Product1 distinct publisher3 min readUpdated
The pairing can now contain a single compromised asset and push east-west traffic into Palo Alto firewalls for Layer 7 inspection. Redirection is Linux-only; Windows has no date.
The Product Desk · Product desk
Compiled by The Product DeskSomething wrong?How this is made
The pairing can now contain a single compromised asset and push east-west traffic into Palo Alto firewalls for Layer 7 inspection. Redirection is Linux-only; Windows has no date.
Zero Networks has expanded its Palo Alto Networks integration from policy orchestration into enforcement, adding containment of individual compromised assets and redirection of selected internal traffic into Palo Alto firewalls for Layer 7 threat prevention [1][3][4][5]. The consequence is that east-west traffic which would normally stay inside the segment it started in can now be deeply inspected, and anything flagged as malicious is blocked with the affected asset cut off [5][6].
The original February 2025 pairing was a context pipe [1]. Zero Networks discovered and tagged assets without agents, Palo Alto firewalls consumed those tags as Dynamic Address Groups, and policy followed a device when it moved [2]. Useful, but it stopped at telling the firewall who was who.
What changed is the granularity of the response and the path traffic takes. Containment now applies to a single asset rather than requiring an entire segment to be pulled offline [4], which is the difference between a contained incident and a self-inflicted outage. Redirection puts firewall inspection on internal flows [5]. Assets and policies managed by Zero Networks also appear inside Strata Cloud Manager, so discovered inventory, applicable segmentation policy and the firewall controls inspecting the traffic sit in one console [8], with dynamic tagging keeping the view current as workloads shift and IP addresses change instead of hand-maintained static rules [9].
Now the fine print that decides whether any of this lands in a real estate: redirection runs on Linux today, and Windows support is planned [7]. Zero Networks itself frames Windows as much of the enterprise attack surface [7]. So the deep inspection story currently applies to the part of the fleet that is generally better instrumented already, while the domain-joined desktops and Windows servers where lateral movement usually happens wait. Automated microsegmentation, dynamic asset tagging, policy synchronization and Linux traffic redirection are available now [16]. Windows redirection has no release date [17].
The second half of the announcement is the AI agent piece, tying Zero Networks AI Segmentation, launched in April, to Prisma AIRS [10]. The problem statement is reasonable: agents connect directly into applications, models, databases and production systems while carrying valid credentials and broad permissions [11], which, according to Zero Networks, makes manipulated or compromised activity hard to distinguish from ordinary automation [12]. Its software identifies agents and sets deterministic, identity-based boundaries on where each may connect, blocks unsanctioned AI services outright, and can send traffic to Prisma AIRS for inspection of prompts, responses and data [13]. That integration also has no release date [17]. Of the six capabilities described, four ship and two do not [18].
Co-founder and Chief Executive Benny Lakunishok said customers "should not have to stitch together separate controls" for firewalls, internal assets and AI agents, with Zero Networks deciding which connections are permitted and Palo Alto running the deep inspection [14]. Neither company is asking for a network redesign; the work runs on enforcement capabilities both platforms already ship across on-premises, cloud, operational technology, Kubernetes and hybrid environments [15].
Watch for a Windows redirection date and, when it arrives, what redirecting Windows east-west traffic through a firewall does to latency and firewall capacity. Zero Networks, founded in 2019, has raised more than $100 million, with Highland Europe leading a $55 million Series C in June 2025 [19].
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
Customers can now contain a compromised asset on its own instead of pulling an entire segment offline.
Anything flagged as malicious gets blocked and the affected asset is cut off.
The second half of the announcement ties Zero Networks AI Segmentation, launched in April, to Prisma AIRS, the Palo Alto Networks product for securing AI traffic.
Zero Networks software identifies the agents and fixes deterministic, identity-based boundaries around where each one is allowed to connect; unsanctioned AI services can be blocked outright, and where a closer look is warranted the traffic goes to Prisma AIRS for inspection of the prompts, responses and data moving through the interaction.
Zero Networks expanded its integration with Palo Alto Networks, adding automated threat containment and a set of controls aimed at AI agents; the two companies first integrated their products in February 2025.
Zero Networks discovers and tags assets without agents; Palo Alto Networks firewalls take that context in as Dynamic Address Groups, and the policy follows a device when it moves.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Single vendor-sourced trade report
Everything rests on one siliconangle.com article derived from the Zero Networks announcement, with a CEO quote and no Palo Alto comment, no independent testing, no benchmark, and no customer reference. The article is internally specific and discloses its own limitation (Linux-only redirection, two undated capabilities), which lifts it above bare marketing copy but leaves capability claims unverified.
Shipping capabilities, no disclosed users
There are dated release events - the February 2025 initial integration and the August 2026 expansion with four generally available capabilities - so the product path is real and available. But no customer, deployment count, design partner or usage figure is disclosed, and the two capabilities carrying the AI narrative are undated, so observed uptake is effectively unmeasured beyond availability.
Unified-enforcement framing runs ahead of shipping scope
The 'single enforcement model' spanning firewalls, internal assets and AI agents is positioned as available today, but the AI-agent leg (Prisma AIRS inspection) has no release date and the enforcement leg redirects traffic only on Linux, with Windows - described in the article itself as much of the enterprise attack surface - unscheduled. No customer evidence or independent measurement supports the containment and inspection efficacy claims. The overstatement is moderate rather than severe because the article discloses the gaps rather than hiding them.
Vendor co-marketing relayed by a sponsor-funded outlet
The story originates as a joint go-to-market announcement: Zero Networks, a venture-funded startup that raised a $55 million Series C in June 2025, benefits from association with a platform incumbent, and the only voice quoted is its own CEO. The publisher appends explicit monetization and community-promotion appeals (theCUBE alumni network, AWS Marketplace purchase request), and no adversarial or independent voice appears anywhere in the cluster.
Facts of the announcement clear, effects unproven
What was announced, what ships, and what does not have a date are stated unambiguously and are unlikely to be wrong. Confidence is capped by single-publisher, single-voice sourcing and by the absence of any independent, customer or performance evidence for the containment, inspection and AI-agent control claims.
invest
A Connecticut judge just priced prompt injection: no fine, no e-filing2 distinct publishers
security
Google's reference agent approved a $10,000 refund on a $149 order, on purpose1 distinct publisher
build
Your agent needs the API call, not the API key1 distinct publisher
build
AgentWorm's lesson: the agent is the malware runtime, not the payload1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 20, 2026