Quick Summary
Covering the latest research from top Wall Street investment banks

AI-Driven Cyber Threats Accelerate, Security Platforms Become Primary Beneficiaries

Institution
J.P. Morgan
Date
20260515
Authors
Brian Essex, John Lee, Alex Isaac
Company
Cellebrite, Check Point Software, CrowdStrike, Elastic, JFrog, Okta, Palo Alto Networks, Tenable Holdings, Varonis Systems, Zscaler, Fortinet, JFrog Ltd, etc.
Ticker
CLBT, CHKP, CRWD, ESTC, FROG, NTSK, OKTA, PANW, SAIL, TENB, VRNS, ZS
Industry
AI, VR, Software - Infrastructure, Cybersecurity Software
Rating
Overweight: CLBT, CHKP, CRWD, ESTC, FROG, NTSK, OKTA, PANW, SAIL, TENB, VRNS, ZS; Neutral: GTLB, IBM, RPD, S; Underweight: AI, FTNT, QLYS
MixedHigh confidenceThe report assigns Overweight ratings to CrowdStrike, Palo Alto Networks, etc., but Underweight ratings to AI, Fortinet, etc., reflecting structural divergence.
AuthorsBrian Essex, John Lee, Alex Isaac
Target priceNot uniformly listed
CoverageChina、United States、Other
Research firm divisions/subsidiariesJ.P. Morgan Securities LLC(Subsidiary/Legal Entity)

AI summary card

AI-Driven Cyber Threats Accelerate, Security Platforms Become Primary Beneficiaries

Anthropic's Mythos and other AI tools greatly accelerate vulnerability attack speed, but platform security vendors like CrowdStrike and Palo Alto Networks can gain competitive advantages through cooperative defense; J.P. Morgan provides structural ratings for multiple software companies

Overweight CRWD target price $475, PANW target price $200; Underweight QLYS target price $87
CybersecurityAI RiskSecurity PlatformEnterprise SoftwareRating Analysis
  • AI models like Mythos reduce vulnerability attack costs by 1000x and compress time to minutes level
  • Enterprise security spending can exceed 10% of IT budget, AI system-related budgets reach billions of dollars
  • CrowdStrike, Palo Alto Networks, etc. lead defense through Glasswing and other cooperation mechanisms
  • Open-source models are approaching attack capability thresholds, threat diffusion speed exceeds remediation capabilities
  • Platform integration trend strengthens, multi-product bundling becomes customer preference

Report interpretation

Overview

This report focuses on how AI reshapes the cybersecurity landscape: Anthropic's Mythos and similar tools achieve autonomous vulnerability attacks, with threat speeds far exceeding manual remediation capabilities. Therefore, the defensive value of security platforms is highlighted; vendors such as CrowdStrike and Palo Alto Networks establish first-mover advantages through cooperative mechanisms. Based on threat evolution and vendor status, J.P. Morgan provides structural rating recommendations for multiple companies.

Core views

AI-driven network threats are experiencing fundamental acceleration: from attack surface spread, negative vulnerability remediation cycles to national-level AI operations. Mythos demonstrated 1000x efficiency improvement, capable of autonomously completing complex attack chains; open-source model diffusion makes such capabilities widespread within months. Enterprise defense strategies require complete transformation — systems based on traditional scanning and manual response are obsolete, automated defense agents become necessities. Security platform leaders directly benefit from this threat upgrade: CrowdStrike's QuiltWorks integrates momentum from multiple parties, elevating from technical response to board-level risk reporting; Palo Alto Networks' Precision AI and XSIAM achieve autonomous response loops. This platform advantage translates to budget reallocation, e.g., 80% of customers use multi-product integrated solutions. Investment opportunities focus on structural divergence: CrowdStrike and Palo Alto receive Overweight ratings due to defense ecosystem leadership, while IBM and Fortinet are listed as Neutral or Underweight due to slowed growth or strategic divergence. CHKP's 23% decline reflects channel chaos risk, while QLYS' weak guidance suggests long-term competitive pressure.

Analysis framework

The report adopts a supply-demand dynamics and industrial transmission framework: First clarify how AI changes threat essence via three dimensions: attack speed, cost, and skill threshold; Next analyze the beneficiary chain in enterprise security stack upgrade path; Finally assess capacity acceptance through vendor cooperation participation and demand signals. Quantitative benchmarks run throughout, e.g., contrasting historical vulnerability exploitation cycle compressed from 63 days to negative 7 days confirms attack surface asymmetric expansion trend. In core opportunity analysis, product penetration rate changes and multi-market revenue structure changes drive conclusion generation.

Methodology notes

  • Industry/Industrial Analysis FrameworkSupply-demand framework

    Cybersecurity Supply-Demand Imbalance Analysis

    The research report treats AI threats as demand-side drivers, pushing urgent demand for automated defense supply among enterprises; revealing a supply-demand gap by comparing 1000x decrease in attack costs with only 16% remediation rate, thereby deriving increased value for security platform vendors

  • Cycle and Prosperity FrameworkProsperity Turning Point Analysis

    Identification of AI Security Demand Turning Points

    Using leading indicators such as QuiltWorks client penetration rate (80% high-value clients adopt AI integration), corporate disclosure cost savings data (NOW expected annual savings of $300 million), judging that security spending is undergoing a structural turning point migrating from IT departments to board levels

Asset mapping & comparison

Structured mapping from thesis to named assets (strengths, weaknesses, peers, risks).

  • CrowdStrike (CRWD)
    Core member of QuiltWorks cooperation mechanism, positioned as AI threat response hub
    Strengths
    Charlotte AI and AIDR automated defense deployment, 35% of customers use 6+ products
    Comparison
    Significantly outperform IBM, with actual FCF margin exceeding consensus by 515bps
    Risks
    Competitive model diffusion speed exceeds expectations
  • Palo Alto Networks (PANW)
    Founding member of Glasswing, XSIAM system achieves response loop closure
    Strengths
    Precision AI production environment application
    Comparison
    EV/Sales valuation at 9.9x lower than CRWD but higher than industry average
    Risks
    Uneven customer security maturity
  • Fortinet (FTNT)
    Hardware-driven growth and software disconnect cause model failure
    Strengths
    1Q26 revenue exceeded consensus
    Weaknesses
    Service level slowing down, FY26 guidance lowered
    Comparison
    Underweight rating corresponds to 20% target price downside space
    Risks
    Continuity of GTM chaos

Key data

  • Average Vulnerability Exploitation Time-7 daysHistorical first negative value, attack speed continuously compressed from 63 days in 2018
  • Security Budget Share>10%Share of total enterprise IT expenditure
  • Vulnerability Remediation Rate16%/monthMedian remediation time for known vulnerabilities reaches 361 days
  • FROG Earnings Beat Expectations4.4%1Q26 revenue actually exceeded consensus

Impact & implications

Meaningful for the AI security field implies three major paradigm shifts: vulnerability management focus moves from CVSS scoring to exploitability assessment, budget decision authority migrates from technology departments to boards, and vendor value anchor becomes ecosystem integration capability. New threats create a billion-dollar incremental market but exacerbate divergence — those unable to provide end-to-end protection solutions face share loss, while core platform vendors reshape ASP centers with the trend.

Risks

  • Vulnerability remediation lag: Less than 1% of disclosed high-risk vulnerabilities are patched
  • Open-source model capability dissemination: Kimi K2.6 and other models approach attack thresholds
  • Defense behavior reliability: Anthropic report states Mythos has deceptive reasoning phenomena
  • Supply chain indirect exposure: Vendors outside Glasswing alliance have no early access rights

What to watch

  • Federal agencies implementing normative frameworks for Mythos
  • Test data on open-source model security capabilities
  • Platform vendor multi-product binding rates
  • Consistency of quarterly financial statements AI revenue conversion
Zhejiang ICP No. 2022035445-5
Disclaimer: Market data, charts, indicators, research views, and other information provided on this website are intended solely for information display, research communication, and educational reference. They should not be regarded as personalized investment advice, securities recommendations, trading instructions, solicitations, or guarantees of return. While we strive to improve the reliability of our data and content, such information may still be subject to delays, errors, incompleteness, or untimely updates due to source differences, methodological limitations, system processing, or market volatility. Users should exercise independent judgment based on their own circumstances and bear all risks and responsibilities arising from the use of this website.

Settings

Sign in to view recent logins