Every organization has a small group of wildly powerful special accounts — the admin, root, and superuser accounts that can shut down servers, wipe databases, move money, and create new users. These are the “keys to the kingdom.” Steal just one of these keys and the game is over — the hacker becomes the system administrator. Privileged Access Management, or PAM, is the discipline of keeping these keys in a vault, lending them out one use at a time, and filming every time someone uses one. This is the innermost layer of the modern security fortress.
Contains
Theme index· base 100 · USD total return
No index history for this theme yet.
Why is Privileged Access Management (PAM) moving?
Latest
▲3
AI agents and a $388M crypto hack drive urgent PAM demand
▲
CrowdStrike CEO calls for treating AI agents as privileged identities CrowdStrike's CEO proposed giving AI agents tightly controlled permissions, short-lived credentials and a kill switch — exactly what PAM does. This pushes the theme up by making privileged access control a mainstream answer to AI-era threats, and CrowdStrike's strong results show security spending is holding up.
Directly ties AI security fears to PAM-style controls, a new demand driver.
▲
Bitget's $388M hack exploited stolen high-level credentials Attackers used a third-party security flaw to grab high-level internal credentials and bypass controls, draining $388 million. This is the year's largest crypto theft and a clear reminder that stolen privileged access is a top risk, pushing demand for PAM tools that lock down and monitor such credentials.
A major real-world breach caused by privileged credential theft, directly boosting the case for PAM.
◆
Palo Alto's CyberArk deal consolidates PAM but integration costs weigh Palo Alto closed its $25 billion CyberArk purchase, making PAM part of a bigger platform and lifting cross-sell potential. But the quarter showed a $282 million GAAP loss from deal costs, and investors sold the stock, showing consolidation can pressure near-term results even as it strengthens the long-term PAM franchise.
The biggest structural change in the PAM market this period, with both positive and negative effects.
▲
AI-powered attacks make privileged access control a boardroom priority Anthropic disrupted a Russia-linked campaign using its AI models against Ukrainian targets, and a study showed AI agents doing advanced hacking for under $50. As AI lowers the cost and skill needed to attack, companies must tighten control over privileged accounts and machine identities, supporting PAM demand.
Shows the threat environment worsening in ways that specifically require PAM controls.
Q3 2026
▲3
AI agents and a $388M crypto hack drive urgent PAM demand
▲
CrowdStrike CEO calls for treating AI agents as privileged identities CrowdStrike's CEO proposed giving AI agents tightly controlled permissions, short-lived credentials and a kill switch — exactly what PAM does. This pushes the theme up by making privileged access control a mainstream answer to AI-era threats, and CrowdStrike's strong results show security spending is holding up.
Directly ties AI security fears to PAM-style controls, a new demand driver.
▲
Bitget's $388M hack exploited stolen high-level credentials Attackers used a third-party security flaw to grab high-level internal credentials and bypass controls, draining $388 million. This is the year's largest crypto theft and a clear reminder that stolen privileged access is a top risk, pushing demand for PAM tools that lock down and monitor such credentials.
A major real-world breach caused by privileged credential theft, directly boosting the case for PAM.
◆
Palo Alto's CyberArk deal consolidates PAM but integration costs weigh Palo Alto closed its $25 billion CyberArk purchase, making PAM part of a bigger platform and lifting cross-sell potential. But the quarter showed a $282 million GAAP loss from deal costs, and investors sold the stock, showing consolidation can pressure near-term results even as it strengthens the long-term PAM franchise.
The biggest structural change in the PAM market this period, with both positive and negative effects.
▲
AI-powered attacks make privileged access control a boardroom priority Anthropic disrupted a Russia-linked campaign using its AI models against Ukrainian targets, and a study showed AI agents doing advanced hacking for under $50. As AI lowers the cost and skill needed to attack, companies must tighten control over privileged accounts and machine identities, supporting PAM demand.
Shows the threat environment worsening in ways that specifically require PAM controls.
Palo Alto Networks Jumps 5.1% After BTIG Raises Price Target to $425
Palo Alto Networks shares jumped 5.1% in the afternoon session after BTIG raised its price target on the cybersecurity provider to $425 from $404 and reiterated a Buy rating following discussions with management. BTIG analyst Gray Powell cited growth potential from Chronosphere, CyberArk, and Prisma AIRS, forecasting pro forma revenue growth above 17%. Separately, NVIDIA launched its Open Agent Safety Platform to govern and secure artificial intelligence agents across compute systems from testing to deployment, and named Palo Alto Networks as one of the industry leaders collaborating on the safety initiative. The shares closed the day at $391.64, up 4.5% from the previous close. Palo Alto Networks is up 118% since the beginning of the year and is trading close to its 52-week high of $396 from August 2026.
Bitget Details $388 Million Security Incident as BTC Withdrawals Resume
Bitget has disclosed further details of the security incident that hit the exchange on Sept. 24, with CEO Gracy Chen saying the attacker exploited a vulnerability in a third-party security product to obtain high-level internal credentials. The incident is tied to a $388 million figure, and BTC withdrawals have resumed. Chen's account identifies the entry point as a flaw in an outside security vendor's product rather than Bitget's own systems, which the attacker used to reach high-level internal credentials.
Cybersecurity & Digital Trust › Privileged Access Management (PAM) ▼Technology
Cybersecurity & Digital Trust › Identity & Access Management ▼Technology
Bitget · Regulation · Negative Bitget disclosed a $388 million security incident where an attacker exploited a third-party product flaw to obtain high-level internal credentials.
Palo Alto Networks Targets 4,000 Platformizations to Drive $20 Billion NGS ARR by FY2030
Palo Alto Networks closed its fiscal fourth quarter with roughly 2,500 platformizations, including a record 220 net additions, as the company bets its platformization strategy can carry growth toward a targeted $20 billion in Next-Generation Security ARR by fiscal 2030. NGS ARR jumped 63% to $9.1 billion in the quarter, a figure that also benefited from acquisitions including CyberArk and Chronosphere, while net retention among platformized customers exceeds 120% and more than 65% of NGS ARR now comes from those customers. The company says it is on track to deliver more than 4,000 platformizations, which it expects to drive the majority of that $20 billion FY2030 target. Palo Alto has been adding capabilities and making strategic purchases to bolster the strategy, launching Unit 42 Continuous Frontier AI Defense on September 22, an annual subscription service that uses multiple frontier AI models to identify, validate and remediate exposures, and acquiring Portkey for an AI gateway, Koi to expand Prisma AIRS into agentic endpoint security, and CyberArk for identity security across human, machine and agentic identities. Gartner estimates global information-security spending will rise about 12% this year to $244 billion, supporting the market backdrop, though the company must integrate several acquisitions while expanding into fast-evolving AI-security markets. Hedge fund holdings in Palo Alto rose to 89 in the second quarter from 87, with Ken Fisher's Fisher Asset Management increasing its stake 2,143%, and short interest stands at 2.66% of the float, down from 2.8%.
Cybersecurity & Digital Trust › AI Security & Agent Guardrails ▲Demand
Cybersecurity & Digital Trust › Identity & Access Management Competition
Cybersecurity & Digital Trust › Privileged Access Management (PAM) Competition
Cybersecurity & Digital Trust › Endpoint & Network Security Competition
Cybersecurity & Digital Trust › Security Operations (SIEM/SOAR/XDR/MDR) Competition
PANW · Demand · Positive Platformizations reached ~2,500 with record 220 net adds and NGS ARR up 63% to $9.1B, with >120% net retention among platformized customers, supporting the $20B FY2030 target.
PANW · Technology · Positive Launched Unit 42 Continuous Frontier AI Defense and acquired Portkey, Koi and CyberArk to expand AI and identity security capabilities.
CrowdStrike CEO Kurtz Warns AI Cyber Threat Is Already Here
CrowdStrike CEO George Kurtz is pushing back against calls to slow frontier AI development, arguing the cybersecurity threat investors should worry about is not theoretical or years away. Kurtz said the genie is out of the bottle, pointing to advanced and open-weight models already available, and warned that AI is giving every criminal and lone actor elite execution, potentially letting less-skilled attackers operate with capabilities previously limited to sophisticated cyber groups. His remarks came in response to Anthropic CEO Dario Amodei, who has called for slowing development of advanced AI, with Kurtz arguing that pacing what comes next does not secure what is already here. He proposed treating AI agents as privileged identities with tightly controlled permissions, short-lived credentials and a kill switch, keeping humans involved in high-stakes decisions, and called for closer cooperation between cybersecurity companies and AI developers including Anthropic and OpenAI, offering CrowdStrike's threat intelligence to independent evaluation efforts. The argument arrives as CrowdStrike's business accelerates: fiscal second-quarter revenue rose 26% to $1.47 billion, annual recurring revenue climbed 25% to $5.84 billion, record net new ARR reached $333 million, up 51%, and free cash flow totaled $377 million, while the company raised its fiscal-2027 net-new-ARR growth outlook. CrowdStrike already generates more than $2.29 billion of ARR from customers using Falcon Flex, and investors are watching whether AI-related security concerns translate into measurable platform expansion through net new ARR, Falcon Flex adoption, customer spending on identity and AI security, and free cash flow.
Artificial Intelligence › Open-Weight Model Developers Regulation
Artificial Intelligence › Agentic AI & Autonomous Workflows Technology
Cybersecurity & Digital Trust › Privileged Access Management (PAM) ▲Technology
Cybersecurity & Digital Trust › Security Operations (SIEM/SOAR/XDR/MDR) ▲Demand
CRWD · Capital · Positive CrowdStrike's fiscal Q2 revenue rose 26% to $1.47B, ARR climbed 25% to $5.84B, record net new ARR hit $333M (up 51%), FCF was $377M, and it raised its fiscal-2027 net-new-ARR growth outlook.
CRWD · Demand · Positive CrowdStrike already generates more than $2.29B of ARR from customers using Falcon Flex, with investors watching AI-security concerns translate into platform expansion and customer spending on identity and AI security.
Anthropic · · Neutral Anthropic CEO Dario Amodei is cited for calling to slow advanced AI development, which Kurtz pushes back against, but no business impact on Anthropic is described.
CrowdStrike and Palo Alto Networks Race Into AI Cybersecurity
CrowdStrike and Palo Alto Networks are racing to answer the question Jensen Huang raised on Sept. 10, when he told investors at the Goldman Sachs Communacopia + Technology Conference that cybersecurity is likely to become AI's next major growth market. CrowdStrike unveiled SafeMind at its Fal.Con conference on Sept. 1, an agentic cybersecurity system built by its own Cyber Superintelligence Lab on top of open Nemotron models, which the company says detects threats 29% more accurately and remediates them six times faster than the frontier models it benchmarked against. CrowdStrike's fiscal second quarter revenue rose 26% to $1.47 billion, with net new annual recurring revenue climbing 51% to a record $333 million, and CEO George Kurtz disclosed an eight-figure Falcon Flex deal with a frontier AI lab. Palo Alto Networks took the opposite path, integrating CyberArk and Chronosphere and adding Console, an AI native platform for agentic enterprise workflows; its Next Generation Security annual recurring revenue reached $9.1 billion, up 63% year over year, and total remaining performance obligations crossed $20 billion for the first time, rising 34% to $21.2 billion, even as it swung to a GAAP net loss of $282 million in the quarter. Investors rewarded only CrowdStrike's report, sending its shares up roughly 20% on Aug. 27, while Palo Alto's shares fell more than 5% despite revenue rising 34% to $3.41 billion in its fiscal fourth quarter. The threat behind both bets is not hypothetical: Anthropic told Reuters it disrupted a Russia-linked hacking campaign that used its Claude models against more than 20 Ukrainian government and defense targets, and a joint study by Wiz and Irregular found AI agents completed sophisticated offensive security challenges for under $50 in computing costs versus close to $100,000 for the same work by paid human researchers.
Cybersecurity & Digital Trust › AI Security & Agent Guardrails ▲Technology
Artificial Intelligence › Agentic AI & Autonomous Workflows ▲Demand
Cybersecurity & Digital Trust › Endpoint & Network Security Competition
Cybersecurity & Digital Trust › Security Operations (SIEM/SOAR/XDR/MDR) Technology
Cybersecurity & Digital Trust › Privileged Access Management (PAM) Competition
CRWD · Capital · Positive CrowdStrike's fiscal Q2 revenue rose 26% to $1.47B with record net new ARR of $333M, and shares jumped ~20%.
CRWD · Technology · Positive CrowdStrike unveiled SafeMind, an agentic cybersecurity system it says detects threats 29% more accurately and remediates six times faster.
PANW · Capital · Positive Palo Alto's Next Generation Security ARR reached $9.1B, up 63%, and remaining performance obligations crossed $20B, up 34%.
PANW · Technology · Neutral Palo Alto integrated CyberArk and Chronosphere and launched Console, an AI-native agentic platform, but swung to a $282M GAAP net loss.
Palo Alto Networks Posts 63% NGS ARR Growth but $282M GAAP Net Loss
Palo Alto Networks reported fiscal fourth-quarter revenue of $3.41 billion, up 34% year over year, alongside a $282 million GAAP net loss after earning $254 million a year earlier. Next-Generation Security annual recurring revenue rose 63% to $9.10 billion, though the company said the increase is not an organic growth rate because the current portfolio includes acquired identity and observability businesses absent from the prior-year base, and remaining performance obligations climbed 34% to $21.2 billion. GAAP operating income fell to $172 million from $497 million, cutting GAAP operating margin to 5.0% from 19.6%, while company-defined non-GAAP operating income reached $1.01 billion and non-GAAP net income was $853 million. The quarter's operating reconciliation included $487 million of share-based compensation-related charges, $281 million of acquired-intangible amortization and $68 million of acquisition-related costs, and the net-income gap also reflected a $524 million fair-value change in convertible senior notes acquired in the CyberArk transaction. Operating cash flow rose to $1.36 billion from $1.02 billion, and management guided fiscal 2027 revenue of $14.10 billion to $14.20 billion, growth of 23% to 24%, with NGS ARR expected to reach $11.075 billion to $11.175 billion, up 22% to 23%.
Cybersecurity & Digital Trust › Identity & Access Management Capital
Cybersecurity & Digital Trust › Privileged Access Management (PAM) Competition
Cybersecurity & Digital Trust › Security Operations (SIEM/SOAR/XDR/MDR) Competition
Cybersecurity & Digital Trust › Cloud & Workload Security Competition
Cybersecurity & Digital Trust › Endpoint & Network Security Competition
PANW · Capital · Neutral Q4 revenue up 34% and strong NGS ARR/guidance but GAAP net loss of $282M and margin collapse to 5.0% from 19.6%
CyberArk Software Ltd · Capital · Neutral Mentioned only as the acquisition behind the $524M convertible-notes fair-value change and non-organic ARR base
Jim Cramer Bullish on Palo Alto After Strong Earnings
Jim Cramer expressed bullishness on Palo Alto Networks after the company delivered strong fiscal fourth-quarter 2026 results, though the stock fell 9.3% on September 2 despite the beat. Palo Alto reported revenue of $3.41 billion, up 34% year over year and above the $3.35 billion estimate, with adjusted earnings of $1.02 per share versus $0.98 expected. Next-Generation Security ARR rose 63% to $9.10 billion, but management's fiscal 2027 guidance implies a slowdown to 22-23% growth for NGS ARR, which is a key concern. The company also faces execution risk from integrating acquisitions like CyberArk and Chronosphere. Hedge fund holdings edged up to 89 funds in the second quarter from 87, and short interest was about 2.8% of float.
Palo Alto Networks reported fiscal fourth-quarter 2026 results that beat expectations, with revenues rising 34% year over year to $3.41 billion and non-GAAP EPS of $1.02, both surpassing consensus estimates. Management framed AI as a durable demand driver, noting that agentic traffic on its SASE platform grew 9x over nine months and Prisma AIRS surpassed $100 million in annual recurring revenue within four quarters. The company added a record 220 net new platformizations in the quarter, with net revenue retention exceeding 120%, and closed large deals including a $126 million global telecom agreement and a $72 million IT services transaction. For fiscal 2027, Palo Alto guided NGS ARR of $11.075 billion to $11.175 billion, up 22% to 23%, and revenues of $14.1 billion to $14.2 billion, up 23% to 24%. The company also highlighted contributions from CyberArk and Chronosphere, with a nine-figure benefit from a large LLM customer's migration, while acknowledging cost pressures from SaaS growth and rising hardware costs.
Palo Alto Networks Earnings Preview: What to Watch on September 1
Palo Alto Networks reports earnings on September 1, with Wall Street expecting strong results after a flurry of price-target hikes from analysts including Benchmark, J.P. Morgan, Robert W. Baird, and Jefferies, all maintaining Buy ratings. The company guided to revenue of about $3.35 billion for the July quarter, up roughly 32% year over year, with its next-generation security business expected to grow close to 60%. This will be the first full quarter including CyberArk, the $25 billion identity security acquisition, and its new AI security product Prisma AIRS has been the fastest-growing product in company history. However, a large portion of that growth is bought rather than earned, so investors should focus on organic growth and whether AI security is converting into recurring revenue. With shares more than doubled this year, a simple beat may not suffice; strong fiscal 2027 guidance is crucial to avoid a selloff. The stock trades at a forward P/E of 241x and a price-to-sales ratio of 24.21x, 109% above its five-year average, while analysts expect EPS growth of 9% to 22% through the decade. The company has $3.11 billion in cash against $2.13 billion in debt, and its balance sheet is clean. In its last reported quarter, revenue rose 31% to $3 billion, with EPS of $0.85 beating consensus, and it raised fiscal 2026 guidance to revenue between $11.415 billion and $11.425 billion. Analysts have a consensus Strong Buy with a mean target of $367.28 and a high target of $475, implying 29% upside.
Palo Alto CEO Held Talks with Okta and Datadog Before CyberArk Deal
Palo Alto Networks CEO Nikesh Arora held acquisition talks with both Okta and Datadog before landing a $25 billion deal for CyberArk, and is now circling Cribl and ClickHouse as his next targets, The Information reported on Wednesday. Between late 2024 and early 2025, Arora met with Okta CEO Todd McKinnon, and discussions progressed to product complementarity but stalled over price disagreements. Okta, valued at roughly $13.5 billion at the start of last year, has since climbed around 30% to a market cap near $23 billion. In spring 2025, Arora approached Datadog CEO Olivier Pomel with a hypothetical acquisition when Datadog was valued at more than $40 billion, but Pomel was not receptive and no formal offer was made; Datadog's market cap has since roughly doubled to more than $80 billion. With both paths closed, Arora executed fallback moves: Palo Alto agreed in July 2025 to acquire CyberArk, and in January 2026 paid $3.35 billion for Chronosphere, a smaller Datadog rival. Together, those two acquisitions contributed $338 million of the $3 billion in revenue Palo Alto generated in the April quarter. Arora's accelerating dealmaking reflects a conviction that AI is fundamentally changing the threat landscape, with AI agents capable of executing cyberattacks humans never could, making continuous monitoring a boardroom priority.
BeyondTrust Unveils First Native Pathfinder Capabilities for Every Identity at Black Hat USA 2026
BeyondTrust announced the first wave of native capabilities built on its Pathfinder platform at Black Hat USA 2026, extending privilege management to every identity that can hold or exercise privileged access. The four new capabilities—PathfinderAI & MCP Server, AI Agent Security, NHI Governance, and Workload Credentials—combine visibility, intelligence, and protection to help organizations discover, prioritize, govern, and protect privileged access across human, machine, workload, and AI identities. PathfinderAI enables natural-language investigation of identity risk, while the MCP Server allows AI agents like Microsoft Copilot and OpenAI to securely connect to BeyondTrust’s identity intelligence. AI Agent Security enforces real-time controls on what AI coworkers and autonomous agents can do on endpoints, and NHI Governance extends privileged access management to service accounts, API keys, and other non-human identities that often outnumber employees. Workload Credentials replaces static secrets with short-lived, auto-expiring credentials for CI/CD pipelines, Kubernetes services, and AI agents, eliminating the risk of leaked secrets. PathfinderAI, the MCP Server, AI Agent Security, and NHI Governance are available now through the Early Access program, with Workload Credentials early access opening soon.
Securden Named Representative Vendor in 2026 Gartner Research on Least Privilege Endpoint Strategies
Securden has been recognized as a Representative Vendor in the 2026 Gartner research report Reduce Cybersecurity Attacks With Least Privilege Endpoint Strategies. The report, authored by Paul Mezzera and Michael Kelley, highlights the cybersecurity risks of persistent local administrator privileges on endpoints and the growing challenges of Shadow AI, noting that 60% of organizations report unsanctioned AI agent automation. Gartner recommends integrating privilege elevation and delegation management into cybersecurity strategies to remove end-user local admin access and control application execution. Securden delivers its PEDM capabilities as a core module of its Unified PAM platform and through a standalone Endpoint Privilege Manager, helping organizations eliminate standing local administrator rights while enabling secure task execution.
Source Logistics warns supply chain industry about rising data-wiping cyberattacks
Source Logistics is warning the supply chain industry about a growing threat of data-wiping cyberattacks that destroy systems and backups rather than demand ransom. The alert follows a March 2026 breach at medical technology company Stryker, where attackers used Microsoft Intune to remotely wipe an estimated 80,000 devices over roughly three hours after gaining Global Administrator-level access. Security researchers at Outpost24 identified 278 compromised credentials tied to the stryker.com domain between October 2025 and March 2026, including 83 in the weeks before the attack, highlighting how stolen credentials enable such destructive intrusions. Source Logistics' defense strategy focuses on phishing-awareness training and limiting administrative privileges, since data-wiping attacks typically require elevated access. The company also undergoes annual third-party cybersecurity audits and is working toward a NIST-aligned security framework, leveraging its SaaS-first, API-first technology platform to adapt security posture more quickly than legacy systems.
SYK · Technology · Negative Stryker suffered a March 2026 breach where attackers wiped 80,000 devices via Microsoft Intune, with 278 compromised credentials found.
Source Logistics · Demand · Positive Source Logistics warns about rising data-wiping attacks and promotes its cybersecurity services, positioning itself as a solution provider.
Outpost24 · Technology · Neutral Outpost24 identified compromised credentials related to the Stryker breach, but the article does not indicate impact on Outpost24 itself.
CrowdStrike Named 2026 Global Company of the Year in Identity Threat Detection and Response by Frost & Sullivan
CrowdStrike has been named the 2026 Global Company of the Year in Identity Threat Detection and Response by Frost & Sullivan. The recognition highlights CrowdStrike's Falcon Next-Gen Identity Security platform, which surpassed $520 million in ending annual recurring revenue and grew more than 34% year-over-year. Frost & Sullivan cited the platform's ability to eliminate standing privileges and enforce real-time, risk-based access for human, non-human, and AI agent identities. The firm also noted CrowdStrike's unified, cloud-native approach that treats identity as a first-class security signal alongside endpoints, cloud, and data.
Cybersecurity & Digital Trust › Workforce & Customer IAM (SSO/MFA) Competition
Cybersecurity & Digital Trust › Privileged Access Management (PAM) Competition
CRWD · Technology · Positive Named Global Company of the Year for its identity threat detection platform, highlighting strong technology and market leadership.
Palo Alto Networks added 110 new platformized customers in the third quarter of fiscal 2026, bringing the total to approximately 2,280 as it pursues a strategy of unifying network, cloud, and endpoint security products. Platformized customers exhibit a 120% net retention rate and single-digit churn, with notable deals including an $80 million next-generation firewall and SASE contract with a large U.S. power producer and a more than $20 million Prisma AIRS deal with a global consulting firm. The company is expanding its platform through acquisitions such as CyberArk for identity security and Chronosphere for observability, and has already launched around 1,000 cross-selling engagements related to CyberArk. Palo Alto Networks aims to surpass 4,000 platformized customers and reach $20 billion in Next-Generation Security annual recurring revenues by fiscal 2030, while Zacks consensus estimates project fiscal 2026 and 2027 revenue growth of approximately 23.7% and 20.2%, respectively.