Investing in US stocks is no longer optional — it has become essential. But knowing what to watch and how to invest remains a challenge. Accurate information and timely analysis are both the starting point and the destination for US stock investors. We will navigate that journey together. Find answers to your questions and concerns in this column on overseas stock investing for Korean retail investors.
"Too dangerous to release."
That was the conclusion US AI company Anthropic reached last April about its latest AI model.
The model, called Mythos, was developed as a general-purpose AI, but Anthropic determined it was so powerful it could not be safely controlled and chose not to release it to the public. Instead, the company built a restricted-access framework called Project Glasswing, involving 12 major corporations — including Amazon, Microsoft and Apple — and 40 institutions.
Mythos uncovered a flaw in OpenBSD that had gone undetected for 27 years and broke through the "sandbox" barriers designed to contain AI behavior. In effect, AI had evolved into a "hacker" capable of independently identifying attack vectors and carrying out actual intrusions.
The so-called Mythos shock has thrown cybersecurity into sharp relief, and related stocks have been on a sharp upward run ever since.
According to Investing.com on Wednesday, shares of US cybersecurity firm Palo Alto Networks have surged 108 percent since the start of the year, with a six-month return reaching 148 percent.
CrowdStrike has also climbed 88 percent year to date. Both stocks closed at all-time highs on Thursday — Palo Alto Networks at $396 and CrowdStrike at $225.53.
Cybersecurity emerges as essential AI-era infrastructure
Memory chips and power have long been cited as the core infrastructure of the AI era, but analysts at home and abroad now broadly expect cybersecurity to join them as a foundational pillar of the AI ecosystem.
In practice, another incident emerged before the Mythos shock had even faded. Last month, OpenAI's latest model, GPT-Sol 5.6, broke out of its sandbox environment and accessed the internet during a test of its cyberattack capabilities. It went on to steal login credentials from the open-source AI platform Hugging Face and hack into its servers.
The smarter AI becomes, the faster and more sophisticated AI-enabled cyberattacks grow. AI can analyze code directly, identify vulnerabilities and dramatically cut the time needed to mount an attack — while rapidly comparing and executing multiple attack strategies. Hacking itself can be automated. Once attackers begin wielding AI as a weapon, defenders have no choice but to respond in kind, making an AI-driven arms race between offense and defense all but inevitable.
US financial services firm Morningstar described the OpenAI hacking incident as evidence that "the offensive cyber capabilities of frontier AI models continue to expand," adding that "AI is fueling an arms race around cyber capabilities."
That arms race is translating into higher corporate security spending. Kim Jae-im, a researcher at Hana Securities, said that since the Mythos shock, "security has been reclassified as essential infrastructure for AI adoption, and the share of corporate security spending is set to rise faster than expected."
Dan Ives, head of global technology research at Wedbush Securities and a closely followed Wall Street analyst, named cybersecurity as a long-term winner of the AI era. He said cybersecurity "will become a non-discretionary, must-have component of the AI technology stack" and projected that cybersecurity spending will double within the next three years.
The outlook grows even more pressing as the age of AI agents takes hold. Because agentic AI accesses systems and data and performs tasks autonomously — without human instruction — a security breach could cause enormous damage.
Kim Jin-gu, a researcher at Kiwoom Securities, said that "for the AI agent era to arrive, robust security capabilities must be in place first," adding that investors should "maintain sustained attention on cybersecurity software-as-a-service providers."
AI-integrated security platform play draws rising Wall St. targets
Palo Alto Networks is the leading US cybersecurity company and is widely regarded as the bellwether of the global cybersecurity sector. Its market capitalization stood at $304.9 billion as of Tuesday.
Founded in 2005, Palo Alto entered the market with a single product — the next-generation firewall. It has since pivoted from a hardware-sales model to one centered on software-as-a-service and cloud subscriptions, transforming itself into an AI-based integrated security platform company.
The defining element of Palo Alto's growth strategy is platformization. Enterprises have traditionally managed dozens of separate security solutions across endpoints, networks and cloud environments. Palo Alto has chosen to bundle everything — from network and cloud security to an AI-powered security operations center — into a single platform.
Aggressive mergers and acquisitions are equally central to the company's success story. Since its founding, Palo Alto has acquired more than 24 companies, snapping up firms with proven technology each time a new security capability emerges.
Its acquisition of CyberArk last February followed the same playbook. The deal was valued at $25 billion. CyberArk is a cybersecurity firm with strengths in privileged access management and identity security. Through the acquisition, Palo Alto gained the ability to protect not only human identities but also machines and AI agents under a unified security framework.
Third-quarter earnings swung to a loss, though the company's growth trajectory remained intact. Palo Alto posted a net loss of $0.22 per share in the fiscal third quarter, reversing from a net profit of $0.37 per share in the same period last year.
Revenue and the forward outlook both beat market expectations. Third-quarter sales rose 31 percent year-on-year to $3 billion, topping the consensus estimate of $2.94 billion.
The company guided fourth-quarter revenue to between $3.35 billion and $3.36 billion, above the market estimate of $3.28 billion. It also raised its full-year revenue guidance to between $11.42 billion and $11.43 billion, surpassing the consensus forecast of $11.29 billion.
Palo Alto also raised its growth forecast for the broader security industry from 5–8 percent to 10–12 percent. Kim Jae-im said that "as AI-related demand spreads beyond hyperscalers to new customer segments such as sovereign infrastructure operators, an additional growth axis is forming that is distinct from the traditional security hardware market."
With earnings growth expectations building, Wall Street has been steadily lifting its price targets for Palo Alto. Wells Fargo on Monday raised its target from $420 to $475, while Morgan Stanley also lifted its target from $320 to $387.
Kim Jin-gu said the company "is evolving into a security platform solutions provider capable of covering the full spectrum of security processes," adding that "its strengthening capabilities in AI agent defense will set it apart from competitors."
moon@heraldcorp.com