Zscaler executive warns AI threats are moving at machine speed
Zscaler innovation chief Nathan Howe told the CAIO Connect Podcast at Zenith Live in Fontainebleau that AI-driven attacks now unfold too fast for traditional patching and perimeter defenses. He said organizations need immediate zero-trust isolation, better asset visibility and tighter governance for autonomous AI agents.
Why it matters: - AI tools are compressing the time between vulnerability discovery and exploitation, which raises the pressure on security teams to respond faster than they can patch. - Howe said enterprises need to shift from reactive patching to zero-trust isolation, or risk exposing apps, users and AI systems to machine-speed attacks. - Legacy systems that cannot be patched, including older industrial machines, face greater exposure unless they are isolated.
What happened: - Nathan Howe, Zscaler’s global vice president of innovation, spoke with Sanjay Puri on the CAIO Connect Podcast during Zenith Live at the Fontainebleau Resort. - Howe said artificial intelligence has changed the offensive cybersecurity landscape and made traditional perimeter security outdated. - He argued that software can now orchestrate multi-layered attacks in seconds.
The details: - Howe pointed to Project Glasswing and Mythos, an AI framework developed with Zscaler’s involvement, as examples of how automation changes vulnerability discovery. - Mythos can uncover hundreds of flaws instantly, while human researchers may take months to find and validate a few vulnerabilities. - Howe said Mythos does more than flag bugs. It can duplicate an application, run test exploits against the copy, gather intelligence and then carry out the final attack. - He said organizations can no longer focus only on “critical” flaws while leaving lower-priority risks open. - Howe said leaders first need full visibility into their digital environment because security depends on knowing every asset. - He said organizations should remove unnecessary systems from the network and use granular segmentation to limit lateral movement. - For systems that cannot be patched, Howe said enterprises must isolate them completely rather than try to modernize obsolete software. - Howe described zero trust as a model where no application, user or automated agent gets access until it clears strict contextual authorization and access controls. - He said Zscaler CEO Jay Chaudhry has championed that approach. - Howe said autonomous AI agents add a governance challenge because they are ephemeral and continuously spin up and down to perform tasks. - He argued AI agents should have identities separate from their human creators to preserve auditability and accountability. - Howe said identity management for these agents remains a major computational problem. - He also said many companies still have not fully classified their data across corporate systems, which weakens agent governance.
Between the lines: - Howe’s comments frame AI security as an architecture problem, not just a tooling problem. - His remarks suggest the biggest weakness is fragmentation: too many assets, too many identity states and too many disconnected controls. - The emphasis on centralized control reflects a broader push in cybersecurity toward fewer tools with broader policy enforcement.
What's next: - Howe expects software-as-a-service and corporate applications to adapt their architecture to AI-related risks over time, similar to how cloud systems evolved. - Industry debate will continue around protocols such as the Model Context Protocol for connecting AI systems. - Howe urged security leaders to focus on a single unified control platform and apply zero-trust policy across users, cloud workloads, autonomous robots and cellular-enabled devices.
The bottom line: - Howe’s message is that machine-speed threats leave little room for incremental fixes. Security teams need visibility, isolation and centralized control now, not after the next patch cycle.
Disclaimer: This article was produced by AGP Wire with the assistance of artificial intelligence based on original source content and has been refined to improve clarity, structure, and readability. This content is provided on an “as is” basis. While care has been taken in its preparation, it may contain inaccuracies or omissions, and readers should consult the original source and independently verify key information where appropriate. This content is for informational purposes only and does not constitute legal, financial, investment, or other professional advice.
Sign up for:
The World Newswire
The daily local news briefing you can trust. Every day. Subscribe now.
Check Your Email!
We sent a one-time activation link to: .
Confirm it's you by clicking the email link.
If the email is not in your inbox, check spam or try again.
Welcome back!
is already signed up. Check your inbox for updates.