Introducing Unit 42 Continuous Frontier AI Defense

Sep 22, 2026
5 minutes

Cybersecurity is in the middle of a generational shift. AI has disrupted a 30-year balance of power between defenders and adversaries.

Armed with agentic AI tools and open-weight models stripped of safety guardrails, threat actors are discovering, validating, and chaining exposures at machine speed. In a recent Unit 42 investigation, the attacker used more than 50 MITRE ATT&CK techniques to reduce weeks of methodical intrusion tradecraft into less than 10 hours—97% faster than a skilled red team could have done. Time-to-exfiltration has compressed to under an hour in real-world attacks. And when new CVEs are publicly disclosed, automated adversary scanners are weaponizing them within 15 minutes.

Defending at human speed is no longer viable. Organizations must close years of accumulated exposure while securing the AI they are rapidly adopting. That demands action on five fronts: continuously find and fix vulnerabilities, reduce exposure, secure AI infrastructure, unify attack prevention, and automate detection and response at machine speed.

Today, we are announcing Unit 42 Continuous Frontier AI Defense to put the first two priorities into practice. Powered by Anthropic's Mythos models and OpenAI's latest GPT cyber models, this always-on, agentic service combines our offensive security experts with proprietary multi-model harnesses to discover vulnerabilities, validate real-world exploitability, and accelerate remediation across applications, identities, cloud infrastructure, and network assets.

Led by our offensive security experts, this service discovers, validates and remediates exposures before they can be exploited. We use proprietary AI harnesses and gated capability models—powerful models restricted from public use—to discover vulnerabilities, prove real-world exploitability, and accelerate remediation across applications, identities, cloud infrastructure, and network assets as an organization’s environment changes.

Continuous Frontier AI Defense builds on Unit 42’s Frontier AI Defense, which launched in April and introduced Frontier AI Exposure Analysis, a point-in-time exposure analysis, and a security blueprint that benchmarks current capabilities to help organizations modernize their cybersecurity systems. In August, Unit 42 expanded the list of frontier AI models to include  OpenAI’s GPT-5.6-Cyber and Anthropic's Claude Mythos 5, giving organizations access to additional AI capabilities.

A Single AI Model Is Not a Security Strategy

Frontier models are powerful, but no single AI model is a cybersecurity silver bullet and the models require equally powerful AI scanning harnesses.

Unit 42 research evaluation of model performance across enterprise codebases and live environments revealed two stark operational realities:

  • Coverage caps: No single AI model catches more than 40% of vulnerabilities in a complex environment.
  • Visibility: Leading cyber models such as Anthropic Claude Mythos 5 and OpenAI GPT-5.6-Cyber have less than 10% overlap in the exposures they identify.

To solve the single model gaps, Continuous Frontier AI Defense runs on proprietary multi-model harnesses. These harnesses act as an intelligent orchestration layer, routing specific offensive testing tasks to the model best suited for the job. This approach aligns model strengths, eliminates individual gaps, and keeps compute spend economical.

We combine these frontier models with Unit 42 threat intelligence, and frontline security expertise to turn raw vulnerability data into verified, actionable protection. Zero Data Retention (ZDR) architectures protect enterprise source code and telemetry, so customer data is never retained or used to train public models.

What Happens When AI Meets Real Enterprise Architecture

We did not build this service on theoretical assumptions. We built and validated it internally  across Palo Alto Networks and across more than 100 customer engagements.

During our internal deployment, continuous Mythos-based scanning achieved over a year’s worth of traditional penetration testing results in just three weeks. The harness identified 3.2 times more high and critical vulnerabilities per product than legacy testing methods, and helped engineering teams cut mean time to remediate by 51%.

When we executed the service across customer environments, the frontline data delivered a clear warning:

  • Hidden exposures: In third-party applications, two out of three validated exposures had no known CVE. Vulnerability-only scanners will never see them.
  • High severity: 37% of identified exposures rated high or critical in severity.
  • Chained attack paths: Flaws rarely existed in isolation. In one financial sector engagement, our harness identified a sequence of individually minor flaws: an application payment link that failed to re-verify identity, a skipped one-time password check, and a session routing flaw. Chained together, an attacker could achieve complete account takeover and payment fraud without any victim action.

Moving from Discovery to Validated Protection

Finding weaknesses without fixing them only creates noise. And, security teams do not lack findings; they already have more alerts than they can act on. The bigger challenge is knowing which weaknesses an attacker can actually exploit and chain into a viable path to compromise, and then remediating them.

Unit 42 Continuous Frontier AI Defense translates findings directly into risk reduction:

  • Continuous Testing Engine: Provides a full-estate baseline scan followed by always-on testing as an organization’s environment changes.
  • Multi-Model AI Harness: Unit 42 deploys proprietary multi-model harnesses, the software architecture to route work to the model best suited for the task, improving efficacy and coverage while managing the cost of frontier AI at scale.
  • Leading Cyber Models: The harnesses are built around gated capability models, including Anthropic Claude Mythos 5 and OpenAI GPT-5.6-Cyber, as well as open weight models. 
  • Advanced Adversary Simulation: Proves real-world exploitability by validating end-to-end attack paths across first- and third-party web apps, APIs, cloud infrastructure, source code repositories, and network assets.
  • Accelerated Remediation: Delivers actionable and prioritized fixes, code-level guidance, and virtual patch recommendations. To implement virtual patches before vulnerabilities are publicly disclosed or official patches exist, organizations can pair this with Frontier Virtual Patching. 

Unit 42 Continuous Frontier AI Defense is available worldwide today on an annual subscription basis. Register for our upcoming virtual Threat Briefing to see how we apply Frontier AI, our proprietary multi-model harness, and offensive security expertise to protect Palo Alto Networks and our customers.

To learn more about Unit 42 Continuous Frontier AI Defense, register for the upcoming Virtual Threat Briefing here.


Subscribe to the Blog!

Sign up to receive must-read articles, Playbooks of the Week, new feature announcements, and more.