Blog da Zscaler

Receba as últimas atualizações do blog da Zscaler na sua caixa de entrada

Products & Solutions

Zscaler Integrates With OpenAI Cyber Models to Secure the AI-Enabled Endpoint

Zscaler Endpoint AI Security will use OpenAI's cyber models to connect risks across AI tools, developer environments, browsers, software, and packages, helping defenders understand what matters and what to address first.

Today, OpenAI and Zscaler are expanding their cybersecurity initiatives with the launch of Zscaler Endpoint AI Security. By mapping how various conditions on the endpoints combine into viable attack paths, this capability allows security teams to target and prioritize their highest-impact remediations.

AI is transforming the modern enterprise endpoint. As employees increasingly rely on AI assistants, coding agents, browser extensions, and connected services to drive productivity, they also introduce new complexities of configurations, permissions, and connections that security teams must navigate.

While traditional endpoint controls deliver essential visibility into vulnerabilities, malware, and policy violations, Zscaler Endpoint AI Security adds a crucial layer of context. By analyzing how distinct conditions interact across workflows, it helps defenders move past disjointed findings to see a clear, accurate picture of real-world risk.

Connecting signals across the modern endpoint

Zscaler Endpoint AI Security dynamically evaluates device and user risk using security-relevant information available on managed endpoints. It examines:

  • AI agents, assistants, and their configurations
  • IDEs, configurations, and installed extensions
  • Browsers, security settings, and installed extensions
  • System and software configurations
  • Python, npm, and other software packages

OpenAI's cyber models help analyze relationships across these signals and identify potential paths to compromise. The assessment can show how a sequence of conditions may contribute to credential exposure, unauthorized remote access, persistence, or data exfiltration.

For example, a developer may follow a routine setup step for a trusted repository, such as installing its software packages. If that process has privileges to execute repository-controlled code on a device that has access to the source code and developer credentials, then permissive security settings may turn a normal workflow into a path for credential exposure, persistence, or data loss. Zscaler Endpoint AI Security helps teams identify the combined exposure and helps to focus remediation on the controls that can break the potentially vulnerable path.

Leverage visibility into AI-enabled workflows to neutralize the attack chain

AI assistants and agents now sit alongside developer tools, browsers, extensions, and software packages in everyday enterprise workflows. Depending on how they are configured and authorized, AI agents can interact with files, applications, and external services, call local tools, run scripts, and invoke workflows that rely on third-party dependencies. Capabilities that were once concentrated on developer workstations are now reaching a much broader set of enterprise users.

In practical terms, AI is giving more users access to developer-like workflows. Even when users do not write code themselves, these workflows can introduce similar execution paths, dependencies, permissions, and supply chain risks across more of the endpoint fleet.

Some of the most consequential risks do not originate from just one AI agent, package, extension, or configuration in isolation. They usually emerge from their combined workflows and relationships. An agent may have access to business data, rely on a package with unexpected behavior, connect to an external service, and operate on a device with permissive controls. Individually, those conditions may appear manageable. Together, they may form a credible path to code execution, credential exposure, persistence, unauthorized remote access, or data loss.

By applying cybersecurity reasoning to this endpoint context, the assessment can help customers:

  • Identify high-impact risks that are difficult to recognize through isolated configuration checks
  • Understand how AI tools and developer workflows affect endpoint exposure
  • Prioritize remediation based on credible attack paths
  • Give security teams clearer context for investigation
  • Strengthen governance across extensions, packages, software, and AI tools

For red teams and defenders, Zscaler Endpoint AI Security provides a focused starting point for investigation. It complements red team assessments by connecting current, endpoint-specific conditions into a detailed attack chain. Security teams now have visibility to how an initial opportunity could lead to execution, and the path of execution that could expose credentials or other valuable access, where persistence may be possible, and which controls could interrupt the sequence.

This context helps red teams prioritize validation around the attack paths most relevant to the device. It also gives defenders a detailed remediation plan. The resulting report goes beyond listing separate weaknesses by explaining how one condition may enable the next, what the potential impact could be, and where the chain can be broken.

The goal is not to add another stream of alerts. It is to help security operations, endpoint engineering, red teams, and risk teams focus on the findings most likely to affect the organization.

Advancing AI-powered defense together

Zscaler Endpoint AI Security builds on the broader collaboration between OpenAI and Zscaler. Zscaler participates in OpenAI's Trusted Access for Cyber program, which helps verified defenders access advanced cyber capabilities with safeguards that scale alongside model capability.

Through this initiative, OpenAI brings advanced cybersecurity reasoning designed to support legitimate defensive work, while Zscaler brings enterprise security expertise, endpoint context, and the Zscaler Zero Trust Exchange platform. Together, the companies are helping customers understand how conditions across a rapidly expanding endpoint attack surface can combine into detailed attack paths, then turn that understanding into practical protection.

To learn more or request a demo, contact Zscaler at zscaler.com/request-a-demo.

form submtited
Obrigado por ler

Esta postagem foi útil??

Aviso legal: este post no blog foi criado pela Zscaler apenas para fins informativos e é fornecido "no estado em que se encontra", sem quaisquer garantias de exatidão, integridade ou confiabilidade. A Zscaler não se responsabiliza por quaisquer erros, omissões ou por quaisquer ações tomadas com base nas informações fornecidas. Quaisquer sites ou recursos de terceiros vinculados neste post são fornecidos apenas para sua conveniência, e a Zscaler não se responsabiliza por seu conteúdo ou práticas. Todo o conteúdo está sujeito a alterações sem aviso prévio. Ao acessar este blog, você concorda com estes termos e reconhece que é de sua exclusiva responsabilidade verificar e utilizar as informações conforme apropriado para suas necessidades.

Receba as últimas atualizações do blog da Zscaler na sua caixa de entrada

Ao enviar o formulário, você concorda com nossa política de privacidade.