Palo Alto Networks CEO Nikesh Arora waded in on Hugging Face's recent breach, which saw the AI firm hacked by OpenAI agents, while finding a good opportunity to tout Palo Alto's browser security wares.
In a series of posts on X (formerly Twitter), Arora addressed both OpenAI and Hugging Face by suggesting AI frontier labs should turn their models inward to audit internal infrastructure, code, and configurations, potentially helping to catch zero-day vulnerabilities and prevent sandbox escapes before further testing.
"Had you done so, it would have possibly avoided the agent obviating your sandbox," Arora wrote.
This was in reference to last week's attack, where Hugging Face saw an autonomous AI agent framework execute "many thousands" of individual actions across a swarm of short-lived sandboxes, with self-migrating command-and-control carried out on public services.
OpenAI admitted on Monday that the attack was driven by a combination of its models, including its security-centric GPT‑5.6 Sol model and "an even more capable pre-release" large language model (LLM). Both firms cooperated on an investigation of the matter.
In further response to OpenAI's admission, Arora advised that to keep autonomous AI models under control, development teams should deploy offensive and defensive agents in tandem as a counterbalance while monitoring AI inference generated by agentic workflows.
"Do not let agents run riot. Keep track of inference consumption to get a sense of activity," the CEO said.
For the Palo Alto Networks chief, the breach maintains "the urgency on enterprises' need to test, validate and improve both their security posture and infrastructure." "The born-in-the-cloud players have a better chance to get this done soon versus the traditional enterprise which has existed for long and has complex network and IT infrastructure," Arora said.
Palo Alto Networks' chief warned it would be hard to discover and remediate vulnerabilities in small and medium business (SMB) enterprises, as well as open-source platforms.
"I think SMBs will eventually migrate to secure browsers and will require full visibility of employee and agentic traffic," Arora wrote in another thread, alluding to his firm's Prisma Access Browser 2.0.
The browser attack surface #
The Prisma offering is a secure access service edge (SASE) and AI-native secure browser with zero trust abilities. Palo Alto Networks claimed in-built web protection for Prisma Browser monitors and discovers more than 5,000 AI apps, enforcing the fight against shadow AI with responsive access policies, real-time user guidance, and AI-assisted approval processes.
Scott McKinnon, UKI CSO at Palo Alto Networks, claimed in a recent interview that the starting point for cybersecurity in the AI era should be securing the browser as this is where most enterprise work takes place.
“With our browser, we can provide a safe environment for these agents to be interconnected and plugged into, and then we can also protect on the backend where you've got cloud native applications that have agency to integrate within different systems," McKinnon said.
The browser security theme saw CrowdStrike acquire browser protection firm Seraphic Security this year, along with browser/SASE integrations from Netskope and AI-native browser launches from AI peddlers like Perplexity.
Recent Gartner SASE rankings saw the research giant knock Palo Alto Networks for what it saw as limited customer need for Prisma Access Browser.