Palo Alto Networks is reportedly in advanced negotiations to acquire Israeli cybersecurity startup Koi Security for approximately $400 million. While Palo Alto Networks has not officially confirmed the deal, sources indicate that a preliminary memorandum of understanding has been signed and both parties are working to finalize the terms. Koi Security, founded by former members of the IDF's 8200 Intelligence Corps, specializes in endpoint software security and has raised $48 million in funding to date. The acquisition would mark Palo Alto Networks’ first purchase of an Israeli company since the departure of its founder Nir Zuk from the CTO role.
The potential deal highlights Palo Alto Networks’ ongoing strategy to expand its portfolio with advanced cybersecurity technologies, particularly those leveraging AI. If completed, the acquisition would provide a significant exit for Koi’s founders and investors, and could signal renewed confidence in Israeli cybersecurity startups amid a recovering tech sector. The move follows a series of recent acquisitions by Palo Alto Networks, including the purchase of Protect AI and ongoing negotiations to acquire CyberArk.

Track how attackers are adapting to this technology.
3 events from the most recent confirmed update back to the earliest known activity.
Multiple outlets reported that Palo Alto Networks was in advanced talks to acquire Koi Security for roughly $400 million. Neither company publicly confirmed the transaction at the time.
Palo Alto Networks and Koi Security signed a memorandum of understanding indicating mutual strategic interest in a potential acquisition. The proposed deal was reported at about $400 million, though it was not yet finalized.
Koi Security was founded in 2024 as a startup focused on securing non-binary software such as extensions, AI models, code packages, and containers across enterprise environments.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
4 references tracked. Mallory keeps watching after this page renders.
bankinfosecurity.com
Open sourcegovinfosecurity.com
Open sourcego.theregister.com
Open sourcetechrepublic.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.