惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Google DeepMind News
Google DeepMind News
L
LangChain Blog
H
Help Net Security
博客园_首页
T
Tailwind CSS Blog
Microsoft Security Blog
Microsoft Security Blog
T
The Blog of Author Tim Ferriss
雷峰网
雷峰网
Recent Announcements
Recent Announcements
D
DataBreaches.Net
U
Unit 42
Vercel News
Vercel News
I
InfoQ
Martin Fowler
Martin Fowler
Microsoft Azure Blog
Microsoft Azure Blog
Apple Machine Learning Research
Apple Machine Learning Research
S
SegmentFault 最新的问题
Jina AI
Jina AI
博客园 - 叶小钗
博客园 - 【当耐特】
罗磊的独立博客
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
月光博客
月光博客
Last Week in AI
Last Week in AI

Security Research | Blog

Operation RapidRust: New APT36 Malware Tools | ThreatLabz SloppyRAT: A New Tool For Ransomware Attacks | ThreatLabz Microsoft Exchange Vulnerability: What Admins Should Do C2Looper Backdoor Uses GitHub for C2 | ThreatLabz Midnight Blizzard launches CaptiveCrunch | ThreatLabz ChainDrop NPM Worm Analysis | ThreatLabz Abyssos Modular RAT Analysis | ThreatLabz Ransomware Victims Research | ThreatLabz Targeted Attack on Middle East Govts (Part 2) | ThreatLabz Technical Analysis of GoGRPC | ThreatLabz Targeted Attack on Middle East Govts (Part 1) | ThreatLabz ClaudeFix: Shared Claude Chats Meet ClickFix | Zscaler Why Do F1 Teams Need Cybersecurity, and What Is AI’s Role? Indirect Prompt Injection Targets AI Agents | ThreatLabz Splunk Enterprise RCE (CVE-2026-20253) | ThreatLabz Edgecution: Malicious Edge Extension Backdoor | ThreatLabz SmartApeSG Supply Chain Attack Targets Okendo | ThreatLabz AI Generated ClickFix Attack Delivers SmartRAT | ThreatLabz What the ThreatLabz 2026 Phishing and Initial Access Report Means for the Public Sector | Zscaler Shai-Hulud: Miasma, Hades, & AI Scanner Evasion | ThreatLabz Zscaler ThreatLabz 2026 Phishing and Initial Access Report Technical Analysis of MLTBackdoor | ThreatLabz When the Scanner Starts Thinking: Learnings from Mythos & GPT 5.5 Cyber in Security Testing | Zscaler OpenClaw Skill Distributes Remcos & GhostLoader | ThreatLabz Tropic Trooper: AdaptixC2 + Custom Beacon | ThreatLabz Do not delete blog (testing) | Zscaler Payouts King Takes Aim at the Ransomware Throne | ThreatLabz The Alibaba Incident and Why Zero Trust Matters More Than Ever In-Memory Loader Drops ScreenConnect | ThreatLabz Supply Chain Attacks Surge in March 2026 | ThreatLabz
Frontier AI and Enterprise Readiness | Zscaler
Deepen Desai · 2026-08-07 · via Security Research | Blog

Zscaler Blog

Get the latest Zscaler blog updates in your inbox

The Breach

It was 9:14 AM when the CISO's VPN connection momentarily dropped, something that normally wouldn’t cause any concern. What he couldn't see was that attackers had already exploited a pre-authentication flaw in the VPN appliance itself, gaining access before any login ever occurred. From there, they extracted stored credentials, forged an identity as his Director of Security Operations, and authenticated through a trust chain that never questioned traffic originating from VPN infrastructure.

By 9:22, that stolen identity was requesting application access at machine speed, hundreds of grants per minute across a footprint of over 4,200 apps, until it reached an ungoverned internal AI endpoint sitting on top of three years of proprietary R&D data. Exfiltration began immediately, disguised as normal outbound traffic. By 9:33, the entire sequence had been autonomously replicated across nine additional VPN entry points. 

While the scenario is hypothetical, it’s increasingly likely—pieced together from findings encountered during the course of conducting our Frontier AI Preparedness Assessments. Its implications are chilling. For enterprises globally, this scenario is rapidly becoming an impending reality. As the US National Security Agency warned recently, fully autonomous cyberattacks are mere months, not years, away.

Preparing for the Storm

Three months ago, we embarked on a journey to help organizations prepare by examining their readiness against these autonomous attacks.

Frontier AI refers to the most advanced, highly capable foundation models that push the boundaries of current artificial intelligence. Unlike traditional, narrow AI, these models possess sophisticated reasoning, planning, and autonomous execution capabilities. In the hands of adversaries, they don't necessarily uncover exotic, never-before-seen zero-days; instead, they find small gaps in the armor and chain them into complete attack paths at machine speed. Like a burglar testing every lock, window, and alarm on an entire street in seconds, an AI adversary compresses the kill chain from initial reconnaissance to full data exfiltration in minutes.

How We Assessed Readiness

To accurately understand and measure this threat, we worked closely with leading Frontier AI companies, gaining early access to their most advanced models. It is important to note that to maintain strict data privacy and security, we deliberately did not use these models directly on any live enterprise data other than our own. Instead, we leveraged them in isolated, controlled simulation environments to emulate the specific attack patterns and velocity of frontier AI.

Using these insights, we evaluated organizations on a 0-100 scale, assessing various axes including data protection, attack surface shielding, and decoy deployment to determine how well they could withstand an autonomous, machine-speed attack.

Current State of Enterprise Readiness for Frontier AI

Across hundreds of enterprises assessed in 2026, the average Frontier AI Readiness Score sat at 37 out of 100. Even more telling, the average AI governance pillar score was just 2.1 out of 20, proving that enterprise readiness for these advanced threats remains virtually at "year zero."

  • 9 out of 10 organizations maintain exposed VPN appliances that serve as prime pre-authentication attack surfaces.
  • More than 1/3 of enterprises leave CISA Known Exploited Vulnerabilities (KEVs) active on internet-facing assets.
  • 100% of assessed organizations lack identity-based authentication for their AI systems.
  • ~36% is the average proportion of encrypted traffic inspected by enterprises, falling far short of the 70% threshold required for inline security controls to function effectively.
  • 64% of organizations use broad segmentation configurations. In one case, 195 wildcard domains exposed over 108,000 applications, creating a worst-case blast radius where a single compromised identity could reach up to 483,250 applications.

When your security stack is blind to nearly two-thirds of encrypted traffic and legacy VPNs expose massive blast radiuses, you aren't just leaving the door unlocked, you are building a high-speed freeway for AI-driven attack chains.

Architecture Beats AI: Closing Critical Gaps Today

You cannot out-algorithm an autonomous attack. When the adversary operates at machine speed, trying to detect and respond in real-time is a losing battle. The winning strategy isn't layering on more reactive AI; it's relying on a fundamentally superior architecture.

Architecture beats AI because a true Zero Trust platform denies exploitable paths by design. By eliminating the attack surface and making lateral movement mathematically impossible, you neutralize the AI's speed advantage entirely.

To build true resilience against machine-speed threats, security leaders should execute a focused 90-day sprint on four core actions:

  • Flip the Switch on Enforcement: Transition dormant controls like IPS, malicious IP blocking, and domain fronting protection from monitor-only to full enforcement mode.
  • Shield VPNs & Patch Known Exploits: Move exposed VPN appliances behind brokered Zero Trust access and patch CISA Known Exploited Vulnerabilities on public-facing assets immediately. If you can’t patch them, hide them. 
  • Gate AI Surfaces & Inspect Encrypted Traffic: Place every AI endpoint and copilot behind enterprise identity verification, and raise SSL/TLS inspection to at least 70% by default.
  • Kill Wildcard Domains & Deploy Deception: Replace broad wildcard domain rules with named FQDNs, and deploy active decoys near critical applications to automatically detect and revoke compromised sessions.

Don't try to outrun the machine. Out-architect it.

To learn more about our findings and how to assess your own organization's readiness, read the full report

form submtited

Thank you for reading

Was this post useful?

Disclaimer: This blog post has been created by Zscaler for informational purposes only and is provided "as is" without any guarantees of accuracy, completeness or reliability. Zscaler assumes no responsibility for any errors or omissions or for any actions taken based on the information provided. Any third-party websites or resources linked in this blog post are provided for convenience only, and Zscaler is not responsible for their content or practices. All content is subject to change without notice. By accessing this blog, you agree to these terms and acknowledge your sole responsibility to verify and use the information as appropriate for your needs.

Explore more Zscaler blogs

When the Scanner Starts Thinking: Learnings from Mythos & GPT 5.5 Cyber in Security Testing

When the Scanner Starts Thinking: Learnings from Mythos & GPT 5.5 Cyber in Security Testing

A human face generated by pixels and computer bytes.

Zscaler CXO Monthly Roundup | June 2026

From Launch to Leadership: Zscaler AI Protect Raises the Bar for AI Security

From Launch to Leadership: Zscaler AI Protect Raises the Bar for AI Security

Get the latest Zscaler blog updates in your inbox

By submitting the form, you are agreeing to our privacy policy.