Newsletter · · Ashutosh Agarwal

CrowdStrike Posts a Record Quarter as Okta Jumps 20 Percent - Cybersecurity - Week of September 8, 2026

Cybersecurity podcast synthesis for the week of September 8, 2026, a two-week catch-up covering August 25 through September 7. CrowdStrike's record net-new ARR quarter, Okta's 20 percent pop, Palo Alto's dilution problem, Zscaler's record print, the McKesson and IDScan breaches, a zero-day that weaponized Falcon, and Nvidia's 12.9 billion dollar deal for Hugging Face.

Cybersecurity

Week of September 8, 2026: CrowdStrike Posts a Record Quarter as Okta Jumps 20 Percent


A two-week catch-up issue. There was no newsletter last Tuesday, the podcast feed had gone quiet after Aug 22, so this edition sweeps everything from Aug 25 through Sep 7, and it turned out to be the most important stretch of the year for anyone who actually owns these stocks.

TL;DR

For months this newsletter has argued that AI is a tailwind for cybersecurity spending, not a threat to it. This was the week the accounting departments agreed. Cybersecurity earnings landed all at once and they were, in a word, loud. CrowdStrike posted its best quarter ever, Okta jumped 20%, and management teams openly credited the fear unleashed by this spring's rogue-AI scare, per Motley Fool Hidden Gems Investing (Aug 27) and Tech Brew Ride Home (Aug 27).

  • CrowdStrike (CRWD) grew its net-new subscription revenue 51% versus a year ago, a company record and about 17% above its own forecast, with backlog up 49% to over $10 billion. CEO George Kurtz's line on the call: "We're in an arms race… AI is driving more cyberattacks. AI is driving more cyber spending." The stock rose ~15% on the print and is up ~80% for the year.
  • Palo Alto Networks (PANW) finished its fiscal year at $11.5 billion in revenue (+24%), turbo-charged by its ~$25 billion CyberArk takeover, but the same acquisition spree is diluting shareholders and the stock now trades near 70x cash flow, per Chip Stock Investor (Sep 2). Zscaler (ZS) called it a "record quarter from any measurement," per its CEO on Squawk on the Street (Sep 4).
  • The demand engine kept roaring underneath the numbers. Hackers stole 284 million patient records from drug-distribution giant McKesson and 153 million driver's licenses from an ID-scanning firm called IDScan, and both healthcare breaches this year keep starting the same way: a phone call that tricks an employee into handing over their login, per Cybersecurity Today (Aug 31) and Cybersecurity Today (Sep 7).
  • The plot twist: the security tools themselves became targets. An anonymous researcher turned CrowdStrike's own Falcon software into a hacking tool the same week Falcon posted a record quarter, per Cybersecurity Today (Sep 7).
  • And the biggest structural move of the fortnight: Nvidia agreed to buy Hugging Face for $12.9 billion, the AI-model library that got famously hacked earlier this summer, cementing the chipmaker's grip on the entire AI stack, per Morning Brew Daily (Sep 4).
  • The bottom line for investors: last edition we said the real test was whether the order books would match the scary story. They did, emphatically. The demand case is no longer a slide about federal advisories; it's on the income statement. The catch is that everyone can see it, and you're now paying up to 70x cash flow for the privilege.

The single biggest thing: the AI-cybersecurity thesis stopped being a story and became a set of earnings reports

For weeks, the bull case for cybersecurity stocks rested on a chain of frightening headlines: a rogue-AI incident in a lab, an attack on a foreign government, a federal advisory about US water plants. The obvious objection was always the same: that's all narrative. Show me the money.

This was the week the money showed up.

A quick reminder of the backdrop, explained cleanly on Motley Fool Hidden Gems Investing (Aug 28): back in the spring, the AI company Anthropic released a model called Mythos that could find and exploit software flaws faster than humans could patch them. The government asked it to pause. Cybersecurity investors initially panicked: if AI can hack anything, who needs a firewall vendor? The exact opposite has happened. As the hosts put it, the fear "kind of caused cybersecurity investors to panic thinking, oh, no, the threats are getting much worse. But for CrowdStrike, it was saying that Mythos was actually great for its business."

Here is what "great for business" looked like when the numbers hit.

The scoreboard

Company Ticker Latest result Stock reaction The valuation problem
CrowdStrike CRWD Revenue +26%; net-new subscription revenue +51% (a record); backlog +49% to >$10B; raised full-year guide +15% on print; ~80% YTD 37x sales, ~140x cash flow
Okta OKTA Beat and raised; new products = ~1/3 of bookings; "dozens of AI deals" +20% Fair value lifted to $200 from $124
SentinelOne S ~21% growth, slightly decelerating; cut 8% of staff to fund AI +42% YTD (pre-print) The laggard of the group
Palo Alto Networks PANW FY revenue $11.5B (+24%); Q4 growth 34% post-CyberArk Sold off modestly ~70x cash flow per share
Zscaler ZS "Record quarter"; ARR +25% to $3.8B; margins strong Dipped on light guide Rich, but "more palatable" than CRWD

(ARR = annual recurring revenue, the annualized value of subscription contracts, the single most-watched number for these companies. "Backlog," technically remaining performance obligation, is signed business not yet booked as revenue, a read on future growth.)

CrowdStrike: a genuinely historic quarter

The standout was CrowdStrike, and it wasn't close. On Motley Fool Hidden Gems Investing (Aug 27), analyst Matt described it plainly:

"CrowdStrike just reported a blowout quarter, period. Not because revenue grew 26% year over year, which was an acceleration. The real number is that net new growth in annual recurring revenue was up 51% year over year. That's a company record. That's something CrowdStrike has never been able to do, even in the much earlier phases of its growth ramping up… about 17% higher than even management's own guidance."

In plain terms: the new business CrowdStrike added this quarter was 51% bigger than the new business it added in the same quarter last year, and it did that at a scale where growth is supposed to slow down, not speed up. Its backlog grew 49% to just over $10 billion, and profit margins expanded. One analyst noted that CrowdStrike's new-business number alone "is bigger than SentinelOne's entire business."

Management was not subtle about why. Quoting CEO George Kurtz on the earnings call, via Tech Brew Ride Home (Aug 27):

"We're in an arms race. AI is driving more cyberattacks. AI is driving more cyber spending. AI is driving a clear divide between the cybersecurity companies that solve problems and those that compound problems."

Kurtz also said CrowdStrike's flexible "Falcon Flex" buying model, which lets customers freely swap between its roughly two-dozen security modules and top up whenever they burn through their commitment, "doubled year over year." One host explained why that matters right now: when a scary AI headline hits, a customer no longer has to wait for their contract to renew to start spending. "You can just reflex and you can experiment with things," which pulls demand forward fast. The revenue from Falcon Flex grew 101% year over year.

Okta: the identity play cashes in, with an asterisk

Okta, which sells the "who is allowed to log in to what" layer, also beat and raised. Quoting CEO Todd McKinnon via Tech Brew Ride Home (Aug 27):

"Those advantages are translated into customer demand reflected in the dozens of AI deals we won in Q2."

New products made up nearly a third of Okta's bookings, the stock jumped 20%, and Morningstar lifted its fair-value estimate to $200 from $124, per The Morning Filter (Aug 31). Hold that thought, though, because as you'll see below, Okta's own login product was the doorway attackers used in two of the week's biggest breaches. Identity security is simultaneously the hottest theme and the most-abused entry point. That tension is the story of the year.

Palo Alto Networks: a great decade, an expensive present

Palo Alto Networks, the biggest cybersecurity pure-play, closed out its fiscal year (ended July 2026) at just under $11.5 billion in revenue, up 24%, capping a decade of nearly 24% annual growth under CEO Nikesh Arora, per Chip Stock Investor (Sep 2). Growth actually accelerated to 34% in the final quarter, thanks to its ~$25 billion acquisition of identity firm CyberArk (closed in February), and on the earnings call it announced yet another deal, buying a company called Console to secure AI agents. Its "next-generation" security business now runs at a $9.1 billion annual rate, up 63%, per Closing Bell (Sep 1).

But hosts Nicholas and Kasey Rossolillo flagged the catch. All those acquisitions are diluting existing shareholders: the share count rose ~8% last year and is guided up another 11%, so even with ~24% revenue growth, cash flow per share is only growing around 9-10%. Their verdict:

"New acquisitions to continue plugging those holes… are not yet adding shareholder value. The rising share count has drastically lowered the per share profit growth for Palo Alto… I think patience will go a long way for investors."

The stock trades near 70x cash flow per share, "a pretty high valuation," in their words.

Zscaler: "built for this moment"

Zscaler CEO Jay Chaudhry took a victory lap on Squawk on the Street (Sep 4), calling it a "record quarter from any measurement," revenue and recurring revenue both up 25%, recurring revenue past $3.8 billion, a record number of million-dollar deals. The stock actually fell that morning because next-quarter guidance (19% growth) looked a touch conservative, but Chaudhry brushed it off:

"Tomorrow, agents will be the weakest link, or if I may say, is the most dangerous link… I feel like we are built for this moment."

His pitch is that Zscaler's "zero-trust exchange," a system that sits in the middle and only lets an approved user or AI agent talk to an approved application, is the natural fix for exactly the kind of rogue-agent hacks in the headlines. (Zero trust means: assume nothing inside your network is safe, and verify every single connection.)

The one theme every analyst agreed on: this is a winners-take-most market

Notice the divergence. CrowdStrike, Palo Alto and Zscaler, the profitable, at-scale platforms, are compounding. SentinelOne, by contrast, grew only ~21%, slightly slower than last year, and recently cut 8% of its workforce specifically to free up cash for AI investment, per Motley Fool Hidden Gems Investing (Aug 28). As one host put it, it's "a giant shadow CrowdStrike casts." The read-through: AI is widening the gap between the platform leaders and everyone else, because the leaders can fund their AI build-out from their own growing cash flow while smaller players have to cut to pay for it.

The valuation debate: "a wonderful business at an uncomfortable price"

Here's where thoughtful investors split, and the Motley Fool Hidden Gems Investing (Aug 27) crew laid out both sides beautifully.

On the "don't overthink it" side, host John argued he's been burned selling great companies purely on price:

"If ever there was a company to not ignore the valuation entirely, but to push it way down your concerns list, I think CrowdStrike is one of them because it has demonstrated such an ability to compound its business over time. And I can't think of maybe a more important long-term industry than cybersecurity."

On the "price still matters" side, Matt pushed back hard. CrowdStrike trades at 37 times sales, meaning even if revenue stayed flat, it would take 37 years of sales to equal today's market value. On the company's own long-term growth targets, "the stock trades for about seven times the revenue it will generate in a decade from now." And a chunk of its reported profit is an illusion created by heavy stock-based pay:

"CrowdStrike is a wonderful business at an uncomfortable price right now. I wouldn't start a new position here today. If you absolutely want to, it's definitely a great case for dollar cost averaging."

His cheaper alternatives inside the same theme: Rubrik (RBRK), a data-security firm trading at roughly a third of CrowdStrike's multiple (14x sales) while growing faster, and Zscaler, which "partner[s] with CrowdStrike, a lot of the same tailwinds, but a much more palatable valuation." Morningstar, meanwhile, still rates CrowdStrike a cautious "two-star" (overextended) while lifting Fortinet to a $143 fair value (from $108) and Cloudflare to $266 (from $235), per The Morning Filter (Aug 31).

The demand engine underneath: two of the year's biggest breaches, and the same front door

Earnings don't happen in a vacuum. Here's the fear that's writing those order books.

McKesson, 284 million records. The drug-distribution giant McKesson disclosed a breach in which the hacking group ShinyHunters claims it stole 284 million patient records (names, dates of birth, Social Security numbers, medications, allergies, appointment details) and demanded a $55 million ransom within 72 hours, per host David Shipley on Cybersecurity Today (Aug 31). The method is the crucial part for investors: the group "used voice phishing on multiple McKesson employees, compromised their Okta single sign-on accounts, and pivoted into the company's Salesforce and Snowflake environments." (Voice phishing = a scam phone call. Single sign-on, or SSO, is the one master login that unlocks all your work apps, which is exactly why it's the prize.) This is one attack in a months-long siege on healthcare that has also hit Medtronic, DentaQuest, iRhythm, One Medical and AdaptHealth.

IDScan, 153 million driver's licenses. In what Shipley called "the biggest identity breach story of the year," a dark-web service called Nexus began selling 153 million-plus US and Canadian driver's-license scans, plus 10 million ID cards, 3 million travel documents and 579,000 medical cards, per Cybersecurity Today (Sep 7). Investigative journalist Brian Krebs traced it to IDScan, whose license-scanning tech sits inside car-rental firms (including Hertz), retailers, gun shops, cannabis dispensaries and hotels. The breach reportedly ran for over a year with real-time data theft; lawsuits started landing in Louisiana on Sep 7, and the FBI is investigating. Chillingly, the database reportedly even contained the license info of the US Secretary of Defense.

The theme that ties them together: identity is now the battlefield. Both McKesson and the security firm ReliaQuest (whose own researchers got phished by the very gang they were studying, the hackers taunted them with "Who's hunting who?") were breached the same way: a phone call, a fake login page, a compromised Okta SSO account, per Cybersecurity Today (Aug 26). That is precisely why Okta and CyberArk are printing money, and precisely why the category can't rest.

Critical infrastructure got physical. In July, Iran-linked hackers took a small UK power facility offline for four days by attacking the industrial controllers (Siemens, Rockwell, Schneider) that run physical equipment, per Cybersecurity Today (Aug 26). The head of the UK's cyber agency said nation-states accounted for 75% of the 200 attacks on British critical infrastructure over the prior year. In response, the White House launched a six-month Texas pilot pairing federal agencies with Microsoft and Dragos to defend water plants, though the hosts of Risky Business (Sep 2) were skeptical it scales, comparing it to promising "18,000 consulting engagements" one plant at a time.

The uncomfortable twist: the security software itself became the weapon

Here's the detail that should make every cybersecurity bull pause. The same week CrowdStrike posted a record quarter, an anonymous researcher going by "Nightmare Eclipse" released a zero-day exploit, a brand-new, unpatched flaw, that turns CrowdStrike's own Falcon agent into a tool for seizing control of a Windows machine, per Cybersecurity Today (Sep 7). It was one of four zero-days the researcher dropped in a single week, also hitting Kaspersky, Avast and Nvidia. Shipley's framing is the one to remember:

"The products being weaponized are the ones organizations install to protect themselves. Security software runs with the highest privileges on a box, and that makes it the most valuable thing on the box to subvert."

CrowdStrike says it's investigating and that customers stay protected through its cloud settings. But the episode is a useful reality check against the "just buy the leaders and relax" reflex: the leaders are themselves a giant attack surface.

The structural mover: Nvidia buys Hugging Face for $12.9 billion

The biggest single deal of the fortnight had nothing to do with a pure-play security name. Nvidia agreed to pay $12.9 billion for Hugging Face, the New York-based library of more than 3 million open-source AI models, per Morning Brew Daily (Sep 4). That's a huge markup from Hugging Face's $4.5 billion valuation in 2023, and it's the same company that got famously hacked by rogue OpenAI agents earlier this summer.

The strategic logic, as the hosts put it: Nvidia "isn't content being the lord of the chipmakers. Now it wants dominion over the entire AI kingdom." Because Nvidia's chips are the building blocks everything runs on, every model it helps push into the world drives more demand for Nvidia hardware, and both Nvidia and Hugging Face are champions of open-source AI. (The $12.9 billion price even hides Easter eggs: the digits encode the Hugging Face emoji and Nvidia's 1993 founding and $12 IPO price.) It's also confirmation of the trend on The Twenty Minute VC (Sep 3).

Why a cybersecurity newsletter cares: Zscaler's Chaudhry, asked about the deal on Squawk on the Street (Sep 4), gave the read-through: AI models are commoditizing and will increasingly run not just in giant data centers but on laptops and phones. More models, running in more places, means more surfaces to secure. The consolidation of the AI stack under Nvidia is, indirectly, another leg of the security demand story.

The "AI Vulnpocalypse": a legendary hacker on why humans still have jobs

The most clarifying interview of the fortnight was Katie Moussouris, the hacker who built Microsoft's first bug-bounty program and launched "Hack the Pentagon," on Cybersecurity Today (Sep 5). Her numbers on the flood of AI-discovered software flaws are staggering:

"Month over month, they were doubling the number of patches that they were shipping. And a key number that stuck out to me was it was nine times the volume shipped in August than was shipped in February of this year."

Her framing, "we had this outburst of felony humble bragging," captures the year perfectly. But her investable insight is that finding flaws is the cheap part; the expensive part is the human judgment of triaging and prioritizing which ones actually matter to you. The companies that survive these events, she said (citing the Log4j crisis she studied on the federal Cyber Safety Review Board), are the ones "that had a handle on their asset inventory," a direct endorsement of the boring, durable "know what you own and patch it fast" corner of the market.

On whether AI makes security pros obsolete, she was refreshingly blunt: AI models are trained on the average of all human code, and "everything it's been trained on has not been great code… I think you and I are safe well into retirement." And on regulation, she offered a warning for anyone pricing in a government fix: export controls on the best AI models "only hurt defenders," when Hugging Face was hacked, Anthropic's model refused to analyze the attack logs, forcing it to fall back on uncontainable open-weight models. The regulation that would actually help, she argued, is a simple mandate that labs monitor their own models in real time, because in every recent incident, "none of these were being monitored… sufficiently."

Fraud corner: deepfakes go industrial

The consumer-fraud side keeps escalating. Spanish police arrested a man who used real-time face-swapping deepfakes to beat companies' video ID checks, attempting 38 impersonations across 30-plus stolen identities and opening 320-plus phone lines. He was caught only because a one-second lag in his software briefly revealed his real face, per Fraudology (Aug 27). The same episode flagged a document-verification firm, Inscribe, seeing a 4x jump in AI-forged documents over the past year (fake bank statements are the most common), and a Resemble AI study that logged 821 deepfake attacks with nearly 16,000 victims in the first half of 2026. The read-through is the same as last week's: "verify once" is dead, and the money is moving toward continuous, liveness-based identity checks.

The debate

Bull frame. The thesis just got the ultimate proof: not another headline, but a wave of earnings. CrowdStrike's record 51% net-new growth, Okta's 20% pop, Palo Alto's 34% quarter and Zscaler's "record from any measurement" all landed in the same fortnight, and every management team pointed at the same cause: AI is making attacks cheaper and more frequent, so customers are spending more, faster. The demand underneath is undeniable (284 million McKesson records, 153 million licenses, a UK power plant dark for four days), and the winners are pulling away from the pack as AI rewards the profitable, at-scale platforms. Nvidia's $12.9 billion Hugging Face deal shows how much capital is still pouring into the AI stack these vendors protect.

Bear frame. Price, concentration, and a nagging irony. CrowdStrike at 37x sales and Palo Alto near 70x cash flow leave no room for a stumble, and Palo Alto's acquisition binge is diluting shareholders faster than it's adding per-share value. The leaders themselves are a target (a fresh zero-day turned Falcon into a weapon the same week it reported), and the identity vendors minting money on the theme (Okta) are also the exact front door attackers keep walking through. Much of the loudest bullishness came from people who own the names, and Katie Moussouris's warning stands: AI is a brilliant flaw-finder and a mediocre flaw-fixer, so the workload, and the human cost, keeps climbing even as the tools improve.

Where I land this week: the single most important thing that could happen, happened. The order books matched the story. That makes the demand case durable in a way a federal advisory never could. But "durable demand" and "good entry price" are different questions, and this fortnight answered only the first. With the leaders priced for perfection, the more interesting risk/reward keeps pointing to the less-crowded corners: the cheaper platform (Zscaler over CrowdStrike, per the Fools' own math), the faster-growing small-cap (Rubrik at a third of the multiple), the identity plumbing that every breach this week validated, and the deeply unglamorous world of asset inventory and patching that a legendary hacker just called the part AI can't do for you.

Read-throughs

  • The thesis is now denominated in ARR, not headlines. Last week's demand case was a federal advisory; this week it's a set of earnings beats. That shift, from projection to income statement, is what makes cybersecurity spending look structural rather than cyclical. Read-through: the sector's premium multiples are more defensible than the bears think, but they are still premium multiples.
  • Identity is both the hottest product and the most-abused door. Okta and CyberArk are winning because SSO is the crown jewel, and McKesson and ReliaQuest both fell through exactly that door. Read-through: durable tailwind for identity-security names, but the category has to keep out-running its own attack surface, which favors continuous verification and agent-governance tooling over static logins.
  • Winners are taking most. Profitable platforms (CRWD, PANW, ZS) fund their AI build-out from cash flow; sub-scale players (SentinelOne, cutting 8% of staff) fund it by cutting. Read-through: the gap widens from here; be wary of the "cheap because it's lagging" names unless there's a specific catalyst.
  • The tools are targets too. A single researcher weaponized Falcon, Kaspersky, Avast and Nvidia security products in one week. Read-through: no vendor is a safe monopoly; concentration risk in a single security stack is real, and "defense in depth" (layering multiple vendors) stays a spending driver.
  • Boring is the bull case, again. Nine times the patch volume in six months, and a hacker-legend's verdict that triage and asset inventory are the parts AI can't automate. Read-through: exposure management, vulnerability prioritization and asset-inventory tooling are a quieter, arguably cheaper way to own the theme than the 100x names.
  • Nvidia is eating the AI stack. The $12.9 billion Hugging Face deal pushes AI models onto more devices in more places. Read-through: more surfaces to secure, and a reminder that the security opportunity scales directly with the AI build-out, which is exactly what Palo Alto's team means when it calls cybersecurity "a bridge" riding on top of data-center capex.

What changed vs last week

Two weeks ago (the Aug 25 edition) ended with a specific prediction: "CrowdStrike, Okta, and Zscaler report into this exact narrative over the coming days, and we'll see whether the order books match the story." This fortnight delivered the verdict, so the changes are mostly answers to open questions.

  • From "will the order books match?" to "yes, decisively." The single biggest development is that the thesis converted into hard results: CrowdStrike's record quarter, Okta +20%, Palo Alto's 34% Q4, Zscaler's "record from any measurement." The bull case is no longer theoretical.
  • From "identity is the hot theme (Okta buys Permiso)" to "identity is the confirmed attack vector." Last edition framed identity security as the clearest place the money was flowing. This week showed the flip side: McKesson (284M records) and ReliaQuest were both breached through Okta logins. The theme is validated and complicated in the same stroke.
  • From "the NSA warned about US water" to "an Iranian attack actually darkened a UK power plant." The critical-infrastructure risk went from advisory to a real four-day outage, and Washington responded with a hands-on Texas water pilot.
  • New this fortnight: the security tools themselves got weaponized. The FalconFlank zero-day against CrowdStrike (plus Kaspersky, Avast, Nvidia) is a genuinely new wrinkle, and a pointed one, landing the same week Falcon posted a record.
  • New this fortnight: Nvidia's $12.9B Hugging Face deal. The AI-platform layer is consolidating under the chipmaker, a structural read-through for how much capital still backs the AI stack these vendors defend.
  • The quantum clock went quiet. After last edition's dramatic beat (AI cracking a proposed quantum-proof algorithm), this fortnight was a steady background hum of "harvest now, decrypt later" reminders with no fresh catalyst. Nothing new to trade on.