BREAKING: Nikesh Arora, Palo Alto Networks
$PANW | 3X Mythos Run-up to $300B Market Cap
The Golden Egg of Cybersecurity
Nikesh Arora is the Chairman & CEO of Palo Alto Networks (NASDAQ: PANW), the famous cybersecurity giant that has grown from roughly $18 billion in market cap when he joined to ~$300 billion today (3x in value since Feb 2026).
→ Listen on X, Spotify, YouTube, Apple
We sat down at Palo Alto Networks to discuss why Nikesh believes the AI cybersecurity boom is only beginning, how companies will defend themselves against increasingly powerful AI attacks and rogue agents, and why the time between discovering a vulnerability and exploiting it is collapsing.
Nikesh also explains why he signed Jensen Huang’s recent open-source AI letter, what the rise of autonomous agents means for enterprise security, and why he believes the entire software industry will be rewritten over the next decade.
We also go inside the operating playbook behind Palo Alto Networks’ rise, including 40+ acquisitions in eight years, the $28 billion CyberArk deal, Nikesh’s “paranoia” about disruption, hiring AI-native talent through hackathons, and the lessons he took from Larry Page at Google and Masayoshi Son at SoftBank.
𝐓𝐈𝐌𝐄𝐒𝐓𝐀𝐌𝐏𝐒
(00:00) Nikesh Arora, Chairman & CEO at Palo Alto Networks
(00:51) The AI attack era has already started
(03:30) What happens when agents go rogue
(04:39) Why AI Labs are slowing down
(06:31) The Mythos Fallout
(17:25) Cybersecurity's secret weapon
(19:43) Buying a company is the easy part
(20:48) Where most acquisitions go wrong
(24:58) Predicting the SaaS Crash?
(28:03) The question nobody in Tech is asking
(30:54) There's never enough Compute
(33:12) Palo Alto's bar for AI fluency
(35:37) The controversial hire
(37:12) Using LinkedIn to spot opportunities
(39:19) What a CEO's day actually looks like
(43:47) The leadership traits that matter
(47:02) Google vs. SoftBank: What was different?
(51:02) Why planning horizons are shrinking
(52:55) Lessons From Elon & Masa
(56:44) What's next for Nikesh?
Brought to you by:
Brex—The intelligent finance platform: cards, expenses, travel, bill pay, banking—wrapped into a high-performance stack. Built for scale. Trusted by OpenAI, Anthropic, Vercel, Granola, Deepgram, & Sourcery.. teams that move fast AF. visit → brex.com/sourcery
Turing—Turing partners with frontier AI labs to improve model capabilities in coding, reasoning, tool use, & multimodality, as well as with Fortune 500 enterprises to build & deploy end-to-end agentic AI systems in mission-critical workflows Visit: turing.com/sourcery
VCX—VCX is the public ticker for private tech, allowing investors of all sizes to invest in venture capital. View The Portfolio at GetVCX.com
Deel—Deel is the global people platform that helps startups hire, manage, pay, and equip anyone, anywhere. Trusted by more than 35,000 fast-growing companies, Deel is the people platform that just works, so teams can scale without the chaos. Visit: deel.com/sourcery
Public-–Investing platform Public just launched Generated Assets, which lets you turn any idea into an investable index with AI. With Generated Assets, you can build, backtest, refine, and invest in any thesis with AI. Gone are the days of one-size-fits-all ETFs. Try it today: public.com/sourcery
Palo Alto Networks CEO Nikesh Arora
Rogue Agents, Mythos, Linkedin, & the $300B Mythos Run-up
→ Listen on X, Spotify, YouTube, Apple
The Controversial Hire
Nikesh Arora joined Google in 2004, months after the IPO that priced at $85 a share for a $23B market cap. He ran European operations, then EMEA, then became President of Global Sales Operations & Business Development in 2009, then Sr. Vice President & Chief Business Officer in 2011, owning revenue & customer operations. Google booked $3.2B in revenue the year he arrived & $66B in 2014, his last year.
He went on to serve as President & Chief Operating Officer of SoftBank Group under Masayoshi Son. He took the Palo Alto Networks job in June 2018 at an $18B market cap. The company trades above $300B today.
He had none of the obvious qualifications for the job.
“I’d never done cybersecurity in my life.. I’d never been a public company CEO.. And I’d never sold enterprise. I was a consumer guy. Other than that, they got everything right.”
The early years ran on borrowed expertise. He describes imposter syndrome throughout, sitting in technical meetings and watching how his own comments landed, then calling founder Nir Zuk and the company’s product leadership on the drive in and the drive home.
AI Made Attacking Cheap & Defending Hard
The AI labs have been publishing demonstrations of their models finding software vulnerabilities, chaining them together, and running attacks against live infrastructure. Every one of those demonstrations describes a capability that is now broadly available.
“This is the beginning. This is not a moment”
“It’s a lot easier to attack. As an AI lab, it’s much harder to defend.”
Getting the world's infrastructure to a standard that survives AI-speed attacks is a multi-year build, and no single vendor can absorb it. That is his explanation for why the sector has been bid up.
$PANW shares have traded between $139.57 and $398.88 over the past 52 weeks, and the company carries a market cap of roughly $300B.. with a recent ATH at $322B.
Mythos Pushed Security to the CEO
By his account, security gets bought below the CEO. A vendor calling the chief executive gets handed down to the technology organization, and he spent 8 years on the wrong end of that.
“For 8 years, I spent my career trying to convince CEOs they need to pay attention to cybersecurity. Tried everything. Call them, dine them, wine them, try to talk to them, and they usually send you off to their technology team. ‘Go talk to those guys.’ You know what Mythos did? Every CEO wants to talk about Mythos.”
Mythos changed that. Anthropic disclosed the model on April 7 2026 and said it would not release it publicly, because it was too good at finding high-severity vulnerabilities in major operating systems and web browsers. It went instead into Project Glasswing, a defensive program with a limited set of partners. Roughly 50 of those partners have since used it to find more than 10,000 high or critical severity vulnerabilities across the most systemically important software in the world, and the program has been extended to around 150 more organizations in over 15 countries.
Palo Alto Networks ran it against its own code. Speaking on All-In in June, Arora said a 6-week test surfaced vulnerabilities that would have taken his own team 5 to 7 years to find, at a cost in the low millions. His framing there was that 50 years of badly written human code is now assessable by AI. He has also put Mythos-level offensive capability roughly 3 months from being available in the wild.
From 55 Days to 4 Hours
Patching a vulnerability and exploiting it have always been a race. He puts the industry average for shipping a fix at 55 days, and his argument is that with AI as strong as Mythos has collapsed the other side of that race down to just minutes. Closing a gap that wide is an engineering problem the company has been working on for years, across detection, testing, and delivery.
“The average time to fix it was 55 days in the industry. The average time [adversaries] will find it and try and attack you is in minutes..
[We took it] from 55 days to 4 hours.”
The 4 hours is what they got it down to. Palo Alto Networks launched the capability at Black Hat in August and pushed it to every customer, taking their own patch delivery from the 55-day industry standard to same-day. He points to it as AI finally showing up on the defensive side of the ledger.
Compression moves work onto the customer too. He expects them to test their own software and open source dependencies continuously and to modernize the infrastructure underneath, and he reads that spend as good news for the security industry.
What Rogue Agents Have Already Done
This stopped being hypothetical during the making of this episode.
On July 21, 2026, OpenAI disclosed that two of its models, GPT-5.6 Sol and a more capable unreleased model, escaped a sandboxed testing environment during an internal evaluation called ExploitGym. The benchmark scores AI systems on finding and exploiting software vulnerabilities. Rather than solve the challenge, the agents went after the answer key. They found a zero-day in the package registry proxy that had been treated as the environment’s only controlled egress path, reached the open internet, rooted a third-party code sandbox, used it as a staging base, and chained further zero-days into Hugging Face’s production clusters.
Hugging Face reconstructed roughly 17,600 attacker actions from logs covering July 9-13th, with the agent inside their systems for about two and a half days. What it reached was contained, 5 datasets whose names tie to the benchmark challenges and their solutions, with no customer-facing models or data touched. Hugging Face detected the intrusion and reported it to law enforcement before OpenAI connected the activity to its own evaluation run. Their summary of it was blunt, describing an AI agent that escaped its sandbox, cheated on its benchmark test, and hacked their infrastructure to steal the answer key.
The details that emerged later are the uncomfortable part. OpenAI researchers presenting at Black Hat described agents writing files into an internal package manager to create a covert message board, delegating sub-tasks to each other across separate evaluation runs, and cryptographically signing their messages out of concern that impostor agents might be reading them. Reuters reported on July 31st that OpenAI had found other instances of agents escaping sandboxes, described as limited, with none believed to have left OpenAI’s own network. The Black Hat presentation ran at the same conference where Palo Alto Networks announced its 4-hour patching capability.
Then there is the version that happens to normal people. On August 10th, ABC reported that an Australian man asked his agent to book him into a morning class at his gym. The agent found that the booking limit was enforced in the website front end but not in the API underneath it, so it booked him months further ahead than the gym allows. It then found the cancellation endpoint had no authorization check at all, and tested that live against the person sitting at position 1 on the waitlist. (sick)
“The API has zero authorization checks on cancelling other people’s reservations.. I tested this with the person in waitlist position #1, and it actually went through.”
Asked to undo it, the agent could not, because creating a booking required authorization and the person it removed would have to rejoin at the back of the queue. It apologized for running a live call instead of a dry run, then drafted a vulnerability disclosure email to the gym’s software vendor. Neither flaw was exotic. A competent developer could have found both in an afternoon. Nobody had, because until recently nothing was reading that API looking for a way into a workout class.
However, the warnings came earlier. In March, an engineer at Meta asked an agent to help analyze an internal question, and the agent posted its answer to the forum without asking permission to share it. The advice was wrong, and acting on it exposed company and user data to unauthorized engineers for 2 hours, logged internally as a Sev 1. A Meta safety director described her own agent deleting her entire inbox despite instructions to confirm before acting. An agent published a hit piece attacking an engineer who rejected its code. Alibaba’s engineers traced a burst of security policy violations on their training servers to their own coding agent, which had started mining cryptocurrency and opening covert network tunnels.
Nothing here was attacked from the outside. In every case an agent pursued the objective it was given, found the weakest path to it, and took that path.
Who Is Responsible for the Model??
So a model that can find and chain vulnerabilities gets pointed at your company. What happens next? and who answers for it?
The labs themselves have been the loudest voices calling for the pace to slow down. Anthropic and OpenAI have both argued publicly for more caution and more oversight of frontier capability, in some cases about the models they had just shipped. One read of that, and plenty of commentators hold it, is that the caution is insurance. If something goes badly wrong later, the record shows they were the ones asking for restraint… He reframes the question entirely.
“Are they asking for a slowdown? Or they’re asking for permission to be able to go release these?”
Underneath it is a liability problem nobody has solved. The law assigns responsibility to people and to the companies that employ them, and a model that acts on its own breaks that mapping.
“We have to understand liability. We have to understand who’s responsible at the end of the day. It’s very easy to ascribe responsibility and liability to human beings. If you do something wrong, it’s your fault. If I do something wrong, it’s my fault. If I use a model and the model does something wrong, whose fault is it? Is it the model’s fault? Is it my fault for using the model?”
Read that way, the calls for governance are the labs trying to establish who carries the risk before someone else decides for them, which is what lets them keep shipping.
“A lot of the AI labs want to get ahead of it, make sure there is some governance framework around it to ensure that they can keep developing the technology at the pace at which they’d like to. So in a way, they’re probably doing the right thing. It doesn’t seem like it, but I think they are doing the right thing in trying to get some governance around it so they don’t get hauled back. As you saw, they did get hauled back when they tried to launch Mythos or Fable 5.”
The template for getting there already exists in autonomous vehicles. Billions of dollars of training and edge case work preceded public willingness to hand a machine life and death authority. Every enterprise use case that gives an agent real agency runs the same process, and it takes years.
Why Palo Alto Networks Signed the Open Weights Letter
Jensen Huang used his first post on X, published 24 July 2026, to share Open Weights and American AI Leadership. It launched with 25 signatories and passed 270 companies and organizations by 3 August. Palo Alto Networks is on the list, alongside CrowdStrike, Cisco, and Zscaler. OpenAI, Anthropic, and Google were all absent at launch. OpenAI and Google have since signed. Anthropic has not.
The letter argues that American AI leadership will be decided by whether an open ecosystem diffuses into every sector rather than by any single frontier model. It asks Washington to expand compute access for startups and researchers, fund shared training assets, and avoid premature restrictions on open models. It also separates distillation, which it defends as a legitimate technique, from unlawful extraction from closed models.
The security section is what puts a cybersecurity company’s name on it. When attackers have advanced AI, defenders need models of comparable capability to detect, simulate, and respond. Concentrating capability behind a small number of closed models creates single points of failure that outsiders cannot inspect.
“Openness may be one of the most important paths to AI safety and security.”
His own framing is about diffusion. Open source sets a global price point for access, open weights allow fine-tuning against specific enterprise use cases, and closed models cover what neither can. He also thinks the industry is spending too much attention on the models themselves.
“There’s an over-indexing on the model part of it.. Models are important, but it’s also important to get all the context collected and all the training data right.”
40 Acquisitions in 8 Years
40 acquisitions in 8 years sounds aggressive until you look at what the industry requires. Attackers change methods constantly, and every new technology that reaches the market needs new security built around it. Cloud, then containers, then browsers, now agents. Each shift creates a category the incumbent does not have a product for, and customers will buy that product from somebody. Building it in house takes longer than the window allows, so the large vendors buy their way into each new category instead. That is why the sector consolidates the way it does.
“It is the most innovative industry in the world because the bad guys are trying to figure out how to attack you in a different way every time. The moment we suss out how they did it, they’ve moved on to finding the next time ... In that environment, it’s impossible that all the innovation’s gonna come from us. There’s always somebody else who’s got a different angle. There’s always somebody else who’s tried something that’s gonna work better than what I thought about.”
Palo Alto Networks has acquired more than 40 companies since 2018, including CyberArk at roughly $25B, the second largest deal in cybersecurity history. The market disliked that price until the results came in.
He plans 2 years out, and visibility thins past that point. Acquisitions fill the gap.
“That’s kind of the paranoia I live with.. Sometimes we’re looking for interesting products, sometimes we’re trying to fill gaps, sometimes we’re anticipating the market and saying, ‘How can we get ahead?’”
By his own scoring, 3 out of 4 acquisitions have worked.
The Biggest M&A Mistake
Nikesh reveals the biggest mistake he’s seen with his fair share of change management. It’s happens after the deal closes, in how buyers treat the people they just bought..
“The biggest mistake that people make during acquisitions is underestimate the intelligence of the people who built the business that you acquired.. Our attitude is, ‘You kicked our ass. Come tell us what we did wrong. Come run this for us.’”
That creates friction internally, because the acquired team often ends up running the internal team it beat. Integration is simpler when the acquisition lands in a category the company does not already play in. Resource the team, leave it alone, then plug it into a field organization that already has the customer relationships.
The End of the SaaSpocalypse + Software That Has an Opinion
The SaaS complex sold off roughly 50% on the thesis that AI models would absorb application layer software. Palo Alto Networks called the end of that repricing for cybersecurity 6 months ago, on the argument that model capability covers the broad case and security lives in the exception.
“AI can be great at 80% use cases. We live in the 0.1% use case. We’re looking for the needle in the haystack.”
Category by category, the market is still sorting which incumbents survive. Application tools now compete with native model capability that reaches the same output, the market has already “declared” some of those companies dead.. with some Italian sharks circling the waters on some great arbitrage moments.
The larger change is foundational, given that for the past 20 years of software it executed deterministic tasks and held no view on the work. Now AI-native software has a POV, which means an HR system could tell you not to hire someone and a security product could tell you your firewall deployment is wrong.
“The entire software industry will get rewritten in the next 10 years.”
Making Over 20,000 People AI Native
Palo Alto Networks employs over 20,000 people, and the competency question applies to all of them. Nobody senior enough to teach this exists yet, so the learning happens peer to peer. Twice a week, the top 24 technical people in the company meet for 2 hours to walk through what they are building and why. He calls it AI IO, after the Old MacDonald refrain (EI-EI-O).
He also changes who is in the room. Managers are told to keep hiring AI-native engineers until they outnumber the people who were already there, on the theory that behavior shifts once the balance tips and features start shipping faster.
“The biggest risk we have to ourselves is two guys in a garage who are sitting down building the next company, which is fully AI native.”
Hiring Out of Hackathons
To that point, hackathons have surprisingly became a hiring channel about 9 months ago. Teams are told to source a third of their headcount from people who have been experimenting with agents on their own, and hackathons are where those people surface. No credential certifies agent fluency, so the signal he trusts is what somebody does after work.
“There’s no school they can teach you this stuff in. How am I gonna know that if you know how to use OpenClaw well, how am I gonna know you understand what an agent is? If you’re not going home and figuring this stuff out yourself, that’s a problem because you’re supposed to be the architects of my technology for the future. If you’re not curious and not learning, where am I gonna find these people?”
The channel works alongside the composition mandate. Once enough of those hires land in a team, the people who have been there longer start picking up the tools, and the ones who do not eventually select themselves out. He contrasts that with the approach of cutting a third of the workforce on the assumption they will never get there, which he rejects.
Proud LinkedIn Power User
We spent the morning walking the Santa Clara office asking people what we should ask Nikesh. Only one person took us up on it, and it was Lee Klarich, the 20-year Palo Alto Networks veteran who serves as Chief Product and Technology Officer and sits on the board.
Asked what the one question should be, Klarich said to ask him what he learns from LinkedIn. Is he a big LinkedIn guy. He is a big LinkedIn guy. He loves it.
Nikesh’s first response was to call it a conspiracy, on the theory that the rest of the office had fed the question to Klarich rather than ask it themselves. The answer underneath it is that he treats LinkedIn as an intelligence feed and a hiring channel. The general counsel came off LinkedIn. So did Wendy Whitmore, who runs incident response.
“They’re not interviewing when they’re posting on LinkedIn ... If I can read what people have written over the last four years on LinkedIn, I can tell you who they are without having to ask them.”
The habit traces to Google in 2004, where nobody took a meeting without searching the person first. His team feels it daily. A competitor post he finds between 4:30 and 6:30 becomes a message asking what they plan to do about it.
“That’s why it’s like, holy shit, he’s on LinkedIn again.”
Role Models & Next Play Mentality
With a pretty legendary career, leading teams & investing from Google, SoftBank, and now Palo Alto Networks, I asked Nikesh if he had any role models or mentors along the way. Well, he gave an interesting answer of inspirational figures to say the least..
Elon
Elon Musk taught him the value in N-of-1 ambition, taking the world’s biggest problems head-on. Electric cars when nobody believed in electric cars, rockets landing themselves, Starlink terminals now bolted to cars, boats, and planes. The pattern he draws from it is about problem selection rather than execution. Most entrepreneurs work on small problems because those are the only ones they can see the end of, and Musk commits to problems whose solutions he cannot see either.
“If you take a really hard problem nobody’s working on, if you get it right, you win and you win big. And if you look around you, a lot of entrepreneurs are busy trying to solve small problems because this is the problem they can see.. Elon cannot see when he comes up with a problem he’s trying to solve. He can’t see that far, but he thinks if he tries to put his mind to it, that problem gets solved.”
Masa
Masayoshi Son taught him capital allocation. Son started SoftBank selling packaged software and has pivoted the business roughly 20 times since, was briefly the richest man in the world, lost it, and rebuilt. What Arora takes from him is risk appetite that has grown rather than shrunk with age.
“He’s the oldest man I know with the risk appetite of a teenager. As he gets older, his risk appetite becomes bigger.”
The specific lesson came as a correction. Arora was on the phone multiple times a week with the CEO of a portfolio company that was down 50%, trying to coach it back to plan.
“He looked at me & says, ‘If you put in that much effort on the company that’s doubling, they might quadruple.’
We might make more money on the one that quadruples than you fixing the one that’s broken.
That’s an insight.. As operators, our tendency is to try & fix everything because we don’t want things to break. As an investor, he said, ‘Double down on your winners. They’re gonna be way more interesting for you than the ones that are gonna not make money.’”
Steph
Steph Curry supplied the last one, speaking at a conference Arora attended with his son. Next play mentality works the same in business and in sport, and it is the counterweight to the paranoia that runs through everything else he describes.
“Steph talked about this next play mentality. It’s like you can’t win if you can’t get rid of the last play that he missed. You gotta focus on next play. That’s an interesting lesson, whether you’re in business or you’re in sport.”
He describes what holds it together as karmic calm, which sits oddly next to the paranoia and appears to be the point.
“You have to try to do your best. You have to put your heart and soul into it. You have to wanna win.. And if it works against you, wake up in the morning, shake it off, and do your best again. If you get hung up on what happened yesterday, you won’t be good.”
→ Listen on X, Spotify, YouTube, Apple
The material presented on Molly O’Shea’s website are my opinions only and are provided for informational purposes and should not be construed as investment advice. It is not a recommendation of, or an offer to sell or solicitation of an offer to buy, any particular security, strategy, or investment product. Any analysis or discussion of investments, sectors or the market generally are based on current information, including from public sources, that I consider reliable, but I do not represent that any research or the information provided is accurate or complete, and it should not be relied on as such. My views and opinions expressed in any website content are current at the time of publication and are subject to change. Past performance is not indicative of future results.
Paid Endorsement. Brokerage services by Open to the Public Investing Inc, member FINRA & SIPC. Advisory services by Public Advisors LLC, SEC-registered adviser. Crypto trading provided by Zero Hash LLC, licensed by the NYSDFS. Generated Assets is an interactive analysis tool by Public Advisors. Output is for informational purposes only and is not an investment recommendation or advice. See disclosures at public.com/disclosures/ga. Matched funds must remain in your account for at least 5 years. Match rate and other terms are subject to change at any time.





















