the fiscal fourth quarter, while the acquisitions of Galileo Technologies and Astrix Securities broaden Cisco's observability and security reach. The push puts Cisco up against Datadog, whose AI offerings include Agent Observability, Agent Console, Data Observability, GPU Monitoring and AI Guard, and CrowdStrike, whose Next-Gen SIEM ending ARR surpassed $695 million and whose Falcon Shield ARR surged more than 185% year over year in the second quarter of fiscal 2027. Cisco shares have appreciated 42.9% year to date, and the Zacks Consensus Estimate for earnings stands at $1.32 per share, implying 32% growth.
Leidos Wins $875 Million Navy Network Modernization Contract Extension
Leidos Holdings secured an $875 million contract extension to support and modernize networks serving more than 650,000 Navy and Marine Corps personnel worldwide. The agreement covers network services and infrastructure supporting the Navy Marine Corps Intranet, ONE-Net and Marine Corps Enterprise Network, enhancing secure connectivity for military operations across global locations. The award aligns with the company's NorthStar 2030 strategy, which focuses on digital modernization, cybersecurity and mission-critical technology solutions, and should provide additional revenue visibility while reinforcing Leidos' role in critical defense IT programs. Shares of Leidos have lost 29.7% in the past year compared with the industry's 17.7% decline, and the stock carries a Zacks Rank #3 (Hold).
Cloudbrink Launches OnGuard to Consolidate Enterprise Security Stack
Cloudbrink introduced OnGuard technology that extends a single Cloudbrink security and connectivity policy across users, devices and machines, taking aim at complex multi-product enterprise security stacks. The expanded platform gives enterprises an alternative to deploying and managing separate Cisco products for secure access, internet security, AI security and remote connectivity, consolidating ZTNA, Internet Security, Secure Web Gateway and AI security into one offering. OnGuard allows policy enforcement to begin when a device itself comes online, even before a user logs in, and to continue independently of the user session, with features including instant OnGuard availability, admin authorization, admin session termination, centralized visibility and selective policy control. CEO Prakash Mana said a single Cloudbrink platform can eliminate a significant portion of the Cisco secure-access stack, arguing that Umbrella, AnyConnect, Secure Access and AI Defense still force enterprises to manage multiple technologies, policies and operating models. The expansion builds on existing deployments, including at one U.S. insurance company where Cloudbrink replaced an environment that included Cisco AnyConnect and Fortinet, moving 300 employees on the first day and more than 600 during the first week, after which remote-connectivity support calls "pretty much disappeared," according to its VP of IT.
Fortinet Opens US$60 Million New York Innovation Hub
Fortinet has opened a new company-owned Innovation Hub in New York City, a 40,000 square foot facility valued at US$60 million that expands its U.S. footprint. The site houses advanced cybersecurity training labs, executive briefing spaces, hands-on technology demonstration areas, and a dedicated Fortinet Cloud point of presence, along with energy-efficient infrastructure aligned with the group's ESG priorities. Fortinet said the hub concentrates its experts, training and a Fortinet Cloud PoP in a single venue, supporting its push toward more software, subscription and services revenue. The company added that the larger executive briefing and demo footprint in a financial hub gives it more surface area to pitch platform-wide deals rather than single products. Fortinet noted the expansion adds to its global data center and PoP footprint while helping its integrated Security Fabric story, though it cautioned that higher fixed costs only work if SASE, cloud and large enterprise wins scale fast enough to offset earlier margin pressure.
Zscaler reported fourth-quarter revenue up 25% year over year to $898.2 million, with ARR rising 25% to $3.77 billion, though organic ARR excluding Red Canary's $141 million contribution grew 20% to $3.63 billion. FBN Securities reiterated an Outperform rating on September 4 and raised its price target to $190 from $175, citing improving underlying momentum. Non-GAAP operating margin hit a record 24% in the quarter, while GAAP net loss per diluted share narrowed to $0.02 from $0.11 a year earlier. For the first quarter of fiscal 2027, Zscaler guided revenue to $935 million to $939 million, up 19% year over year, with a non-GAAP gross margin of about 80%. However, the company's fiscal 2027 ARR guidance of $4.396 billion to $4.426 billion implies growth of only 16.6% to 17.4%, raising concerns that Zscaler could shift from a 25% growth cybersecurity company to a high-teens grower and face multiple compression amid competition from Palo Alto Networks and CrowdStrike.
F5 Launches New AI Security Tools as Shares Trade Near Fair Value
F5 is expanding deeper into application and AI security with new Distributed Cloud Bot Defense features and Workforce AI Security, tools designed to monitor devices, score risk in real time, and govern AI-driven activity. The launch comes as F5 shares have climbed 4.71% over one day and 10.59% over seven days, with a year-to-date share price return of 67.90% against a one-year total shareholder return of 33.10%. F5 last closed at $430.88, just below the most widely followed fair value estimate of $436.10, which uses an 8.81% discount rate, leaving only a thin valuation cushion. The stock trades at a P/E of 33.6x, above the US Communications sector at 33.2x and above an estimated fair ratio of 27.8x. Early deployments of F5's AI-focused offerings, including AI data delivery, AI gateway, and runtime security, along with partnerships with NVIDIA BlueField-3 and MinIO, are establishing new insertion points for the business, though the bullish narrative could appear stretched if hardware-heavy demand persists or hyperscalers keep more security and delivery in house.
F5 Launches AI Guardrails and Bot Defenses for Enterprise Security
F5 announced new AI-driven cybersecurity upgrades to its Distributed Cloud Bot Defense and enterprise security platform. The company introduced persistent device intelligence and agentic AI detection aimed at curbing automated fraud and abuse across client applications. F5 also launched Workforce AI Security to provide oversight of workforce AI usage, and integrated with MuleSoft's Agent Fabric for AI Guardrails. F5 runs multicloud application security and delivery services for enterprises across the US and several international regions, and the new AI-focused controls plug directly into the core traffic and workloads many corporate systems already rely on. The unresolved piece is how quickly these AI features convert into meaningful, recurring software revenue rather than remaining primarily as feature additions for existing customers, with the earliest proof point being management's disclosure of AI Security Platform traction when F5 reports results through fiscal 2027.
SentinelOne Named AI Security Platform Leader by Latio
SentinelOne was recognized as an AI Security Platform Leader by analyst firm Latio in its 2026 AI Security Market Report, sending shares up 2.9% in the afternoon session. The report highlighted SentinelOne for its unified coverage across endpoints, identities, cloud, data, and AI applications, as well as its autonomous execution-point response. The stock closed the day at $23.34, up 4.2% from the previous close. SentinelOne is up 59.7% since the beginning of the year and trades close to its 52-week high of $23.84 from August 2026.
Nokia Supplies 800G Optics to Telxius and DDoS Defense to ESpanix
Nokia Oyj is supplying 800G coherent pluggable optics to Telxius as the company upgrades the international terrestrial transport networks connecting its subsea cables, while ESpanix in Spain is deploying Nokia Deepfield Defender to power a new DDoS protection service for internet exchange customers. The two deployments are separate pieces of Nokia's broader telecom and security business rather than a single combined contract. Telxius plans to use Nokia optical technology to scale bandwidth and capacity on routes supporting its global subsea infrastructure. Nokia's profit margin stands at 3.4%, down from 5% a year earlier, leaving investors watching whether heavier AI and security workloads convert into higher quality earnings. The key marker over the next 12 to 24 months is the number of clearly disclosed commercial deals citing these 800G and Deepfield deployments as live, scaled services across Europe, the United States and Latin America.
Nokia Deploys Deepfield Defender DDoS Protection Across ESpanix Platforms in Spain
Nokia has expanded its network security business in Spain by deploying its Deepfield Defender solution across the Madrid and Barcelona platforms of ESpanix, the country's largest Internet exchange point. The deployment extends Nokia's distributed denial-of-service protection technology to more than 200 national and international networks connected to ESpanix. Nokia's technology combines AI-powered network analytics with its Deepfield Secure Genome security intelligence to detect and mitigate DDoS attacks within seconds, delivering protection directly within network infrastructure so ESpanix can mitigate attacks without redirecting traffic to external scrubbing centers, keeping Spanish Internet traffic and security operations within the country. The move expands Nokia's existing relationship with ESpanix and demonstrates the scalability of its Deepfield portfolio across multiple networks through a single Internet exchange platform. Nokia faces competition from Ericsson, which is incorporating Zero Trust principles and AI-driven security into 5G and next-generation network operations, and from Cisco Systems, which is expanding its AI-powered cybersecurity portfolio across networks, cloud environments and applications.
SE Labs Launches First Public PIVOT Security Test With Five Major Vendors
SE Labs announced the first public evaluation under PIVOT, its advanced security testing programme, with Broadcom, CrowdStrike, Fortinet, Palo Alto Networks and Sophos confirmed to take part. Results will be published in early 2027 and will include a comparative analysis of the participating products, detailed findings from the attack scenarios and SE Labs' inaugural public PIVOT Rankings. The evaluation arrives as several major vendors have stepped away from MITRE Engenuity ATT&CK Evaluations, reducing the number of leading products assessed through what had been one of the industry's most prominent common sources of technical evaluation data. PIVOT follows complete attack chains to show what happened during an attack, how far an attacker progressed, what defenders could see and understand, and how those outcomes compare across competing products, rather than stopping at evidence of what a product detected. Simon Edwards, CEO and founder of SE Labs, said the underlying evidence will be made available to Gartner and Forrester so their analysts can examine it and add their own independent interpretation.
CrowdStrike Expands Project QuiltWorks With North America AI Security Push
CrowdStrike Holdings expanded Project QuiltWorks with new U.S. and Canada localized AI cybersecurity services in September 2026. The company integrated its AI-driven security stack with data platform partner VAST Data to connect customer environments more directly to threat detection, and added Anthropic Claude Marketplace access to align its Falcon ecosystem with third party frontier AI tools used by enterprise clients. New partnerships include specialized North American security providers focused on frontier AI risk, remediation services, and incident response support. The shelf registration for about US$442.4 million of Class A shares adds capital flexibility. The clearest test for this read will be whether CrowdStrike starts tying QuiltWorks localization and AI marketplace routes to specific outcomes such as increased Falcon Next Gen SIEM and Guardian uptake, or higher annual recurring revenue mix from AI security modules in upcoming quarterly updates and partner case studies.
F5 Launches Agentless Workforce AI Security Offering
F5 announced the upcoming availability of F5 Workforce AI Security, a new agentless offering within the F5 AI Security Platform that gives organizations visibility and policy control over employee AI use and actions taken by AI agents on users' behalf. The Seattle-based company, which trades on NASDAQ under FFIV, said the offering is designed to govern workforce AI use, attribute AI interactions to users and agents, control agent actions before execution, and enforce policy in the interaction path. According to F5's 2026 State of Application Strategy Report, 66% of organizations already permit AI to automatically adjust policies and configurations. Kunal Anand, Chief Product Officer at F5, said employees are handing work to AI agents that can reach into enterprise systems, call tools, and change data on their behalf, and that Workforce AI Security applies intent-based guardrails in the network path to enforce policy before risky actions occur. The offering requires no additional endpoint client and integrates into existing SASE environments, with capabilities spanning browsers, CLIs, coding agents, MCP clients, and agent harnesses.
Leidos Wins $875 Million Navy Option Year for Network Contract
The Department of the Navy has awarded Leidos $875 million for the second option year of the Next Generation Enterprise Network Service Management, Integration and Transport contract, keeping more than 650,000 U.S. Navy and Marine Corps personnel securely connected worldwide. Under the award, Leidos manages more than 425,000 devices at more than 2,500 sites around the globe, handling all aspects of user support, operations and IT transformational activities on the Navy Marine Corps Intranet, the Outside the Continental United States Navy Enterprise Network and the Marine Corps Enterprise Network. Steve Hull, president of Leidos Digital, said military and civilian personnel rely on these networks to communicate, make decisions and carry out missions that protect the nation and its allies. Since being awarded the contract in 2020, Leidos has introduced automation that delivers patches to network devices 93% faster and accelerates patching across the enterprise by 94%. DJ LeGoff, a retired Navy captain and the Navy and Marine Corps portfolio leader at Leidos, said the results reflect the team's round-the-clock dedication. The award supports Leidos' NorthStar 2030 strategy and its focus on digital modernization, cyber capabilities and mission software.
CrowdStrike and Palo Alto Networks Race Into AI Cybersecurity
CrowdStrike and Palo Alto Networks are racing to answer the question Jensen Huang raised on Sept. 10, when he told investors at the Goldman Sachs Communacopia + Technology Conference that cybersecurity is likely to become AI's next major growth market. CrowdStrike unveiled SafeMind at its Fal.Con conference on Sept. 1, an agentic cybersecurity system built by its own Cyber Superintelligence Lab on top of open Nemotron models, which the company says detects threats 29% more accurately and remediates them six times faster than the frontier models it benchmarked against. CrowdStrike's fiscal second quarter revenue rose 26% to $1.47 billion, with net new annual recurring revenue climbing 51% to a record $333 million, and CEO George Kurtz disclosed an eight-figure Falcon Flex deal with a frontier AI lab. Palo Alto Networks took the opposite path, integrating CyberArk and Chronosphere and adding Console, an AI native platform for agentic enterprise workflows; its Next Generation Security annual recurring revenue reached $9.1 billion, up 63% year over year, and total remaining performance obligations crossed $20 billion for the first time, rising 34% to $21.2 billion, even as it swung to a GAAP net loss of $282 million in the quarter. Investors rewarded only CrowdStrike's report, sending its shares up roughly 20% on Aug. 27, while Palo Alto's shares fell more than 5% despite revenue rising 34% to $3.41 billion in its fiscal fourth quarter. The threat behind both bets is not hypothetical: Anthropic told Reuters it disrupted a Russia-linked hacking campaign that used its Claude models against more than 20 Ukrainian government and defense targets, and a joint study by Wiz and Irregular found AI agents completed sophisticated offensive security challenges for under $50 in computing costs versus close to $100,000 for the same work by paid human researchers.
Devicie Automates 1,500-Plus Apps Inside Microsoft Intune
Devicie announced a major expansion of the application management capabilities within its Intune management and automation platform, automating the operational work of keeping Windows and macOS applications current inside Microsoft Intune. The platform now automatically manages more than 1,500 Windows and macOS applications, alongside an organization's own line-of-business software at no additional charge, with new application versions typically made ready within Microsoft Intune within hours of publisher release. The company cited accelerating update pressure, noting that Microsoft's 8 September 2026 monthly security update addressed more than 950 vulnerabilities in a single release, while Jerry Gamblin's analysis of the CVE List records 1,255 Microsoft CVEs across the whole of 2025, and that Adobe moved from monthly to twice-monthly security bulletins in July 2026. Remediation deadlines have tightened as well, with the U.S. Cybersecurity and Infrastructure Security Agency in June 2026 replacing its earlier fourteen-day deadline for known exploited vulnerabilities with a tiered directive whose fastest tier is three days. Chief Executive Officer Alex Hesterberg said enterprises cannot meet that pace by adding more manual work and that automation at this speed requires trust. The catalog spans widely used software including Microsoft 365 Apps, Microsoft Visual Studio Code, Microsoft OneDrive, Google Chrome, Adobe Acrobat, Slack, Zoom Workplace and Mozilla Firefox, and Devicie said John Holland Group runs the enhanced application management in production across more than 60 worksites with $1.2 million in annual return, while Toyota Financial Services moved a 1,300-device fleet to modern management on Intune with Devicie, reducing device builds to 20 minutes.
Arista Issues Critical EOS and VeloCloud Security Advisories
Arista Networks released a batch of security advisories on September 9, turning an advance warning into an immediate customer maintenance task, with critical vulnerabilities affecting EOS and VeloCloud. Arista's updated summary lists critical EOS gNPSI and P4Runtime vulnerabilities with CVSS v3.1 scores of 10, alongside other findings, and customers must assess the conditions and remediation for their own environments. Cisco Systems' September 4 security commentary describes the broader problem, saying vulnerability discovery is accelerating beyond customers' ability to remediate it, and its September 2 advisories already include critical issues involving IOS XR and Nexus 9000 switches using Silicon One, with customers directed to fixed software. Cisco says it scanned 1.8 billion lines of code across 25 languages in eight weeks using frontier models, while Arista's May statement said AI-assisted testing caught complex flaws before software release. For both Cisco Systems and Arista Networks, the investment question is whether suppliers can keep expanding AI networks without letting the cost and disruption of securing them erode customer confidence, since finding defects creates engineering and service obligations before it creates incremental revenue.
PhillipCapital Downgrades Palo Alto Networks to Neutral, Raises Target to $346
PhillipCapital downgraded Palo Alto Networks to Neutral from Accumulate on September 7, while raising its price target to $346 from $320. The call captures the central debate on the cybersecurity company: its AI and platformization opportunity is compelling, but a roughly 160% stock rally from its February low to its August peak has raised the bar for further gains. Palo Alto's revenue rose 34% year over year to $3.4 billion in its fiscal 2026 fourth quarter, and Next-Generation Security ARR surged 63% to $9.10 billion, with nearly $1 billion of net new NGS ARR added in the quarter and more than 65% of that ARR coming from platformized customers. For fiscal 2027, management expects NGS ARR growth of 22% to 23% and revenue growth of 23% to 24%, though it still expects 63% NGS ARR growth in the fiscal 2027 first quarter, and it targets $20 billion in NGS ARR by fiscal 2030. PhillipCapital rolled its valuation forward and lifted its weighted average cost of capital to 5.2%, citing higher debt and a larger share count following acquisitions, while hedge funds holding the stock rose to 89 in the second quarter from 87 in the first and short interest reached 22.4 million shares, or 2.79% of the public float, as of August 14.
Zscaler CEO Cites AI Security Surge and Zero-Trust Momentum at Citi Conference
Zscaler CEO and Founder Jay Chaudhry said at Citi's TMT Conference that the company entered fiscal 2027 with an expanded product portfolio, improving sales momentum and growing customer interest in AI security and zero-trust architecture. Chaudhry said Zscaler expanded its AI-security lineup from one product a year ago, GenAI Security, to six integrated products, and that security-for-AI bookings exceeded $100 million over the 12 months disclosed after the third quarter, with fourth-quarter bookings in the category up 50% sequentially. Net-new annual recurring revenue growth rose from 7% in fiscal 2025 to 10% in the first half of fiscal 2026 and 17% in the fourth quarter, while customers using Zero Trust Everywhere increased from 300 a year earlier to 950 and the company completed a record number of $1 million deals. Zscaler launched Agentic SecOps at the conference, supported by its Red Canary acquisition, and introduced Z Flex, a flexible purchasing structure whose participating customers generated 30% higher upsell than non-participants in its first year. Chaudhry said AI security and Zero Trust Everywhere are the areas most likely to provide upside in fiscal 2027, and that he is watching adoption of the company's Agentic Exchange, which is in limited availability.
Ken Fisher Adds Cisco and Palo Alto Networks in AI Security Bet
Ken Fisher's Fisher Asset Management increased its stakes in Cisco Systems and Palo Alto Networks, according to consecutive SEC filings covering March-to-June changes. Cisco shares rose from 17,301,583 to 33,412,725, while the Palo Alto position increased from 256,661 to 5,755,989 shares. Cisco's fiscal fourth-quarter networking revenue increased 28% to approximately $9.8 billion, with security revenue up 14% to about $2.2 billion and total operating cash flow of $5.4 billion. Palo Alto's September 1 results showed fiscal fourth-quarter revenue up 34% to $3.41 billion and next-generation security annual recurring revenue of $9.10 billion, alongside a $282 million GAAP net loss driven by a fair-value charge on acquired convertible notes. August 14 short interest stood at 1.50% of Cisco's float and 2.79% of Palo Alto's, and the filings disclose no AI thesis behind the positions.
Netskope Posts 27% ARR Growth, Raises Full-Year Outlook on AI Security Push
Netskope reported second-quarter annual recurring revenue of $899 million, up 27%, with revenue of $220.5 million beating guidance as management raised its full-year outlook. Remaining performance obligations rose 36% to $1.35 billion, net retention held at 114%, and customers generating over $100,000 in annual recurring revenue grew 23% to 1,686, now 87% of total ARR. The company pegs its AI security greenfield opportunity at $170 billion within a broader $336 billion market, with about a third of that pipeline already in or entering the proof-of-concept phase. Netskope posted negative free cash flow of $29.8 million and guided to a full-year free cash flow margin of about 2%, cut roughly 5% of its workforce, and said its shift to annual billing is deferring cash collections, while third-quarter guidance implies growth slowing to roughly 24% from 29%.
Palo Alto Networks Falls 3% After Critical PAN-OS Vulnerability Advisory
Palo Alto Networks shares fell 3% in the afternoon session after the company published a security advisory addressing a critical buffer overflow vulnerability in its PAN-OS software. The advisory detailed an XML processing flaw cataloged as CVE-2026-0310 with a CVSSv4 base score of 9.2, a high-severity vulnerability that enables unauthenticated attackers to execute arbitrary code with root privileges or trigger denial-of-service conditions. The decline came despite positive analyst action, as Wedbush analyst Steven Wahrhaftig assumed coverage of Palo Alto Networks with a Buy rating and a $400 price target, placing the stock on the firm's Best Ideas List due to its platformization leadership. After the initial drop, the shares shed some of the losses and rose to $328.75, down 2.9% from the previous close. The stock is up 83.3% since the beginning of the year but remains 17% below its 52-week high of $396 from August 2026.
Nvidia and CrowdStrike Unveil SafeMind Agentic Cybersecurity System
Nvidia and CrowdStrike unveiled SafeMind, an agentic cybersecurity system built on Nvidia Nemotron models and technology from CrowdStrike's Cyber Superintelligence Lab, at CrowdStrike's Fal.Con 2026 conference. Nvidia described the architecture as a continuous loop in which offensive and defensive AI systems challenge and improve one another. Nvidia CEO Jensen Huang reinforced the thesis on September 10 at Goldman Sachs' Communacopia + Technology Conference, arguing cybersecurity is a natural successor to AI coding because defensive systems can operate continuously rather than waiting for a human prompt. For CrowdStrike, AI is simultaneously creating a threat and a product opportunity, since attackers can automate vulnerability discovery, phishing, malware development and lateral movement, while CrowdStrike's endpoint and identity telemetry gives its AI agents proprietary context. For Nvidia, cybersecurity creates a potentially attractive inference workload, as security agents may operate continuously across millions of endpoints, generating recurring demand for inference rather than one-time model training. Hedge-fund ownership of CrowdStrike rose to 89 funds in Q2 from 79 in Q1, while Nvidia rose to 285 from 275, and short interest stood at about 2.4% of CrowdStrike's float and 1.2% of Nvidia's float as of August 14.
CrowdStrike Holdings has been assigned a Zacks Rank #4 (Sell), with the consensus estimate for the current quarter falling 87% over the last 30 days to $0.31 per share, still a 29.2% increase from the year-ago quarter. The consensus estimate for the current fiscal year stands at $1.26, a year-over-year change of 35.5%, though that figure has dropped 61% over the past 30 days, while the next fiscal year's estimate of $1.61, up 28.2%, has risen 2.8% over the past month. Revenue consensus for the current quarter is $1.53 billion, a 23.7% year-over-year change, with current and next fiscal year estimates of $5.99 billion and $7.33 billion, representing changes of 24.5% and 22.3%. In the last reported quarter, CrowdStrike posted revenues of $1.47 billion, up 25.8% year over year, and EPS of $0.31 versus $0.23 a year ago, beating the Zacks Consensus Estimate of $1.44 billion by 2.15% on revenue and by 6.9% on EPS, and the company has topped consensus EPS and revenue estimates in each of the trailing four quarters. CrowdStrike is graded F on the Zacks Value Style Score, indicating it trades at a premium to its peers, and its shares have returned -7.4% over the past month versus the Zacks S&P 500 composite's -2% change, while the Zacks Security industry has lost 7.8% over the same period.
Japan finds hacked servers at Digital Agency, risking data leak for 246,000 people
Japan's Digital Agency disclosed that its servers were accessed without authorization, potentially exposing the personal data of about 246,000 citizens and related individuals. Large-scale file access was detected on the Government Solution Service network, or GSS, in late June through an account used for system maintenance. An investigation found that attackers exploited a vulnerability in a virtual private network, or VPN, to gain access to the system and may have stolen data belonging to civil servants and others using the network. The potentially leaked data includes names, email addresses, and phone numbers, but so far no evidence has confirmed that the data was misused. The incident comes amid increasingly severe cyberattacks in Japan, with the National Police Agency reporting that in the first half of 2026 Japan saw 123 ransomware attacks, the highest number in any six-month period since the government began keeping such statistics.
Cisco Slips as Huawei Trade-Secret Trial Opens in Brooklyn
Cisco Systems shares slipped approximately 0.5% to $108.865 Thursday as Huawei's federal criminal trial opened in Brooklyn, where prosecutors accused the Chinese technology company of conspiring to steal trade secrets from five U.S. businesses, including source code for Cisco's router operating system. Federal prosecutors also alleged sanctions and financial-system violations tied to Iran, while Huawei rejected the charges and described the disputed activity as legitimate business conduct or isolated employee behavior. The trial could run for roughly three months, and Cisco is not prosecuting the case, leaving investors with no disclosed financial recovery to price into the shares. Separately, Cisco booked $9.3 billion of fiscal 2026 AI orders, equal to about 14.7% of its $63.33 billion in annual revenue, and expects AI revenue to climb from approximately $4 billion to $7.5 billion in fiscal 2027. Cisco trades 46.56% above its $74.28 GF Value estimate.
Palo Alto Networks Posts 63% NGS ARR Growth but $282M GAAP Net Loss
Palo Alto Networks reported fiscal fourth-quarter revenue of $3.41 billion, up 34% year over year, alongside a $282 million GAAP net loss after earning $254 million a year earlier. Next-Generation Security annual recurring revenue rose 63% to $9.10 billion, though the company said the increase is not an organic growth rate because the current portfolio includes acquired identity and observability businesses absent from the prior-year base, and remaining performance obligations climbed 34% to $21.2 billion. GAAP operating income fell to $172 million from $497 million, cutting GAAP operating margin to 5.0% from 19.6%, while company-defined non-GAAP operating income reached $1.01 billion and non-GAAP net income was $853 million. The quarter's operating reconciliation included $487 million of share-based compensation-related charges, $281 million of acquired-intangible amortization and $68 million of acquisition-related costs, and the net-income gap also reflected a $524 million fair-value change in convertible senior notes acquired in the CyberArk transaction. Operating cash flow rose to $1.36 billion from $1.02 billion, and management guided fiscal 2027 revenue of $14.10 billion to $14.20 billion, growth of 23% to 24%, with NGS ARR expected to reach $11.075 billion to $11.175 billion, up 22% to 23%.
Fortinet Raises Full-Year 2026 Guidance After 26% Revenue Growth
Fortinet raised its full-year 2026 guidance across every major metric after second-quarter revenue climbed 26% year over year to $2.05 billion, with product revenues surging 52% and billings expanding 33%. For the full year, the cybersecurity company now expects revenues of $8.02 billion to $8.18 billion, billings of $9.35 billion to $9.55 billion, and non-GAAP earnings per share of $3.41 to $3.47, alongside a non-GAAP operating margin target of 35% to 37%. The Zacks Consensus Estimate for 2026 earnings stands at $3.40 per share, implying 23.19% year-over-year growth. Fortinet also expanded its FortiEndpoint platform with AI visibility and control, native data security, endpoint risk scoring and FortiAI-assisted operations, and in September 2026 moved to acquire Virtue AI, an innovator in AI runtime protection and automated AI validation. Fortinet shares have rallied 98% in the year-to-date period, outperforming the Zacks Security industry's 71.1% and the broader Computer and Technology sector's 18.5%, and the stock carries a Zacks Rank #1 (Strong Buy).
Japan records 123 ransomware cases in first half, a record high, with SMEs the main target
Japan's National Police Agency (NPA) said on September 10 that a total of 123 ransomware attacks were reported in Japan in the first half of this year, the highest half-year figure since record-keeping began in 2020. Of these, 79 targeted small and medium-sized enterprises (SMEs), 31 hit large companies, and 13 targeted other types of organizations. The NPA said more than half of all cases took over a month to recover systems, and 9 cases brought all business operations to a halt. Meanwhile, the number of detected suspicious accesses, often preparations for cyberattacks, rose by more than 4,000 per day per IP address compared with the same period a year earlier, reflecting the growing severity of cyber threats. The NPA has compiled half-year ransomware statistics since the second half of 2020. Ransomware is malware in which attackers demand a ransom in exchange for restoring access to a company's data, which has been encrypted and rendered unusable.
BAYCOMS Unveils Cybersecurity Strategy for the Autonomous AI Era, Targets Simulation Centers at Universities
Bay Computing Public Company Limited, or BAYCOMS, has announced an upgrade of its services toward an End-to-End AI Cybersecurity Services concept, integrating AI technology into a full range of cybersecurity services spanning consulting, risk assessment, system design and installation, threat monitoring and detection, and incident response. Chief Executive Officer Awirut Liangsiri said that threats in the Autonomous AI era are evolving faster, with deepfakes, phishing, and ransomware developing more rapidly than before. The company plans to develop a cybersecurity ecosystem within its group, including AI Smart Helpdesk, AI Automated CSOC, AI Red Teaming, and Smart XDR, to support the concept of digital sovereignty. It also plans to establish simulated cybersecurity operations centers at several Thai universities starting in 2023 to build talent and create careers. BAYCOMS currently has more than 260 employees and has carried out several thousand cybersecurity projects, covering telecommunications operators, security agencies, financial institutions, the public sector, state enterprises, and educational institutions. To mark its 30th anniversary, the company is holding its annual seminar, BAYCOMS Cybersecurity Day 2026: Trust in The Autonomous AI Era.
Cloudflare Shares Jump 10.5% After CFO Raises Long-Term Growth Outlook
Cloudflare Inc. raised its long-term growth outlook to 50 percent annually from 40 percent at present, sending its shares up 10.51 percent on Wednesday to close at $10.51 apiece. Speaking at the Goldman Sachs Communacopia + Technology Conference 2026, Chief Finance Officer Thomas Seifert said the company is moving beyond a traditional software-as-a-service model to become an agentic AI platform, and that its future opportunity could be much larger than its business, with revenues projected to grow 36 percent year-on-year. In the second quarter, Cloudflare grew revenues 36 percent to $696.1 million from $512 million a year earlier, while its net loss widened 237 percent to $169.98 million from $50.4 million amid a 206 percent higher operating loss. Earlier this month the company partnered with OpenAI on the early launch of Vulnerability Discovery and Remediation, available in early access through Cloudflare Managed Defense, which CEO Matthew Prince said shifts defense strategy from chasing patches one vulnerability at a time to an automated approach. Institutional interest also rose in the second quarter, with 87 hedge funds holding positions in the stock, up from 84 in the prior quarter, and their combined holdings climbing 11.8 percent to $3.97 billion from $3.55 billion.
U.S. stock futures traded below the flatline on Wednesday as oil prices climbed above $100 a barrel and investors awaited inflation data that could reinforce expectations for the Federal Reserve to raise interest rates later this month. By 06:13 ET, S&P 500 futures had fallen 19 points, or 0.3%, while Nasdaq 100 futures were down 134 points, or 0.5%, and Dow Jones futures had slipped 206 points, or 0.4%. Meta Platforms shares surged 3.6% in premarket trading after the company launched Muse, its autonomous AI personal agent, and introduced a tiered AI subscription model with plans at $20 and $100 per month. Evommune shares fell 13.9% to $11.26 after its EVO756 drug candidate failed to meet primary and secondary endpoints in a Phase 2b trial for atopic dermatitis, and the company will not advance it in that indication. Braze shares tumbled 11.5% despite beating fiscal second-quarter estimates, as its third-quarter profit guidance fell short of consensus and growth showed signs of slowing. NETGEAR shares jumped 8.9% after the FCC banned imports of new consumer routers manufactured outside the U.S., a move that could benefit NETGEAR due to its existing FCC approval exemption.
CrowdStrike CEO Warns AI Exposes Gaps in Legacy Cybersecurity Tools
CrowdStrike Holdings CEO George Kurtz said AI is exposing gaps in corporate cybersecurity defenses that legacy tools cannot handle, speaking on CNBC's "Mad Money" a day after the company posted record quarterly results that sent shares up more than 20% to a record-high close near $228. Kurtz noted that many companies recognize that legacy technology is not good enough, citing Anthropic's Mythos model and an OpenAI agent that breached AI startup Hugging Face last month as evidence of the rapidly evolving threat landscape. CrowdStrike's fiscal second-quarter revenue rose 26% to $1.47 billion, with annual recurring revenue up 25% to $5.84 billion and a record $332.8 million in net new ARR added during the quarter. The stock's surge was driven by these record results, and Kurtz's comments highlight a potential switching opportunity for CrowdStrike as customers consolidate tools to address AI-driven threats. However, the sharp rally raises expectations, and the company must prove it can sustain its growth amid competing technology priorities and tighter budgets.
SentinelOne Shares Fall 7.7% Despite Raised Guidance and New OpenAI Tools
In late August 2026, SentinelOne reported second-quarter revenue of US$291.98 million and a net loss of US$93.4 million, raised full-year revenue guidance to US$1.20–US$1.21 billion, and later announced expanded Wayfinder Frontier AI Services powered by OpenAI Daybreak models such as GPT-5.6-Cyber to enhance threat detection and remediation. The integration of frontier AI models like GPT-5.6-Cyber into Wayfinder Frontier AI Services, coupled with human-validated code risk analysis and compromise assessments, could materially strengthen SentinelOne's positioning in AI-powered cybersecurity workflows where accuracy, speed, and expert oversight are critical. Despite these developments, the stock fell 7.7%, reflecting investor concerns about persistent losses and margin pressure from heavy R&D investment. The company's narrative projects US$1.7 billion revenue and US$196.5 million earnings by 2029, requiring 18.0% yearly revenue growth and a US$515.2 million earnings increase from -US$318.7 million today, with a fair value estimate of US$19.87.