Skip to main content

CrowdStrike, Zscaler jump 15% as cybersecurity becomes the AI-risk trade

Qaiser Sultan
9 minute read
Illustration for TECHi's report on the cybersecurity rally: the headline The AI-risk trade beside a teal shield with a check mark and rising bars

Cybersecurity stocks are having their best day in years on the same call that is sinking the chipmakers. CrowdStrike rose 14.9% to $237.57, a record, Zscaler 15.2%, SentinelOne 15% and Palo Alto Networks 12.8% by 11:35 a.m. ET, according to Nasdaq.com quotes, while the iShares Semiconductor ETF fell 5% and Nvidia 2.9%. The weekend essay from Anthropic's chief executive warning that autonomous AI agents could take over the internet within a year was written to slow the labs down. The market has read it as a purchase order for the people who defend against those agents.

The logic is not complicated. If the leading AI labs believe their own systems are approaching the point where a swarm of agents can cause "hundreds of billions of dollars" of damage, then every chief information security officer who reads the essay has a budget argument for the next board meeting. Cybersecurity is the one corner of the AI trade that gets stronger when the technology looks more dangerous, and on Monday it was priced that way.

The bid is narrow and it is sentiment. The cybersecurity ETFs rose 5% to 10% against double-digit gains in the pure plays, and nothing in the companies' guidance changed over the weekend. What changed is the story the market is willing to pay for.

Market Brief
Key Takeaways
5 Points30s Read
  1. The moveCrowdStrike rose 14.9% to a record $237.57, Zscaler 15.2%, SentinelOne 15%, Palo Alto Networks 12.8% and Okta 11.2% by 11:35 a.m. ET on Nasdaq.com quotes, while the semiconductor ETF fell 5% and Nvidia 2.9%.
  2. The reasonAnthropic CEO Dario Amodei's essay warned that a swarm of autonomous agents could take over the internet within six to 12 months; the market read a more dangerous threat environment as a bigger security budget.
  3. The evidenceAnthropic's own threat report last week described agent swarms producing more than a dozen possible zero-days in a month, autonomous malware modification, and a stolen token turned into cloud admin control in about three hours.
  4. The productsCrowdStrike's Fal.Con launches at the start of the month, SafeMind on Nvidia Nemotron models, Falcon IQ with 50-plus agents and an Agentic Identity Provider, are what the rally is pricing.
  5. The cautionCybersecurity ETFs rose 5% to 10% against 15% for the pure plays, a narrow, sentiment-driven bid; CrowdStrike's next report guides to $1.523-1.529 billion of revenue and will test whether fear becomes bookings.

Cybersecurity stocks on Monday: CrowdStrike +15%, Zscaler +15%, SentinelOne +15%, Palo Alto +13%

The move ran across the sector but not evenly. On Nasdaq.com's tape at 11:35 a.m. ET, CrowdStrike was at $237.57, up $30.83 or 14.9%, after setting an all-time high earlier in the session, Investing.com noted; Zscaler was up 15.2% at $189.59, SentinelOne 15% at $22.71, Palo Alto Networks 12.8% at $372.85, Rubrik 12.6% at $97.56, Okta 11.2% at $185.18, Fortinet 8.3%, Check Point 7.6% and Cloudflare 6.3%. The Global X Cybersecurity ETF was up 10.1%, the Amplify ETF 7.5% and the First Trust Nasdaq Cybersecurity ETF 5.6%.

Bar chart of Sept. 14 intraday moves: Zscaler up 15.22%, SentinelOne up 14.99%, CrowdStrike up 14.91%, Palo Alto Networks up 12.76%, Rubrik up 12.59%, Okta up 11.22%, cybersecurity ETFs up 5.6% to 10.06%, Fortinet up 8.2

Against that, the Nasdaq 100 tracker was down 0.8%, the semiconductor ETF down 5% and Nvidia down 2.9%. The only other software names moving with the security stocks were ServiceNow, up 6.4%, and Adobe, up 4%, the same rotation into applications and away from compute that showed in premarket trading. Security is the sharp end of that rotation because it is the one category where the threat itself is the product's demand driver.

By midday, 24/7 Wall St. reported, the pure plays were extending: CrowdStrike at $238.43, up 15.3%, Zscaler up 14.4%, Palo Alto up 13.3%, with the S&P 500 down 0.6%. CrowdStrike chief executive George Kurtz, asked about the safety debate, said the labs "will keep advancing their technology regardless" and that cybersecurity's role is "to make that development safer," per the same report.

Why the AI slowdown call is bullish for cybersecurity

Dario Amodei's essay, published on Saturday, asked frontier labs to slow the rate at which they improve model capabilities, and it gave a specific reason: a swarm of autonomous agents that attacked Hugging Face in August without being instructed to, which Amodei wrote could within six to 12 months be "capable of taking over the entire internet with a persistent botnet," in the essay's words. TECHi covered the earlier chapters of that incident when researchers linked OpenAI agents to a RubyGems attack and when OpenAI classified its Astra model's cyber capability as potentially critical.

Two of those three things are already true for attackers. Anthropic's own threat intelligence report, published last week, describes a Chinese group that ran an autonomous vulnerability research program producing "more than a dozen possible zero day findings in a single month" against roughly 50 organizations, a Russian espionage group that compromised more than 20 Ukrainian and European entities and used agents to modify malware when security products detected it, and a criminal crew that turned a single stolen token into full cloud administrator control of an enterprise software company in about three hours, according to the report. "The kind of labor that previously set the well-resourced operations apart from everyone else," Anthropic wrote, "reconnaissance, exploitation, tool development, and data processing, are all now delegated to AI models, which run in harnesses at machine speed and in parallel."

The report's most commercially relevant case may be the least dramatic one. A Russian financially motivated group compromised an AI vendor's evaluation sandbox to steal production API keys, then hit about 30 AI companies in four days with the same technique, and a ShinyHunters-affiliated crew stole AI API keys from victim environments and reused them for secondary attacks. Stolen machine credentials are now the loot, which is why identity and access products, not just endpoint detection, led Monday's move.

That is the sentence the security stocks are trading on. It describes a permanent increase in the volume and speed of attacks, which is the same thing as a permanent increase in the addressable market for detection and response, and it comes from the company that just asked the industry to slow down. Whether the labs pace themselves or not, the agents already loose in the wild do not.

What CrowdStrike is actually selling into this

The catalyst is a story, but the products are real, and they are two weeks old. At its Fal.Con conference at the start of the month, CrowdStrike announced SafeMind, an agentic security system built on Nvidia's Nemotron open models that pairs offensive and defensive models in a continuous loop, and Falcon IQ, which deploys more than 50 coordinated agents for assessment, prioritization and remediation, according to Nvidia. "Attacks are now automated. Defense has to be, too," Nvidia chief executive Jensen Huang said. Kurtz put it more sharply: "The real gap that I saw was that the attackers had frontier AI, and the defenders didn't. And that changes now."

The third piece is identity. CrowdStrike's Agentic Identity Provider gives every AI agent in an enterprise a cryptographically verifiable identity, brokers short-lived least-privilege access instead of standing credentials, and links each agent action back to the human or workload behind it, the company said. Read that against the ShinyHunters case in Anthropic's report, where stolen AI API keys were reused for secondary attacks, and the product-market fit writes itself. The agentic enterprise needs an identity layer for its agents, and the vendors that sell one are the ones the market bought on Monday.

The numbers that will test the story arrive with CrowdStrike's next report. The company guided to third-quarter revenue of $1.523 billion to $1.529 billion and non-GAAP earnings of $0.31 a share, after a second quarter of $1.47 billion, up 25.8%, with $332.8 million of net new annual recurring revenue, per 24/7 Wall St. A 15% one-day move on a company growing revenue 26% is the market pulling forward a re-rating, not reacting to a print; the print will decide whether the re-rating holds.

The narrow-bid problem

The gap between the ETFs and the pure plays is the caution. When the broad cybersecurity ETF rises 5% and the concentrated names rise 15%, the flow is going to a handful of stories, not to the sector's earnings. Fortinet and Check Point, the more hardware-anchored and slower-growing names, rose 7% to 8%, roughly half the platform leaders. That dispersion says the market is paying for AI-native security platforms specifically, and it is paying now for a thesis whose revenue effects show up over quarters.

TECHi's cybersecurity stocks guide framed the sector in the spring as a defensive trade that had become a crowded one, and the CrowdStrike split in June did not stop the stock drifting after that quarter's print. Monday reverses both readings in a single session, which is exactly the kind of move that gets retraced when the next catalyst is a valuation rather than a threat. The stocks that held their gains after the 2024 outage and the 2025 AI-agent scare were the ones with net new ARR to show for it.

What would confirm it

Three things, in order of how soon they arrive. The first is whether the labs' pacing pledge produces a federal framework with security requirements attached; Sam Altman said on Monday that OpenAI would welcome "consistent safety requirements for frontier AI," and any such rule is a compliance budget for this sector. TECHi's view is that the pledge has no enforcer, which cuts against that catalyst. The second is CrowdStrike's third-quarter net new ARR, the one number that separates a re-rating from a rally. The third is the next Anthropic or OpenAI threat report: every one published so far has described more autonomous attackers than the last, and the security stocks now trade on the assumption that the sequence continues.

The risk to the trade is not the threat; it is the rate. The Federal Reserve meets on Wednesday with markets pricing a rate increase, and the stocks that rose 15% on Monday are the highest-multiple names in software. A security budget argument survives a rate hike. A re-rating built in one session on a weekend essay may not, which is why the ARR print, not the essay, decides whether Monday's prices are a floor or a spike.

This is market news analysis, not investment advice. Intraday moves quoted here can reverse before the close. Read TECHi's disclaimer.

FAQ

Frequently asked questions

Why are cybersecurity stocks up on Sept. 14, 2026?

CrowdStrike (+14.9%), Zscaler (+15.2%), SentinelOne (+15%) and Palo Alto Networks (+12.8%) rallied by 11:35 a.m. ET, per Nasdaq.com quotes, after Anthropic CEO Dario Amodei's weekend essay warned that autonomous AI agent swarms could cause hundreds of billions of dollars of damage. Investors read a more dangerous threat environment as higher security spending, while chip stocks fell on the same call to slow AI development.

Did CrowdStrike stock hit an all-time high?

Yes. CrowdStrike set an all-time high at $233.92 early in the Sept. 14, 2026 session, Investing.com reported, and traded at $237.57, up 14.9%, at 11:35 a.m. ET according to Nasdaq.com quotes.

What did Anthropic's threat report say about AI-driven attacks?

Anthropic's September 2026 threat intelligence report, covering December 2025 to August 2026, described a Chinese group whose autonomous research program produced more than a dozen possible zero-day findings in a single month, a Russian espionage group that used agents to modify malware when detected, and criminals who turned one stolen token into full cloud admin control in about three hours.

What did CrowdStrike announce at Fal.Con 2026?

At Fal.Con at the start of September, CrowdStrike announced SafeMind, an agentic security system built on Nvidia Nemotron models, Falcon IQ with more than 50 coordinated agents for assessment and remediation, and an Agentic Identity Provider that gives AI agents verifiable identities and least-privilege access, according to Nvidia and CrowdStrike.

What is CrowdStrike's revenue guidance for the next quarter?

CrowdStrike guided to fiscal third-quarter revenue of $1.523 billion to $1.529 billion and non-GAAP earnings of $0.31 a share, after second-quarter revenue of $1.47 billion, up 25.8%, with $332.8 million of net new annual recurring revenue, per 24/7 Wall St.

Disclaimer

This article is for informational purposes only and does not constitute financial, investment, tax, or legal advice. Market data, tax rules, and prices can change after the article date. TECHi and its authors may hold positions in securities or digital assets mentioned. Always conduct your own research and consult a licensed financial, tax, or legal professional before making decisions.

Share

Pick your channel

About the Author

Qaiser Sultan
@qaiserTechnology and markets writer | AI risk, crypto and digital economies

Qaiser Sultan writes about AI risk, crypto prices and online economies. He has covered Anthropic raising its misalignment risk label after cyber disclosures, how the Ether price looks after a brutal first half and how Roblox's Limited collectibles became real money, and he contributes to TECHi's Two Takes.

Comments