* [Blog](https://www.paloaltonetworks.com/blog) * [Security Operations](https://www.paloaltonetworks.com/blog/security-operations/) * [AI and Cybersecurity](https://www.paloaltonetworks.com/blog/security-operations/category/ai-and-cybersecurity/) * GlassWorm Goes Mac: Fresh... # GlassWorm Goes Mac: Fresh Infrastructure, New Tricks [](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fwww.paloaltonetworks.com%2Fblog%2Fsecurity-operations%2Fglassworm-goes-mac-fresh-infrastructure-new-tricks%2F) [](https://twitter.com/share?text=GlassWorm+Goes+Mac%3A+Fresh+Infrastructure%2C+New+Tricks&url=https%3A%2F%2Fwww.paloaltonetworks.com%2Fblog%2Fsecurity-operations%2Fglassworm-goes-mac-fresh-infrastructure-new-tricks%2F) [](https://www.linkedin.com/shareArticle?mini=true&url=https%3A%2F%2Fwww.paloaltonetworks.com%2Fblog%2Fsecurity-operations%2Fglassworm-goes-mac-fresh-infrastructure-new-tricks%2F&title=GlassWorm+Goes+Mac%3A+Fresh+Infrastructure%2C+New+Tricks&summary=&source=) [](https://www.paloaltonetworks.com//www.reddit.com/submit?url=https://www.paloaltonetworks.com/blog/security-operations/glassworm-goes-mac-fresh-infrastructure-new-tricks/&ts=markdown) \[\](mailto:?subject=GlassWorm Goes Mac: Fresh Infrastructure, New Tricks) Link copied By [Gal Hachamov](https://www.paloaltonetworks.com/blog/author/gal-hachamov/?ts=markdown "Posts by Gal Hachamov") Oct 01, 2026 12 minutes [AI and Cybersecurity](https://www.paloaltonetworks.com/blog/security-operations/category/ai-and-cybersecurity/?ts=markdown) **Originally published December 29, 2025** ***Editor's note:*** *This article was originally published by Koi Security on December 29, 2025. Koi is now part of Palo Alto Networks, and this article has been adapted for the Palo Alto Networks blog. The technical findings and infrastructure observations reflect the December 2025 investigation and should not be interpreted as an assessment of the campaign's current status.* GlassWorm's fourth observed wave marked a significant change in the campaign: a shift from Windows to macOS, a new encrypted delivery mechanism and code designed to replace legitimate cryptocurrency wallet applications with attacker-controlled versions. In the December 2025 investigation, Koi researchers identified three malicious extensions on the Open VSX marketplace with approximately 50,000 reported downloads combined. The extensions connected to infrastructure associated with earlier GlassWorm activity, including a previously observed command-and-control (C2) server. That download figure indicates potential exposure---not 50,000 confirmed infections. The campaign illustrates how[software supply chain attacks](https://www.paloaltonetworks.com/cyberpedia/what-is-supply-chain-attack?utm_source=chatgpt.com&ts=markdown) can reach organizations through the tools their developers install. A familiar marketplace or useful-looking extension does not establish that the underlying code is trustworthy. Earlier waves concealed malicious code using invisible Unicode characters and later delivered compiled Rust binaries. This wave instead embedded AES-256-CBC-encrypted payloads in the extensions' JavaScript code. It also introduced a 15-minute execution delay and macOS-specific functionality for persistence and credential collection. The delivery changed. The underlying objective remained familiar: compromise a developer's environment, collect sensitive information and use remotely controlled infrastructure to deliver additional functionality. ![](https://www.paloaltonetworks.com/blog/wp-content/uploads/2026/09/word-image-369010-1.png) Figure 1: Koidex Report for Prettier Pro ## Key Takeaways * **The analyzed payload targeted macOS.** It used AppleScript, LaunchAgents and macOS Keychain access rather than the Windows-specific techniques described in previous waves. * **Encrypted JavaScript and delayed execution changed the detection challenge.** The loader combined AES-256-CBC encryption with a 15-minute delay before executing the decrypted payload. * **Solana remained part of the C2 discovery mechanism.** A new blockchain address and reused server infrastructure connected the activity to earlier GlassWorm findings. * **Wallet application replacement was an observed code capability, not a confirmed successful deployment.** During testing on December 29, 2025, the replacement endpoints returned empty files, preventing that installation path from completing. ![](https://www.paloaltonetworks.com/blog/wp-content/uploads/2026/09/word-image-369010-2.png) Figure 2: Prettier Pro on Open-VSX ## From Windows to macOS: A Platform-Specific Payload Previous GlassWorm waves documented by Koi targeted Windows. The fourth wave's analyzed payload targeted macOS and incorporated techniques specific to that operating system. **AppleScript execution.** The payload used AppleScript to run shell commands and interact with the system. One observed command invoked the macOS security utility to retrieve a named Keychain item. **LaunchAgent persistence.** The payload used a LaunchAgent as its persistence mechanism, replacing the Windows-oriented persistence approaches described in earlier research. **Keychain database collection.** The malware included functionality to copy the user's login Keychain database: ~/Library/Keychains/login.keychain-db These behaviors demonstrate a macOS-specific implementation rather than a simple reuse of the earlier Windows payload. Collecting a Keychain database should not be confused with automatically decrypting every credential it contains. Access to protected secrets depends on the relevant passwords and access conditions. Nevertheless, suspicious processes reading Keychain files or invoking credential-access functions warrant investigation. ## Encrypted JavaScript and a 15-Minute Delay The fourth wave changed how GlassWorm concealed its malicious functionality. Instead of relying on invisible Unicode characters or compiled Rust binaries, the extensions contained an encrypted payload in their JavaScript code. The loader used AES-256-CBC with a hardcoded encryption key and initialization vector. Researchers identified the same key across all three extensions, providing another connection among the samples. The loader also contained a timer value of 9e5 milliseconds: 900,000 milliseconds, or 15 minutes. Execution of the decrypted payload was delayed until after that wait. The original code screenshot shows both the decryption routine and the delayed execution sequence. That delay matters because[sandboxing](https://www.paloaltonetworks.com/cyberpedia/sandboxing?utm_source=chatgpt.com&ts=markdown) observes software behavior within a controlled analysis environment. A sandbox that stops monitoring before the 15-minute timer expires could miss the next stage. Delayed execution does not guarantee evasion, however; defenders can account for deferred behavior and combine dynamic analysis with code inspection. ![](https://www.paloaltonetworks.com/blog/wp-content/uploads/2026/09/word-image-369010-3.png) Figure 3: JavaScript loader using AES-256-CBC decryption and a 900,000-millisecond delay before payload execution. However, delayed execution does not guarantee sandbox evasion, and it does not make static analysis ineffective. The encrypted data, hardcoded decryption material, execution logic and timer remain available for inspection. The defensive lesson is to combine code analysis with behavioral observation rather than treat an initially quiet execution as evidence that an extension is safe. ## Solana-Based C2 Discovery and Reused Infrastructure GlassWorm continued to use the Solana blockchain to discover its current[command-and-control (C2)](https://www.paloaltonetworks.com/cyberpedia/command-and-control-explained?utm_source=chatgpt.com&ts=markdown) endpoint. C2 communications allow attackers to send instructions to compromised devices and direct additional malicious activity. In the mechanism described by Koi, the attacker placed base64-encoded URLs in transaction memos. The malware queried the blockchain, decoded the endpoint information and contacted the referenced infrastructure. The blockchain served as an address-discovery layer; the subsequent payload delivery and data collection still depended on other systems. The fourth wave used the following Solana address: BjVeAjPrSKFiingBn4vZvghsGj9KCE8AJVtbc9S8o8SC The investigation traced a November 27, 2025 transaction to 217.69.11\[.\]60. By December, the referenced C2 endpoint had changed to 45.32.151\[.\]157, which had also appeared in the third wave. Researchers additionally identified 45.32.150\[.\]251 as an exfiltration server. The reused IP address, shared delivery characteristics and continued use of Solana-based discovery supported the connection to previous GlassWorm activity. An IP address alone, however, should not be treated as definitive proof of an operator's identity. This architecture also complicates disruption. Removing a conventional domain is not enough to eliminate a discovery mechanism recorded on a public blockchain. That does not make the operation impossible to disrupt: defenders can still investigate and restrict malicious endpoint activity and address the payload-hosting and exfiltration infrastructure identified in the campaign. ## Hardware Wallet Applications Become a Target One of the fourth wave's most notable additions was code intended to replace cryptocurrency hardware-wallet companion applications. The payload checked for these application directories: ![](https://www.paloaltonetworks.com/blog/wp-content/uploads/2026/09/word-image-369010-4.png) *Figure 4: AppleScript checking for Ledger Live and Trezor Suite before invoking wallet replacement routines.* When either application was present, the code invoked a wallet installation routine. The original analysis described a sequence intended to download a replacement, remove the legitimate application and install the attacker-supplied version. ### What Researchers Confirmed---and What They Did Not **During testing on December 29, 2025, the wallet replacement endpoints returned empty files.** The installation routine checked the downloaded file's size and rejected files smaller than 1,000 bytes. Consequently, the empty downloads did not proceed through the replacement process. The researchers observed the replacement logic, but they did not confirm successful installation or operation of a trojanized wallet application during that testing. ![](https://www.paloaltonetworks.com/blog/wp-content/uploads/2026/09/word-image-369010-5.png) *Figure 5: Wallet installation routine rejecting downloaded files smaller than 1,000 bytes.* This distinction is important. The code demonstrated an intended attack path, not evidence that a fully functioning wallet trojan had been delivered to victims. A malicious companion application could potentially misrepresent receiving addresses, present misleading transaction information or use fraudulent recovery prompts to solicit sensitive information. Those are risks associated with compromising the software interface. The findings did not establish compromise of the hardware devices themselves or extraction of private keys stored on those devices. The unavailable wallet replacement downloads did not eliminate the broader threat. The original investigation reported that other functionality---including credential collection, persistence and data exfiltration---remained operational during the investigation. ## The Data Targeted by GlassWorm The payload's collection routines extended beyond cryptocurrency applications. They also targeted credentials and local data associated with development tools, browsers and the operating system. The original investigation identified the following categories. | Target category | Examples identified in the research | |--------------------------------------|---------------------------------------------------------------------------------------------------------------------------------------------------| | Browser-based cryptocurrency wallets | More than 50 wallet extensions, including MetaMask, Phantom, Coinbase Wallet, Exodus, Keplr, Solflare, Trust Wallet and Rabby. | | Desktop cryptocurrency wallets | Electrum, Coinomi, Exodus, Atomic, Ledger Live data, Trezor Suite data, Monero and Bitcoin Core. | | Developer credentials | GitHub tokens in VS Code storage, cached Git credentials, npm tokens in .npmrc and files in ~/.ssh. | | System and browser data | macOS Keychain information and database files, VPN configurations, and cookies and local storage associated with Chrome, Firefox, Brave and Edge. | The malware staged collected data in: /tmp/ijewf/ It then compressed the collected material and sent it to the reported exfiltration endpoint: 45\.32.150\[.\]251/p2p These paths and network indicators describe the December 2025 samples and infrastructure. This collection-and-transfer sequence represents[data exfiltration](https://www.paloaltonetworks.com/cyberpedia/data-exfiltration?utm_source=chatgpt.com&ts=markdown): the unauthorized movement of sensitive information out of an environment. Defenders should correlate suspicious file collection and archive creation with unexpected outbound connections rather than investigate each event in isolation. For organizations, the potential consequences extend beyond the affected workstation. Stolen developer tokens, SSH credentials and browser session data could enable subsequent[credential-based attacks](https://www.paloaltonetworks.com/cyberpedia/what-is-a-credential-based-attack?utm_source=chatgpt.com&ts=markdown), depending on the permissions, validity and protections associated with those credentials. An investigation should therefore assess both the endpoint and the accounts it could access. ## Four Waves, Changing Delivery Techniques The December investigation documented substantial changes across GlassWorm's first four reported waves. The dates below follow the timeline in the original research. | Wave | Date in 2025 | Reported developments | |--------|--------------|---------------------------------------------------------------------------------------------------------------------------------------------------| | Wave 1 | October 17 | Windows-focused activity using invisible Unicode in Open VSX extensions, with Solana and Google Calendar involved in C2 discovery. | | Wave 2 | November 6 | Additional malicious extensions using the same general technique. Koi reported evidence of affected organizations, including a government entity. | | Wave 3 | November 22 | A shift to compiled Rust binaries, changing the payload's packaging and analysis requirements. | | Wave 4 | December 19 | macOS targeting, encrypted JavaScript, a new Solana address and wallet application replacement logic. | The operational lesson is not that every wave used entirely new infrastructure or that one particular encoding technique defined the threat. GlassWorm changed its delivery while retaining recognizable behaviors and infrastructure connections. Defenders should therefore track the broader activity: extension execution, credential access, persistence, endpoint discovery and data transfer---not just the appearance of a particular payload. ## Recommended Defensive Actions The following recommendations translate the reported findings into investigation and prevention priorities. ### Establish Visibility Into Developer Extensions Inventory installed extensions, their full publisher identifiers, versions and installation sources. Match the complete extension IDs in the indicators below rather than relying on display names such as "Prettier" or "Svelte." Use the extension-management controls available in each development environment to restrict unapproved software. For managed VS Code deployments, Microsoft documents policies for controlling allowed extensions and versions. Apply equivalent controls in other editors where supported. **Investigate Behavior Beyond Installation** Pair extension inventory and approval controls with[endpoint detection and response (EDR)](https://www.paloaltonetworks.com/cyberpedia/what-is-endpoint-detection-and-response-edr?utm_source=chatgpt.com&ts=markdown) telemetry to investigate process execution, file changes and network activity. Correlating these events over time can help analysts reconstruct what happened after an extension was installed. Build investigation workflows around the behaviors documented in the campaign: unexpected AppleScript execution, LaunchAgent creation, access to Keychain databases or developer credential files, and staging of data in temporary directories. Correlate those events with the responsible editor or extension process and subsequent network activity. Do not treat encryption, a timer or a connection to blockchain infrastructure as conclusive evidence of malware by itself. Evaluate those signals in the context of what the extension does and which resources it accesses. ### Treat Confirmed Execution as an Incident Where investigation establishes that the payload executed, isolate the affected endpoint and preserve relevant evidence. Assess persistence and application integrity before returning the system to service. Use a known-clean system to revoke or rotate potentially exposed developer tokens, SSH credentials and other secrets. Review associated account activity, repository changes and package-publishing events. Removing the extension alone should not be the entire response: the reported payload established persistence and collected credentials independently of its original delivery mechanism. **Reassess Trust Over Time** Evaluate extensions and their updates throughout their lifecycle, not only when they are first approved. The changes documented across GlassWorm's waves support a defense that combines software governance, code inspection and endpoint behavior analysis rather than relying exclusively on known signatures. *For broader guidance on reducing risk across development environments, read* [*How To Prevent the 5 Most Common Software Supply Chain Weaknesses*](https://www.paloaltonetworks.com/blog/cloud-security/common-software-supply-chain-weaknesses/?ts=markdown)*, which examines third-party components, access controls, version control systems and CI/CD pipelines.* ## Indicators of Compromise The following indicators were reported in the December 2025 investigation. They are provided for historical hunting and investigation; their inclusion does not establish their present-day ownership or activity. Network addresses are defanged. ### Open VSX Extension Identifiers studio-velte-distributor.pro-svelte-extension cudra-production.vsce-prettier-pro Puccin-development.full-access-catppuccin-pro-extension Use these complete identifiers when reviewing extension inventories. The original report did not provide a complete affected-version matrix. ### Network and Host Indicators | Indicator | Reported role | |----------------------------------------------|------------------------------------------------------| | 45.32.151\[.\]157 | Primary C2 server; also observed in Wave 3. | | 45.32.150\[.\]251 | Exfiltration server. | | 45.32.150\[.\]251/p2p | Exfiltration endpoint. | | 217.69.11\[.\]60 | Earlier C2 endpoint referenced on November 27, 2025. | | BjVeAjPrSKFiingBn4vZvghsGj9KCE8AJVtbc9S8o8SC | Solana address used for C2 discovery. | | /tmp/ijewf/ | Local staging directory for collected data. | These indicators and their roles are drawn from the original Koi investigation. ***Recommended Reading:*** [***Securing the Agentic Endpoint***](https://www.paloaltonetworks.com/blog/2026/02/securing-the-agentic-endpoint/?ts=markdown) ## Protecting the Software Behind Developer Workflows GlassWorm's macOS wave illustrates why developer extensions deserve the same scrutiny as other software running on enterprise endpoints. In this investigation, malicious extensions provided a delivery path to credential collection, persistence and attempted application replacement. The appropriate response is layered: understand which software is installed, evaluate its behavior, restrict unapproved components and investigate suspicious activity across both the endpoint and the accounts it can access. The risks associated with developer extensions are part of a broader challenge: maintaining visibility and control over software installed outside centralized oversight.[Securing the Agentic Endpoint](https://www.paloaltonetworks.com/blog/2026/02/securing-the-agentic-endpoint/?utm_source=chatgpt.com&ts=markdown) examines that challenge across IDE plugins, browser extensions, code packages and AI tools, and explains the role of Koi within Palo Alto Networks. Palo Alto Networks [Cortex Agentic Endpoint Security](https://www.paloaltonetworks.com/cortex/agentic-endpoint-security?ts=markdown) provides visibility, risk assessment and governance capabilities across extensions and other components of the modern AI software environment. Organizations can use these capabilities as part of a broader strategy for managing the software operating on their endpoints. **Explore Cortex Agentic Endpoint Security to learn more about identifying and governing software risks across your organization.** *** ** * ** *** ## Related Blogs ### [AI and Cybersecurity](https://www.paloaltonetworks.com/blog/security-operations/category/ai-and-cybersecurity/?ts=markdown), [Data Security](https://www.paloaltonetworks.com/blog/category/data-security/?ts=markdown), [Data Security Platform](https://www.paloaltonetworks.com/blog/security-operations/category/data-security-platform/?ts=markdown), [DDR](https://www.paloaltonetworks.com/blog/security-operations/category/ddr/?ts=markdown), [DLP](https://www.paloaltonetworks.com/blog/security-operations/category/dlp/?ts=markdown), [DSPM](https://www.paloaltonetworks.com/blog/security-operations/category/dspm/?ts=markdown) [#### What the 2026 OWASP Top 10 Tells Us About the Growing Role of Data Security in AI](https://www.paloaltonetworks.com/blog/security-operations/owasp-top-10-data-security-2026/) ### [AI and Cybersecurity](https://www.paloaltonetworks.com/blog/security-operations/category/ai-and-cybersecurity/?ts=markdown), [AI Security](https://www.paloaltonetworks.com/blog/category/ai-security/?ts=markdown), [Announcement](https://www.paloaltonetworks.com/blog/category/announcement/?ts=markdown), [Cybersecurity](https://www.paloaltonetworks.com/blog/category/cybersecurity/?ts=markdown), [Must-Read Articles](https://www.paloaltonetworks.com/blog/security-operations/category/must-read-articles/?ts=markdown), [News and Events](https://www.paloaltonetworks.com/blog/security-operations/category/news-and-events/?ts=markdown), [Products and Services](https://www.paloaltonetworks.com/blog/category/products-and-services/?ts=markdown) [#### Cortex XDR is the only Certified Leader in AV-Comparatives EPR 7 years in a row](https://www.paloaltonetworks.com/blog/security-operations/cortex-xdr-is-the-only-endpoint-security-market-leader-to-be-certified-by-av-comparatives-7-years-in-a-row/) ### [AI and Cybersecurity](https://www.paloaltonetworks.com/blog/security-operations/category/ai-and-cybersecurity/?ts=markdown), [AI Security](https://www.paloaltonetworks.com/blog/cloud-security/category/ai-security/?ts=markdown), [Cloud Workload Protection Platform](https://www.paloaltonetworks.com/blog/cloud-security/category/cloud-workload-protection-platform/?ts=markdown), [Cybersecurity](https://www.paloaltonetworks.com/blog/category/cybersecurity/?ts=markdown), [Threat Intelligence](https://www.paloaltonetworks.com/blog/category/threat-intelligence-1/?ts=markdown), [Use-Cases](https://www.paloaltonetworks.com/blog/sase/category/use-cases/?ts=markdown) [#### Beyond the SEG: Why Single-Domain Email Defenses Break Down in the Modern SOC](https://www.paloaltonetworks.com/blog/security-operations/beyond-the-seg-why-single-domain-email-defenses-break-down-in-the-modern-soc/) ### [AI and Cybersecurity](https://www.paloaltonetworks.com/blog/security-operations/category/ai-and-cybersecurity/?ts=markdown), [Must-Read Articles](https://www.paloaltonetworks.com/blog/security-operations/category/must-read-articles/?ts=markdown), [Product Features](https://www.paloaltonetworks.com/blog/security-operations/category/product-features/?ts=markdown) [#### Building an Agentic SOC: 7 Keys for Success](https://www.paloaltonetworks.com/blog/security-operations/building-an-agentic-soc/) ### [AI and Cybersecurity](https://www.paloaltonetworks.com/blog/security-operations/category/ai-and-cybersecurity/?ts=markdown), [Announcement](https://www.paloaltonetworks.com/blog/category/announcement/?ts=markdown), [Cybersecurity](https://www.paloaltonetworks.com/blog/category/cybersecurity/?ts=markdown), [Must-Read Articles](https://www.paloaltonetworks.com/blog/security-operations/category/must-read-articles/?ts=markdown), [Product Features](https://www.paloaltonetworks.com/blog/security-operations/category/product-features/?ts=markdown), [Products and Services](https://www.paloaltonetworks.com/blog/category/products-and-services/?ts=markdown), [Use-Cases](https://www.paloaltonetworks.com/blog/security-operations/category/use-cases/?ts=markdown) [#### Cortex XDR Scores Perfect 100% in SE Labs 2026 Ransomware Test](https://www.paloaltonetworks.com/blog/security-operations/cortex-xdr-scores-perfect-100-in-se-labs-2026-ransomware-test/) ### [AI and Cybersecurity](https://www.paloaltonetworks.com/blog/security-operations/category/ai-and-cybersecurity/?ts=markdown), [News and Events](https://www.paloaltonetworks.com/blog/security-operations/category/news-and-events/?ts=markdown), [Uncategorized](https://www.paloaltonetworks.com/blog/category/uncategorized/?ts=markdown) [#### Introducing Active Directory Security Posture Management in Cortex XSIAM](https://www.paloaltonetworks.com/blog/security-operations/active-directory-security-posture-management/) ### Subscribe to Security Operations Blogs! Sign up to receive must-read articles, Playbooks of the Week, new feature announcements, and more. ![spinner](https://www.paloaltonetworks.com/blog/wp-content/themes/panwblog2023/dist/images/ajax-loader.gif) Sign up Please enter a valid email. By submitting this form, you agree to our [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use?ts=markdown) and acknowledge our [Privacy Statement](https://www.paloaltonetworks.com/legal-notices/privacy?ts=markdown). Please look for a confirmation email from us. If you don't receive it in the next 10 minutes, please check your spam folder. This site is protected by reCAPTCHA and the Google [Privacy Policy](https://policies.google.com/privacy) and [Terms of Service](https://policies.google.com/terms) apply. {#footer} {#footer} Products and Services * [AI-Powered Network Security Platform](https://www.paloaltonetworks.com/network-security?ts=markdown) * [Secure AI by Design](https://www.paloaltonetworks.com/ai-security?ts=markdown) * [Prisma AIRS](https://www.paloaltonetworks.com/ai-security/prisma-airs?ts=markdown) * [AI Access Security](https://www.paloaltonetworks.com/sase/ai-access-security?ts=markdown) * [Cloud Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions?ts=markdown) * [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention?ts=markdown) * [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering?ts=markdown) * [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire?ts=markdown) * [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security?ts=markdown) * [Enterprise Data Loss Prevention](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention?ts=markdown) * [Enterprise IoT Security](https://www.paloaltonetworks.com/network-security/enterprise-device-security?ts=markdown) * [Medical IoT Security](https://www.paloaltonetworks.com/network-security/medical-device-security?ts=markdown) * [Industrial OT Security](https://www.paloaltonetworks.com/network-security/ot-security-solution?ts=markdown) * [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security?ts=markdown) * [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall?ts=markdown) * [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations?ts=markdown) * [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls?ts=markdown) * [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager?ts=markdown) * [SD-WAN for NGFW](https://www.paloaltonetworks.com/network-security/sd-wan-subscription?ts=markdown) * [PAN-OS](https://www.paloaltonetworks.com/network-security/pan-os?ts=markdown) * [Panorama](https://www.paloaltonetworks.com/network-security/panorama?ts=markdown) * [Secure Access Service Edge](https://www.paloaltonetworks.com/sase?ts=markdown) * [Prisma SASE](https://www.paloaltonetworks.com/sase?ts=markdown) * [Application Acceleration](https://www.paloaltonetworks.com/sase/app-acceleration?ts=markdown) * [Autonomous Digital Experience Management](https://www.paloaltonetworks.com/sase/adem?ts=markdown) * [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention?ts=markdown) * [Prisma Access](https://www.paloaltonetworks.com/sase/access?ts=markdown) * [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser?ts=markdown) * [Prisma SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan?ts=markdown) * [Remote Browser Isolation](https://www.paloaltonetworks.com/sase/remote-browser-isolation?ts=markdown) * [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security?ts=markdown) * [AI-Driven Security Operations Platform](https://www.paloaltonetworks.com/cortex?ts=markdown) * [Cloud Security](https://www.paloaltonetworks.com/cortex/cloud?ts=markdown) * [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud?ts=markdown) * [Application Security](https://www.paloaltonetworks.com/cortex/cloud/application-security?ts=markdown) * [Cloud Posture Security](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security?ts=markdown) * [Cloud Runtime Security](https://www.paloaltonetworks.com/cortex/cloud/runtime-security?ts=markdown) * [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud?ts=markdown) * [AI-Driven SOC](https://www.paloaltonetworks.com/cortex?ts=markdown) * [Cortex XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam?ts=markdown) * [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr?ts=markdown) * [Cortex XSOAR](https://www.paloaltonetworks.com/cortex/cortex-xsoar?ts=markdown) * [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse?ts=markdown) * [Unit 42 Managed Detection \& Response](https://www.paloaltonetworks.com/unit42/respond/managed-detection-response?ts=markdown) * [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam?ts=markdown) * Observability * [Cortex XCOR](https://www.paloaltonetworks.com/cortex/xcor?ts=markdown) * [Next-Generation Identity Security](https://www.paloaltonetworks.com/idira?ts=markdown) * [Privileged Access Management](https://www.paloaltonetworks.com/idira/human/privileged-access-management?ts=markdown) * [Identity and Access Management](https://www.paloaltonetworks.com/idira/human/identity-and-access-management?ts=markdown) * [Endpoint Privilege Manager](https://www.paloaltonetworks.com/idira/human/endpoint-privilege-manager?ts=markdown) * [Identity Governance](https://www.paloaltonetworks.com/idira/human/identity-governance?ts=markdown) * [Workforce Password Management](https://www.paloaltonetworks.com/idira/human/workforce-password-management?ts=markdown) * [Agentic Identities](https://www.paloaltonetworks.com/idira/agentic?ts=markdown) * [Secrets Management](https://www.paloaltonetworks.com/idira/machine/secrets-management?ts=markdown) * [Unified Secrets Governance](https://www.paloaltonetworks.com/idira/machine/unified-secrets-governance?ts=markdown) * [Application Credentials Delivery](https://www.paloaltonetworks.com/idira/machine/application-credentials-delivery?ts=markdown) * [Vendor Privileged Access](https://www.paloaltonetworks.com/idira/human/vendor-privileged-access?ts=markdown) * [Threat Intel and Incident Response Services](https://www.paloaltonetworks.com/unit42?ts=markdown) * [Prepare for Emerging Risks](https://www.paloaltonetworks.com/unit42/prepare-for-emerging-risks/continuous-frontier-ai-defense?ts=markdown) * [Strengthen Your Defenses](https://www.paloaltonetworks.com/unit42/strengthen-your-defenses?ts=markdown) * [Build Your Security Strategy](https://www.paloaltonetworks.com/unit42/build-your-security-strategy?ts=markdown) * [Understand the Adversary](https://www.paloaltonetworks.com/unit42/threat-intelligence?ts=markdown) * [Respond to a Cyber Attack](https://www.paloaltonetworks.com/unit42/respond?ts=markdown) Company * [About Us](https://www.paloaltonetworks.com/about-us?ts=markdown) * [Careers](https://jobs.paloaltonetworks.com/en/) * [Contact Us](https://www.paloaltonetworks.com/company/contact-sales?ts=markdown) * [Corporate Responsibility](https://www.paloaltonetworks.com/about-us/corporate-responsibility?ts=markdown) * [Customers](https://www.paloaltonetworks.com/customers?ts=markdown) * [Investor Relations](https://investors.paloaltonetworks.com/) * [Location](https://www.paloaltonetworks.com/about-us/locations?ts=markdown) * [Newsroom](https://www.paloaltonetworks.com/company/newsroom?ts=markdown) Popular Links * [Blog](https://www.paloaltonetworks.com/blog/?ts=markdown) * [Communities](https://www.paloaltonetworks.com/communities?ts=markdown) * [Content Library](https://www.paloaltonetworks.com/resources?ts=markdown) * [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia?ts=markdown) * [Event Center](https://events.paloaltonetworks.com/) * [Manage Email Preferences](https://start.paloaltonetworks.com/preference-center) * [Products A-Z](https://www.paloaltonetworks.com/products/products-a-z?ts=markdown) * [Product Certifications](https://www.paloaltonetworks.com/legal-notices/trust-center/certifications?ts=markdown) * [Report a Vulnerability](https://www.paloaltonetworks.com/security-disclosure?ts=markdown) * [Sitemap](https://www.paloaltonetworks.com/sitemap?ts=markdown) * [Tech Docs](https://docs.paloaltonetworks.com/) * [Unit 42](https://unit42.paloaltonetworks.com/) * [Do Not Sell or Share My Personal Information](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd) ![Palo Alto Networks Logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/pan-logo-dark.svg) * [Privacy](https://www.paloaltonetworks.com/legal-notices/privacy?ts=markdown) * [Trust Center](https://www.paloaltonetworks.com/legal-notices/trust-center?ts=markdown) * [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use?ts=markdown) * [Documents](https://www.paloaltonetworks.com/legal?ts=markdown) Copyright © 2026 Palo Alto Networks. All Rights Reserved * [![Youtube](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks) * [![Podcast](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/icons/podcast.svg)](https://www.paloaltonetworks.com/podcasts/threat-vector?ts=markdown) * [![Facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/) * [![LinkedIn](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks) * [![Twitter](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks) * EN Select your language