IntroductionMore than half of the Fortune 500 and over 40% of the Global 2000 already run on Zscaler. They made security to the cloud, inline and close to the user, sending their traffic through the world’s largest inline security cloud.Enterprises running firewalls and VPN could argue they had time. AI has taken that argument away.Attackers now use AI to turn a disclosed CVE into a working exploit in hours, generate malware variants faster than signature pipelines can catalog them, and stand up phishing sites that vanish before reputation feeds notice them. Research shows defenders had roughly 63 days between disclosure and exploitation in 2018; today, exploitation routinely happens before a patch exists. At the same time, traffic is moving to WebSockets, QUIC, and HTTP/3 that appliance-era inspection was never built to parse. And the post-quantum shift isn’t coming; it’s here. Browsers already negotiate post-quantum key exchange by default, which means a growing share of encrypted traffic is invisible to any inspection layer that can’t keep up. Perimeter architectures cannot close either gap. A firewall that has to backhaul, decrypt and correlate after the fact is losing a race it was never designed to run, and it can’t inspect a handshake it can’t join. The only architecture built for machine-speed threats is one that inspects every transaction inline, in the cloud, at the moment it happens, including traffic that’s already post-quantum.That is the architecture the world’s largest enterprises already chose.At ZenithLive 2026, we introduced major architectural advancements across both Zscaler Internet Access (ZIA) and Zscaler Private Access (ZPA). Together, they represent a unified philosophy: every transaction across the internet, SaaS, and private applications must be subjected to real-time Zero Trust verification without adding operational complexity.Here is a small but important subset of new capabilities across the platform.Part 1: What’s New in Zscaler Internet Access (ZIA)Inline security is only as effective as the traffic that receives an actual, real-time verdict. When inspection engines induce latency, teams resort to exceptions where breaches occur. The latest innovations in ZIA focus on closing inspection blind spots, eliminating latency tradeoffs, and equipping SOC teams with rich transactional context.1. Zscaler is Post-Quantum Ready. Enterprise traffic is moving to protocols designed for speed and future cryptographic resilience. Inspection engines must keep pace:Post-Quantum Cryptography (PQC) Readiness: Most post-quantum coverage focuses on “harvest now, decrypt later” – an adversary recording encrypted traffic today to break it once a sufficiently capable quantum computer exists. That risk is real, the timeline is genuinely unknown, and nobody who tells you they know the date does.But there’s a nearer-term problem that gets far less attention, and it isn’t hypothetical. Browsers already negotiate hybrid post-quantum key exchange by default. As server-side support spreads, more and more sessions will complete a handshake your inspection layer cannot participate in. At that point a middlebox has two options, and both are bad: fail open and lose visibility, or fail closed and break the connection. The question that matters in 2026 isn’t, “am I quantum-safe?” It’s “when both endpoints go post-quantum, do I go blind?”So we sequenced our work as visibility, then inspection, then forwarding:PQC visibility and analytics: Classical versus post-quantum cipher usage across your traffic, a crypto inventory to plan migration against, and six new Web Insight logging fields covering client and server key exchange algorithms, digital signature algorithms, and client-side proposals. You cannot plan a migration you cannot measure, and most organizations currently cannot measure this. This is available today to Zscaler customers.PQC traffic inspection at scale: TLS inspection with hybrid ML-KEM / DH key exchange, delivering real-time inspection and policy enforcement across every combination: PQC client to PQC server, classical client to PQC server, and PQC client to classical server. No configuration change is required to start seeing PQC traffic. In beta now, this feature will be in limited availability later this year.IPsec with post-quantum pre-shared keys: quantum-safe forwarding to Zscaler from PPK-capable VPN gateways on your premises, so the tunnel carrying the traffic is protected on the same terms as the traffic itself. This feature will be available to customers early next year. Alongside these, two controls for organizations with specific cryptographic obligations: custom crypto profiles, which let administrators configure, restrict or prioritize cipher suites during TLS inspection with per-profile minimum TLS versions, and custom certificate key lengths supporting RSA-4096 and ECDSA P-256 for intermediate certificates driven largely by German BSI requirements, though the applicability is broader.Modern AI Protocols (WebSockets, QUIC, HTTP/3): Because streaming AI interfaces rely heavily on WebSockets for real-time model interaction, ZIA delivers deep bidirectional text inspection across sanctioned applications (including Microsoft Copilot and Grammarly), alongside native enforcement for QUIC, HTTP/3, and WebTransport. In beta now; this feature will be in limited availability later this year.2. Eliminating Sandbox Latency: AI Instant Verdict and CDRThe historical dilemma of sandboxing has always been the tradeoff between accuracy and latency. Accurate remediation takes minutes; business moves in seconds. When employees need a file immediately, security teams face pressure to allow downloads before analysis completes.AI Instant Verdict: Powered by a model trained on more than 600 million file samples, ZIA now scores files inline. Anything scoring 91–100 is blocked immediately, before it reaches an endpoint. In production, about 91% of files receive an instant benign verdict and are delivered with no perceptible delay, some are escalated for deeper dynamic analysis, and about some are blocked outright. Throughput runs to 10,000+ files in 20 minutes.The point is not that the model replaces detonation. It doesn’t – the 9% still goes to the sandbox, and that’s where it belongs. The point is that the common case stops waiting on the uncommon one. This feature is available today.Content Disarm and Reconstruction (CDR): For workflows where a file is likely benign but immediate access is critical, CDR strips active macros and embedded scripts from Office documents and PDFs, reconstructing a sanitized version in real time. Rather than debating allow-versus-block, users get safe files instantly while eliminating file-based attack surfaces. This feature will be available to all current ZIA customers in Limited Availability starting early next year.Brand Phishing Defense: Modern credential harvesting pages stand up, harvest credentials for six hours, and vanish before URL reputation feeds catch up. ZIA’s brand phishing engine inspects visual layout cues, credential input forms, and page construction in real time, rendering verdicts on zero-hour phishing infrastructure independently of historical domain reputation.This feature will be available to all current ZIA customers in Limited Availability starting early next year.3. Securing the New Executable: Agentic AI and MCP ArchitectureFor thirty years, security stacks assumed malware meant compiled binaries (EXEs, DLLs, ELFs). Today, the definition of an executable has fundamentally changed.As developers and business units deploy agentic AI frameworks, these tools download instruction manifests, skill files, and connect to Model Context Protocol (MCP) servers. A skill file is a plaintext file, but functionally, it is an executable program instructing an autonomous agent to execute actions with user permissions. Conventional security controls overlook them completely.ZIA extends inline enforcement to agentic workflows:Rogue MCP Server Blocking: Prevents local systems, enterprise internal applications, and autonomous agents from establishing connections to unauthorized, vulnerable, or malicious Model Context Protocol (MCP) servers across the network layer. This feature will be available later this year.Agentic Tool Download Inspection: Identifies, inspects, and halts unauthorized agentic AI frameworks and tooling at download time rather than discovering them later at runtime. This feature will be available later this year.Skill File Sandbox Detonation: Inspects and behaviorally analyzes text-based skill manifests and tool instruction files within Cloud Sandbox upon download before they can be loaded by an agent. This automated dynamic analysis catches both known malicious skills and novel variants that lack signatures. This feature will be available later this year.                  4. Comprehensive Visibility: Offline Channels and JA4 FingerprintingInline coverage has a structural blind spot: files that never traverse the network. A contractor’s USB stick, an AirDrop between two laptops in the same room, a Bluetooth transfer. These are just a meaningful fraction of ways malware actually arrives in offices.Cloud Sandbox now operates across four channels rather than one:Inline sandbox: real-time blocking of malicious content in traffic.Endpoint Sandbox: unknown EXE and DLL files arriving over offline channels are hashed and queried; if the file is unknown, it’s sent to Cloud Sandbox for full analysis, with the client notifying the user while the check runs.API-driven file analysis: on-demand submission for investigation, supporting multiple API keys, so the SOC can push a suspect file through the same engine that makes inline decisions.We also widened what the sandbox can take: EXE and DLL analysis up to 200 MB, and macOS DMG support.JA4 Fingerprinting (Encrypted Traffic Analysis): Certain endpoints such as OT controllers, medical devices, or services with pinned certificates cannot be decrypted. Using JA4 fingerprinting of the TLS handshake, ZIA models baseline communications. When a device that has behaved like a camera for months suddenly negotiates a session characteristic of a command-and-control framework, alerts fire immediately without needing plaintext decryption. This feature is generally available for Zscaler customers. 5. SOC Empowerment and ProvenanceThe standard architecture for SOC context is reassembly: EDR, firewall, SWG, NDR, identity and cloud each emit telemetry, and a SIEM correlates it after the fact. Correlation works, but it costs time and it’s lossy, i.e. you’re reconstructing a single event from artifacts several systems produced independently.Endpoint Context leverages Zscaler’s vantage point in the end-to-end network to change this. Application, process and vulnerability insight from the endpoint feeds directly into detection and enforcement, so the context is attached to the transaction rather than joined to it later. This isn’t a reporting improvement; it produces detections that don’t otherwise exist.A concrete case: chrome.exe running from a directory it has no business running from, unsigned, with an unknown version, opening a remote connection. No individual signal there is conclusive, and nothing in the packet stream is anomalous. Together they’re enough to generate a new IPS signature and block it. A control that only sees the network cannot make that call, because the evidence isn’t on the network.The same endpoint intelligence, drawn from 50 million-plus endpoints, has improved command-and-control detection. Our C2 model previously leaned on URL and domain reputation. It now incorporates endpoint-derived context, and we’ve moved to rate-based C2 detection rather than purely pattern-based, which has reduced false positives noticeably. Living-off-the-land techniques and commodity C2 frameworks such as Cobalt Strike are the primary beneficiaries.AI/ML Detection Attribution: Every alert explicitly identifies the specific underlying model, heuristic, or detection engine responsible for the verdict. Security teams gain transparent auditability rather than opaque “black-box” scores.Closed-Loop MDR & NDR Enforcement: Continuous traffic capture from ZIA to NDR partners like Vectra, ExtraHop, and Corelight improves SOC maturity for incident hunting and early lateral movement detection using rate, anomaly, and heuristic algorithms, significantly enhancing SASE visibility when combined with ZPA traffic. Here is a quick status update on our core NDR integrations:Vectra (GA): Generally Available for AWS S3 environments.ExtraHop (LA): Currently in Limited Availability.Microsoft Azure (LA): Traffic capture for Azure environments launches in October.Corelight (Preview): Private preview is active, with public preview scheduled by the end of the year.Part 2: What’s New in Zscaler Private Access (ZPA)While ZIA secures outbound access to SaaS, the web, and external AI models, ZPA governs access to internal crown jewels: proprietary private applications, private AI clusters, and hosted environments.Legacy connectivity models rely on VPN tunnels that terminate external users directly onto internal networks. If an endpoint is compromised, attackers gain unfettered lateral traversal. ZPA fundamentally inverts this model: users and entities are connected strictly to authorized applications, never to the underlying network.At ZenithLive, we introduced key capabilities to automate segmentation, secure unmanaged endpoints, and virtually patch internal vulnerabilities.1. Zscaler Autonomous Application Shield: Machine-Speed Defense for Private ApplicationsFrontier AI models have fundamentally altered the economics of exploitation, compressing the window from CVE disclosure to weaponized, chained exploit from weeks to hours. Yet enterprise remediation remains trapped in human-speed patch cycles, testing windows, and change boards. Autonomous Application Shield is an AI-driven capability natively integrated into ZPA that shifts private application security from reactive ticketing to continuous, autonomous protection:Continuous Posture: App Connectors safely and continuously assess application exposure points, APIs, and runtime risk, replacing periodic scans with a living, real-time security posture.Context-Aware Reasoning: The Zscaler cloud evaluates each application’s unique architecture and observed traffic, applying only relevant, targeted protections to preserve performance and eliminate false positives.Global Threat Intelligence: Zero-days and novel attack vectors observed across Zscaler’s global exchange instantly inform and sharpen protection policies worldwide without manual tuning.Pipeline-Speed Virtual Patching: Defenses adapt dynamically as developers push code, deploying automated virtual patches at the App Connector boundary in minutes—neutralizing exploits before a permanent code patch can even be scheduled.Autonomous Application Shield is now open for early access.  2. Comprehensive Access Visibility with Autonomous User-to-App SegmentationMost organizations actively manage only their crown jewel applications, leaving the vast majority of internal services and dynamically provisioned cloud workloads unmapped, poorly documented, and dangerously exposed behind overly permissive wildcard application segments (*.internal, *.corp). Traditional network segmentation projects fail because manual traffic analysis and static firewall rules cannot keep pace with modern hybrid cloud velocity.Autonomous User-to-App Segmentation eliminates this blind spot by automating the entire policy lifecycle:1. AI-Driven Automation: Application Fingerprinting and ZPA Data AgentApplication Fingerprinting: Leveraging machine learning algorithms trained across global enterprise telemetry, ZPA now automatically identifies, categorizes, and labels internal applications based on operational behavior and traffic patterns.Interactive ZPA Data Agent: Administrators can query complex deployment telemetry using plain language to gain visibility into underlying data alongside interactive telemetry, streamlining audit readiness and troubleshooting workflows.  2. See Every Application (Continuous Discovery & Inventory)Passive, Agentless Workload Sensing: Continuously senses and catalogs all active private workloads across on-premises datacenters, public clouds (AWS, Azure, GCP), and OT/factory environments without requiring intrusive endpoint scanners or complex network re-architecting.Surface Hidden Shadow Services: Detects untracked microservices, legacy internal web tools, and uncataloged container endpoints that typically evade standard configuration management databases (CMDBs).Expose Wildcard Risk: Automatically flags overly broad application definitions and wildcard domains that grant excessive IP reachability, giving security teams an authoritative, real-time baseline of their actual attack surface.3. Segment with Intelligence (AI-Powered Policy Recommendations)Behavioral Traffic Analysis: Analyzes historical and real-time user-to-application communication patterns, user identity groups, and transaction behaviors using advanced machine learning models.Automated Least-Privilege Rules: Automatically generates discrete, application-specific segment definitions and context-aware access policies, systematically replacing flat network access with precise, 1:1 micro-tunnels.Frictionless, One-Click Deployment: Allows administrators to review, test, and apply recommended policy boundaries in minutes rather than months, eliminating the risk of business disruption or broken application dependencies.4. Strengthen Security Posture (Posture Governance & Actionable Insights)Continuous Relationship & Dependency Mapping: Visualizes real-time communication pathways between user groups, third-party contractors, and application workloads to detect anomalous access trends or permission drift.Quantifiable Maturity Tracking: Feeds directly into maturity metrics (such as the ZPA App Segmentation Index), evaluating discovery velocity, policy effectiveness, and operational hygiene so teams can track quarter-over-quarter progress.Proactive Attack Surface Reduction: Delivers ongoing, prioritized recommendations to retire dormant policies, tighten access entitlements, and eliminate emerging vulnerabilities before threat actors can exploit them.Ensuring users and compromised devices are connected exclusively to specific, authorized applications, never to the underlying corporate network. This drastically shrinks the breach blast radius. This approach halts lateral threat movement while automating the labor-intensive tasks of application mapping and firewall rule maintenance, which frees security and network engineering teams from endless manual triage. Ultimately, it compresses segmentation deployment schedules from multi-year infrastructure overhauls into a rapid, phased, data-driven rollout with measurable executive reporting, accelerating Zero Trust time-to-value.Autonomous User-to-App Segmentation is available now.    3. Secure Cross-Company Collaboration: B2B FederationModern business depends on ecosystem partnerships, from joint ventures and supply chain relationships to mergers, acquisitions, and divestitures. Yet connecting partner users to private applications today means accepting network risk: site-to-site VPNs, shared credentials, and firewall rules that create exactly the lateral movement exposure Zero Trust is designed to eliminate. What makes it worse, this process typically takes months to set up.ZPA B2B Federation changes that. Enterprises can onboard a partner and provide Zero Trust access to private applications in under 30 minutes, without site-to-site VPN tunnels, complex routing tables, or cross-tenant network exposure.Core deployment scenarios include:External Partner Connectivity: Onboard third-party contractors, vendors, and distributors quickly and securely. Partner users get authenticated access only to the applications they need, with Zero Trust policies enforced end-to-end, no network connectivity, no lateral movement risk.M&A Integration and Divestitures: Deliver immediate Day-1 access to essential ERP, HR, and productivity platforms without consolidating networks or merging identity infrastructures. Offboarding requires only a swift policy adjustment.Multi-Tenant Enterprise Deployments: Large enterprises with multiple ZPA tenants can use Federation to simplify app sharing across parent companies and OpCos, while each unit retains control of its infrastructure, applications, and access policies.Federal and Cross-Cloud Environments: Facilitate secure resource sharing across FedHigh, FedMod, and commercial instances without interconnecting physical networks or violating regulatory mandates.  4. Securing the Unmanaged Endpoint with Zero Trust Browser Extension for ZPAThird-party contractors, supply chain partners, and BYOD employees frequently require access to sensitive internal systems without having full device management profiles installed:The Zero Trust Browser Extension establishes an isolated, enterprise-controlled workspace directly inside modern web browsers.It enforces deep runtime data-loss prevention, blocking keystroke loggers, screen capture utilities, and clipboard copying.Device posture checks are evaluated locally, ensuring unmanaged endpoints cannot be leveraged as attack vectors into corporate resources.Standalone and hardened Enterprise Browser is also available as an alternative form factor.Zero Trust Browser Extension is available now. The Strategic Path ForwardWhen reviewing your cybersecurity roadmap, the most critical metric is not the sheer count of point products deployed or how many firewall policies are active.The question every executive and security architect should ask is:What percentage of our traffic actually receives an inline, deterministic Zero Trust verdict?If your outbound inspection cannot parse modern streaming protocols, negotiate post-quantum handshakes, or render instant verdicts on files, critical traffic is silently failing open. And if your private applications remain reachable via public IPs and routable VPN connections, an attacker compromising a single user or contractor endpoint can traverse laterally to your data.By combining the real-time inline threat engines of Zscaler Internet Access with the cloaking and autonomous segmentation of Zscaler Private Access, organizations establish a unified Zero Trust fabric. Attacks are stopped cold inline, critical internal workloads remain entirely invisible to the outside world, and enterprises can safely adopt AI and modern cloud architectures at scale. Learn how you can protect your enterprise in this AI-era by visiting our ZenithLive 2026 on-demand event.  

​[#item_full_content] IntroductionMore than half of the Fortune 500 and over 40% of the Global 2000 already run on Zscaler. They made security to the cloud, inline and close to the user, sending their traffic through the world’s largest inline security cloud.Enterprises running firewalls and VPN could argue they had time. AI has taken that argument away.Attackers now use AI to turn a disclosed CVE into a working exploit in hours, generate malware variants faster than signature pipelines can catalog them, and stand up phishing sites that vanish before reputation feeds notice them. Research shows defenders had roughly 63 days between disclosure and exploitation in 2018; today, exploitation routinely happens before a patch exists. At the same time, traffic is moving to WebSockets, QUIC, and HTTP/3 that appliance-era inspection was never built to parse. And the post-quantum shift isn’t coming; it’s here. Browsers already negotiate post-quantum key exchange by default, which means a growing share of encrypted traffic is invisible to any inspection layer that can’t keep up. Perimeter architectures cannot close either gap. A firewall that has to backhaul, decrypt and correlate after the fact is losing a race it was never designed to run, and it can’t inspect a handshake it can’t join. The only architecture built for machine-speed threats is one that inspects every transaction inline, in the cloud, at the moment it happens, including traffic that’s already post-quantum.That is the architecture the world’s largest enterprises already chose.At ZenithLive 2026, we introduced major architectural advancements across both Zscaler Internet Access (ZIA) and Zscaler Private Access (ZPA). Together, they represent a unified philosophy: every transaction across the internet, SaaS, and private applications must be subjected to real-time Zero Trust verification without adding operational complexity.Here is a small but important subset of new capabilities across the platform.Part 1: What’s New in Zscaler Internet Access (ZIA)Inline security is only as effective as the traffic that receives an actual, real-time verdict. When inspection engines induce latency, teams resort to exceptions where breaches occur. The latest innovations in ZIA focus on closing inspection blind spots, eliminating latency tradeoffs, and equipping SOC teams with rich transactional context.1. Zscaler is Post-Quantum Ready. Enterprise traffic is moving to protocols designed for speed and future cryptographic resilience. Inspection engines must keep pace:Post-Quantum Cryptography (PQC) Readiness: Most post-quantum coverage focuses on “harvest now, decrypt later” – an adversary recording encrypted traffic today to break it once a sufficiently capable quantum computer exists. That risk is real, the timeline is genuinely unknown, and nobody who tells you they know the date does.But there’s a nearer-term problem that gets far less attention, and it isn’t hypothetical. Browsers already negotiate hybrid post-quantum key exchange by default. As server-side support spreads, more and more sessions will complete a handshake your inspection layer cannot participate in. At that point a middlebox has two options, and both are bad: fail open and lose visibility, or fail closed and break the connection. The question that matters in 2026 isn’t, “am I quantum-safe?” It’s “when both endpoints go post-quantum, do I go blind?”So we sequenced our work as visibility, then inspection, then forwarding:PQC visibility and analytics: Classical versus post-quantum cipher usage across your traffic, a crypto inventory to plan migration against, and six new Web Insight logging fields covering client and server key exchange algorithms, digital signature algorithms, and client-side proposals. You cannot plan a migration you cannot measure, and most organizations currently cannot measure this. This is available today to Zscaler customers.PQC traffic inspection at scale: TLS inspection with hybrid ML-KEM / DH key exchange, delivering real-time inspection and policy enforcement across every combination: PQC client to PQC server, classical client to PQC server, and PQC client to classical server. No configuration change is required to start seeing PQC traffic. In beta now, this feature will be in limited availability later this year.IPsec with post-quantum pre-shared keys: quantum-safe forwarding to Zscaler from PPK-capable VPN gateways on your premises, so the tunnel carrying the traffic is protected on the same terms as the traffic itself. This feature will be available to customers early next year. Alongside these, two controls for organizations with specific cryptographic obligations: custom crypto profiles, which let administrators configure, restrict or prioritize cipher suites during TLS inspection with per-profile minimum TLS versions, and custom certificate key lengths supporting RSA-4096 and ECDSA P-256 for intermediate certificates driven largely by German BSI requirements, though the applicability is broader.Modern AI Protocols (WebSockets, QUIC, HTTP/3): Because streaming AI interfaces rely heavily on WebSockets for real-time model interaction, ZIA delivers deep bidirectional text inspection across sanctioned applications (including Microsoft Copilot and Grammarly), alongside native enforcement for QUIC, HTTP/3, and WebTransport. In beta now; this feature will be in limited availability later this year.2. Eliminating Sandbox Latency: AI Instant Verdict and CDRThe historical dilemma of sandboxing has always been the tradeoff between accuracy and latency. Accurate remediation takes minutes; business moves in seconds. When employees need a file immediately, security teams face pressure to allow downloads before analysis completes.AI Instant Verdict: Powered by a model trained on more than 600 million file samples, ZIA now scores files inline. Anything scoring 91–100 is blocked immediately, before it reaches an endpoint. In production, about 91% of files receive an instant benign verdict and are delivered with no perceptible delay, some are escalated for deeper dynamic analysis, and about some are blocked outright. Throughput runs to 10,000+ files in 20 minutes.The point is not that the model replaces detonation. It doesn’t – the 9% still goes to the sandbox, and that’s where it belongs. The point is that the common case stops waiting on the uncommon one. This feature is available today.Content Disarm and Reconstruction (CDR): For workflows where a file is likely benign but immediate access is critical, CDR strips active macros and embedded scripts from Office documents and PDFs, reconstructing a sanitized version in real time. Rather than debating allow-versus-block, users get safe files instantly while eliminating file-based attack surfaces. This feature will be available to all current ZIA customers in Limited Availability starting early next year.Brand Phishing Defense: Modern credential harvesting pages stand up, harvest credentials for six hours, and vanish before URL reputation feeds catch up. ZIA’s brand phishing engine inspects visual layout cues, credential input forms, and page construction in real time, rendering verdicts on zero-hour phishing infrastructure independently of historical domain reputation.This feature will be available to all current ZIA customers in Limited Availability starting early next year.3. Securing the New Executable: Agentic AI and MCP ArchitectureFor thirty years, security stacks assumed malware meant compiled binaries (EXEs, DLLs, ELFs). Today, the definition of an executable has fundamentally changed.As developers and business units deploy agentic AI frameworks, these tools download instruction manifests, skill files, and connect to Model Context Protocol (MCP) servers. A skill file is a plaintext file, but functionally, it is an executable program instructing an autonomous agent to execute actions with user permissions. Conventional security controls overlook them completely.ZIA extends inline enforcement to agentic workflows:Rogue MCP Server Blocking: Prevents local systems, enterprise internal applications, and autonomous agents from establishing connections to unauthorized, vulnerable, or malicious Model Context Protocol (MCP) servers across the network layer. This feature will be available later this year.Agentic Tool Download Inspection: Identifies, inspects, and halts unauthorized agentic AI frameworks and tooling at download time rather than discovering them later at runtime. This feature will be available later this year.Skill File Sandbox Detonation: Inspects and behaviorally analyzes text-based skill manifests and tool instruction files within Cloud Sandbox upon download before they can be loaded by an agent. This automated dynamic analysis catches both known malicious skills and novel variants that lack signatures. This feature will be available later this year.                  4. Comprehensive Visibility: Offline Channels and JA4 FingerprintingInline coverage has a structural blind spot: files that never traverse the network. A contractor’s USB stick, an AirDrop between two laptops in the same room, a Bluetooth transfer. These are just a meaningful fraction of ways malware actually arrives in offices.Cloud Sandbox now operates across four channels rather than one:Inline sandbox: real-time blocking of malicious content in traffic.Endpoint Sandbox: unknown EXE and DLL files arriving over offline channels are hashed and queried; if the file is unknown, it’s sent to Cloud Sandbox for full analysis, with the client notifying the user while the check runs.API-driven file analysis: on-demand submission for investigation, supporting multiple API keys, so the SOC can push a suspect file through the same engine that makes inline decisions.We also widened what the sandbox can take: EXE and DLL analysis up to 200 MB, and macOS DMG support.JA4 Fingerprinting (Encrypted Traffic Analysis): Certain endpoints such as OT controllers, medical devices, or services with pinned certificates cannot be decrypted. Using JA4 fingerprinting of the TLS handshake, ZIA models baseline communications. When a device that has behaved like a camera for months suddenly negotiates a session characteristic of a command-and-control framework, alerts fire immediately without needing plaintext decryption. This feature is generally available for Zscaler customers. 5. SOC Empowerment and ProvenanceThe standard architecture for SOC context is reassembly: EDR, firewall, SWG, NDR, identity and cloud each emit telemetry, and a SIEM correlates it after the fact. Correlation works, but it costs time and it’s lossy, i.e. you’re reconstructing a single event from artifacts several systems produced independently.Endpoint Context leverages Zscaler’s vantage point in the end-to-end network to change this. Application, process and vulnerability insight from the endpoint feeds directly into detection and enforcement, so the context is attached to the transaction rather than joined to it later. This isn’t a reporting improvement; it produces detections that don’t otherwise exist.A concrete case: chrome.exe running from a directory it has no business running from, unsigned, with an unknown version, opening a remote connection. No individual signal there is conclusive, and nothing in the packet stream is anomalous. Together they’re enough to generate a new IPS signature and block it. A control that only sees the network cannot make that call, because the evidence isn’t on the network.The same endpoint intelligence, drawn from 50 million-plus endpoints, has improved command-and-control detection. Our C2 model previously leaned on URL and domain reputation. It now incorporates endpoint-derived context, and we’ve moved to rate-based C2 detection rather than purely pattern-based, which has reduced false positives noticeably. Living-off-the-land techniques and commodity C2 frameworks such as Cobalt Strike are the primary beneficiaries.AI/ML Detection Attribution: Every alert explicitly identifies the specific underlying model, heuristic, or detection engine responsible for the verdict. Security teams gain transparent auditability rather than opaque “black-box” scores.Closed-Loop MDR & NDR Enforcement: Continuous traffic capture from ZIA to NDR partners like Vectra, ExtraHop, and Corelight improves SOC maturity for incident hunting and early lateral movement detection using rate, anomaly, and heuristic algorithms, significantly enhancing SASE visibility when combined with ZPA traffic. Here is a quick status update on our core NDR integrations:Vectra (GA): Generally Available for AWS S3 environments.ExtraHop (LA): Currently in Limited Availability.Microsoft Azure (LA): Traffic capture for Azure environments launches in October.Corelight (Preview): Private preview is active, with public preview scheduled by the end of the year.Part 2: What’s New in Zscaler Private Access (ZPA)While ZIA secures outbound access to SaaS, the web, and external AI models, ZPA governs access to internal crown jewels: proprietary private applications, private AI clusters, and hosted environments.Legacy connectivity models rely on VPN tunnels that terminate external users directly onto internal networks. If an endpoint is compromised, attackers gain unfettered lateral traversal. ZPA fundamentally inverts this model: users and entities are connected strictly to authorized applications, never to the underlying network.At ZenithLive, we introduced key capabilities to automate segmentation, secure unmanaged endpoints, and virtually patch internal vulnerabilities.1. Zscaler Autonomous Application Shield: Machine-Speed Defense for Private ApplicationsFrontier AI models have fundamentally altered the economics of exploitation, compressing the window from CVE disclosure to weaponized, chained exploit from weeks to hours. Yet enterprise remediation remains trapped in human-speed patch cycles, testing windows, and change boards. Autonomous Application Shield is an AI-driven capability natively integrated into ZPA that shifts private application security from reactive ticketing to continuous, autonomous protection:Continuous Posture: App Connectors safely and continuously assess application exposure points, APIs, and runtime risk, replacing periodic scans with a living, real-time security posture.Context-Aware Reasoning: The Zscaler cloud evaluates each application’s unique architecture and observed traffic, applying only relevant, targeted protections to preserve performance and eliminate false positives.Global Threat Intelligence: Zero-days and novel attack vectors observed across Zscaler’s global exchange instantly inform and sharpen protection policies worldwide without manual tuning.Pipeline-Speed Virtual Patching: Defenses adapt dynamically as developers push code, deploying automated virtual patches at the App Connector boundary in minutes—neutralizing exploits before a permanent code patch can even be scheduled.Autonomous Application Shield is now open for early access.  2. Comprehensive Access Visibility with Autonomous User-to-App SegmentationMost organizations actively manage only their crown jewel applications, leaving the vast majority of internal services and dynamically provisioned cloud workloads unmapped, poorly documented, and dangerously exposed behind overly permissive wildcard application segments (*.internal, *.corp). Traditional network segmentation projects fail because manual traffic analysis and static firewall rules cannot keep pace with modern hybrid cloud velocity.Autonomous User-to-App Segmentation eliminates this blind spot by automating the entire policy lifecycle:1. AI-Driven Automation: Application Fingerprinting and ZPA Data AgentApplication Fingerprinting: Leveraging machine learning algorithms trained across global enterprise telemetry, ZPA now automatically identifies, categorizes, and labels internal applications based on operational behavior and traffic patterns.Interactive ZPA Data Agent: Administrators can query complex deployment telemetry using plain language to gain visibility into underlying data alongside interactive telemetry, streamlining audit readiness and troubleshooting workflows.  2. See Every Application (Continuous Discovery & Inventory)Passive, Agentless Workload Sensing: Continuously senses and catalogs all active private workloads across on-premises datacenters, public clouds (AWS, Azure, GCP), and OT/factory environments without requiring intrusive endpoint scanners or complex network re-architecting.Surface Hidden Shadow Services: Detects untracked microservices, legacy internal web tools, and uncataloged container endpoints that typically evade standard configuration management databases (CMDBs).Expose Wildcard Risk: Automatically flags overly broad application definitions and wildcard domains that grant excessive IP reachability, giving security teams an authoritative, real-time baseline of their actual attack surface.3. Segment with Intelligence (AI-Powered Policy Recommendations)Behavioral Traffic Analysis: Analyzes historical and real-time user-to-application communication patterns, user identity groups, and transaction behaviors using advanced machine learning models.Automated Least-Privilege Rules: Automatically generates discrete, application-specific segment definitions and context-aware access policies, systematically replacing flat network access with precise, 1:1 micro-tunnels.Frictionless, One-Click Deployment: Allows administrators to review, test, and apply recommended policy boundaries in minutes rather than months, eliminating the risk of business disruption or broken application dependencies.4. Strengthen Security Posture (Posture Governance & Actionable Insights)Continuous Relationship & Dependency Mapping: Visualizes real-time communication pathways between user groups, third-party contractors, and application workloads to detect anomalous access trends or permission drift.Quantifiable Maturity Tracking: Feeds directly into maturity metrics (such as the ZPA App Segmentation Index), evaluating discovery velocity, policy effectiveness, and operational hygiene so teams can track quarter-over-quarter progress.Proactive Attack Surface Reduction: Delivers ongoing, prioritized recommendations to retire dormant policies, tighten access entitlements, and eliminate emerging vulnerabilities before threat actors can exploit them.Ensuring users and compromised devices are connected exclusively to specific, authorized applications, never to the underlying corporate network. This drastically shrinks the breach blast radius. This approach halts lateral threat movement while automating the labor-intensive tasks of application mapping and firewall rule maintenance, which frees security and network engineering teams from endless manual triage. Ultimately, it compresses segmentation deployment schedules from multi-year infrastructure overhauls into a rapid, phased, data-driven rollout with measurable executive reporting, accelerating Zero Trust time-to-value.Autonomous User-to-App Segmentation is available now.    3. Secure Cross-Company Collaboration: B2B FederationModern business depends on ecosystem partnerships, from joint ventures and supply chain relationships to mergers, acquisitions, and divestitures. Yet connecting partner users to private applications today means accepting network risk: site-to-site VPNs, shared credentials, and firewall rules that create exactly the lateral movement exposure Zero Trust is designed to eliminate. What makes it worse, this process typically takes months to set up.ZPA B2B Federation changes that. Enterprises can onboard a partner and provide Zero Trust access to private applications in under 30 minutes, without site-to-site VPN tunnels, complex routing tables, or cross-tenant network exposure.Core deployment scenarios include:External Partner Connectivity: Onboard third-party contractors, vendors, and distributors quickly and securely. Partner users get authenticated access only to the applications they need, with Zero Trust policies enforced end-to-end, no network connectivity, no lateral movement risk.M&A Integration and Divestitures: Deliver immediate Day-1 access to essential ERP, HR, and productivity platforms without consolidating networks or merging identity infrastructures. Offboarding requires only a swift policy adjustment.Multi-Tenant Enterprise Deployments: Large enterprises with multiple ZPA tenants can use Federation to simplify app sharing across parent companies and OpCos, while each unit retains control of its infrastructure, applications, and access policies.Federal and Cross-Cloud Environments: Facilitate secure resource sharing across FedHigh, FedMod, and commercial instances without interconnecting physical networks or violating regulatory mandates.  4. Securing the Unmanaged Endpoint with Zero Trust Browser Extension for ZPAThird-party contractors, supply chain partners, and BYOD employees frequently require access to sensitive internal systems without having full device management profiles installed:The Zero Trust Browser Extension establishes an isolated, enterprise-controlled workspace directly inside modern web browsers.It enforces deep runtime data-loss prevention, blocking keystroke loggers, screen capture utilities, and clipboard copying.Device posture checks are evaluated locally, ensuring unmanaged endpoints cannot be leveraged as attack vectors into corporate resources.Standalone and hardened Enterprise Browser is also available as an alternative form factor.Zero Trust Browser Extension is available now. The Strategic Path ForwardWhen reviewing your cybersecurity roadmap, the most critical metric is not the sheer count of point products deployed or how many firewall policies are active.The question every executive and security architect should ask is:What percentage of our traffic actually receives an inline, deterministic Zero Trust verdict?If your outbound inspection cannot parse modern streaming protocols, negotiate post-quantum handshakes, or render instant verdicts on files, critical traffic is silently failing open. And if your private applications remain reachable via public IPs and routable VPN connections, an attacker compromising a single user or contractor endpoint can traverse laterally to your data.By combining the real-time inline threat engines of Zscaler Internet Access with the cloaking and autonomous segmentation of Zscaler Private Access, organizations establish a unified Zero Trust fabric. Attacks are stopped cold inline, critical internal workloads remain entirely invisible to the outside world, and enterprises can safely adopt AI and modern cloud architectures at scale. Learn how you can protect your enterprise in this AI-era by visiting our ZenithLive 2026 on-demand event.