Palo Alto Networks has acquired Console, an AI-native platform that lets organizations create agentic workflows through natural-language instructions. The company plans to integrate Console into its Cortex security-operations platform, enabling agents to investigate alerts, enrich and correlate events, prioritize cases, coordinate with enterprise data sources, isolate endpoints, and execute remediation across security and IT environments. Financial terms were not disclosed.
The acquisition is intended to move Cortex beyond analyst-facing recommendations toward governed autonomous operations. Palo Alto Networks said such deployments require restricted system access, comprehensive activity logging, approvals for high-impact actions, and safeguards against inaccurate or unauthorized agent behavior. The announcement accompanied the company’s fiscal fourth-quarter 2026 results, which reported $3.41 billion in revenue and nearly $1 billion in net new next-generation security ARR; the timing and success of Console integration remain uncertain.

Track how attackers are adapting to this technology.
3 events from the most recent confirmed update back to the earliest known activity.
For the quarter ended July 31, Palo Alto Networks reported $3.41 billion in revenue, up 34% year over year, and nearly $1 billion in net new next-generation security ARR. It also reported a GAAP net loss of $282 million.
Palo Alto Networks announced the acquisition of Console, an AI-native platform for building natural-language agentic workflows. The company plans to integrate Console into Cortex to support security investigation, prioritization, and automated remediation; financial terms were not disclosed.
Palo Alto Networks acquired observability vendor Embrace during the fourth quarter of fiscal 2026. The acquisition was separate from its acquisition of AI-native IT service-management platform Console.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
3 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcesecurityweek.com
Open sourcesdxcentral.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.