Tired of ads? Enjoy an ad-free experience by signing up.
👩‍🍳 How we use AI at Tech in Asia, thoughtfully and responsibly.
🧔‍♂️ A friendly human may check it before it goes live. More news here

Palo Alto buys Israeli cybersecurity startup Koi in $400m deal

Palo Alto Networks has completed its acquisition of Koi in a deal estimated at about US$400 million.

The move expands its push into AI and software supply chain security.

Koi raised US$48 million, including a US$38 million series A round last September.

The company builds tools to monitor third-party software and protect enterprise endpoints.

After the acquisition, Koi’s technology will be added to its Prisma AIRS and Cortex XDR products.

The deal marks its 12th acquisition of an Israeli cybersecurity company since 2014.

🔗 Source: Calcalist

🧠 Food for thought

Implications, context, and why it matters.

A fake extension helped illustrate a roughly US$400 million opportunity

  • Koi’s founders tested demand by publishing a fake Visual Studio Code, or VS Code, extension called “Darcula Official.” It quietly sent developers’ source code and machine details to an external server 1.
  • Within a week, it reached more than 300 organizations. Targets included one of the world’s largest Endpoint Detection and Response (EDR) vendors and a national court network, and it landed on the VS Code Marketplace front page 2.
  • The test argued that many security products focus on executables and operating systems. They often miss risks from non-executable software such as developer packages and integrated development environment (IDE) extensions 3. It also covers containers, Model Context Protocol (MCP) servers that connect AI models to external tools and data, and AI models 3.
  • These components outnumber executable files by orders of magnitude. Many stay unmanaged and hard for corporate security teams to spot 3.

The endpoint security battleground shifts toward governance of agentic tools

  • Palo Alto Networks is tying the acquisition to a category it calls “Agentic Endpoint Security” (AES). The pitch centers on protecting AI agents and the systems they can access 4.
  • The approach assumes agentic AI tools may run with access to sensitive data and critical systems. Palo Alto Networks described that risk as the “ultimate insider threat” 4.
  • The focus moves beyond catching malicious behavior on devices while software runs. It also pushes governance upstream to the software supply chain that feeds endpoints, including AI agents and plugins 2.
  • Palo Alto Networks plans to keep Koi as a standalone product. The company says it can work alongside existing EDR tools, including non-Palo Alto options 4.

Recent Palo Alto Networks developments

Stay ahead in Asia’s tech landscape

You've reached your 2 free content limit for the month. Sign up for free to read the full story.

🏄 For casual readers / 👶 Free

Basic

US$0

Free forever

Get instant access to this article and more every month

0 premium content

Unlimited news briefs

5

5 articles

Ad-free reading experience

Just US$0 per day

⌛Sign up in 20s. No payment details needed.

📖 For learners / 👍 Starter

Lite

US$4.92/month

Billed annually at US$59/year

Get instant access to this article and more every month

4

4 premium content

Unlimited news briefs & articles

Ad-free reading experience

Just US$0.17 per day

Cancel anytime

Our subscriber community includes professionals from these companies:

Stay updated on the go with our mobile app.

Get latest insights with smoother, more personalized experience through TIA mobile app.