Palo Alto Networks acquires Koi Security for $400M to advance agentic endpoint security

2 Sources

Share

Palo Alto Networks has acquired Koi Security, a file security startup, for a reported $400 million to bolster its AI security capabilities. The Tel Aviv-based startup, which raised $48 million from Battery Ventures, specializes in protecting enterprises from risky file downloads and securing AI agent usage on endpoint devices. The acquisition strengthens Palo Alto Networks' Prisma AIRS and Cortex XDR platforms.

Palo Alto Networks Expands AI Security Portfolio with Koi Acquisition

Palo Alto Networks announced the acquisition of Koi Security, a Tel Aviv-based file security startup that prevents employees from downloading risky software assets

1

. While the companies did not disclose financial terms, Calcalist reported the transaction is valued at $400 million

1

. Koi Security had previously raised $48 million from Battery Ventures and other investors before the deal

1

.

Source: CRN

Source: CRN

The acquisition comes just one week after Palo Alto Networks completed its $25 billion purchase of CyberArk and follows its $3.35 billion acquisition of observability provider Chronosphere in late January

2

. These deals signal an aggressive expansion strategy focused on protecting AI workloads and securing AI agent usage across enterprise environments.

Introducing Agentic Endpoint Security as a New Category

Koi Security's technology forms the foundation for what Palo Alto Networks calls a new cybersecurity platform category: agentic endpoint security

2

. Founded in 2024 by the team previously behind SaaS security company Canonic, which Zscaler acquired in 2023, Koi addresses a critical gap in enterprise security

2

.

The platform focuses on files beyond traditional binary executables, including scripts, code editor plug-ins, browser extensions, and AI training datasets that developers frequently download from third-party websites

1

. When users navigate to websites hosting such files, Koi replaces standard download buttons with "request approval" buttons, forcing a security review before any file reaches endpoint devices

1

.

How Koi's Threat Detection Engine Works

Koi's cybersecurity platform evaluates multiple factors before approving downloads. It checks whether file developers are associated with malicious activity, analyzes the file's code, and studies how files behave when opened by users

1

. The platform monitors network traffic generated by files and tracks changes they make to host machines, creating a comprehensive view of potential attack vector points

1

.

Source: SiliconANGLE

Source: SiliconANGLE

For open-source components that receive regular updates, Koi includes a tool that detects when updates roll out and delays installation, giving administrators time to search for risks before deployment

1

. After download, the built-in threat detection engine continuously monitors files, displaying risky items in a dashboard with remediation features

1

. Administrators can remove files, isolate them from corporate networks, or roll back problematic updates to previous versions

1

.

Integration Plans for Prisma AIRS and Cortex XDR

Palo Alto Networks plans to integrate Koi's capabilities into Prisma AIRS, its AI security platform, and Cortex XDR, its endpoint security product

1

2

. Cortex XDR protects cloud instances, employee devices, and other technology assets, while Prisma AIRS focuses specifically on protecting AI workloads

1

.

The integration will deliver greater visibility across AI attack surfaces and enhance prevention of malware while improving adherence to security policies

2

. In October 2025, Palo Alto Networks launched Prisma AIRS 2.0, which included full integration of capabilities from its acquisition of Protect AI, enabling in-line defense against prompt injection, malicious agents, and tool misuse in real time

2

. The addition of Koi's technology will further strengthen these capabilities as enterprises increasingly deploy AI agents that interact with external files and datasets, creating new security challenges that traditional endpoint protection struggles to address.

Today's Top Stories

TheOutpost.ai

Your Daily Dose of Curated AI News

Don’t drown in AI news. We cut through the noise - filtering, ranking and summarizing the most important AI news, breakthroughs and research daily. Spend less time searching for the latest in AI and get straight to action.

© 2026 Triveous Technologies Private Limited
Instagram logo
LinkedIn logo