What is happening with cybersecurity companies - a comprehensive and in-depth post!
Three times in just three months, the AI company Anthropic managed to shake the cybersecurity market and cause a sharp decline in the value of leading stocks.
Each time the event occurred around the launch of a different product, but investors' reaction remained identical and consistent.
The storm began on February 22 with the launch of Claude Code Security, which sent stocks to significant declines:
CrowdStrike $CRWD fell by 8% Cloudflare $NET fell by 9% Okta $OKTA fell by 9% Zscaler $ZS fell by 10%
The second wave arrived on March 27, when details about Claude Mythos were 'accidentally' leaked in a company blog post.
In this case,
$CRWD stock fell by 7%. $PANW stock lost 6%. and $ZS weakened by 4.5%.
But the peak was recorded on April 7 with the official announcement of Project Glasswing...
This time the declines were particularly dramatic: Cloudflare plunged by 25% Zscaler lost 23% CrowdStrike fell by 17% Palo Alto weakened by 15%
The reason for the selling pressure stems from a deep perceptual shift in the market -
Investors are starting to wonder about the true value of companies like CrowdStrike or Palo Alto if an advanced AI model can scan, identify, and fix software vulnerabilities much faster and cheaper than a human security team...
The main question is whether the traditional business models of cybersecurity giants can keep pace with new AI tools that render a large part of current manual operations obsolete.
The big question is - is this a false panic?
Let's hear what J.P. Morgan has to say about this - and then, of course, some interesting companies to watch!
First of all - what is special about Anthropic's new model?
It is so powerful and aggressive that Anthropic is not opening it to the general public.
It achieved a success rate of 83.1% in identifying and restoring complex security vulnerabilities - compared to only 66.6% in previous models.
Here are a few more incredible examples of this tool's capabilities -
The model's amazing capabilities were demonstrated in identifying 'ancient' security vulnerabilities that survived decades under the radar...
It identified a 27-year-old vulnerability in the OpenBSD system and a 17-year-old vulnerability in FreeBSD that allows 'Root' access (full administrator access) without authentication.
Additionally, it managed to find a vulnerability in the FFmpeg video software that had survived 5 million previous automated tests.
One of the fascinating data points in the report is that the model independently developed 'Proofs of Concept' (PoC)
Meaning it not only found the hole in the wall - but also showed exactly how to pass through it without any human assistance.
Engineers without formal security training simply left the model to work overnight - and in the morning they already had a working and fully executed exploit.
And despite everything - according to Goldman Sachs, the software sector is not only not expected to be harmed by this, but quite the opposite...
The Goldman Sachs report quotes a senior executive at CrowdStrike:
The gap between the moment a vulnerability is discovered and the moment attackers exploit it has almost disappeared and has turned from months into mere minutes -
This reality requires organizations to use artificial intelligence to combat AI threats, which significantly increases demand for advanced security software. In other words - does this model prove that demand for cybersecurity is entering a new growth cycle?
The report notes another equally interesting point:
The issue of 'Shadow AI' -
This is a situation where employees in an organization use AI applications without the knowledge or approval of the IT department...
CrowdStrike identified over 1,800 such applications in its customers' environments - with more than 50% of AI usage in organizations occurring through private and hidden means.
This situation pushes security managers (CISOs) to allocate new budgets for protecting these projects - which allows security companies to grow beyond traditional IT budgets.
And here - it is appropriate to ask another question:
Do you really think Anthropic will become the next global cybersecurity giant?
Or does its tool simply prove that cybersecurity companies are becoming AI powerhouses?
We promised some interesting tickers to watch at the end -
1. Cloudflare $NET, which monitors internet activity (you have surely encountered their check that you are not bots more than once) - identity verification is expected to grow significantly as AI agent activity gains momentum online...
2. Datadog - $DDOG - When AI agents operate, they generate a lot of 'logs' and metrics - Datadog provides the tools to monitor and analyze all this information in real time.
3. Rubrik $RBRK - which is behind sophisticated backup systems for AI agents - and is now trying to enter the identity verification field as well.
And a bonus! -
We found that last week a senior executive at Rubrik purchased $500,000 worth of shares - an unusual purchase...
We are monitoring