Every claim in this report traces back to one of 85 evidence records below. Each was captured passively during recon, hashed at capture for chain-of-custody, and graded per the Admiralty Scale (NATO STANAG 2511). Click any ev_xxx chip elsewhere in the report to jump straight to its source record.
GLEIF full record for LEI 549300QXR2YVZV231H43: PALO ALTO NETWORKS, INC., ACTIVE, FULLY_CORROBORATED. legalAddress: 251 Little Falls Drive, Wilmington, DE 19808, c/o Corporation Service Company. headquartersAddress: 3500 South Dupont Highway, Dover, DE 19901, c/o Incorporating Services Ltd. Incorporated 2005-02-28. GLEIF initial registration 2013-01-12, last updated 2026-05-21, next renewal 2027-05-31. Managing LOU 5493001KJTIIGC8Y1R12. Direct-parent: reporting-exception (no LEI parent). [...]
ev_003F-6
Sourcecrunchbase·Captured
Crunchbase lookup failed on both attempts. Attempt 1: camoufox errored (NotInstalledGeoIPExtra: pip install camoufox[geoip]), scrapedo_render timed out after 46.5s. Attempt 2 (allow_scrapedo_super=true): identical errors. Crunchbase entirely unavailable for this run.
TheOrg lookup via curl_cffi returned HTTP success but null for all fields: name, legal_name, website, executives, board, advisors, investors all null/empty. Profile URL confirmed as https://theorg.com/org/palo-alto-networks but Next.js __NEXT_DATA__ extraction yielded no data.
Palo Alto Networks, Inc. is an American multinational cybersecurity company with headquarters in Santa Clara, California. The core product is a platform that includes advanced firewalls and cloud-based offerings that extend those firewalls to cover other aspects of security. The company serves over 70,000 organizations in over 150 countries, including 85 of the Fortune 100. It is home to the Unit 42 threat research team and hosts the Ignite cybersecurity conference. It is a partner [...]
Nikesh Arora is an Indian-American billionaire business executive. He has been the chairman and chief executive officer of the American cybersecurity company Palo Alto Networks since June 2018. Arora was formerly a senior executive at Google and president of SoftBank Group from October 2014 to June 2016. According to the Bloomberg Billionaires Index, his net worth was estimated at $1.5 billion in early 2024.
CrowdStrike Holdings, Inc. is an American cybersecurity technology company based in Austin, Texas. It provides endpoint security, threat intelligence, and cyberattack response services. The company was co-founded in 2011 by George Kurtz, Dmitri Alperovitch, and Gregg Marston. Kurtz serves as the CEO. CrowdStrike went public on the Nasdaq in 2019 and joined the S&P 500 index in 2024.
Fortinet, Inc. is an American cybersecurity company headquartered in Sunnyvale, California. It develops and sells security products including firewalls, endpoint security and intrusion detection systems. Fortinet has offices in the US, Canada, and UK.
Check Point Software Technologies Ltd. is an Israeli cybersecurity company. With operations in over 60 countries, the company protects over 100,000 organizations globally through its software services. It is a partner organization of the World Economic Forum and is home to the Check Point Research team.
Zscaler, Inc. is an American cloud security company based in San Jose, California. The company offers cloud-based services to protect enterprise networks and data.
SentinelOne, Inc. is an American cybersecurity company listed on NYSE based in Mountain View, California. The company was founded in 2013 by Tomer Weingarten, Almog Cohen and Ehud (Udi) Shamir. Weingarten acts as the company's CEO. The company has approximately 2,800 employees. The company uses machine learning for monitoring personal computers, IoT devices, and cloud workloads using its patented behavioral AI.
Cisco Systems, Inc., doing business as Cisco, is an American multinational technology conglomerate corporation that develops, manufactures, and sells hardware, software, telecommunications equipment and other high-technology services and products focused on networking, cyber security and AI. The company is headquartered in San Jose, California, and, as of December 2025, has a market capitalization of $317 billion.
William Hiroyuki Saito is a Japanese American businessman, venture capitalist and former advisor to the government of Japan specializing in cybersecurity.
Wikidata P108/P3320/P169/P488 query on Q7128508 returned: Nikesh Arora (Q7034852); Nir Zuk (Q19447315, entrepreneur/industrialist); William Saito (Q8018047, businessperson/venture capitalist); John Kindervag (Q136992412, computer security consultant); Harsh Verma (Q139827028).
ev_016B-2
Sourcewikidata·Captured
Wikidata P127 (owned by) Q7128508 returned 50+ patents. Representative: US11526564 'Triggered scanning based on network available data change'; US11520852 'Encoding-free javascript stringify for clientless VPN'; US11451571 'IoT device risk assessment and scoring'; US11477165 'Securing containerized applications'; US11374946 'Inline malware detection'; US11323466 'Malicious HTTP cookies detection and clustering'; US11431602 'Network asset discovery'; US11283820 'Context profiling for [...]
ev_017B-2
Sourcecompanies_house·Captured
Companies House search for 'Palo Alto Networks' returned 4 active UK entities: PALO ALTO NETWORKS (UK) LIMITED (06851390, active 2009), PALO ALTO NETWORKS FS INTERNATIONAL LIMITED (13789823, active 2021), PALO ALTO NETWORKS (UK HOLDING 1) LIMITED (12289825, active 2019), PALO ALTO NETWORKS (UK HOLDING 2) LIMITED (12289823, active 2019). All registered at 22 Bishopsgate Level 55, London EC2N 4BQ.
ev_018B-2
Sourcecompanies_house·Captured
PALO ALTO NETWORKS (UK) LIMITED, company 06851390, incorporated 2009-03-18, active, jurisdiction england-wales, SIC 26200 (Manufacture of computers and peripheral equipment), 22 Bishopsgate Level 55 London EC2N 4BQ, no charges, no insolvency history, last accounts made up 2025-07-31 (full accounts).
ev_019B-2
Sourcecompanies_house·Captured
PALO ALTO NETWORKS FS INTERNATIONAL LIMITED, company 13789823, incorporated 2021-12-08, active, jurisdiction england-wales, SIC 62020 (Information technology consultancy activities), 22 Bishopsgate Level 55 London EC2N 4BQ, no charges, no insolvency history, last accounts made up 2025-07-31 (small accounts).
ev_020B-2
Sourcecompanies_house·Captured
PALO ALTO NETWORKS (UK HOLDING 1) LIMITED, company 12289825, incorporated 2019-10-30, active, jurisdiction england-wales, SIC 64209 (Activities of other holding companies n.e.c.), 22 Bishopsgate Level 55 London EC2N 4BQ, no charges, no insolvency history, last accounts made up 2025-07-31 (full accounts).
ev_021B-2
Sourcecompanies_house·Captured
PALO ALTO NETWORKS (UK HOLDING 2) LIMITED, company 12289823, incorporated 2019-10-30, active, jurisdiction england-wales, SIC 64209 (Activities of other holding companies n.e.c.), 22 Bishopsgate Level 55 London EC2N 4BQ, no charges, no insolvency history, last accounts made up 2025-07-31 (full accounts).
ev_022B-2
Sourcecodex:baseline·Captured
Confirmed baseline: Palo Alto Networks, Inc. CIK 0001327567, ticker PANW. Entities ent_001 through ent_032 surfaced in prior waves.
Kindervag, J. (2010). Build security into your network's DNA: The zero trust network architecture. Forrester Research. 520 citations. Foundational Zero Trust paper defining never trust, always verify.
Kindervag, J., Balaouras, S., Mak, K. et al. (2016). No more chewy centers: The zero trust model of information security. Forrester Research. 464 citations. The trust model is broken; there are four critical pitfalls with today's approach to network security.
Kindervag, J. (2011). Applying zero trust to the extended enterprise. Forrester Research. 12 citations. PDF hosted on media.paloaltonetworks.com — indicates PANW relationship with Kindervag predated his formal employment.
Kokko, K. (2017). Next-generation firewall case study. Theseus. 2 citations. Palo Alto Networks was founded in 2005 by a former Israeli engineer Nir Zuk. Zuk worked at Check Point Software Technologies in the 1990s and was writing parts of the world's first stateful inspection firewall.
Liang, J. & Kim, Y. (2022). Evolution of firewalls: Toward securer network using next generation firewall. IEEE. 97 citations. Nir Zuk was one of the few people who helped develop the earliest stateful inspection firewall and invented the concept of the next generation firewall. Confirms Nir Zuk CTO/co-founder role.
Huang, K. & Hughes, C. (2025). The Commercial Landscape of Agentic AI Security. Springer. 5 citations. SentinelOne Purple AI Athena is a prime example of autonomous AI security. Confirms SentinelOne Purple AI Athena as a named competitor product to PANW Cortex XSIAM.
Sobb, T. & Turnbull, B. (2025). CrowdStrike: Lessons in Mission Assurance. IEEE Access. 1 citation. CrowdStrike has a global endpoint security market share of approximately 17.7%. Mugu et al. 2024 (19 citations): its 75% market share among Fortune 500.
Falevich, N. (2018). Start-Up Nation Central: Israel Cybersecurity Industry in 2018. 2 citations. Palo Alto Networks — reportedly $100M. For the US-based Palo Alto Networks, this was the fourth acquisition in Israel. Confirms PANW made 4+ Israeli acquisitions by 2018, one at approximately $100M.
Manthri, P. & Sharda, A. (2015). SoftBank and India. Google Inc. is taken on board to lead the transformation... president Nikesh Arora who is in lead to succeed Masayoshi Son. Confirms Arora's Google CBO role and SoftBank COO role as heir apparent.
Uber Technologies Annual SEC Filing (2023). We welcomed Nikesh Arora as an independent director and are benefiting from his expertise in cybersecurity and artificial intelligence. Confirms Arora holds independent director seat at Uber while serving as PANW CEO.
Parikh, A. (2019). Cloud security and platform thinking: Analysis of Cisco Umbrella. MIT. 20 citations. Nir Zuk, Founder and CTO of Palo Alto Networks invented world's first next generation firewall. Confirms Nir Zuk founding/CTO role and NGFW invention.
Arvatz, A. (2023). The Battle for Your Computer: Israel and the Growth of the Global Cyber-security Industry. 3 citations. technology owned by companies like Palo Alto Networks and Checkpoint began in the elite IDF cybersecurity unit known as Unit 8200. Confirms Israeli tech-intelligence ecosystem origin for both PANW and Check Point.
Rousseau, J.P. (2017). The history and impact of unit 8200 on Israeli hi-tech entrepreneurship. OhioLink. 5 citations. of Palo Alto Networks, Inc., since March 2005. He is a successful serial entrepreneur and a network security expert. Associates Nir Zuk with Israeli military-intelligence entrepreneur ecosystem.
Daghita, D. & Lipkowitz, S. (2025). Securing Library Systems: Cybersecurity Best Practices for Public Libraries. Taylor & Francis. firewall devices have a critical vulnerability, CVE-2025-0111 is a file read vulnerability in the PAN-OS... Exploiting this vulnerability could enable an authenticated attacker.
Kim, J. & Shin, Y. (2025). PathFault: Automated Exploit Generator for Web Services via HTTP Message Parser Discrepancies. Springer. CVE-2025-0108 vulnerability shows how path confusion leads to critical security vulnerabilities... level-evasion vulnerabilities in web application firewalls. Affects PAN-OS.
Rezaeianfardoue, H. & Saedi, M. (2025). Study of Failover Time in Site-to-Site VPNs Across Leading Firewall Vendors: Fortinet, Check Point, Palo Alto, and Cisco. IEEE. Confirms PANW as one of four dominant enterprise firewall vendors in academic comparative analysis.
Parikh, A. (2019). Cloud security and platform thinking. MIT. 20 citations. Palo Alto Networks, a leading network security company believes the future of cybersecurity is all about the platform. Earliest academic documentation of PANW platformization thesis.
Equity Research: Check Point Software Technologies. UNL. with Check Point such as Fortinet, Palo Alto Networks... enterprise value-to-ebitda to be at 13x in comparison. Positions PANW as primary Check Point competitor in financial analysis context.
Nazeer, O.A. AI-Powered Security Operations Centers in the Cloud. IJETCSIT. 3 citations. Cortex XSIAM ingests complete security data across hundreds of sources... AI SOC analysts can reduce the number of false positives. Confirms Cortex XSIAM architecture.
Nguyen, V.K. & Husain, M.I. (2025). Penetration Testing of Agentic AI. arXiv:2512.14860. Unit 42 at Palo Alto Networks (2025) identified critical security vulnerabilities specific to agentic AI. Confirms Unit 42 published agentic AI vulnerability research in 2025.
Pescatore, J. (2019). SANS Top New Attacks and Threat Report. 15 citations. vulnerabilities were announced in November and December 2019, including CVE-2019-17440, an issue in PAN-OS. Documents older PAN-OS CVE.
Piens, T. (2022). Mastering Palo Alto Networks. Springer. covering most of Palo Alto Networks features (GlobalProtect...) look at how threats can be prevented and malware blocked. Confirms GlobalProtect as core PANW product alongside threat prevention.
George, A.S. et al. (2026). Cloud Security Architecture: A Comprehensive Guide. PUIIJ. such as Wiz, Palo Alto Prisma Cloud, and Orca Security. Positions Wiz and Prisma Cloud as direct CNAPP competitors. Youvan 2025 confirms: Wiz has rapidly become a dominant player in cloud security and was acquired by Google.
Palo Alto Networks announces agreement to acquire CyberArk. Will Create the End-to-End Security Platform for the AI Era — will accelerate PANW platform strategy by establishing Identity as a core pillar. Announced July 30, 2025.
Palo Alto Networks announced it has completed its blockbuster acquisition of CyberArk, a $25 billion deal providing a crucial missing piece for its platform strategy. Completed February 11, 2026.
Palo Alto Networks will buy Israeli peer CyberArk Software for about $25 billion in its biggest deal yet, as CEO Nikesh Arora seeks to build a comprehensive security platform for the AI era. July 30, 2025.
Palo Alto Networks Completes Acquisition of Protect AI. Extends AI security leadership with comprehensive protection for the entire AI lifecycle. July 22, 2025.
Palo Alto Networks acquires Portkey, integrating its AI Gateway into Prisma AIRS. Provides unified control plane to securely govern and operationalize AI agents at scale. May 12, 2026.
Palo Alto Networks finalized its acquisition of AI Gateway technology developer Portkey on May 29, 2026, to strengthen its Prisma AIRS security platform.
After completing its $25 billion purchase of CyberArk, Palo Alto Networks is in negotiations to acquire one-year-old Israeli startup Koi for $400 million. January 4, 2026.
Palo Alto Networks completed the acquisition of CyberArk in February 2026 and began integrating CyberArk's privileged access management capabilities. Integrating CyberArk, Koi, and Portkey and launches Idira to bolster AI and identity security. May 18, 2026.
Palo Alto Networks Introduces Idira: the Next-Generation Identity Security Platform Built for the AI Enterprise. Delivers modern privileged access management by democratizing security controls for every human, machine, and agentic identity. May 12, 2026.
Idira launches as Palo Alto Networks extends CyberArk tech to machine and agentic identities. Machine-to-human identity ratio in enterprise now 109:1. Zero Standing Privilege extended to all identity types.
CVE-2026-0257 is being actively exploited on PAN-OS devices since May 17, 2026, enabling unauthorized VPN access and network exposure via GlobalProtect authentication bypass.
CISA adds critical Palo Alto Networks firewall flaw CVE-2026-0257 to Known Exploited Vulnerabilities catalog. The vulnerability in a vital defensive technology creates serious risks for federal networks.
CVE-2026-0257: Rapid7 caught attackers abusing forged VPN cookies against multiple customers. Authentication bypass via forged GlobalProtect auth cookies. Exploitation confirmed since May 17, 2026. Two attack waves, starting mid-May.
Palo Alto Networks and Deutsche Telekom (XETRA: DTE) announce Sovereign Cortex with T Security — AI-driven security platform with advanced data sovereignty controls for European regulated industries. Announced June 9, 2026, Amsterdam.
Deutsche Telekom and Palo Alto Networks launch Sovereign Cortex with T Security, combining AI-powered security with strict data sovereignty controls for regulated European markets. DTE shares declined 17% despite Q1 revenue beat amid MagentaTV subscriber slowdown.
NATO is joining forces with Microsoft, Palo Alto Networks, and ESET to enhance resilience to cyber threats and promote free, open, peaceful and secure cyberspace. Strategic non-commercial partnership. May 27, 2026.
Nutanix forms Palo Alto Networks partnership as client adoption increases. PANW and Nutanix integrate AI infrastructure with advanced enterprise AI security controls via Prisma AIRS. Nutanix opening agentic AI innovation center in Canada. May 2026.
ev_069B-2
SourceSDxCentral·Captured
Google Cloud closes Wiz acquisition, begins platform player brawl. Analysts point to $12.9B CNAPP addressable market. Google closed $32B acquisition of Wiz approximately March 11, 2026 — now direct PANW CNAPP competitor.
Cybersecurity researchers shed light on macOS malvertising campaign Operation FlutterBridge spreading FlutterShell backdoor via malicious Google and YouTube ads. Approximately June 4, 2026.
Unit 42 active research output May-June 2026: May 2026 Threat Bulletin; Out of the Crypt cyber extortion economy report; FIFA World Cup 2026 attack surface; Paved With Intent ROADtools nation-state cloud attacks; CVE-2026-0257 active exploitation threat brief; Operation FlutterBridge/FlutterShell macOS backdoor.
PANW Q3 FY2026 reported June 2, 2026: revenue $3.0B (+31% YoY), non-GAAP EPS $0.85 vs $0.79 consensus, record quarter. Full-year guidance raised. Targets 40% non-GAAP operating margin by 2028. ARR approximately $6B. Stock hit 52-week high $301+ on June 1, dipped 3-4% post-earnings, recovered +3.44% by June 11. CEO Nikesh Arora reported surge in client meetings driven by AI security demand.
ev_073B-2
SourceWikipedia pageviews API·Captured
PANW Wikipedia monthly views 2026: Jan 16849, Feb 21311 (spike — CyberArk close Feb 11), Mar 21332 (spike — Wiz/Google deal era), Apr 16227, May 17124. CyberArk views spike: Jul 2025 15993 (deal announcement), Feb 2026 7324 (deal close). Zscaler views: Mar 2026 spike to 11509 from 8694 Feb, correlating with Wiz/Google CNAPP market disruption. CrowdStrike: steady 14-18K/month.
Zscaler (ZS) down 32.4% since late May 2026 after Q3 FY2026 earnings; trading near 52-week low as of June 11, 2026. Headwinds: slowing growth, sales leadership turnover. PANW beneficiary: surged 8% on Fortinet earnings. Fortinet downgraded to Hold at DZ Bank, $125 target. PANW +60% YTD pre-Q3.
Palo Alto Networks PAN-OS contains an authentication bypass caused by flaws in the GlobalProtect portal and gateway, letting attackers establish unauthorized VPN connections, exploit requires network access to the portal or gateway. Python PoC, updated 2026-06-03, 2 stars.
CVE-2024-3400 CVSS 10.0: Detection, analysis, and response strategies for exploitation attempts targeting Palo Alto PAN-OS GlobalProtect portals. Includes IOCs, exploit patterns, and mitigation guidance. Multiple repos (CyberBibs, hashdr1ft, SimoesCTT) document this as SOC274 training scenario through 2025-2026.
Official PANW repo: Deploy the AI Red Teaming network channel client using Docker Compose — no Kubernetes or Helm required. Topics: ai, docker, network-channel, paloaltonetworks, redteaming. Pushed 2026-06-10, 2 stars, 1 fork.