palo alto networks
– Giacomo Lee/SDxCentral

New updates from Palo Alto Networks showed off tools from its recent Koi Security acquisition, as well as CyberArk intelligence in its response to a "reset" in cryptographic trust.

Released in time for the RSA 2026 event, Palo Alto Networks issued a new capability designed to solve growing operational risk associated with certificate life cycles. Dubbed Next-Generation Trust Security (NGTS), the network-native platform aims to unify certificate life cycle management (CLM) with real-time network enforcement and visibility.

Spurring NGTS are changing certificate renewal cycles, with the the CA Browser Forum authority dropping maximum validity period for public TLS certificates from 398 days to 200 days. That number will reduce to 100 days in 2027, before dropping to 47 days by 2029.

This marks a big change from when digital certificates – so-called "passports" of the digital economy – used to last years with little modification. Galvanizing the transformation are post-quantum expectations alongside abrupt decertification of global trust authorities, forcing organizations to replace thousands of certificates at once.

"Organizations are now confronting what can best be described as a cryptographic reset. Security teams are fighting a battle on two fronts: trust and integrity," Shivajee Samdarshi, SVP of products and technology for machine identity management at Palo Alto Networks, explained, adding that advances in quantum computing threaten to undermine today's public key cryptography standards.

"Within the coming decade, sufficiently powerful quantum systems are expected to break widely used algorithms such as RSA and ECC. ... Automation and continuous visibility must replace human-led manual processes. For this to happen efficiently, the network must become the ultimate point of cryptographic control."

NGTS is framed as turning the network into the trust control plane, with CLM directly embedded within the network security platform via machine identity intelligence courtesy of the recently acquired CyberArk. Specifically, the tool eliminates hidden certificates and blind spots while enhancing operational resilience through automated detection and renewal of credentials to prevent outages and trust failures.

"Because the network already observes encrypted traffic and certificate usage, discovery happens automatically across environments through existing next-generation firewall (NGFW) and secure access service edge (SASE) infrastructure," Samdarshi explained. "Once certificates are discovered, automated life cycle workflows ensure they are renewed, deployed, and governed according to policy. The result is a system that continuously maintains digital trust without placing an additional operational burden on security teams."

AIRS' agentic wares

NGTS is available via Strata Cloud Manager. Meanwhile, agentic AI wares aplenty come with Prisma AIRS 3.0, the latest iteration of the security giant's AI-centric cybersecurity platform. Palo Alto Networks nodded to its recent warnings on AI agent security with the suite's new promise of end-to-end security for the entire agentic AI lifecycle.

The AIRS update leverages Palo Alto Network's ongoing acquisition of endpoint security vendor Koi Security, touting an Agentic Endpoint Security provision for full visibility across AI endpoint applications.

"Prisma AIRS 3.0 expands visibility across the full AI enterprise: Mapping enterprise agents across cloud and software-as-a-service (SaaS) environments, endpoint agents (including vibe coding agents) running on developer systems and browser-based agents," claimed Jaimin Patel, VP product management for Prisma AIRS. "Organizations gain real-time visibility into how these agents operate, surfacing model context protocol (MCP) servers, plugins, and tool interactions. This brings shadow AI and unsanctioned agents into view, closing one of the largest blind spots in AI adoption."

Helping with this closure is the ability to promptly inventory AI agents, models, and connections across a user's environment, as well as tools to map out an agent's architecture and scanning for vulnerabilities. A red team function simulates context-aware agentic attacks, estimating the potential blast radius from pesky agents in the machine.

Palo Alto Networks also unveiled a limited preview of AI Agent Gateway, said to be a central control plane that enforces agent runtime, identity security, governance, and observability.