While regulators debate the long-term risks of artificial intelligence, the threats are already materializing. Researchers used Anthropic’s Claude technology to break into OpenAI’s ChatGPT systems, the latest in a string of AI-aided breaches that underscore the immediate dangers facing organizations worldwide.
The effort, part of a bug-hunting program, was aided in large part by fast-developing AI technology, The Wall Street Journal reported. Axios cited business executives and former government officials voicing growing alarm over AI-powered cyberattacks, while The Washington Post flagged the Pentagon’s “antiquated computer networks” as a national-security risk. As a new research paper put it, recent breaches have stemmed not from a developing superintelligence—as some leading AI figures warn—but from plain-old network vulnerability.
Cybersecurity is no longer optional for businesses, and AI is making the stakes—and the investment opportunity—considerably larger. Global security spending is expected to reach roughly $308 billion in 2026, according to International Data Corp., as companies pour money into AI-driven security platforms to combat increasingly sophisticated threats.
The shift is already visible in the data. Verizon’s 2026 Data Breach Investigations Report found that exploitation of software vulnerabilities has overtaken stolen credentials as the leading way attackers gain access to organizations. With cloud computing growing into an industry worth hundreds of billions of dollars annually, sales of cloud-native security software have skyrocketed—leaving today’s cybersecurity landscape unrecognizable from a decade ago.
Legacy leaders, cloud pivot. Palo Alto Networks (PANW), which hails from the pre-cloud firewall era, is now the largest pure-play cybersecurity company by both revenue and market capitalization—roughly $307 billion, with a 65.48% gross margin. Its legacy business still commands strong demand, but the real growth is in the cloud: a highly profitable platform has helped it acquire more than a dozen smaller cloud-native firms in recent years. Management projects double-digit percentage revenue growth for its next-generation security portfolio, and the stock has been one of the sector’s best performers from 2023 to 2026, trading at a discount to younger, high-flying cloud-native rivals.
Fortinet (FTNT), another legacy provider, has taken a different path—investing in organic cloud security development rather than an acquisition spree. It has maintained double-digit growth and high profitability, and its best-in-class firewall hardware continues to generate revenue as organizations build out data centers and 5G networks. It is also building a software-based internet security product with European telecom giant Telefónica.
Cloud-native endpoint security. CrowdStrike (CRWD) provides cloud-based endpoint protection for laptops, phones, and internet-connected devices—well suited to a remote-work world. Its software uses machine learning to detect breaches and hunt threats, and the company has steadily expanded its platform modules while maintaining strong free cash flow.
SentinelOne (S), a direct CrowdStrike rival, raised $1.2 billion in its June 2021 IPO—at the time the largest-ever cybersecurity IPO. Its cloud-based endpoint platform automatically detects and resolves threats, and the company is making steady progress toward profitability.
Identity and zero trust. Zscaler (ZS) started with a software-as-a-service platform designed for network protection in the cloud era and has since added internet security and end-user monitoring products. With global cloud spending expected to grow by $1–2 trillion annually this decade, Zscaler is positioned to ride a massive secular trend.
Okta (OKTA), a pioneer in identity and access management, has reimagined security through a zero-trust architecture that requires constant user verification. A January 2022 cyberattack affecting two of its largest customers accelerated a stock decline during the inflation-driven bear market, but as of August 2026, shares have begun a slow but steady climb back into triple digits.
Monitoring and infrastructure. Datadog (DDOG) is a cloud-native observability platform that uses AI to automate monitoring of large, complex cloud data sets, and it has been steadily adding cloud security and data monitoring modules. Akamai (AKAM), the content delivery network leader, ensures data reaches its destination securely and acquired several smaller security specialists from 2022 to 2024 to bolster ransomware protection and edge-computing capabilities.
For those who prefer a diversified approach, five cybersecurity ETFs stand out in 2026:
With “AI attacking AI” moving from concept to reality, cybersecurity has ceased to be a side note in the technology sector. Software vulnerabilities replacing stolen credentials, AI lowering the barrier to entry for attackers, and the Pentagon’s aging networks serving as a warning—all point to the same conclusion: this is a structural, multi-year theme driven by real-world threats. Whether investors back individual winners like Palo Alto Networks and CrowdStrike or gain exposure through an ETF, they are looking at a market being repriced by the AI era.