Insights from Black Hat : Networking in Cybersecurity | TSG Ep. 898
Alan Shimel shares insights from Black Hat 2025, highlighting the significance of networking in cybersecurity. Upcoming Black Hat content features exclusive interviews and showcases extensive preparations for security measures. The rise of AI in security is discussed, along with concerns about data leaks. The release of the 2025 global IR reports is emphasized, and viewers are invited to engage with Cortex Orion for more updates.
Transcript
Hey everyone, it's Alan Shimmel for Techstrong. As I said in the opening, if you've never been a blackout or you're not here this year and you're wondering what it was like, you've come to the right tech strong gang. This is a very special episode, excuse me, won't be joined by my usual gang compadres.
It's, this is solo, but I've been out here this week interviewing and talking and catching up, of course, on all my friends in the cybersecurity space. And I gotta tell you, between RSA and Black Hat, it's always great to come out and see people that I know, some cases 20, 25 and more years, and, uh, to hear what's going on in the security world. We've got some great video we're gonna be playing over the course of next week from our Black Hat interviews, but I wanted to bring three special ones to you today.
First one is an exclusive Textron. It is by the Black Hat Knock Crew themselves, and it's an exclusive behind the scenes look at what goes on in the Black Hat Knock, perhaps one of the most heavily defended and heavily attacked knocks, uh, in the private world because everyone would love to scalp and say they broke Black Hat's Network. But, uh, it's a great episode, so you'll check that out.
I'm gonna follow that up with a great conversation we had with our friends, uh, from Palo Alto Networks about the Cortex Cloud offering and what's new there. Like everything else at Black Hat, there's a little AI in there for you too. And then finally, we're gonna end with a, uh, a video shot here in our studio, rather than on the floor of, uh, interview with my good friend, rich Mogul of Fireman.
Of course, many of you know Richman's years at Garner and Securosis and Disrupt ops. And, and, you know, rich is one of the smartest people in security. I know he wrote the Cloud Security Alliances classes, but he's here at, uh, he's been at Fireman now for a number of years, and he's talking about network security, N-S-P-M-A recent Survey Fireman did on that, as well as an, uh, recent announcement partnering with Illumio on, on, uh, microsegmentation and Zero Trust.
So three good ones, and if you like these, there's a lot more behind them. Stay tuned. Next week, we are gonna be playing all of our great Black hat videos, so thanks for joining us today on this special Textron Gang.
Let's go ahead over now and find out about the Black Hat Knock. Hi, I'm James Pope, and welcome to the Black Hat Knock. I am the SOC leader here for the Black Hat Knock, and I'm also the Technical Marketing Engineering Director for Core Light.
We start prepping a long time before this conference to get ready to make sure that we can build an entire network from scratch. We bring in the ISP, we bring in switching firewalls access points, and then we bring in all of our security tools on top to make sure that A is available and b, that it's secure. Part of the security part is we have core light doing full P cap and network visibility of all the traffic that is here, or threat hunting, finding the really bad and the bad.
We call these black hat positives. Those are things where they are a legit bad thing, but we're gonna let it happen on this network. A student comes to learn about some how to run a malicious tool or carry out an attack, and they get taught that, and we see that across the wire, and we let that happen in this environment.
We care about the things that are truly bad and that bad students attacking students, somebody attacking registration or backbone. So we have a lot of eyes on a lot of screens paying attention to make sure that we are spotting those things. We're alerting on it, and we're res responding appropriately to that.
Some of the findings and things that we find every time is users who have a green checkbox in the bottom corner. So everything's secure, but they have a VPN that's leaking out credentials. They got some sassy tool that is sending all the proxy of all their information out in Clear Text.
Uh, I'm calling it the rise of, uh, ai, you know, everybody's calling it that. But the rise of Vibes, vibe Coding is taking off, and we're seeing a lot more apps, whether that be a weather app or whether that be, uh, leaking out all the GPS information or a, this year, a few different chat applications that are sending out all the corresponding information of that entire chat, including their voice and translation. So we're just seeing way more stuff in clear than we would like to see, especially at a security conference or let alone from any of these corporate laptops in this environment.
We do that with a lot of different ways. We use detections, search based alerts. We have Yara signatures.
We're leveraging Zeke and CTA on the back end. And then we're using ML hits and also AI detections. We work with our partners.
We do truly call them partners here. No, no tool out there can decide. It wants to be a part of the Black Hat Knock.
We go and choose the best of the best, and we ask them to come, bring their tools, bring their people, and, uh, make sure that we have a good experience. Those partners are Cisco, Palo Alto Networks, Arista, and Core Light. This year, we're leveraging a lot more with ai.
We're using Palo Alto Networks XIM to do a lot of summarization and categorization. We're also using a core light MCP server that lets us directly from an LOM client, whether it be Gemini or Claude or anything else, or a Slack bot where you can ask it, tell me about this incident. Tell me about this IP address, MAC Address, FQDN.
And we're leveraging that MCP server to go into the raw data, give us a relevant pieces of information and bring them back. It's working amazingly well for tier one, tier two people who might not know how to write SXQL queries or SPL queries, or insert some version of QL queries. They can ask a question, get the results, and then they can start acting on that information, uh, quicker and faster.
Uh, this year we also had two different organizations. One was a bank, one was a Fortune 50, who their security tools were actually giving away information about their machine, their patch level, their logs through misconfiguration, or just not enabling TLS. So we are in the year of vibing, but vibe and verify, validate that the things that you built are good.
I have the luxury of having all these expensive tools where I can look at it and validate that my stuff is good, but Zeke is free. Scot is free. TCP dump is free, Wireshark is free.
Go and validate that your stuff is not leaking out things before you send them to conferences or even just to go to your coffee shop or fast food where they're on any hotel network. And also leaking out that same information. While we do have a very highly customized network here that's very purpose built for this conference, there's a lot of things that people can do in their organizations they can take from this and use at their orgs.
One is all the detections and alerts we see. If a, somebody gets up and does a presentation on a brand new thing that they find, inevitably somebody turns around and tries to do that. So we want to look for that.
We create detections for that, and then we build those integrations with other partners and those detections that help our customers going forward. But yeah, organization, you wanna make sure that your stuff is secure. Your people are secure on their end points, not just for Black Hat, but for all conferences everywhere, where they're operating that they're doing in a secure manner.
Thanks for coming and visiting us in the Black Hat Knock. And we are here for the US Show Europe and Asia. You wanna learn more?
We do have a Twitch stream. You can watch us live in our fishbowl, but if you come to the conferences, you can come in and do a tour and see what's happening in here. Come learn more about Black Hat Knock and come learn more about Coral Light.
Hey everyone, welcome back here to Techstrong tv. So we came off of that crazy show floor to our luxurious broadcast suite here at the Luxor Hotel. MGM Tell My wife I love her.
Yes. Um, but thanks for joining us in our continuing Black Hat 2025 coverage. My next guest really needs no introduction to, to security people and, and, uh, our audience at Techstrong.
It's my friend Rich Mogul. First of all, rich, welcome back to Techstrong tv. Thanks.
Thanks for only the best for you, rich. Only the best. But, um, thanks for coming up and being with us.
I appreciate it. Rich. Of course, you're at Fireman.
Yep. You know, I forgot your title. Is it VP of Cloud Security?
S VP of Cloud Security. You Got it. S VP of Cloud Security.
The S is for special. Well, you know, I wrote an article last month. The S in Vibe, in Vibe coding stands for security.
You know, that brings me up. Remember we did a podcast once with the CEO of Mongo db. I will never forget that.
Me, I bring it up all the time And I talk about it all The time. And why not is this is no sequel, mean no security, and they said, we'll have security when our customers Was their answer. And then everybody got breached and then they added security.
And I think the same thing's gonna happen with Vibe. Yep. Agree.
When people start demanding security, they'll do something about it. But until then, as I said, the s and right coating stands for security. Um, but Rich, you're at Fireman as we mentioned, but of course, if you know Rich Long distinguished career as a Gartner analyst covering the, uh, Data security D-L-P-D-L-P space.
Yes. Yep. That, that, well, those were my days.
Those were my years. DLP and stuff like that. And then of course, rich and our good friend Mike Rothman went on to found, uh, Securosis.
Yep. Uh, kind of reset, broke the mold in security analyst firms over the years. And then you guys, rich, you were the primary driver of, of a product vision that that came out and that's how you came to Firemont.
Yeah. So they, uh, acquired our startup Disrupt ops mm-hmm. About three or so years ago.
And, uh, yeah. And then so It's been a ride. It's been a ride, my friend.
It's, Uh, yeah. Any little corner of this industry you could hit. I've probably, I'm, well, you know, I always like to think it's a round room And there are no corners.
But you're, you're right. We've been there. But you, you wanna know the nice thing coming to Black Hat?
Our next guest is in the green room waiting for us here. Fred Wilmut. I've had a chance to meet so many people and you've met more, you know, more than me.
And, but we've met so many people. And you come to this or you come to an RSA, maybe twice a year, we get together and, uh, it's good to see these people. I mean, some of these relationships are 20, 25 or more years old.
I've Known you for over 20 years. Absolutely. I'm ashamed to tell you longer than that, my friend, because I think the first security bloggers network was over 20 years ago.
Party. Yeah. I think it was 2003.
I, I'm bad at math. No, I know. Well, I, it's easy 'cause we're in a 25 year, so it's easy to say what 25 years is, right?
Yeah. But next year it'll throw me off. Anyway.
Hey, rich, we're here to talk a little bit about Fireman, though. I think most of our audience knows Fireman, but for those who maybe aren't, why don't we start there at that 50,000 foot level? What, what is Fire?
Yeah. Fireman focuses on security operations, and the area that we're most focused on is network security policy management. So NSPM is the core product.
Uh, we do also have, uh, my old product, which is a cloud security posture management product. Uh, we have an asset manager product as well. Okay.
And if you have really large, complex, uh, it doesn't even need to be really large. If you need to manage firewalls from different vendors, different environments, make sure those things are all compliant, uh, fireman is kind of the best at that. Yep.
And just, you know, to serve as, uh, cybersecurity historian Fireman, of course, was spun out of Gary Fish's. Yep. Fishnet Security.
The CTO of Fishnet was a guy named Jody Brazil. Yep. Brazel.
And, and Jody, they spun it out as fireman. And Jody was the first CEO he left for a while, but he came back. He's still CEO.
Yeah. So it was, uh, it was a pretty wild story. So Jody invented it, basically because he was doing these consulting projects, and he did the, let's see if I can automate myself out of a job.
Mm-hmm. And he came up with ways to do automation, connected to all these different firewalls and have this consistent policy enforcement went to Gary. Gary spun it out.
So Jody was, he was the tech founder. Everything became CEO. Now, when he left, after some, I guess some external investment years later, uh, I was his next startup.
So he was my co-founder of Disrupt ops, uh, him, Brandy Peterson, Mike Roth, and Adrian Lane. We all founded this company, disrupt Ops. And then Fireman acquired Disrupt Ops.
And it was like a reverse merger because Jodi then took fireman back over again. Right. It's an, it is an interesting story, but, you know, politics makes strange bed flows.
Yeah. And security stories are constantly, you know, strange. It's a strange engine.
Circular and circular. Right. Exactly.
No corners. Um, but Rich, I, I, you know, speaking of network policy management and I, I left a a, an A, uh, an initial outta there, didn't I? It's NSPM, network, network Security.
Policy Management. Management, yep. Fireman recently put out a report.
Yep. Talk to us. What's it about?
So, Uh, we had this new product called Insights. Mm-hmm. And well, you know, kind of product kind of feature.
So we actually leveraged some of the stuff that I had done in cloud as the base platform for this, or me, our team. I mean, it was 30 people won't get acquired. But, uh, the insights product for customers that are willing to share the, uh, um, use this, it uses their data and does analysis to help them optimize their use of their firewalls.
So it gives you all this really wild reporting and stuff that nobody else has seen before. Well, we found out that there was, uh, some interesting things that we didn't even know, because historically we've got our little silos of customers here, here, and here. And we had a way to look at kind of the data in the big picture.
Now, again, all privacy preserving customer driven, like, let's, let's be careful we're not stealing our customer's data, but we found that like 90% of firewalls had, uh, critical policy failures. And what, what do we mean by that is it's a compliance failure, uh, an obvious compliance failure. And it can be anything like somebody left Port 22 open where that shouldn't have been.
Or, uh, clearex protocols where it shouldn't have been or, or anything along those lines. So those policies, and, and there are standards around, like PCI, for example, we map those specific firewall rules to what PCI requires. And there were that the high degree of failure, but then there's some, or sorry, it was 60%.
I'm gonna cheat and pull my numbers up. 60%. Okay.
The high severity compliance checks, the 90% is actually 95% of the numbers, uh, falling Short of critical levels. Yeah. Well, it wasn't even that.
It's like inefficiencies. So 95% of the application objects that people define, so you can define application objects and firewall rules were used. Right?
So you're turning on your burden CPU cycles. You have these bigger, complex policies that are gonna be problematic to deal with. And, uh, and You're not in compliance, that you're not secure.
Yeah. So here's what I find not fascinating, revolting, that, you know, I've known about fireman since he spun it out. Yeah.
I remember going to Kansas City, talking to them, um, And We've had firewalls, next generation, firewalls, web application firewalls, this firewall, that firewall. We've had companies like Fireman and, and some of their competitors back in the day, TwoFin and, uh, I forgot the other one. I forget 'em all, But whoever they are, but, you know, that have preached firewall policy management religiously for 15, 20 years.
Well, It's in every audit and every assessment. So why, why do we still deal with this? Why are we still It's ai Help me.
Yeah. I mean, can AI automate this once and for all? I Mean, and we actually have some of that available in insights to help you, like, explore your environment.
So we have an AI chat bot up there, uh, which you didn't even know when you asked me the question, but the, it's more of, um, so this was new to me. Like even though I've been in security forever, I haven't really dug into firewalls too much. And, uh, after the acquisition, even though I'm very cloud focused, uh, some of what I had to do also began having to focus a lot more on the network security angle.
Specifically. There's so many reasons why. One is like somebody will put a rule in to get something working.
Mm-hmm. They'll forget to take it out or manually trying to manage these rules in these heterogeneous environments. If you have, you know, checkpoint IMP Palo and Cisco and Fortinet, and a lot of organizations do, and even they try to standardize on one, then they're gonna acquire or have a merger or something like that, and they're gonna get other ones out there.
So it just creates all of these extra levels of complexity. The other is, is when you're dealing with these at scale, the process of manning managing those rule changes and pushing those out to where they need to be, uh, it blew me away how much goes into that. There's organizations that literally have dozens of people dedicated to just managing firewall world changes.
And it's not an exaggeration. I, I was like, wait, you have how many people? And I'm like, don't you have any automation?
They go, yes. This is after the automation. These are all the exceptions.
'cause some of these orgs just have these, you know, incredibly large, complex environments. Oh, absolutely. And then the mid-size, they don't have enough people to manage what they do have.
And that's also been a problem. Yeah. Forever and ever.
Right. But that's why we love the insights, because that is exposing information to them. That was, that data was al always there.
But within the, the market, like, we weren't providing that in a way that was like impactful. Like, you can go to your CEO go, we're failing 60%. I mean, that's the average in the report, not the 90 I said at first.
Right. The 60% we're failing 60% of our compliance checks, you know, that are higher above. Mm-hmm.
We're, we have 95% of our application objects aren't even used. Like, that's just wasted space and added complexity. Yep.
So that's the kind of stuff that was like the, I'll, I'll be honest, when our team saw the results, they were like, oh, this is really good. Well, it's good for fireman, right? But Well, yeah, but it's bad for what's going on out there.
I think you pulled the 90% number, 60% of enterprise enterprise firewalls fail high severity compliance checks. Yep. Another 34% falling short at critical levels.
Yeah. So that's where you probably got 90, 90%, 94%. I wanna pivot if we can a little bit.
Recently Fireman announced an integration with Illumio. Yep. The Zero Trust.
And of course, Ilum Illumio is the leader in the segment network segmentation market. Let's talk about that. Yeah.
So, and that was, uh, actually what one of the things that I was involved with. So that was, uh, kind of the products that I work on with the Illumio integration. So we're not releasing all the specific technical details around this, but when you're using these micro-segmentation products and you have traditional firewalls and other network security controls in your environment, uh, there can be conflict.
So a lot of times the reason an enterprise is gonna bring in Illumio is because of, uh, a couple of different things. Maybe not enough firewalls, or they need deeper segmentation. You know, and there's cost effectiveness becomes a factor there.
Uh, you can't necessarily drop boxes everywhere in. And then there's also the additional layer of what products like Lumira are good for is they start giving you a better ability to manage rules based on what something is, as opposed to firewalls, which were designed purely to protect a good network from a bad network. Well, the problem that you can encounter is that for products like I lumio at work, they have to have agents everywhere.
And so there's a couple of different layers of issues where you, you can potentially run into issues. One of those is, uh, imagine you are a hospital or manufacturing or other facilities. You can't always install agents on everything.
Mm-hmm. And so you're still gonna need the firewalls to provide the rules, uh, around protecting those objects. But you still want it to work well with Illumio.
So what we've done a lot of the, and as we announced more about this, get out more details, but it actually can glue together the firewalls and illumio in intelligent ways so that they can actually be more compatible. The other issue is, is what if you want your, uh, illumio assets to talk to each other, but you've gotta get across the firewalls. And sometimes that can be a problem as well.
Sure. So those are like the two most common problems that we've kind of built this to, uh, go ahead and be able to address. And, and that's why it's great 'cause we can get to the asset level, attribute level security, and we can do it with your existing firewalls and then, and have that also work with the microsegmentation with the rail.
Got it. Now look, it's a zero trust play. Yeah.
But we should also mention it. It is, uh, it's, it's about resilience too. Yep.
Right. And, and that's a big thing, right. You know, people may not associate, uh, network security, uh, posture manager NSPM with resilience, but that's part of the resilience model, right.
Is try to contain Yeah. Where we, where we, where we're threatened, where something goes on, right. So we don't lose the whole ship.
Yeah. Being able to respond more dynamically. So there's that security, resilience play, and then there's also the resilience of what if a firewall goes down or this goes down or that goes down and being able to actually, you know, have the ability to like, update your environments to account for those kinds of situations.
Yeah. And, and it plays into the zero trust thing, which I, I think is finally, you know, with all due respect to John Kinder, that guy who was talking to John a couple weeks ago, a lot of people poo-pooed it and gave it a hard time, but it's really become part of the Concept. Every, every company I talk, like I had to do a bunch of research for our new products that we're working on.
And, uh, it blew me away that they all had some kind of zero trust initiative. Yeah. It's, it's the way it is.
Yeah. It's the way it is. Anyway, rich, I think we covered the topics that our corporate overlords have, uh, asked us to, to cover.
Is there anything else that we missed, you think, or? No, it was, uh, I mean, pretty good. The, uh, you know, tying in a little bit back to the zero trust piece of it too.
The part is is I like, like you, I poo-pooed some of the early stuff. Mm-hmm. Let's, let's be honest.
We all Did. Yeah. And, but I've come around on it because, uh, particularly now, because we have all this complexity, uh, that's been added to our networks with cloud and with containers and, you know, ephemeral, virtualized assets and everything else.
And like a lot of our security models just haven't worked for that on the network security side because it's port protocol source destination. And as somebody who's very cloud centric, this has been the, I had forgotten how much harder a problem. It's in a data like cloud.
I have a lot of capabilities. I can do all these. You thought, and that's funny.
'cause initially we thought we didn't have that in the cloud. Right? We didn't have enough control, we didn't have enough insight, we didn't have enough ability to manipulate what we needed.
But now you're saying, you know, I'm so used to doing that, that this stuff in the data center is a lot harder. It is a lot harder. But some of those principles, like in cloud, I can very easily write rules that refer to the assets or the attributes.
I mean, that's a really powerful part of this. Mm-hmm. Like this asset with these tags connect to this thing over here.
And those are things that we have really struggled intensely with in the data center. And so, you know, either with our, you know, bringing that asset intelligence and doing it in a way that works for enterprises, like that's a big part of all of this is, is really easy to show this stuff off in a lab. Agreed.
But you go into some of these large, it's A real world, and Our clients are huge. Some of these environments. Oh, I, I remember that.
I mean, I, you know, I know the firewall story. What, what freaked me out when I first became from really familiar with Fireman is you had customers who had dozens, if not hundreds of firewalls. Hundreds or thousands is not uncommon.
Yeah. It's crazy that have to be managed and now in multiple locations. And now you've gotta layer in cloud capabilities, like understand the cloud network and then harmonize the cloud network with the on-premises network.
Um, because you've got all this hybrid stuff that needs to talk to each other, and yet in the end, we want this thing to talk to this thing and not talk to, it's A relatively simple thing, right? Yeah. So that's where like this lumio partnership and other things that, you know, come out someday, but being able to have more of an ability to kind of make those decisions, uh, and have that, that higher level intelligence so you're not down to a five couple of firewall rule anymore.
I Get it. Hey Rich, we're about to add a time. I appreciate you coming up here to the thanks for having Taj Mahal and, uh, Am I allowed to leave?
No, no. You just, you gotta see the why are plastic Yeah. A corner there.
Yeah. We're gonna edit all this out, guys. Um, just make sure you stop in the bathroom.
Wash your hands real good. Okay. Rich Mogul Fireman here at Black Hat.
We're gonna take a break. Hey everyone. We're back here at Black Hat on the show floor.
If you can't tell from the lights and the noise, it's live. Uh, people are all over. But we carved out some room here at the Palo Alto, uh, exhibit, if we could call it that booth.
If you want. Let me introduce you to Orion Ca. Caseta Cato.
Cato. Yep. I apologize, Orion.
It's all good. I did get Orion right, though. You got the important part, like the star.
But, um, Orion, thanks for joining us here on Techstrong tv. Say hello to our audience, give them a little bit about you. Yeah.
Um, my name's Orion Cato. I'm Senior Director of product marketing for the Cortex Cloud Solutions of Palo Alto Networks. Um, I've been kicking around the cybersecurity space for about 20 years.
About a third of my career is in application security, a third in security operations, and a third in cloud security. It's a nice, it's a nice third, third and a third kind of rounded out thing. Um, Orion look, our audience knows Palo Alto.
Yep. But you know, this isn't like your grandma's Palo Alto. It's, it's more than just next Gen firewall, obviously you mentioned Cortex Cloud.
Yep. That's the cloud security offering. There's Unit 42, the, uh, the, uh, security research.
Yep. Division. You guys have done a couple of acquisitions recently.
Some bigger than others. They're not all closed yet, but you could follow along on Security Boulevard to get all the news on that. Uh, what have I left out?
Uh, the thing we're talking about today is Cortex Cloud, which you talked about a minute ago. Um, what Cortex Cloud is, is essentially a re-architecture of our Prisma Cloud solutions, which is our cloud security, uh, portfolio. What we essentially did was we took, you know, our well-known market leading solutions, Prisma Cloud, we re-architected them on top of our security operations platform, which is Cortex.
That's how we got to Cortex Cloud. The benefit though, is essentially we now have, you know, our application security, our cloud posture security, our cloud runtime security solutions, all on the same unified data layer layer as our security operations solutions. So they have, you know, context running all the way from code to cloud, and then a unified policy and AI engine and the automation engine of Cortex.
I love it. Um, look, you, you shoved a lot there in a little bit of time. I did.
I hope I can, uh, you know, distill it well, We're not gonna play it any slower because that's not gonna help. But let's peel the lead the onion back a couple little, let's dive into each of these days. Sure.
So the problem in the cloud security market essentially is fragmentation and the natural silos that exist within the platform. So cloud security essentially is, um, three things. It's your application security, so the app, the applications you build, there's a whole bunch of six or seven tools that everybody has to have to make that work.
Then you have your cloud posture security, which is essentially kind of a, a proactive battening down of the hatches and making sure your misconfigurations are dealt with. And then finally you have your runtime security. So, you know, finding attacks in real time reacting to those.
And so what Cortex Cloud is, is essentially taking the, you know, 16 or so solutions that an average company would have to build these together, and then putting 'em onto one platform to break down the silos of those tools and the silos of the teams that run those, which is application security, uh, your, uh, cloud security team, and then your security operations team all on one platform. I love it. I love it.
Look, the theme of this year's show is definitely, uh, ai. Yeah. And I know you guys are doing stuff with AI within Cortex.
Talk to us about that a little bit. Yeah, I think it really has, um, two implications on, has two implications on our, uh, portfolio. The first is, people don't often think about this, but when you're building an AI application, it's actually a cloud native application underneath it.
So the more AI you use, the more cloud you use, and our solutions help you to secure that cloud. So that's the first thing. The second thing is, you know, the proliferation of AI is starting to reach all sorts of areas in one that's very important is AI generated code.
So about 95% of code will be AI generated by 2030 according to Microsoft Report. Um, what that means though is, you know, we have a lot of code being generated by ai and a lot of that is vulnerable and being pushed into production to the point that around 74% of cloud breaches are now due to insecure go. So really drives home the need for not only greater cloud security, but also, you know, an integrated approach that brings application security into that.
I love it. Very cool. Um, let's talk black hat.
Yeah. What are you hearing from people? What's been the reception for what's happening with Cortex and Palo Alto on, on a broader stage?
Yeah, it's a great show this year. Um, there's a lot of buzz in the air. So we announced our application Security Posture Management, our A STN features.
Yep, yep. Um, it's been very, very well received. Um, you know, at least for this booth, it's one of the hot topics.
I, I think A SPM is pretty hot all around. What about, I, I know you're not part of, but unit 42 news there. Uh, yeah.
We recently released the, uh, I think the 2025 global IR reports. Um, so, you know, lots of good tidbits in that. Lots of good research.
The unit 42 guys are always cooking up amazing stuff. It's a good, it's a talented team they got over there. Absolutely.
Absolutely. How can people engage with Cortex Orion? Yeah.
Um, the best way to get involved, uh, the best way to get involved is to, uh, check out our website. So both the Cortex Solutions and the Cortex Cloud solutions. com.
Um, we also have live interactive demos that you can, you can do for the products and, uh, you know, kick the tires. Fantastic. Hey, I, I know we, we took over the, uh, the theater here.
Yeah. We gotta give it back. But I want to thank you for coming on and getting us a little bit educated.
Our Cortex. Of course. It's Palo Alto.
com or palo alto network com. Networks com. Com.
And then they could click through to Cortex from there. Yep. Alright, Orion, thank you very much.
Enjoy the rest of Black hat, keep up the good work. Thank you. Cortex Cloud from Palo Alto Networks here at Black Hat.
We are, well, we're not live, we're edited, but we hope you've enjoyed this. Stay tuned for more Black Hat coverage on Techstrong tv. Hey everyone, it's Alan back here.
I hope you've enjoyed these three, uh, videos, which give you a taste of what we've been covering here at Black Hat this week. As I mentioned, next week, we will be playing the entirety of our Black Hat video series. There's some great ones, including Samantha Kar Quala, CEO, talking about, uh, agentic ai, uh, rocks Risk Operation Centers.
We're gonna be talking with, uh, my friends, Jeremiah Grossman and Robert Hansen, our snake about their new venture. Uh, just a lot more, a lot more push. Security is another one that comes to mind, was really great.
I, I think you're gonna enjoy them all. But for now, that wraps up our text on Gang for this Friday. I hope you enjoy it.
I'm Alan Shimel. Have a great day.