Illustration of a glowing shield beside stacked cubes and angular shapes in violet and cyan, shown on a dark navy panel with a light border

Palo Alto Networks Adds Virtual Patching to PAN-OS 12.2 to Compress Exposure Windows

Palo Alto Networks announced “Frontier Virtual Patching” on Aug. 20. It ships in PAN-OS 12.2 through a new paid tier, Advanced Threat Prevention Plus. The feature combines pre-disclosure vulnerability intelligence from two internal programs, NOVA and a Critical Defense Program, with inline defenses from its Precision AI engine to generate protections before a patch or public disclosure exists.

Palo Alto cites an industry-average 55-day patch window and a VulnCheck figure that 29% of CVEs are weaponized within 24 hours of disclosure. Both are third-party metrics that Di1 has not independently verified.

If mean-time-to-protect claims hold up under outside testing, this could compress the gap between weaponization and remediation that teams currently absorb as risk. However, these claims are strictly vendor-asserted. The blog gives no false-positive or false-negative rates, no rollback detail, and the primary text is truncated before it explains how signatures are generated and validated.

Buyers should note two governance flags. First, the same vendor discovers the vulnerabilities and sells the fix, a structural conflict federal buyers will want resolved with third-party validation. Second, Network World’s earlier Black Hat coverage described PAN-OS 12.2 features under different names, so confirm scope with Palo Alto before deploying anything to production.

Source: Palo Alto Networks blog


Leave a Reply

Discover more from Digerati One (Di1) | AI Integration & Multi-Cloud Architecture

Subscribe now to keep reading and get access to the full archive.

Continue reading