"I can tell you without exaggeration that we believe that this is a generational shift in cybersecurity," Sam Rubin, senior vice president of Palo Alto Networks’ threat intelligence arm, said in a media briefing.
Sam Rubin: a broken balance and machine-speed attacks
Unit 42’s leadership says frontier AI capabilities have ended a period of relative balance between security and exposure. Rubin warned that capabilities demonstrated by readily available agentic AI models, and those unlocked by frontier AI models that remain gated for defense, have "shifted the balance of power from defenders to attackers." He added that "the defenses that we’ve had built up over years weren’t necessarily built for or prepared for these machine-speed attacks." According to Rubin, organizations are "ill-equipped to detect and to respond quickly in the face of these attacks."
Sherrod DeGrippo: AI across the attack chain
Sherrod DeGrippo, vice president of threat intelligence at Unit 42, said AI is already embedded across the entire attack chain. "AI has seeped into every part of what threat actors do," she said, listing malware development at scale, delegation, social engineering and ransomware negotiations as concrete areas where attackers are applying AI. DeGrippo described the evolution as incremental today—"piece by piece by piece"—and warned Unit 42 is "not far from fully agentic attacks across all at once."

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleObserved incident: 50 applications and ten hours
Unit 42 is actively investigating a customer breach in which an attacker used an agentic framework to exploit "50 applications and other weaknesses across the enterprise in less than 10 hours." Rubin estimated AI enabled the attacker to accomplish in 10 hours what "would have taken at least 10 days in a pre-AI era." Unit 42 described these intrusions as part of the "early waves of this threat in the wild."
Project Glasswing, Mythos, and the one‑year estimate
Unit 42’s concerns were foreshadowed in April when Anthropic convened Palo Alto Networks and other major technology companies to form Project Glasswing—an initiative intended "to find and address security defects with its Mythos model." At that time Unit 42 estimated that the same capabilities would be in the hands of attackers within a year. Rubin noted that five months after Project Glasswing's formation, Unit 42 is already observing the early manifestations of those risks.
What this means for technologists and security teams, enterprises, and nation-sponsored threat groups
- Technologists and security teams: Unit 42 warns that existing defenses were "weren’t necessarily built for or prepared for these machine-speed attacks," implying defenders must reassess detection and response tools to cope with agentic and frontier-model-driven operations.
- Affected enterprises and procurement leaders: The incident Unit 42 is investigating—an attacker exploiting 50 applications in under 10 hours—highlights exposure across large, interconnected estates and the need to prioritize rapid patching, inventory of dependent libraries, and monitoring for orchestrated agentic activity.
- Nation-sponsored threat groups: DeGrippo said nation-sponsored groups are "learning more about points of weakness in enterprise systems," signaling that advanced external actors are adopting model-driven techniques to map and exploit systemic weaknesses.
Unit 42 frames the present moment as transformative. DeGrippo cautioned "nobody is fully prepared for what’s coming" and called it a "transformative period," while Rubin’s assessment places urgency on adapting defensive posture to defend against attacks executed at machine speed. The record Unit 42 provides is stark: agentic frameworks and frontier-model capabilities are already enabling faster, broader intrusions, and a major vendor's threat arm says the imbalance favors attackers unless defenders rapidly change how they detect, respond to, and remediate compromises.
Read the original report on CyberScoop: https://cyberscoop.com/unit-42-palo-alto-networks-warning-agentic-ai-frontier-models/




