IT security used to be like building a castle — dig a moat, raise a wall (firewall) around the office. Anyone inside the city counts as safe. But once everyone works from home and the apps move to the cloud, the castle stands empty — people and data are all outside the walls. So the new idea flips it on its head: stop trusting anyone based on location, and check everyone every single time they ask for access (zero trust), then lift the entire security job up to the cloud (SASE). This is one of the fastest-growing markets in all of security.
Contains
Theme index· base 100 · USD total return
No index history for this theme yet.
News & notes movingNetwork Security & SASE
Network Security & SASE▲
Palo Alto Networks Fair Value Estimate Raised 17% to US$395.38
The fair value estimate for Palo Alto Networks has been raised from US$336.70 to US$395.38, a roughly 17% increase in the underlying model, after a wave of analyst price target hikes. RBC Capital, Wells Fargo, BofA, Morgan Stanley and Truist lifted their targets into the low to mid US$400s, citing stronger cybersecurity demand as AI usage expands and customers consolidate spending with larger platforms. Goldman Sachs, Oppenheimer, BTIG and Susquehanna pointed to solid Q4 results and guidance, with broad based strength across firewalls, SASE, observability, identity and AI security modules. On the bearish side, Bernstein and Phillip Securities moved to more neutral stances while still raising targets, and Stephens and UBS described the risk or reward as more balanced with shares near peak valuation levels. The updated model trims the revenue growth assumption to about 17.31% from about 19.09% and the net profit margin outlook to about 13.84% from about 14.51%, while the future P/E rises to about 197.87x from about 164.67x and the discount rate adjusts to about 8.60% from 8.40%.
Palo Alto Networks SASE Bookings Jump 40% as Displacements Hit $400 Million
Palo Alto Networks said its SASE bookings grew 40% in fiscal 2026, with the company displacing legacy vendors in nearly 100 customer accounts representing more than $400 million in total contract value, roughly double the prior year's displacement volume. Management said PANW is currently the No. 2 player in SASE and aims to become the market leader over the next five to seven years, helped by integrating SASE with its firewall and SD-WAN products so existing customers can standardize on one vendor. In the fourth quarter of fiscal 2026, a global telecom leader signed a $126 million agreement to expand its next-generation firewall footprint while replacing legacy proxy providers with Prisma Access for SASE, and agentic traffic on the company's SASE platform has increased 9x over the past nine months. Rival Fortinet said its SASE Firewall business grew 34% in the second quarter of 2026 to more than $2 billion, while Unified SASE billings rose 35%, and Zscaler reported ARR up 25% year over year in the fourth quarter of fiscal 2026. Palo Alto Networks shares have jumped 104.1% year to date versus a 92.6% gain for the Zacks Security industry, and the stock trades at a forward price-to-sales ratio of 21.31X against an industry average of 19.13X.
Fastly Posts 23% Revenue Growth as Security Sales Jump 43%
Fastly reported quarterly revenue of $183 million, up 23% year over year, with security revenue climbing 43% and delivery services revenue rising 17%, CFO Rich Wong said at a Piper Sandler conference. Remaining performance obligations increased 38% year over year, and the current portion of RPO rose 44%, which Wong attributed to stronger customer commitments amid component shortages. Wong credited the security growth to an expanded portfolio that now spans five security products, up from a single web application firewall, and to improved sales execution under Scott Lovett, who joined as head of sales in mid-2024. Bot management and DDoS protection each posted triple-digit year-over-year growth, and net retention reached a four-year high of 117%. Fastly also said it will hold an investor day at Nasdaq MarketSite in New York to discuss a longer-term operating model and its outlook over the next three years, though it does not plan to provide fiscal 2027 guidance at the event.
Cisco's Splunk Push Adds AI Security Tools as Rivals CrowdStrike and Datadog Close In
Cisco Systems is expanding its Splunk portfolio with new artificial intelligence security and observability capabilities after the unit posted double-digit order growth in the fourth quarter of fiscal 2026. Splunk contributed to several whole-portfolio agreements, added more than 280 customer logos and notched its highest number of competitive wins in any quarter of fiscal 2026, pushing Cisco past its full-year target of adding 1,000 Splunk customer logos. The enhancements include Cisco AI POD for Splunk, expanded AI-agent observability, Tokenomics capabilities and stronger agentic security operations, aimed at helping enterprises deploy, secure and monitor agentic AI at scale. More than 1,500 customers bought newer Cisco security products such as Secure Access, XDR, Hypershield and AI Defense in the fiscal fourth quarter, while the acquisitions of Galileo Technologies and Astrix Securities broaden Cisco's observability and security reach. The push puts Cisco up against Datadog, whose AI offerings include Agent Observability, Agent Console, Data Observability, GPU Monitoring and AI Guard, and CrowdStrike, whose Next-Gen SIEM ending ARR surpassed $695 million and whose Falcon Shield ARR surged more than 185% year over year in the second quarter of fiscal 2027. Cisco shares have appreciated 42.9% year to date, and the Zacks Consensus Estimate for earnings stands at $1.32 per share, implying 32% growth.
Leidos Wins $875 Million Navy Network Modernization Contract Extension
Leidos Holdings secured an $875 million contract extension to support and modernize networks serving more than 650,000 Navy and Marine Corps personnel worldwide. The agreement covers network services and infrastructure supporting the Navy Marine Corps Intranet, ONE-Net and Marine Corps Enterprise Network, enhancing secure connectivity for military operations across global locations. The award aligns with the company's NorthStar 2030 strategy, which focuses on digital modernization, cybersecurity and mission-critical technology solutions, and should provide additional revenue visibility while reinforcing Leidos' role in critical defense IT programs. Shares of Leidos have lost 29.7% in the past year compared with the industry's 17.7% decline, and the stock carries a Zacks Rank #3 (Hold).
Cloudbrink Launches OnGuard to Consolidate Enterprise Security Stack
Cloudbrink introduced OnGuard technology that extends a single Cloudbrink security and connectivity policy across users, devices and machines, taking aim at complex multi-product enterprise security stacks. The expanded platform gives enterprises an alternative to deploying and managing separate Cisco products for secure access, internet security, AI security and remote connectivity, consolidating ZTNA, Internet Security, Secure Web Gateway and AI security into one offering. OnGuard allows policy enforcement to begin when a device itself comes online, even before a user logs in, and to continue independently of the user session, with features including instant OnGuard availability, admin authorization, admin session termination, centralized visibility and selective policy control. CEO Prakash Mana said a single Cloudbrink platform can eliminate a significant portion of the Cisco secure-access stack, arguing that Umbrella, AnyConnect, Secure Access and AI Defense still force enterprises to manage multiple technologies, policies and operating models. The expansion builds on existing deployments, including at one U.S. insurance company where Cloudbrink replaced an environment that included Cisco AnyConnect and Fortinet, moving 300 employees on the first day and more than 600 during the first week, after which remote-connectivity support calls "pretty much disappeared," according to its VP of IT.
Fortinet Opens US$60 Million New York Innovation Hub
Fortinet has opened a new company-owned Innovation Hub in New York City, a 40,000 square foot facility valued at US$60 million that expands its U.S. footprint. The site houses advanced cybersecurity training labs, executive briefing spaces, hands-on technology demonstration areas, and a dedicated Fortinet Cloud point of presence, along with energy-efficient infrastructure aligned with the group's ESG priorities. Fortinet said the hub concentrates its experts, training and a Fortinet Cloud PoP in a single venue, supporting its push toward more software, subscription and services revenue. The company added that the larger executive briefing and demo footprint in a financial hub gives it more surface area to pitch platform-wide deals rather than single products. Fortinet noted the expansion adds to its global data center and PoP footprint while helping its integrated Security Fabric story, though it cautioned that higher fixed costs only work if SASE, cloud and large enterprise wins scale fast enough to offset earlier margin pressure.
Zscaler reported fourth-quarter revenue up 25% year over year to $898.2 million, with ARR rising 25% to $3.77 billion, though organic ARR excluding Red Canary's $141 million contribution grew 20% to $3.63 billion. FBN Securities reiterated an Outperform rating on September 4 and raised its price target to $190 from $175, citing improving underlying momentum. Non-GAAP operating margin hit a record 24% in the quarter, while GAAP net loss per diluted share narrowed to $0.02 from $0.11 a year earlier. For the first quarter of fiscal 2027, Zscaler guided revenue to $935 million to $939 million, up 19% year over year, with a non-GAAP gross margin of about 80%. However, the company's fiscal 2027 ARR guidance of $4.396 billion to $4.426 billion implies growth of only 16.6% to 17.4%, raising concerns that Zscaler could shift from a 25% growth cybersecurity company to a high-teens grower and face multiple compression amid competition from Palo Alto Networks and CrowdStrike.
F5 Launches New AI Security Tools as Shares Trade Near Fair Value
F5 is expanding deeper into application and AI security with new Distributed Cloud Bot Defense features and Workforce AI Security, tools designed to monitor devices, score risk in real time, and govern AI-driven activity. The launch comes as F5 shares have climbed 4.71% over one day and 10.59% over seven days, with a year-to-date share price return of 67.90% against a one-year total shareholder return of 33.10%. F5 last closed at $430.88, just below the most widely followed fair value estimate of $436.10, which uses an 8.81% discount rate, leaving only a thin valuation cushion. The stock trades at a P/E of 33.6x, above the US Communications sector at 33.2x and above an estimated fair ratio of 27.8x. Early deployments of F5's AI-focused offerings, including AI data delivery, AI gateway, and runtime security, along with partnerships with NVIDIA BlueField-3 and MinIO, are establishing new insertion points for the business, though the bullish narrative could appear stretched if hardware-heavy demand persists or hyperscalers keep more security and delivery in house.
F5 Launches AI Guardrails and Bot Defenses for Enterprise Security
F5 announced new AI-driven cybersecurity upgrades to its Distributed Cloud Bot Defense and enterprise security platform. The company introduced persistent device intelligence and agentic AI detection aimed at curbing automated fraud and abuse across client applications. F5 also launched Workforce AI Security to provide oversight of workforce AI usage, and integrated with MuleSoft's Agent Fabric for AI Guardrails. F5 runs multicloud application security and delivery services for enterprises across the US and several international regions, and the new AI-focused controls plug directly into the core traffic and workloads many corporate systems already rely on. The unresolved piece is how quickly these AI features convert into meaningful, recurring software revenue rather than remaining primarily as feature additions for existing customers, with the earliest proof point being management's disclosure of AI Security Platform traction when F5 reports results through fiscal 2027.
Nokia Supplies 800G Optics to Telxius and DDoS Defense to ESpanix
Nokia Oyj is supplying 800G coherent pluggable optics to Telxius as the company upgrades the international terrestrial transport networks connecting its subsea cables, while ESpanix in Spain is deploying Nokia Deepfield Defender to power a new DDoS protection service for internet exchange customers. The two deployments are separate pieces of Nokia's broader telecom and security business rather than a single combined contract. Telxius plans to use Nokia optical technology to scale bandwidth and capacity on routes supporting its global subsea infrastructure. Nokia's profit margin stands at 3.4%, down from 5% a year earlier, leaving investors watching whether heavier AI and security workloads convert into higher quality earnings. The key marker over the next 12 to 24 months is the number of clearly disclosed commercial deals citing these 800G and Deepfield deployments as live, scaled services across Europe, the United States and Latin America.
Nokia Deploys Deepfield Defender DDoS Protection Across ESpanix Platforms in Spain
Nokia has expanded its network security business in Spain by deploying its Deepfield Defender solution across the Madrid and Barcelona platforms of ESpanix, the country's largest Internet exchange point. The deployment extends Nokia's distributed denial-of-service protection technology to more than 200 national and international networks connected to ESpanix. Nokia's technology combines AI-powered network analytics with its Deepfield Secure Genome security intelligence to detect and mitigate DDoS attacks within seconds, delivering protection directly within network infrastructure so ESpanix can mitigate attacks without redirecting traffic to external scrubbing centers, keeping Spanish Internet traffic and security operations within the country. The move expands Nokia's existing relationship with ESpanix and demonstrates the scalability of its Deepfield portfolio across multiple networks through a single Internet exchange platform. Nokia faces competition from Ericsson, which is incorporating Zero Trust principles and AI-driven security into 5G and next-generation network operations, and from Cisco Systems, which is expanding its AI-powered cybersecurity portfolio across networks, cloud environments and applications.
SE Labs Launches First Public PIVOT Security Test With Five Major Vendors
SE Labs announced the first public evaluation under PIVOT, its advanced security testing programme, with Broadcom, CrowdStrike, Fortinet, Palo Alto Networks and Sophos confirmed to take part. Results will be published in early 2027 and will include a comparative analysis of the participating products, detailed findings from the attack scenarios and SE Labs' inaugural public PIVOT Rankings. The evaluation arrives as several major vendors have stepped away from MITRE Engenuity ATT&CK Evaluations, reducing the number of leading products assessed through what had been one of the industry's most prominent common sources of technical evaluation data. PIVOT follows complete attack chains to show what happened during an attack, how far an attacker progressed, what defenders could see and understand, and how those outcomes compare across competing products, rather than stopping at evidence of what a product detected. Simon Edwards, CEO and founder of SE Labs, said the underlying evidence will be made available to Gartner and Forrester so their analysts can examine it and add their own independent interpretation.
F5 Launches Agentless Workforce AI Security Offering
F5 announced the upcoming availability of F5 Workforce AI Security, a new agentless offering within the F5 AI Security Platform that gives organizations visibility and policy control over employee AI use and actions taken by AI agents on users' behalf. The Seattle-based company, which trades on NASDAQ under FFIV, said the offering is designed to govern workforce AI use, attribute AI interactions to users and agents, control agent actions before execution, and enforce policy in the interaction path. According to F5's 2026 State of Application Strategy Report, 66% of organizations already permit AI to automatically adjust policies and configurations. Kunal Anand, Chief Product Officer at F5, said employees are handing work to AI agents that can reach into enterprise systems, call tools, and change data on their behalf, and that Workforce AI Security applies intent-based guardrails in the network path to enforce policy before risky actions occur. The offering requires no additional endpoint client and integrates into existing SASE environments, with capabilities spanning browsers, CLIs, coding agents, MCP clients, and agent harnesses.
Leidos Wins $875 Million Navy Option Year for Network Contract
The Department of the Navy has awarded Leidos $875 million for the second option year of the Next Generation Enterprise Network Service Management, Integration and Transport contract, keeping more than 650,000 U.S. Navy and Marine Corps personnel securely connected worldwide. Under the award, Leidos manages more than 425,000 devices at more than 2,500 sites around the globe, handling all aspects of user support, operations and IT transformational activities on the Navy Marine Corps Intranet, the Outside the Continental United States Navy Enterprise Network and the Marine Corps Enterprise Network. Steve Hull, president of Leidos Digital, said military and civilian personnel rely on these networks to communicate, make decisions and carry out missions that protect the nation and its allies. Since being awarded the contract in 2020, Leidos has introduced automation that delivers patches to network devices 93% faster and accelerates patching across the enterprise by 94%. DJ LeGoff, a retired Navy captain and the Navy and Marine Corps portfolio leader at Leidos, said the results reflect the team's round-the-clock dedication. The award supports Leidos' NorthStar 2030 strategy and its focus on digital modernization, cyber capabilities and mission software.
Arista Issues Critical EOS and VeloCloud Security Advisories
Arista Networks released a batch of security advisories on September 9, turning an advance warning into an immediate customer maintenance task, with critical vulnerabilities affecting EOS and VeloCloud. Arista's updated summary lists critical EOS gNPSI and P4Runtime vulnerabilities with CVSS v3.1 scores of 10, alongside other findings, and customers must assess the conditions and remediation for their own environments. Cisco Systems' September 4 security commentary describes the broader problem, saying vulnerability discovery is accelerating beyond customers' ability to remediate it, and its September 2 advisories already include critical issues involving IOS XR and Nexus 9000 switches using Silicon One, with customers directed to fixed software. Cisco says it scanned 1.8 billion lines of code across 25 languages in eight weeks using frontier models, while Arista's May statement said AI-assisted testing caught complex flaws before software release. For both Cisco Systems and Arista Networks, the investment question is whether suppliers can keep expanding AI networks without letting the cost and disruption of securing them erode customer confidence, since finding defects creates engineering and service obligations before it creates incremental revenue.
PhillipCapital Downgrades Palo Alto Networks to Neutral, Raises Target to $346
PhillipCapital downgraded Palo Alto Networks to Neutral from Accumulate on September 7, while raising its price target to $346 from $320. The call captures the central debate on the cybersecurity company: its AI and platformization opportunity is compelling, but a roughly 160% stock rally from its February low to its August peak has raised the bar for further gains. Palo Alto's revenue rose 34% year over year to $3.4 billion in its fiscal 2026 fourth quarter, and Next-Generation Security ARR surged 63% to $9.10 billion, with nearly $1 billion of net new NGS ARR added in the quarter and more than 65% of that ARR coming from platformized customers. For fiscal 2027, management expects NGS ARR growth of 22% to 23% and revenue growth of 23% to 24%, though it still expects 63% NGS ARR growth in the fiscal 2027 first quarter, and it targets $20 billion in NGS ARR by fiscal 2030. PhillipCapital rolled its valuation forward and lifted its weighted average cost of capital to 5.2%, citing higher debt and a larger share count following acquisitions, while hedge funds holding the stock rose to 89 in the second quarter from 87 in the first and short interest reached 22.4 million shares, or 2.79% of the public float, as of August 14.
Zscaler CEO Cites AI Security Surge and Zero-Trust Momentum at Citi Conference
Zscaler CEO and Founder Jay Chaudhry said at Citi's TMT Conference that the company entered fiscal 2027 with an expanded product portfolio, improving sales momentum and growing customer interest in AI security and zero-trust architecture. Chaudhry said Zscaler expanded its AI-security lineup from one product a year ago, GenAI Security, to six integrated products, and that security-for-AI bookings exceeded $100 million over the 12 months disclosed after the third quarter, with fourth-quarter bookings in the category up 50% sequentially. Net-new annual recurring revenue growth rose from 7% in fiscal 2025 to 10% in the first half of fiscal 2026 and 17% in the fourth quarter, while customers using Zero Trust Everywhere increased from 300 a year earlier to 950 and the company completed a record number of $1 million deals. Zscaler launched Agentic SecOps at the conference, supported by its Red Canary acquisition, and introduced Z Flex, a flexible purchasing structure whose participating customers generated 30% higher upsell than non-participants in its first year. Chaudhry said AI security and Zero Trust Everywhere are the areas most likely to provide upside in fiscal 2027, and that he is watching adoption of the company's Agentic Exchange, which is in limited availability.
Netskope Posts 27% ARR Growth, Raises Full-Year Outlook on AI Security Push
Netskope reported second-quarter annual recurring revenue of $899 million, up 27%, with revenue of $220.5 million beating guidance as management raised its full-year outlook. Remaining performance obligations rose 36% to $1.35 billion, net retention held at 114%, and customers generating over $100,000 in annual recurring revenue grew 23% to 1,686, now 87% of total ARR. The company pegs its AI security greenfield opportunity at $170 billion within a broader $336 billion market, with about a third of that pipeline already in or entering the proof-of-concept phase. Netskope posted negative free cash flow of $29.8 million and guided to a full-year free cash flow margin of about 2%, cut roughly 5% of its workforce, and said its shift to annual billing is deferring cash collections, while third-quarter guidance implies growth slowing to roughly 24% from 29%.
Palo Alto Networks Falls 3% After Critical PAN-OS Vulnerability Advisory
Palo Alto Networks shares fell 3% in the afternoon session after the company published a security advisory addressing a critical buffer overflow vulnerability in its PAN-OS software. The advisory detailed an XML processing flaw cataloged as CVE-2026-0310 with a CVSSv4 base score of 9.2, a high-severity vulnerability that enables unauthenticated attackers to execute arbitrary code with root privileges or trigger denial-of-service conditions. The decline came despite positive analyst action, as Wedbush analyst Steven Wahrhaftig assumed coverage of Palo Alto Networks with a Buy rating and a $400 price target, placing the stock on the firm's Best Ideas List due to its platformization leadership. After the initial drop, the shares shed some of the losses and rose to $328.75, down 2.9% from the previous close. The stock is up 83.3% since the beginning of the year but remains 17% below its 52-week high of $396 from August 2026.
Japan finds hacked servers at Digital Agency, risking data leak for 246,000 people
Japan's Digital Agency disclosed that its servers were accessed without authorization, potentially exposing the personal data of about 246,000 citizens and related individuals. Large-scale file access was detected on the Government Solution Service network, or GSS, in late June through an account used for system maintenance. An investigation found that attackers exploited a vulnerability in a virtual private network, or VPN, to gain access to the system and may have stolen data belonging to civil servants and others using the network. The potentially leaked data includes names, email addresses, and phone numbers, but so far no evidence has confirmed that the data was misused. The incident comes amid increasingly severe cyberattacks in Japan, with the National Police Agency reporting that in the first half of 2026 Japan saw 123 ransomware attacks, the highest number in any six-month period since the government began keeping such statistics.
Cisco Slips as Huawei Trade-Secret Trial Opens in Brooklyn
Cisco Systems shares slipped approximately 0.5% to $108.865 Thursday as Huawei's federal criminal trial opened in Brooklyn, where prosecutors accused the Chinese technology company of conspiring to steal trade secrets from five U.S. businesses, including source code for Cisco's router operating system. Federal prosecutors also alleged sanctions and financial-system violations tied to Iran, while Huawei rejected the charges and described the disputed activity as legitimate business conduct or isolated employee behavior. The trial could run for roughly three months, and Cisco is not prosecuting the case, leaving investors with no disclosed financial recovery to price into the shares. Separately, Cisco booked $9.3 billion of fiscal 2026 AI orders, equal to about 14.7% of its $63.33 billion in annual revenue, and expects AI revenue to climb from approximately $4 billion to $7.5 billion in fiscal 2027. Cisco trades 46.56% above its $74.28 GF Value estimate.
Fortinet Raises Full-Year 2026 Guidance After 26% Revenue Growth
Fortinet raised its full-year 2026 guidance across every major metric after second-quarter revenue climbed 26% year over year to $2.05 billion, with product revenues surging 52% and billings expanding 33%. For the full year, the cybersecurity company now expects revenues of $8.02 billion to $8.18 billion, billings of $9.35 billion to $9.55 billion, and non-GAAP earnings per share of $3.41 to $3.47, alongside a non-GAAP operating margin target of 35% to 37%. The Zacks Consensus Estimate for 2026 earnings stands at $3.40 per share, implying 23.19% year-over-year growth. Fortinet also expanded its FortiEndpoint platform with AI visibility and control, native data security, endpoint risk scoring and FortiAI-assisted operations, and in September 2026 moved to acquire Virtue AI, an innovator in AI runtime protection and automated AI validation. Fortinet shares have rallied 98% in the year-to-date period, outperforming the Zacks Security industry's 71.1% and the broader Computer and Technology sector's 18.5%, and the stock carries a Zacks Rank #1 (Strong Buy).
Cloudflare Shares Jump 10.5% After CFO Raises Long-Term Growth Outlook
Cloudflare Inc. raised its long-term growth outlook to 50 percent annually from 40 percent at present, sending its shares up 10.51 percent on Wednesday to close at $10.51 apiece. Speaking at the Goldman Sachs Communacopia + Technology Conference 2026, Chief Finance Officer Thomas Seifert said the company is moving beyond a traditional software-as-a-service model to become an agentic AI platform, and that its future opportunity could be much larger than its business, with revenues projected to grow 36 percent year-on-year. In the second quarter, Cloudflare grew revenues 36 percent to $696.1 million from $512 million a year earlier, while its net loss widened 237 percent to $169.98 million from $50.4 million amid a 206 percent higher operating loss. Earlier this month the company partnered with OpenAI on the early launch of Vulnerability Discovery and Remediation, available in early access through Cloudflare Managed Defense, which CEO Matthew Prince said shifts defense strategy from chasing patches one vulnerability at a time to an automated approach. Institutional interest also rose in the second quarter, with 87 hedge funds holding positions in the stock, up from 84 in the prior quarter, and their combined holdings climbing 11.8 percent to $3.97 billion from $3.55 billion.
Zscaler Falls 7.8% on Slower 2027 Outlook and AI Restructuring
Zscaler, Inc. recently reported its fourth-quarter and full-year fiscal 2026 results, posting revenue of US$898.19 million for the quarter and US$3.35 billion for the year, while remaining loss-making on a net income basis. The company issued fiscal 2027 guidance pointing to slower revenue and ARR growth, announced a roughly 3% workforce reduction to prioritize AI-focused initiatives, and filed a US$1.69 billion shelf registration for ESOP-related common stock offerings. The fiscal 2027 outlook calls for ARR of US$4.40 billion to US$4.43 billion and revenue of US$3.91 billion to US$3.94 billion, representing about 16.6% to 17.5% growth, a step down from prior growth rates. This slower guidance and restructuring have raised concerns about demand cooling and longer sales cycles, contributing to the stock's 7.8% decline.
Zscaler reported fourth-quarter fiscal 2026 non-GAAP earnings of $1.19 per share, up 33.7% year over year and beating the Zacks Consensus Estimate by 9.2%. Revenues rose 24.9% to $898.2 million, topping expectations by 2.4%, driven by broad geographic growth, platform adoption, and AI-related demand. Annual recurring revenue increased 25% to $3.771 billion, with total net new ARR of $246 million, up 24% year over year. Excluding the Red Canary acquisition, net new ARR was $232 million, up 17%, while total ARR excluding the acquisition grew 20% to $3.63 billion; Red Canary contributed $141 million in ARR. The company issued fiscal 2027 guidance projecting revenues of $3.908-$3.938 billion, ARR of $4.396-$4.426 billion, and non-GAAP earnings of $4.86-$4.90 per share, while also announcing a workforce restructuring affecting about 3% of employees with charges of $30-$33 million.
Corero shares jump 10% on $3.9 million telecom and NeoCloud deals
Corero Network Security PLC saw its shares rise 10% to 8p after securing a combined $3.9 million in new agreements to deploy its sovereign cybersecurity defenses across the UK telecommunications sector and the global NeoCloud sector. The larger of the two deals is a five-year contract worth $3.4 million with a leading UK-based tier 1 fixed and mobile telecom provider, delivered with a strategic alliance partner, integrating SmartWall ONE and CORE platforms with advanced Layer 7 TLS protection to meet obligations under the Telecommunications Security Act and the UK Cyber Security and Resilience Bill. Separately, the company signed a three-year agreement worth $0.5 million to provide real-time DDoS protection for one of the world's largest NeoCloud operators, deploying the technology across two data centers to ensure high uptime and rapid response. These wins underscore the company's on-premises technology and strengthen its position in critical national infrastructure, with management eyeing further opportunities in AI and NeoCloud data center markets.
F5 Unveils AI-Powered WAF and Virtual Patching to Block Frontier AI Threats
F5 has announced new innovations to its AI-powered web application firewall and runtime security that enable faster virtual patching, allowing security teams to block frontier AI-driven threats in minutes. The enhancements, available now on Distributed Cloud as part of the F5 Application Delivery and Security Platform, include anomaly detection and agentic threat intelligence, which together provide real-time protection by scoring each request dynamically. In internal testing, the solution achieved 98% threat detection efficacy while reducing false positives to 1%. The virtual patching capabilities also extend to F5 WAF for BIG-IP, and F5 Insight for ADSP accelerates patching of underlying infrastructure. These features give organizations time to make risk-based decisions rather than reactive compromises, addressing the collapse of time between vulnerability discovery and exploitation caused by frontier AI.
Nile Integrates Secure NaaS with CrowdStrike Falcon Next-Gen SIEM
Nile, the pioneer of Secure Network-as-a-Service, announced at Fal.Con 2026 a new integration with CrowdStrike Falcon Next-Gen SIEM, bringing Nile's network events, security alerts, and audit logs into the Falcon platform. This integration enables security teams to correlate network activity with CrowdStrike telemetry, accelerating threat detection, investigation, and response. The connector is available today, and Nile will preview its next-phase integration at the conference, which will bring CrowdStrike endpoint posture and active-threat signals into the Nile Portal. Suresh Katukam, Nile's CPO, noted that nearly 60% of breaches occur outside the data center in campus and edge environments, highlighting the importance of this partnership. The integration is the first step in a broader collaboration aimed at unifying Zero Trust defense across managed, unmanaged, IoT, and OT devices.
Sygnia Reveals China-Nexus Threat Actor Fire Ant Targeting Trusted Infrastructure
Sygnia, a global cyber readiness and response firm, has released findings on ongoing espionage activity by a China-nexus threat actor tracked as Fire Ant, which is targeting routers, authentication systems, and Linux management hosts to collect intelligence and explore paths toward connected high-value environments. The 2026 activity marks an evolution from Fire Ant's 2025 focus on VMware ESXi and vCenter virtualization infrastructure to strategic abuse of trusted infrastructure, including Cisco IOS XR routers used as operational platforms to suppress evidence, collect traffic and credentials, and expand access. The investigation uncovered two novel tools: BridgeAgent, a masquerading implant for tunnelling and persistence, and TacTap, a TACACS credential-collection toolset. Fire Ant also established resilient persistence through long-lived implants, manipulated logs and firewall rules, and disabled SELinux on Linux systems. Sygnia's findings highlight a campaign targeting interconnected environments where routers, TACACS servers, and Linux hosts serve as a broader access and collection layer, potentially enabling visibility and access beyond the immediate victim.
Fortinet Shares Up 12% Since Q2 Beat, Outlook Raised
Fortinet shares have risen about 12% since its last earnings report, outperforming the S&P 500, after the company posted second-quarter 2026 non-GAAP EPS of 90 cents, beating the Zacks Consensus Estimate by 20% and up 40.6% year over year, with total revenues of $2.05 billion, up 25.6% and beating estimates by 9.1%. The company raised its full-year 2026 revenue guidance to $8.02-$8.18 billion from $7.71-$7.87 billion, and non-GAAP EPS to $3.41-$3.47 from $3.10-$3.16, while also guiding third-quarter revenues to $2.01-$2.10 billion and non-GAAP EPS to 83-87 cents. Fortinet's product revenues surged 51.9% to $773 million, and total billings grew 33.4% to $2.37 billion, with strong growth in secure networking, OT security, Unified SASE, and AI-driven security operations. The company generated $1.04 billion in operating cash flow and repurchased 1.9 million shares for $146 million in the quarter, leaving about $766 million in buyback authorization. Analysts have revised estimates upward, and Fortinet holds a Zacks Rank #1 (Strong Buy).
Hillstone Networks' first-half loss narrows to 21.12 million yuan, revenue up 8.3% year on year
Hillstone Networks released its 2026 interim report on August 27. First-half operating revenue was 451 million yuan, up 8.3% year on year. Net profit attributable to the parent narrowed from a loss of 76.56 million yuan in the same period last year to a loss of 21.12 million yuan, while net profit attributable to the parent excluding non-recurring items narrowed from a loss of 76.59 million yuan to a loss of 22.13 million yuan. In the second quarter, the company's operating revenue was 271 million yuan, up 4.5% year on year, and net profit attributable to the parent successfully turned positive at 13.37 million yuan. The company is focused on its core cybersecurity business and has launched a dual-A strategy centered on self-developed ASIC security chips and AI technology. ASIC security products have achieved large-scale commercial deployment and become the core driver of operational improvement. Perimeter security products generated operating revenue of 346 million yuan, up 10.95% year on year, while cloud security products and services revenue was 25.84 million yuan, down 31.90% year on year.
Cisco Expands Secure AI Factory with NVIDIA to Counter Palo Alto and Fortinet
Cisco Systems is expanding its Secure AI Factory with NVIDIA, embedding security directly into the AI infrastructure stack to counter rivals Palo Alto Networks and Fortinet. The architecture combines Cisco networking, NVIDIA AI infrastructure, and Supermicro rack-scale compute, with security built from silicon through applications and AI agents. Cisco's security revenues rose 14% year over year to $2.23 billion in the fourth quarter of fiscal 2026, and firewall orders grew over 30%. The company added more than 6,400 net new customers for products like Secure Access, XDR, Hypershield, and AI Defense since launch. Fortinet's SASE Firewall business grew 34% to over $2 billion in the second quarter of 2026, while Palo Alto's Prisma AIRS surpassed 300 customers in the third quarter of fiscal 2026. Cisco shares are up 44.2% year to date, and the Zacks Consensus Estimate for fiscal 2027 earnings is $5.11 per share, up 7% over the past 30 days.
Fortinet Federal Achieves CMMC Level 2 Certification
Fortinet Federal, a wholly owned subsidiary of Fortinet, Inc., announced it has achieved Cybersecurity Maturity Model Certification (CMMC) Level 2 following an assessment by an Authorized CMMC Third-Party Assessment Organization. The certification validates the implementation of 110 security requirements aligned with NIST SP 800-171 Revision 2 for protecting Controlled Unclassified Information within its assessed environment. Fortinet Federal pursued the certification to strengthen cybersecurity across its operations and supply chain, providing customers and partners with independent validation of its security practices. Steve Hoffman, president of Fortinet Federal, emphasized the company's commitment to rigorous security practices and continuous improvement. The company's FortiGate Next-Generation Firewall maps to 83 of the 110 CMMC Level 2 security requirements, supporting nearly all 14 security domains.
Palo Alto Networks Network Security Growth Accelerates on AI Demand
Palo Alto Networks reported its Network Security business had its strongest quarter in several years during the third quarter of fiscal 2026, driven by rising enterprise spending on AI and cloud infrastructure. Next-generation firewall bookings grew nearly 40% year over year, supported by Gen 5 appliances and AI data center buildouts, while software firewall ARR increased 25% year over year. Network Security accounts for about 70% of total revenues, and hardware revenues, about 10% of total, had their best quarter in a decade with a record backlog. Management expects data center expansion and higher traffic volumes to remain key growth drivers for the next several quarters and potentially several years. Competitors CrowdStrike and Zscaler are also benefiting from AI-related cybersecurity demand, with CrowdStrike's AIDR solution seeing ending ARR grow more than 250% sequentially and Zscaler surpassing 700 Zero Trust Everywhere enterprises.
Cybersecurity ETFs Gain as Top Holdings Post Robust Q2 Results
Cybersecurity ETFs are drawing investor attention after top holdings CrowdStrike, Palo Alto Networks, and Fortinet delivered robust second-quarter results. CrowdStrike reported a 26% year-over-year revenue increase to $1.19 billion and a 50.7% jump in adjusted earnings per share, while Palo Alto Networks posted 31% revenue growth to $3 billion and a 60% surge in Next-Generation Security ARR to $8.1 billion. Fortinet crushed estimates with quarterly revenues of $2.05 billion, up 26% year over year, and received a Moody's upgrade to A3, the highest rating of any public cybersecurity company. The Nasdaq CTA Cybersecurity Index has soared 36.5% year to date, outperforming the broader Nasdaq Index's 13% return. Four ETFs highlighted include First Trust NASDAQ Cybersecurity ETF CIBR, Amplify Cybersecurity ETF HACK, Global X Cybersecurity ETF BUG, and iShares Cybersecurity and Tech ETF IHAK, with year-to-date gains ranging from 36.4% to 43.5%.
Enterprise Networking Market to Reach $193.77 Billion by 2030
The enterprise networking market is projected to grow from $124.59 billion in 2025 to $193.77 billion by 2030, a CAGR of 9.2%, according to a new report from MarketsandMarkets. The firm attributes the expansion to enterprise modernization of network infrastructure for hybrid work, multi-cloud environments, and stronger cybersecurity. North America is expected to hold the largest share, while Asia Pacific is the fastest-growing region. Key players include Cisco Systems, Broadcom, Hewlett Packard Enterprise, Juniper Networks, Arista Networks, Huawei, Extreme Networks, Fortinet, Cloudflare, and Alcatel-Lucent Enterprise.
Singapore tightens controls on online platforms to curb scammers, with fines of up to 10 million Singapore dollars
Singapore has launched and updated new guidelines to strengthen measures against scams and cyber activities on major online platforms. The Singapore Police Force said the new rules cover messaging and online meeting services, social media, and e-commerce platforms, building on measures that took effect in 2024. Scam cases reported through regulated online services fell by about 37 percent between 2024 and 2025. The new messaging code requires platforms to obtain user consent before unknown contacts can add them to groups, issue alerts about suspicious accounts, and offer options to filter or block messages and calls from unknown individuals. The social media guidelines require platforms to prevent and remove suspected scam advertisements, verify advertiser identities, and ensure that financial advertisements targeting users in Singapore come only from licensed providers. The updated e-commerce guidelines will raise protections for login security and advertising. Platforms must comply with the new requirements by 31 January 2027, and draft legislation proposes raising maximum fines to 10 million Singapore dollars, or 7.83 million US dollars, for non-compliance.
Fortinet CFO Highlights Surging Hardware and SASE Demand
Fortinet CFO Christiane Ohlgart said the cybersecurity company's second-quarter performance was supported by broad-based global demand, accelerating hardware sales and growing adoption of secure networking and unified SASE offerings. Product revenue grew 52%, its second consecutive quarter of acceleration, driven by customers purchasing larger hardware appliances to support AI infrastructure, higher network traffic, SD-WAN and OT security needs. Unified SASE grew 35% to roughly one-quarter of sales, while FortiSASE billings more than doubled. OT billings rose 55%, service billings increased 26%, and remaining performance obligations reached $7.7 billion, up 16% year over year.
Fortinet Raises 2026 Guidance on Firewall and SASE Demand
Fortinet has raised its full-year 2026 guidance, citing accelerating firewall refresh cycles and surging SASE adoption. The company now expects revenue between $8.02 billion and $8.18 billion, up from the prior range of $7.71 billion to $7.87 billion, with billings projected at $9.35 billion to $9.55 billion and non-GAAP EPS between $3.41 and $3.47. The upgraded outlook follows second-quarter results that beat the high end of prior guidance, and management also lifted third-quarter revenue guidance to $2.01 billion to $2.10 billion. Fortinet shares have gained 103.9% year to date, and the company recently launched the FortiGate 1200G series with FortiSASE Outpost, while also announcing a collaboration with Intel on its next-generation security processor.