Zscaler Endpoint Security Assessment will use OpenAI’s cyber models to connect risks across AI tools, developer environments, browsers, software, and packages, helping defenders understand what matters and what to address first.Today, OpenAI and Zscaler are expanding their cybersecurity initiatives with the launch of Zscaler Endpoint Security Assessment. By mapping how various conditions on the endpoints combine into viable attack paths, this capability allows security teams to target and prioritize their highest-impact remediations.AI is transforming the modern enterprise endpoint. As employees increasingly rely on AI assistants, coding agents, browser extensions, and connected services to drive productivity, they also introduce new complexities of configurations, permissions, and connections that security teams must navigate.While traditional endpoint controls deliver essential visibility into vulnerabilities, malware, and policy violations, Zscaler Endpoint Security Assessment adds a crucial layer of context. By analyzing how distinct conditions interact across workflows, it helps defenders move past disjointed findings to see a clear, accurate picture of real-world risk. Connecting signals across the modern endpointZscaler Endpoint Security Assessment dynamically evaluates device and user risk using security-relevant information available on managed endpoints. It examines:AI agents, assistants, and their configurationsIDEs, configurations, and installed extensionsBrowsers, security settings, and installed extensionsSystem and software configurationsPython, npm, and other software packagesOpenAI’s cyber models help analyze relationships across these signals and identify potential paths to compromise. The assessment can show how a sequence of conditions may contribute to credential exposure, unauthorized remote access, persistence, or data exfiltration.For example, a developer may follow a routine setup step for a trusted repository, such as installing its software packages. If that process has privileges to execute repository-controlled code on a device that has access to the source code and developer credentials, then permissive security settings may turn a normal workflow into a path for credential exposure, persistence, or data loss. Zscaler Endpoint Security Assessment helps teams identify the combined exposure and helps to focus remediation on the controls that can break the potentially vulnerable path. Leverage visibility into AI-enabled workflows to neutralize the attack chainAI assistants and agents now sit alongside developer tools, browsers, extensions, and software packages in everyday enterprise workflows. Depending on how they are configured and authorized, AI agents can interact with files, applications, and external services, call local tools, run scripts, and invoke workflows that rely on third-party dependencies. Capabilities that were once concentrated on developer workstations are now reaching a much broader set of enterprise users.In practical terms, AI is giving more users access to developer-like workflows. Even when users do not write code themselves, these workflows can introduce similar execution paths, dependencies, permissions, and supply chain risks across more of the endpoint fleet.Some of the most consequential risks do not originate from just one AI agent, package, extension, or configuration in isolation. They usually emerge from their combined workflows and relationships. An agent may have access to business data, rely on a package with unexpected behavior, connect to an external service, and operate on a device with permissive controls. Individually, those conditions may appear manageable. Together, they may form a credible path to code execution, credential exposure, persistence, unauthorized remote access, or data loss.By applying cybersecurity reasoning to this endpoint context, the assessment can help customers:Identify high-impact risks that are difficult to recognize through isolated configuration checksUnderstand how AI tools and developer workflows affect endpoint exposurePrioritize remediation based on credible attack pathsGive security teams clearer context for investigationStrengthen governance across extensions, packages, software, and AI toolsFor red teams and defenders, Zscaler Endpoint Security Assessment provides a focused starting point for investigation. It complements red team assessments by connecting current, endpoint-specific conditions into a detailed attack chain. Security teams now have visibility to how an initial opportunity could lead to execution, and the path of execution that could expose credentials or other valuable access, where persistence may be possible, and which controls could interrupt the sequence.This context helps red teams prioritize validation around the attack paths most relevant to the device. It also gives defenders a detailed remediation plan. The resulting report goes beyond listing separate weaknesses by explaining how one condition may enable the next, what the potential impact could be, and where the chain can be broken.The goal is not to add another stream of alerts. It is to help security operations, endpoint engineering, red teams, and risk teams focus on the findings most likely to affect the organization. Advancing AI-powered defense togetherEndpoint Security Assessment builds on the broader collaboration between OpenAI and Zscaler. Zscaler participates in OpenAI’s Trusted Access for Cyber program, which helps verified defenders access advanced cyber capabilities with safeguards that scale alongside model capability.Through this initiative, OpenAI brings advanced cybersecurity reasoning designed to support legitimate defensive work, while Zscaler brings enterprise security expertise, endpoint context, and the Zscaler Zero Trust Exchange platform. Together, the companies are helping customers understand how conditions across a rapidly expanding endpoint attack surface can combine into detailed attack paths, then turn that understanding into practical protection.To learn more or request a demo, contact Zscaler at zscaler.com/request-a-demo.  

​[#item_full_content] Zscaler Endpoint Security Assessment will use OpenAI’s cyber models to connect risks across AI tools, developer environments, browsers, software, and packages, helping defenders understand what matters and what to address first.Today, OpenAI and Zscaler are expanding their cybersecurity initiatives with the launch of Zscaler Endpoint Security Assessment. By mapping how various conditions on the endpoints combine into viable attack paths, this capability allows security teams to target and prioritize their highest-impact remediations.AI is transforming the modern enterprise endpoint. As employees increasingly rely on AI assistants, coding agents, browser extensions, and connected services to drive productivity, they also introduce new complexities of configurations, permissions, and connections that security teams must navigate.While traditional endpoint controls deliver essential visibility into vulnerabilities, malware, and policy violations, Zscaler Endpoint Security Assessment adds a crucial layer of context. By analyzing how distinct conditions interact across workflows, it helps defenders move past disjointed findings to see a clear, accurate picture of real-world risk. Connecting signals across the modern endpointZscaler Endpoint Security Assessment dynamically evaluates device and user risk using security-relevant information available on managed endpoints. It examines:AI agents, assistants, and their configurationsIDEs, configurations, and installed extensionsBrowsers, security settings, and installed extensionsSystem and software configurationsPython, npm, and other software packagesOpenAI’s cyber models help analyze relationships across these signals and identify potential paths to compromise. The assessment can show how a sequence of conditions may contribute to credential exposure, unauthorized remote access, persistence, or data exfiltration.For example, a developer may follow a routine setup step for a trusted repository, such as installing its software packages. If that process has privileges to execute repository-controlled code on a device that has access to the source code and developer credentials, then permissive security settings may turn a normal workflow into a path for credential exposure, persistence, or data loss. Zscaler Endpoint Security Assessment helps teams identify the combined exposure and helps to focus remediation on the controls that can break the potentially vulnerable path. Leverage visibility into AI-enabled workflows to neutralize the attack chainAI assistants and agents now sit alongside developer tools, browsers, extensions, and software packages in everyday enterprise workflows. Depending on how they are configured and authorized, AI agents can interact with files, applications, and external services, call local tools, run scripts, and invoke workflows that rely on third-party dependencies. Capabilities that were once concentrated on developer workstations are now reaching a much broader set of enterprise users.In practical terms, AI is giving more users access to developer-like workflows. Even when users do not write code themselves, these workflows can introduce similar execution paths, dependencies, permissions, and supply chain risks across more of the endpoint fleet.Some of the most consequential risks do not originate from just one AI agent, package, extension, or configuration in isolation. They usually emerge from their combined workflows and relationships. An agent may have access to business data, rely on a package with unexpected behavior, connect to an external service, and operate on a device with permissive controls. Individually, those conditions may appear manageable. Together, they may form a credible path to code execution, credential exposure, persistence, unauthorized remote access, or data loss.By applying cybersecurity reasoning to this endpoint context, the assessment can help customers:Identify high-impact risks that are difficult to recognize through isolated configuration checksUnderstand how AI tools and developer workflows affect endpoint exposurePrioritize remediation based on credible attack pathsGive security teams clearer context for investigationStrengthen governance across extensions, packages, software, and AI toolsFor red teams and defenders, Zscaler Endpoint Security Assessment provides a focused starting point for investigation. It complements red team assessments by connecting current, endpoint-specific conditions into a detailed attack chain. Security teams now have visibility to how an initial opportunity could lead to execution, and the path of execution that could expose credentials or other valuable access, where persistence may be possible, and which controls could interrupt the sequence.This context helps red teams prioritize validation around the attack paths most relevant to the device. It also gives defenders a detailed remediation plan. The resulting report goes beyond listing separate weaknesses by explaining how one condition may enable the next, what the potential impact could be, and where the chain can be broken.The goal is not to add another stream of alerts. It is to help security operations, endpoint engineering, red teams, and risk teams focus on the findings most likely to affect the organization. Advancing AI-powered defense togetherEndpoint Security Assessment builds on the broader collaboration between OpenAI and Zscaler. Zscaler participates in OpenAI’s Trusted Access for Cyber program, which helps verified defenders access advanced cyber capabilities with safeguards that scale alongside model capability.Through this initiative, OpenAI brings advanced cybersecurity reasoning designed to support legitimate defensive work, while Zscaler brings enterprise security expertise, endpoint context, and the Zscaler Zero Trust Exchange platform. Together, the companies are helping customers understand how conditions across a rapidly expanding endpoint attack surface can combine into detailed attack paths, then turn that understanding into practical protection.To learn more or request a demo, contact Zscaler at zscaler.com/request-a-demo.