Fracturing Software Security With Frontier AI Models
Summary
Unit 42 (Palo Alto Networks) tested frontier AI models and found they can autonomously identify vulnerabilities, chain complex exploits, and dramatically shorten the time from discovery to exploitation. The report flags open-source software as particularly exposed because models perform strongly against source code, raising the risk of large-scale supply-chain compromises. Unit 42 describes end-to-end AI-enabled attack flows (reconnaissance, initial access, lateral movement, exploitation, exfiltration) and warns the threat landscape will likely see faster, larger, and more automated campaigns. The report urges defenders to assume breach conditions, enforce SBOMs and code governance, harden build environments, collapse patching windows, and automate incident response and triage to keep pace.