Frontier AI & Project Glasswing

Interview with Haider Pasha, VP & CSO at Palo Alto Networks

What is behind the Claude Mythos? What role does Project Glasswing play? And what does it mean for businesses? Exclusively for NTS, Haider Pasha, VP & CSO at Palo Alto Networks, answers questions about the latest developments and the next steps organizations should take.

With more than 20 years of experience in IT, Haider Pasha brings extensive expertise in cybersecurity.

The biggest surprise from Project Glasswing: What surprised you most when using frontier models against your own products — not the number of findings, but the nature of the insight?

Haider Pasha: Yes, exactly that. The surprise wasn’t the volume of findings, it was how the model thinks like an attacker. Frontier AI excels at vulnerability chaining (combining lower-severity issues), things that individually would never make a patch priority list, into critical-level exploit paths, in near real-time. Concrete example from our testing: two medium sev and one low-sev vulnerability linked into a single critical exploit. None of the 3 would have been prioritized on its own.

Scale surprise is another one: in 3 weeks of Mythos-based scanning, we achieved the equivalent of 2+ years of pen testing effort. And it found logic-based vulnerabilities that traditional tools structurally miss.

The other insight is the real leap being not necessarily the coding ability, but its ability to be persistent. Most models run in short sessions (minutes), these cyber optimized models sustain long running sessions for hours. A human red team can’t hold that much context at once, a model can. The model became genuinely powerful once we built harnesses feeding it deep context (what the code does, how prior attacks worked, our Threat Intel, etc). Overall, we believe we understated the model’s capabilities with our own testing.

The lesson here is that severity-focused treatment of singular issues will not offer resilience. We now prioritize severity-agnostic, by exploit path.

Frontier AI collaboration in practice: What exactly are you doing differently in your product development today now that you have access to frontier models?

Haider Pasha: We began testing Mythos on April 7 as a Project Glasswing launch partner, and within weeks ran a full initial scan of over 130 products across all three of our platforms. The result went public in our May Patch Wednesday: 26 CVEs covering 75 issues, versus our typical volume of fewer than 5 CVEs a month, roughly five times our normal findings rate, none exploited in the wild, with all SaaS products already patched and patches available for every customer-operated product, all through the same PSIRT process customers already plan around.

The trajectory is the real proof point of “attack yourself first”: around 5 CVEs a month historically, 26 in the frontier sweep, and after the cleanse we expect to settle at an even lower run-rate than before. A one-time spike, then a permanently stronger baseline, that’s the curve every organization should want to draw for itself.

Day to day, three things changed. We built AI scanning harnesses, because the models aren’t magic; high-fidelity results require context, guardrails, and threat intelligence engineered around them. We rescan continuously, feeding every learning back into the harness. And we’ve shifted left, putting these models directly into the software development lifecycle so engineers break their own software before merge. Remediation is now ranked on attacker reachability, business impact, and AI exploitability, not CVE severity.

Volume vs. Value: How exactly does a customer recognize whether a scan result is truly actionable?

Haider Pasha: Raw counts tell you almost nothing. In early testing, roughly a third of raw findings were false positives, and of the true findings, the majority would never have impacted a customer. That’s the reality of raw model output, it’s noisy. Human validation of every finding isn’t optional; it’s the difference between a security program and a noise generator. So when we tell customers to attack themselves with these models, that expectation-setting comes with it. Those who don’t will drown their teams in volume while real exploit paths go unaddressed.

A result is truly actionable when it answers three questions. Can an attacker actually reach it – reachability, not theoretical presence? What happens if they do – the business impact and the full exploit path, including how it chains with other issues? And can AI exploit it – because AI exploitability is now a first-class ranking factor.

The practical test for any customer: if the report gives you a re-ranked remediation queue based on exploit paths, it’s actionable. If it just gives you a longer CVE list, it’s noise.

The 3 concrete things: If an IT manager could only do three things in the next 90 days — which three would you recommend?

Haider Pasha:
First, attack yourself first.
Use AI to find and fix vulnerabilities across your code, applications, and open-source supply chain before attackers do, build a complete exposure inventory of what’s actually reachable, and re-rank remediation by exploit path rather than severity.

Second, close the structural gaps. Zero trust and identity security for every human, machine, and AI identity, hardening of non-human identities and lateral movement and outbound connection controls, combined with pushing prevention toward 100% coverage: XDR everywhere, agentic endpoint security, and a secure enterprise browser.

Third, get faster. Automate patching capacity now, because in the coming deluge every patch that is not applied immediately becomes a known, targetable vulnerability, and modernize the SOC toward single-digit-minute detection and response.

The framework isn’t new, but the standard of execution is now absolute: organizations that are “mostly protected” are effectively unprotected.

Identity as the new front line: Why is identity the lever right now, of all things — and not classic patching?

Haider Pasha: Because of the rise of inside-out attacks. AI-driven attackers increasingly land directly inside infrastructure (think Solarwinds from a few years ago), bypassing the conventional attack steps that perimeter controls were built to catch. This isn’t theoretical, more recent supply chain attacks on tools like LiteLLM and Trivy show exactly this pattern, and the rush to deploy AI infrastructure has made it more acute, because the AI supply chain itself (runtime environments, communication infrastructure, model dependencies) is often insufficiently protected. Once an attacker is inside, the attack runs on identity: credentials, tokens, privileges, lateral movement. And it’s no longer just human identity – machine identities and now AI agent identities outnumber humans many times over and are usually the least governed.

There’s also an uncomfortable truth about patching alone: attackers will find and exploit vulnerabilities before patches even exist. You cannot patch your way out of a zero-day discovered by a frontier model. Identity modernization, zero trust segmentation, and short-lived secrets hold even against the vulnerability you don’t know about yet.

So it’s not identity instead of patching, it’s identity as the layer that holds when patching inevitably lags.

“The AI labs provide the capability — partners like NTS are how that defence actually lands in customer environments.”

Haider Pasha VP & CSO, Palo Alto Networks

AI as a double-edged sword: What is the biggest misconception customers currently have regarding the “AI threat”?

Haider Pasha: The biggest misconception is that this is a future problem, and that it’s mostly about better phishing emails. The reality is a change in speed and structure: AI discovering vulnerabilities at scale, generating exploits in near real time, chaining low-severity issues into critical paths, and moving from AI-assisted to fully autonomous attack agents. It’s a democratization of advanced attack capability; what once took days or weeks of skilled manual effort will soon execute in minutes, in far more hands.

The second misconception is that guardrails will keep this contained. They won’t. We estimate a narrow three-to-five-month window before these capabilities reach open-source models and attacker hands.

The third is that defenders need an entirely new framework. They don’t, so far, frontier models find new attacks, not new attack techniques, and that’s the defender’s advantage. What changes is the standard of execution: 100% coverage and machine-speed response.

New dimension, new time window: What role do system integrators like NTS play in ensuring these developments actually reach your joint customers on time and correctly?

Haider Pasha: Our view is simple: the AI labs provide the capability, the security industry provides the operational defence. And partners like NTS are how that defence actually lands in customer environments. The gap we see everywhere is that customers can buy advanced capability but struggle to deploy and operationalize it. The new standard is 100% coverage and optimization, and that is fundamentally a deployment and operations challenge, exactly where integrators live.

Concretely, NTS translates this moment into exposure assessments that show customers their real risk, closing the deployment gaps to full prevention coverage, driving the automation that gets SOCs to single-digit-minute response, and being the trusted local hand for customers who don’t have the in-house resources.

The three-to-five-month window is what makes this urgent: this transition has to happen across thousands of organizations, in parallel, within a couple of quarters. That simply doesn’t scale without the channel.

Outlook: What do you expect by the end of the year — and what does that mean for the cooperation with NTS?

Haider Pasha: My personal view is escalation, not easing. Our estimate is a three-to-five-month window before frontier cyber capabilities appear in open-source models and attacker hands, which lands before year end. Expect the vulnerability and patching deluge, more inside-out attacks, and the first genuinely AI-driven autonomous attack cycles. And I’d make one reframe explicitly: the urgency isn’t really about today’s models, which are in vetted defenders’ hands, it’s about the generation that follows, once this capability is commonplace. Customers preparing now are preparing for what’s coming, not reacting to what’s here.

But there’s a defender-side acceleration coming too. Virtual patching is being reimagined as a mitigation layer to buy teams time during the patch deluge, especially valuable in OT and critical infrastructure, where you can’t send a crew to a remote site every Patch Wednesday; a virtual patch at the firewall and IPS layer blocks the exploit pattern immediately and buys the operational window.

For NTS, this means joint urgency: lead with exposure assessments, then help customers modernize controls and operations. The customers we prepare together this half will be in a fundamentally different position than those who wait.

From 25 to under 15 minutes: How are these two phases related, and what does this mean for a customer SOC without fully automated response?

Haider Pasha: These are the two ends of the attack chain, both coming down at once. Under 15 minutes is how fast attackers start scanning for a newly published CVE, the time-to-target. Twenty-five minutes is initial access to exfiltration in AI-assisted scenarios, the time-to-impact. Combined, the entire attack, from a vulnerability becoming known to your data leaving the building, can complete faster than most SOCs triage a single alert.

The new bar is explicit (MTTD and MTTR under five minutes) and it’s achievable, because we live it ourselves. Our own SOC ingests around 180TB of data a day in one place, with detection and remediation in roughly one minute, against the fastest attack we’ve observed at about 23 minutes. When your response is measured in one minute and the attack in twenty-three, the defender wins; reverse those numbers and you lose every time.

The perimeter hardens over time — the durable investment is the real-time SOC, built on ML-driven detections, unified data across all sources, and automation throughout, delivered as a platform, because the seams between point solutions are exactly where those twenty-five minutes are lost.

Identity in 89% of cases: Is identity security now more important than classic vulnerability patching? Where should a customer with a limited budget invest first?

Haider Pasha: It’s not either/or, but if I’m forced to sequence a constrained budget, I’d do it in three steps. Start with an AI-driven exposure assessment (you can’t prioritize spend without knowing your actual exploit paths) it’s inexpensive relative to what it de-risks, and it tells you whether your biggest problem is exposure or identity. Then identity and zero trust, because it’s the horizontal control: it contains the phished credential, the unpatched vulnerability, and the zero-day alike, across human, machine, and AI identities. If identity shows up in nearly nine of ten investigations, it’s the control with the broadest coverage per euro. Patching runs in parallel, but ruthlessly prioritized, not “patch everything,” but the internet-reachable, chainable, high-business-impact exposures the assessment surfaced.

The way I’d frame it: patching reduces the number of doors, identity limits what an attacker can do once through any door, including the one you haven’t found yet, and the real-time SOC is the durable investment that catches whatever gets through either.

Two frontier partners at the same time (Glasswing + Trusted Access for Cyber): What does one provider deliver that the other does not? And should customers conclude that a multi-model approach is sensible for them too?

Haider Pasha: We deliberately partnered with both programs because our testing showed something important: there is real variance across models, driven by differences in their training, and each discovers unique vulnerabilities the other doesn’t. As our CTO Lee Klarich put it in our May Defender’s Guide, a multi-model approach is required to identify the superset of vulnerabilities. It’s defense in depth applied to discovery, multiple independent perspectives reduce blind spots and concentration risk on any one lab’s roadmap.

What doesn’t democratize is the engineering around the model. The harness is the moat, not the model. Anyone will be able to call these APIs soon; what took our hundreds of security engineers months to build is the harness work of deep context, threat intelligence, guardrails, and validation discipline that turns noisy raw output into verified exploit paths.

So should customers conclude a multi-model approach makes sense for them? Directionally yes, with two caveats. Governance first: restrict the source-code context you share, and make zero data retention contractual with every model provider. And capability isn’t defence: the labs provide the capability, but turning it into validated, prioritized, operational outcomes is a different discipline. That’s what Unit 42 Frontier AI Defense exists to do, customers get the outcomes of a multi-model, harness-engineered approach without having to build any of it themselves.

About Haider Pasha

Haider Pasha is VP & CSO at Palo Alto Networks and has more than 20 years of experience in the IT industry. Throughout his career, he has earned numerous professional certifications, including CCNP, CCSP, CISSP, CCIE (Security), and CEH.

Want to learn more about Frontier AI & Project Glasswing?

If you would like to learn more, get in touch with us and schedule a meeting with one of our experts: sales@nts.eu.