Koi
– Getty Images

Palo Alto Networks will snap up endpoint security vendor Koi Security, a deal that comes in a mixed fortnight of fortunes for the security giant, including success with its latest financials.

As rumored early last month, Palo Alto was looking to shell out $400 million on the Tel Aviv-founded firm, following a trip CEO Nikesh Arora took to Israel to meet Koi while checking in on Palo Alto's other fresh Israeli investment in CyberArk.

Established in January 2024, Koi Security trades in endpoint security posture management (ESPM), in which endpoint devices are inspected through automation for vulnerabilities such as misconfigurations and missing patches.

Financial details of the deal were not disclosed. However, Koi has raised $48 million to date, with a $38 million Series A round last year seeing investment from Battery Ventures, Team8, Picture Capital, NFX, and Cerca Partners. It has between 40 and 50 clients, including OpenAI, Fireblocks, FHLBank Dallas, as well as Palo Alto Networks itself.

Palo Alto's current endpoint services come via its Cortex XDR platform, which was most recently bolstered acquisition-wise when it snapped up incident response business Crypsis in 2020. With the new acquisition, Koi's agentic endpoint security will extend to Palo Alto's Prisma Air platform, as well as enhancing the Cortex XDR endpoint security solution.

For Mauricio Sanchez, senior director at Dell’Oro Group, Palo Alto’s intent to acquire Koi reads as a logical extension of its AI security push.

“As AI agents and copilots are deployed, they function like privileged ‘insiders’ on endpoints, which means visibility and policy control must extend beyond files and processes to the agent tooling itself – plugins, extensions, scripts, and packages,” Sanchez said. “Koi’s value is at the install and supply-chain layer on the endpoint, where extensions and packages are becoming an expanding blind spot for many enterprises.

"Traditional endpoint controls are not consistently designed to govern that layer, so Palo Alto can use Koi to strengthen coverage while positioning it as a platform capability – extending Prisma Airs and improving visibility, policy, and malware prevention within Cortex XDR," Sanchez continued. "More broadly, I see Palo Alto trying to establish a new technology category. By emphasizing ‘agentic endpoint security,’ Palo Alto is labeling an emerging risk surface and aiming to own that control point as AI-native workflows scale.”

The analyst added Palo Alto is treating AI agents and their add-ons as the next major endpoint attack surface, with Koi a way to govern the agentic layer before it becomes an enterprise-wide blind spot.

Arora talks agents; Unit 42 calls out China

In Palo Alto’s earnings call accompanying release of its second quarter of fiscal 2026 earnings, Arora said he was “immediately impressed” by Koi on his Israel trip, especially with their “foresight into the next generation of endpoint threats.”

The CEO referred to agentic security threats that arose like wildfire following the widespread adoption of the OpenClaw system, which lets AI agents coordinate workflows. Researchers like Snyk have found almost 80 confirmed malicious payloads on the ClawHub registry, a central hub for discovering and installing skills for customizing OpenClaw, while Zenity Labs revealed how indirect prompt injection can be used to establish persistent attacker control inside OpenClaw.

A recent investigation by SDxCentral uncovered AI agents sharing security evasion tips, specifically on circumventing security guardrails for carrier IPs. The discovery was made on Moltbook, a forum run and used exclusively by agents, some of whom operate on the OpenClaw system.

“We believe this is the latest example of what the future of the AI attack surface will look like, and that Koi will help our XDR platform remain well positioned to provide the most innovative security solutions to our customers,” Arora said during the earnings call. “After closing, Koi will also be able to provide … visibility to any AI software and browsers that are only present on the endpoint, resulting in the most comprehensive visibility to the AI attack surface. Over time, this will help ensure that the endpoint becomes more agentic.”

Arora also pointed to data from Palo Alto’s Unit 42 research arm, confirming end-to-end attacks are now four-times faster than a year ago due to AI, with attackers able to break in and exfiltrate data in under one hour in nearly one quarter of the cases. Said data was published in Palo Alto’s "Global Incident Response Report," which was preceded by another report this month that saw accusations of sino-washing by apparently not tying a prolific hacking group to China in its final form. Instead, the group in question was framed as a “state-aligned group that operates out of Asia” in the publication.

The rumors suggested Palo Alto was not looking to ruffle any feathers in China – yet in contrast, Unit 42’s latest report from this week mentions China as an attacker base freely and with general aplomb.

The CyberArk factor

Palo Alto Networks' latest earnings showed total revenue rose about 15% year-over-year (YoY) to roughly $2.59 billion, while what it terms "next-generation security" average recurring revenue (ARR) grew to about $6.3 billion at an increase of around 33% YoY.

Despite the gains, the firm issued earnings per share (EPS) guidance for next quarter of between $0.78 and $0.80, which came in well below analyst forecasts. This was put down to higher acquisition-integration and deal-related costs, such as the likes of Chronosphere and its blockbuster CyberArk deal. The market reacted by sending Palo Alton's stock down roughly 7% after hours.

According to the earnings, Palo Alto expects a $2.3 billion cash outlay during its fiscal third quarter following the completion of its $25 billion CyberArk acquisition.

No mention was made in the call of headcount reductions, despite Palo Alto laying off 10% of CyberArk’s 4,000-strong global workforce shortly after the deal closed.