Zscaler announced the acquisition of browser security startup SquareX to expand zero-trust enforcement into the browser layer, aiming to better control access and data handling in web sessions—particularly for unmanaged devices and third-party access. The deal positions browser-based controls as a way to apply security policy where work increasingly happens (SaaS and web apps) without requiring organizations to deploy full standalone enterprise browsers.
Reporting indicates SquareX’s approach relies on browser-based components (described as extensions and “hyper objects”) to enable capabilities such as device posture checks and data loss prevention (DLP) redaction, while keeping policy and enforcement centralized in the cloud rather than distributed across endpoints. Zscaler leadership framed the acquisition as reducing operational overhead by avoiding endpoint agents while still enabling consistent browser security controls across users and devices.

Track how attackers are adapting to this technology.
3 events from the most recent confirmed update back to the earliest known activity.
Zscaler announced on February 6, 2026 that it had acquired SquareX to extend zero-trust security into the browser. The deal adds browser-based device posture checks and DLP redaction without requiring endpoint agents or a full enterprise browser.
In April 2025, SquareX closed a $20 million Series A round led by SYN Ventures. The company had raised $26 million in total by the time of the acquisition announcement.
SquareX was founded in 2023 to develop browser security technology aimed at protecting access and data in web sessions.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.