Offense went agentic this week, and it runs your models too. ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏
The Agent Stack mascot
The Agent Stack _
Daily B2B AI automation brief · Thursday, September 24, 2026 · Issue #104

Hey there 👋

Two security companies shipped the same idea this week from opposite ends, and once you see it you cannot unsee it. Palo Alto now rents you an attacker. Proofpoint now rents you a guard. Both run on the same frontier models.

I read Palo Alto's whole writeup looking for the part where the scary number turns into marketing. Every figure in it is their own, so some of that is there. But one line is not a claim about their product at all, and it is the one that should change your Thursday: when a new vulnerability goes public, automated scanners are weaponizing it in about fifteen minutes.

If I had to bet on where your next bad week comes from, it is not the model invoice everyone was worried about on Tuesday. It is the gap between how fast the attack moves now and how slow your patch cycle still runs.

So today is about the security market growing up in one week: offense you can buy, defense you can buy, and the uncomfortable fact that both sides are renting the same brains.


The Big Thing

The pentest is now a subscription that never sleeps

Palo Alto's Unit 42 launched Continuous Frontier AI Defense this week, available worldwide today on an annual subscription. Underneath the category name it is a simple, slightly unsettling product: an always-on agent that attacks your own systems, over and over, the way a real intruder would. It runs on a harness that routes each job between two gated models, Anthropic's Claude Mythos 5 and OpenAI's GPT-5.6-Cyber, picking whichever one is better for the task.

Palo Alto measured all of this itself, so grade it accordingly. Inside the company, continuous scanning did about a year of traditional penetration testing in three weeks, found 3.2 times more high and critical bugs per product than the old method, and cut time to fix by roughly half. Across more than a hundred customer engagements, 37% of what it turned up rated high or critical, and two of every three real exposures in third-party apps had no published CVE at all. A vulnerability-only scanner would never have seen them.

The reason this matters even if you never buy it: Palo Alto built the thing because the offense already looks like this. In one investigation they cite, an attacker used more than fifty known techniques to compress weeks of careful intrusion into under ten hours. Time from break-in to stolen data is now under an hour in real cases. And that fifteen-minute figure again: a fresh CVE drops, and automated scanners are trying it against you before you have finished reading the advisory.

One caveat they raise themselves, which is rare in a launch post: no single model caught more than 40% of the bugs in a complex system, and their two models overlapped on less than 10% of what they found. That is why the thing needs a multi-model harness. It is also a quiet admission that any one AI security tool is leaving most of the holes on the floor.

Ship it? Pilot the service if you have a security team that can act on what it surfaces, with tight scopes and a rollback plan before you let an agent probe production. But the deploy that matters for everyone reading is a mindset. The offense against you is now a continuous agent. A pentest twice a year and a patch cycle measured in weeks are defending last year's threat.

Sources: Palo Alto Networks Unit 42 blog, Sep 22 2026, plus its investor release and The Next Web. Every performance figure comes from Palo Alto's own testing; measure it against your own systems before you believe it about yours.


Tour de Headlines

🛡️ The defense mirror shipped the same week. Proofpoint announced its Agentic Data and AI Security system this week, and it is the guard to Palo Alto's burglar. Three agents run it: one spots risky agent behavior, one investigates, one tightens the controls. The idea underneath is the useful part. Most tools today see one side or the other: what an agent is trying to do, or the data it can reach. Proofpoint built one graph that reasons across intent and access together. It can turn a written business rule into a control that blocks in the moment instead of a log you read after the money has left. Proofpoint's survey says 87% of companies have pushed AI assistants past pilot while 52% doubt they would catch a compromise. Believe the gap, grade the percentages. This one is a watch: general availability is slated for year end.

🏪 Anthropic opened a store for agents. The Claude Marketplace went live this week: more than two thousand connectors and plugins, and, more telling, agents and products from companies like CrowdStrike, Cursor, Harvey and Snowflake that you can buy with money you already committed to Anthropic. Alongside it, Agent Skills left beta on the API, so you can package a reusable skill without a special header now. Watch what this does to how agents get chosen. When a buyer can spend existing model budget on a partner's agent in two clicks, ease of purchase starts to beat raw capability. CrowdStrike's security platform sitting in the launch lineup tells you where this is heading.

⚖️ Legal tech got its first purpose-built agents, and said so honestly. Casepoint put two agents into its eDiscovery tool this week: one decides whether a document is relevant and shows the reasoning behind the call, one handles issue coding. They run inside the same permissions and audit trail the customer already uses, which is the right way to build it. The honest part, and they printed it themselves: this is an alpha, live with a handful of customers, with a beta before year end. So it is a picture of where the legal vertical is heading. Do not put it on a real matter yet. Worth watching because document grading is exactly the shaped hole an agent fits, and showing its work is what earns a lawyer's trust.


Sponsor

Your team's calls are full of signal. Measure it.

RapportScore reads the calls your team already records and scores how your people communicate: talk ratio, questions asked, trust signals. Deterministic measurement, not vibes. See where a rep is losing the room before the deal does.

See your team’s score →

Tool of the Day

💳 AgentCard

What it's for: giving an agent a card it can check out with, on limits you set.

If you have tried to build an agent that buys something, you already hit the wall: the agent finds the product and then cannot pay for it, because no merchant takes "an AI said so." Alchemy's AgentCard, now carrying Mastercard's Agent Pay, fills that gap. It hands the agent a real way to transact, a one-time tokenized card number tied to your existing Mastercard, so your rewards and credit line carry over and no fresh account gets created. You set the rules up front, a price ceiling and what it is allowed to buy, and the card carries proof that you authorized the purchase.

You program it through a CLI, so this is a builder tool, not a consumer toy. Treat the first runs like a new intern holding your credit card: small limits, one or two categories, and a human approving each purchase until you trust the pattern. The quiet shift here is that the hard part of agentic shopping was never the shopping. It was giving the agent a way to pay that a bank could still keep on a leash.

How AgentCard works →


Worth a Click

  • The numbers behind today's lead. Palo Alto Unit 42's own post, including the fifteen-minute CVE weaponization figure and why one model is not enough. (Palo Alto Networks)
  • One governance rule worth stealing. Akamai's new report argues you should give an agent autonomy in proportion to how verifiable and how reversible its actions are, and keep a human in the loop for anything high-stakes. It also found 40% of enterprise users have installed AI browser extensions, a quarter of which changed their own permissions inside a year. (Akamai)
  • The intent-plus-access idea, first-hand. Proofpoint explains the shared graph that ties what an agent means to do to the data it can reach. (Proofpoint)

Agent of the day: the harness. Strip the logos and the security market grew up this week. It stopped selling you tools and started selling you agents that fight other agents, and both sides are renting the same frontier models. Palo Alto rents you the attacker so you find the holes before someone else does. Proofpoint fields three agents to watch yours. Akamai says quit checking the agent's ID at the door and start watching what it does once it is inside. The brains are the same on offense and defense now. The only edge left is running yours before someone runs theirs.

— Ron

You’re receiving this because you subscribed to The Agent Stack. · Unsubscribe