 |
THE ZHERO DIGEST |
#001 September 2026 7 min read |
What changed, what to check, what shipped. For the people who run Zscaler.
|
|
A note from Daniele
I started this newsletter for a selfish reason.
I run Zscaler tenants for customers. Every summer, release notes pile up, a few trust advisories carry a date I should have written down, and I find out in October. So I built the email I wanted to receive: once a month, what changed in Zscaler, what to check in your own tenant, and what shipped in ZHERO.
One thing struck me this summer. Zscaler shipped Health360, a free score of how healthy your deployment is. That is Zscaler making our question official. Health360 grades the plumbing. ZHERO grades the configuration, rule by rule, and lets you change it. Both belong on the same desk.
This first issue covers July to mid-September, so the Release Radar counts 85 releases. Nothing was cut: the important ones are on top, the rest is one click away.
Reply and tell me what you want more of next month.
Daniele
|
|
|
WHAT CHANGED
Zscaler is moving into the browser. Enterprise Browser for Zero Trust Browser (1 Jul) puts private app access and daily browser protection in one place; WebMCP Security Controls (27 Aug) extend policy to the tool calls AI agents make inside the browser; and the Zero Trust Browser extension now runs inside the embedded browser of the ChatGPT desktop app (9 Sep). The browser is becoming a policy enforcement point in its own right, next to Client Connector. If Zero Trust Browser is in your entitlement and nobody ever turned it on, this is the quarter to ask why.
AI governance is now a configuration item, not a PDF. Tenant Profiles now cover Claude (14 Aug): you can restrict access to specific workspace IDs, with API support. Cloud App Control gets a granular Upload action for Google Gemini (31 Aug). And Zscaler announced policy enforcement inside Claude via inference hooks (5 Aug). Practical reading: open your AI & ML rules in Cloud App Control. If they still say Allow with no granular action and no tenant profile, the policy your board thinks you have is not the one in the console.
Zscaler now answers "is my deployment healthy?" itself. Health360 (5 Aug) scores your deployment on best practices, connector health and service health, with trends and remediation steps: tunnel redundancy, double tunneling, load distribution. Free in Experience Center, GA planned for the second half of 2026, ZIA and Client Connector first. Our reading: Health360 tells you whether the plumbing is sound. Which rule or access policy is missing a posture condition is the layer ZHERO reads.
Read the Hugging Face breach for the questions, not the drama. Zscaler's write-up (31 Aug) of the incident where an unreleased model broke out of its sandbox and ran a full kill chain on its own ends with a list every security leader is now being asked: who can reach what, from where, with which device. Those are configuration questions. They are the reason this newsletter exists.
Also worth a line: the AI/ML categorization model for Miscellaneous and Unknown URLs was upgraded (10 Aug; if you allow those categories anywhere, expect some traffic to move); Sandbox Patient Zero alerts changed (29 Aug; check your alert subscriptions); ZDX replaced Copilot with ZAgent (2 Sep); and if you ever need to explain SSE to a non-technical audience, Zscaler's SSE Architecture Explained is the cleanest version I have seen.
|
|
|
ACTION NEEDED
Advisories worth a calendar entry. All from the Zscaler Trust Portal.
- By 30 Sep. Experience Center: the standalone admin portals are phased out. The default sign-on already lands on Experience Center (since 19 Jun), and a cohort of tenants is being upgraded automatically from 6 September. Before the switch: review admin roles and legacy IdP admin access, and hunt for bookmarks, runbooks and scripts that still point at the old portals. Self-initiating the upgrade beats being surprised by it.
- By 13 Oct. Client Connector on Windows 10: support ends. Zscaler keeps supporting Windows 10 for twelve months after Microsoft's end of support, then stops. Count your Windows 10 devices now (see What to check below) and plan the OS upgrades, not the ZCC ones.
- Client Connector 4.8 builds before 4.8.0.190: rare Windows crash on upgrade or uninstall. The advisory explains the driver timing issue; the 4.8.0.291 and 4.9.0.455 installers (14 Aug) now embed the mitigation logic. Check which 4.8 builds are still in the fleet and upgrade with the mitigating installer, not with a mass uninstall.
- During September. Microsoft 365 Copilot moves under a new FQDN; One Click keeps excluding it. Zscaler explains the impact on One Click (5 Sep). If you handled Copilot with manual bypasses, SSL exemptions or firewall rules on the old endpoints, they are about to stop matching. One Click is exactly the kind of configuration you set once and forget: this is the month to open it.
- macOS Tahoe and Sequoia: intermittent loss of connectivity with route-based interception. The native macOS firewall delays or drops ZCC traffic after boot and wake (15 Jul). If your Mac forwarding profiles use route-based traffic interception, read the workaround and decide per profile.
- If you run Client Connector on Linux from Debian packages. An expired package-signing key means six .deb builds no longer auto-upgrade (14 Aug): 4.2.1.64, 4.2.1.114, 4.2.1.122 and 3.7.2.64, 3.7.2.70, 3.7.2.76. Zscaler has pulled those packages; the installed builds keep working, but the next upgrade is a manual install with the refreshed packages. Filter Enrolled Devices by Linux and client version, count the devices on those builds and plan the manual step.
- If you run ZPA infrastructure on RHEL or in Azure. A Red Hat update can prevent App Connectors, Private Service Edges, Private Cloud Controllers and Network Connectors on RHEL 9.x from booting after an OS upgrade (follow-up with next steps, 21 Jul); updated images with a 4 GB boot partition shipped on 23 Jul. In Azure, opt out of the Microsoft Azure Network Adapter for ZPA VMs: automatic transitions started on 1 August. And the Manager software is at 26.57.1 (9 Sep). ZHERO's ZPA Infrastructure dashboard lists your connectors with version and platform, if you would rather not open them one by one.
|
|
|
RELEASE RADAR
Every Zscaler release from 1 July to 12 September, by product.
Worth your attention
- Export Diagnostics Logs (ZPA, 7 Aug). Diagnostics logs export to CSV, with background jobs for the big ones. The thing every ZPA troubleshooting session ended up doing by copy-paste.
- Partial Configuration Handling Mechanism (ZIA, 17 Jul). A new Advanced Setting decides how a Service Edge enforces policy when it only has a partial configuration during a transient disruption. Three modes, one decision about fail-open versus fail-closed. Worth a deliberate choice.
- Support for Claude in Tenant Profile (ZIA, 14 Aug) and Upload action for Google Gemini (ZIA, 31 Aug). AI governance as configuration, see What changed.
- New Network Applications in Firewall Control (ZIA, 17 Jul). WARP, DoQ, DoH3, STOMP and AMQP are now identifiable network applications. Encrypted DNS and third-party tunnels finally have a name in your firewall rules.
- Adaptive Access Engine in Diagnostics and Access Policies (ZPA, 20 Jul). Adaptive Access Profiles become a criterion in access policies and a filter in User Activity diagnostics.
- Client Connector 4.8.0.291 and 4.9.0.455 (14 Aug). Installers with the blue-screen mitigation built in, plus a fix for the Firewall posture check failing when a firewall profile was disabled by GPO. 4.10 (14 Aug) adds automatic installation of the Endpoint AI Security software.
- Manager Software Updates 26.57.1 (ZPA, 9 Sep). Recommended RPM packages for App Connector, Private Service Edge, Private Cloud Controller and Network Connector on RHEL 8.x and 9.x. Boring, and exactly what a ZPA admin has to schedule.
- Enterprise Browser for Zero Trust Browser (ZIA and ZPA, 1 Jul). See What changed.
- Device Count Enhancement (ZDX, 4 Sep). Device counts now account for devices shared by multiple users. Small, and it changes the numbers in your reports.
|
|
|
WHAT TO CHECK
Is your Client Connector fleet ready for October?
Three of the advisories above land on the same layer: Windows 10 devices lose ZCC support on 13 October, 4.8 builds before 4.8.0.190 need the mitigating installer, and Mac fleets on Tahoe or Sequoia may need a forwarding profile decision. The risk is not one device. It is the long tail nobody counts: the laptops that never got the OS upgrade, the pilot group still on an old 4.8 build, the ten Macs in a country office.
How to check it by hand. In Experience Center (or the Mobile Admin Portal, while you still have it) open Client Connector > Enrolled Devices. Filter by OS version and export the list; then filter by Client Connector version and export again. In a spreadsheet, pivot on OS version to count Windows 10 devices, and on client version to find every 4.8 build below 4.8.0.190. Do the same for macOS by version. Repeat monthly until October, because the fleet moves.
The shortcut. ZCC Fleet Health in ZHERO shows the version and OS distribution of the whole fleet on one page, with a drill-down to the devices behind each bar, and scores each app profile so the worst ones come first. Same data, no pivot table.
|
|
|
FROM THE BLOG
|
|
|
FROM ZHERO
Four releases of ZHERO since July. The two that change what you can do:
v3.1.15 (14 Aug), "Posture Enforced, Audit Unified". New analysis checks flag ZPA Access Policies that grant access with no domain-join and no EDR/antivirus posture condition (machine-tunnel and block rules correctly excluded), plus a firewall default rule left on Allow and SSL inspection bypasses spread across policies. ZCC posture profiles become first-class entities, cross-linked both ways with the ZPA criterion that enforces them. One audit timeline now merges changes made directly in the Zscaler console with the work your team drove from ZHERO. And the privacy line gets stronger: no configuration snapshots in our cloud, field-level diffs from a store that never leaves the browser.
v3.1.0 (13 Jul), "Change at Scale, a Score You Can Trust". Mass Edit applies one reviewed change to many entities, with a plain-language diff before commit. The posture score becomes a trend with per-change attribution, and a projected score previews your staged changes.
Also shipped: v3.1.13 (15 Jul) makes QUIC exposure detection exact per tenant and places the one-click Block QUIC rule right above the rule that let QUIC through, plus resizable side panels; v3.1.24 (4 Sep) is a performance release, with the initial analysis of a large tenant completing in about half the time and the ZCC fleet import surviving very large device exports. Full notes in the changelog.
|
|
|
Before you go
If one of the checks above turned up something you would rather not have found, bring your tenant to a demo: in about an hour we read it together, on your configuration or on one of ours. Pick a time here.
Or just reply to this email. It lands in my inbox, not in a queue.
Daniele Tieghi Founder, ZHERO LinkedIn
|
|
You receive The ZHERO Digest #001 because you subscribed at zhero.ai or asked ZHERO to keep you posted. One email a month, no automation in between.
ZHERO Srl, Via Friuli 8/B, 20135 Milano, Italy
Unsubscribe · View in browser · Privacy
|
|