Original Coverage & Source Attribution: investorplace.com
As autonomous software gains access to sensitive systems, identity and runtime security are becoming much harder to ignore
Listen to the audio version of this article (generated by AI).
Editor’s Note: A piece of code smaller than a text message once knocked out ATMs and airline flights in 10 minutes. That’s where my friend Jonathan Rose starts today – and he ends with two cybersecurity stocks he thinks you should consider now.
Today’s issue showcases the thing I appreciate most about how he works. Instead of stopping at “here’s a great company,” he tells you exactly what he needs to see before risking a dollar on it. That discipline comes from nearly three decades on America’s busiest trading floors, including years as a market maker. And it shows in the results – since launching in 2024, his Advanced Notice recommendations have averaged an 81% gain, winners and losers included.
Now Jonathan is issuing a challenge – he calls it the $10K to $100K Challenge – and next Wednesday, Oct. 14, at 8 p.m. Eastern, he’s laying out the approach behind it: how he spots unusual trading activity, how he structures trades you can enter for less than $500, and how he decides what he’s willing to lose before he ever thinks about what he might make – for free. Reserve your spot here.
Now, here’s Jonathan.
Just after midnight on January 25, 2003, a tiny piece of code began racing across the internet.
It was a computer worm – dubbed the SQL Slammer – that could copy itself from one vulnerable machine to the next without anyone clicking a link.
Slammer was only 376 bytes long. It simply told each infected server to send out more copies of itself, as fast as it could.
That was enough.
The number of infected machines doubled about every 8.5 seconds. Within 10 minutes, Slammer had reached more than 90% of the computers vulnerable to it. The flood of traffic knocked networks offline, interfered with ATMs, and disrupted airline flights.
Microsoft Corp. (MSFT) had released a fix for the weakness Slammer exploited months earlier, but plenty of organizations still hadn’t installed it.
AI Agents Create a Different Version of the Same Problem
We’re at a similar moment with AI agents – software that can search for information, use tools, and carry out tasks with little human guidance. Companies putting agents to work have to control what those agents can access and catch them when they do something nobody intended.
Recent incidents have shown why. OpenAI says its reviews have found agents from their lab bypassing access controls, using exposed credentials, and interacting with third-party systems beyond their intended access. It has notified dozens of affected hacked parties – including the Australian and U.S. governments – while the reviews continue.
That creates a new job for cybersecurity companies. And I see two stocks investors should consider buying now.
Let me show you what each company sells – and what I’m watching before making a trade.
AI Agent Security Is Creating a New Cybersecurity Market
Think of an employee’s credentials as a set of keys. An AI agent working for that employee may need access to certain files and applications. Give it too many keys, and an error – or an attacker manipulating the agent – can carry it somewhere it shouldn’t go.
That makes identity security unusually important.
Palo Alto Networks: Securing the Agent’s Identity
This is where Palo Alto Networks Inc. (PANW) has made a significant move. It completed its acquisition of CyberArk in February, adding that company’s identity-security products to a business that already sells network, cloud, and security-operations tools.
In plain English, Palo Alto is trying to give large customers a single place to manage more of their defenses, including the permissions granted to AI agents. The integration is still underway, so investors need to watch how well it delivers on that plan.
In its latest reported quarter, Palo Alto’s revenue rose 34% from a year earlier, to $3.41 billion. Its next-generation security annual recurring revenue – the value of subscriptions it expects to collect over a year – reached $9.1 billion. Those figures include the effects of acquisitions, so I’m watching what growth looks like as the businesses are brought together.
PANW is my first buy of the two. It gives me a large, established cybersecurity business with a clear path to sell more to customers as they add AI agents.
CrowdStrike: Watching AI Agents Where They Work
CrowdStrike Holdings Inc. (CRWD) comes at the AI agent problem from another direction.
Its Falcon software already operates across customers’ computers and other devices – the places where a great deal of AI-agent activity starts. This month, CrowdStrike introduced Falcon Guardian, designed to help companies discover which agents are running, see what they do, control which ones have permission to run, and respond when their behavior becomes dangerous.
It’s a new product, so I would watch customer adoption before assuming it will become a major revenue source.
CrowdStrike ended its latest reported quarter with $5.84 billion in annual recurring revenue, up 25% from a year earlier.
I would buy CRWD, too, but I’d start with a smaller position. Investors already recognize how strong this company is. That can leave less room for disappointment if a new product takes longer to catch on or growth slows.
And spending on security is still growing. Gartner forecasts worldwide information-security spending of about $244 billion in 2026, with demand for products that both use AI to improve defenses and secure companies’ own AI use.
A Good Cybersecurity Stock Can Still Be a Bad Trade
I look for a good business first. Then I look at the market.
One signal I follow is unusual trading activity: a burst of trading that stands out from a stock’s normal pattern. It can tell me that someone is making a large bet.
For example, in August, we spotted a spike in trading activity in oil-services company SLB NV (SLB). I recommended a bullish trade. Over the following week, SLB shares rose about 9%. Our recommended trade gained 219%.
We saw another example in MP Materials Corp. (MP). Our recommended trade returned 534% in three days. For both examples, the maximum possible loss was the amount paid for each contract.
Those were standout winners. These trades can also expire worthless, which is why choosing the trade and controlling its size matter as much as finding the company.
So if I see that activity in a stock, I check the news, the stock’s price, and the amount I could lose. Some days I’m looking at cybersecurity. Other days, it’s energy, healthcare, or a company I hadn’t expected to discuss when the market opened.
That signal – and the risk rules wrapped around it – is exactly what my free $10K to $100K Challenge is about.
On Wednesday, Oct. 14, at 8 p.m. Eastern, I’ll walk through the strategy I believe could help traders turn $10,000 into $100,000 or more over the next year. If that number sounds aggressive, good – you should be skeptical of big claims. Come learn the process behind it and judge for yourself. Save your seat for the $10K to $100K Challenge right here.
The Bottom Line: AI Agents Give Cybersecurity Companies a New Market
All of this brings me back to 2003. SQL Slammer didn’t create the cybersecurity business. It made the cost of leaving connected systems unprotected impossible to miss.
AI agents are extending that same problem to a new kind of worker. Companies need to know what their agents can reach, what they’re doing, and how to stop them if they start hacking.
I think Palo Alto and CrowdStrike have a real chance to collect a meaningful share of that spending.
Remember… the creative trader wins…




