News

Black Hat USA 2026: Security Vendors Go Agentic

Black Hat USA 2026 opened its main conference in Las Vegas amid a wave of security product announcements built around AI agents, cloud runtime data, nonhuman identity, exposure management and automated testing. The event runs Aug. 1-6 at Mandalay Bay.

Agentic AI was, of course, everywhere. It's increasingly being used by both the white hatters and the bad hackers, and security vendors are scrambling to keep pace with new stuff coming out all the time, so IT security pros eye this big conference carefully. Yesterday, we took a look at all the security research published during the event, again featuring agentic AI front and center.

Security vendors are addressing AI agents that invoke tools and APIs, cloud resources spread across multiple providers, data moving into large language model services, and software environments in which applications, identities and vulnerabilities cannot be assessed separately. Black Hat also added its first Healthcare Summit, held with HIMSS, broadening the event's focus on sector-specific infrastructure and operational risk.

The announcements reviewed for this roundup do not represent a single product category. They include cloud-native application protection, identity controls, data security, network defense, vulnerability detection, exposure management, autonomous penetration testing and open source AI testing. Several vendors describe their products as autonomous or agentic. Those terms refer to different capabilities, however, and availability varies. Some products are generally available, while others are scheduled for later release, offered through early-access programs or presented without a documented availability date.

Sysdig Brings Coordinated AI Experts to Cloud Defense
Sysdig announced Sysdig Secure AI, an AI-native offering built on the company's cloud-native application protection platform. The product uses coordinated AI security specialists to investigate, prioritize and support remediation using Sysdig's runtime telemetry. The company said the approach is intended to let security teams conduct investigations at machine speed while retaining human oversight and auditability.

  • Primary function: Investigate cloud security events, prioritize findings and recommend remediation.
  • Data foundation: Runtime telemetry from workloads and infrastructure monitored by Sysdig.
  • Architecture: The platform uses multiple coordinated AI security experts rather than a single general-purpose assistant.
  • Vendor metrics: Sysdig said customers can conduct more than 10 times as many investigations at 88% lower cost.
  • Availability: A specific general-availability date was not documented in the announcement.

ServiceNow Expands Its Autonomous Security Portfolio
ServiceNow introduced ServiceNow Autonomous Security, a portfolio spanning exposure management, vulnerability detection, cyber-physical systems, identity, incident response, cyber risk and compliance. The company is positioning the portfolio around the use of AI agents and workflow data across security operations.

  • Available capabilities: Agentic Exposure Management, Autonomous Remediation Agents, application security, dynamic application security testing and external attack-surface management.
  • Identity coverage: AI Agent Access Security and remediation for nonhuman identities are included among the available offerings.
  • Operational technology: The portfolio includes agentic security functions for cyber-physical environments.
  • December 2026 schedule: ServiceNow expects to release Tier 2 SOC AI Specialist, Vulnerability Resolution AI Specialist, Continuous Control Monitoring and Cryptographic Asset Compliance.
  • Availability distinction: Several capabilities are available now, while the named specialist and compliance products remain scheduled for later release.

SentinelOne Adds Governed, Closed-Loop SOC Response
SentinelOne announced governed, closed-loop response across its Singularity Platform. Purple AI and Singularity Hyperautomation can investigate alerts, reach verdicts and execute response actions within boundaries established by security teams. SentinelOne said each AI-driven action remains traceable, auditable and subject to human override.

  • Investigation: Purple AI can be invoked at multiple points within a Hyperautomation workflow.
  • Evidence: Investigation reports, verdicts and supporting evidence can feed directly into automation logic.
  • Response: Workflows can select and execute validated response actions based on investigation findings.
  • Governance: Teams determine where the system acts autonomously and where human approval is required.
  • Availability: The new Hyperautomation workflow capabilities are expected to become generally available later this quarter.

Rubrik Applies Runtime Controls to AI-Agent Identity
Rubrik unveiled Rubrik Agent Identity, a system intended to monitor AI agents and Model Context Protocol activity as agents invoke tools, access data and act for users. The product is designed to issue short-lived, narrowly scoped permissions for individual tool calls rather than giving agents persistent credentials.

  • Discovery: Inventories active agents, MCP servers, skills and plug-ins.
  • Delegation: Supports on-behalf-of identity federation so an agent's action can remain linked to a user or service.
  • Authorization: Applies just-in-time permissions for each tool invocation.
  • Decision process: Rubrik describes behavioral analysis, access policy and identity verification as three control checkpoints.
  • Identity integrations: The announcement names Microsoft Entra ID and Okta.
  • Availability: A general-availability date was not documented in the release.

Palo Alto Networks Updates PAN-OS for AI-Era Traffic
Palo Alto Networks announced PAN-OS 12.2 Ceres, an update the company said contains more than 55 security and operational enhancements. The release includes Advanced Virtual Patching, Advanced IP Defense, additional Network Security Agents in Strata Cloud Manager and new hardware intended for higher-throughput network environments.

  • Virtual patching: Advanced Virtual Patching is designed to apply protections before an organization's normal software patching cycle is complete.
  • IP controls: Advanced IP Defense combines real-time IP intelligence, contextual analysis and a zero-trust IP model.
  • Agent functions: Six Network Security Agents are presented through Strata Cloud Manager.
  • Hardware claims: Palo Alto Networks listed up to 300 Gbps of threat inspection, 1.4 Tbps of throughput and 5-microsecond latency for new systems.
  • Edge deployment: The PA-50R is a ruggedized appliance with 5G connectivity.
  • Availability: Advanced Virtual Patching is available through a PAN-OS software upgrade; other unreleased functions remain subject to the company's forward-looking availability caveat.

Tanium Adds Autonomous Endpoint and Exposure Functions
Tanium used Black Hat week to present autonomous security capabilities based on its Tanium Atlas platform. The announcement covers endpoint performance analysis, background AI agents, automated remediation sequences, external attack-surface management, attack-path mapping and guided threat hunting.

  • Automation: Tanium Automate can sequence endpoint actions and steps using REST or GraphQL APIs.
  • MCP integration: Tanium's Atlas MCP Server supports Claude, Microsoft Security Copilot, Microsoft Copilot Studio and other MCP clients.
  • External exposure: A Censys integration contributes internet-facing asset and exposure data.
  • Threat intelligence: The company also described integration with Google Threat Intelligence.
  • Availability: The release does not provide one common availability date for every announced function, and Tanium notes that future functionality may change.

Qualys Introduces Scanless Vulnerability Detection
Qualys launched InstaScan and Agent Insta for detecting exposure without waiting for a scheduled vulnerability scan. The service correlates newly disclosed vulnerabilities and vendor advisories against live asset inventory and telemetry from Qualys and third-party sources.

  • Detection model: The system evaluates exposure continuously instead of requiring a new scan job for each disclosure.
  • Response objective: Qualys said customers can identify affected assets within minutes of vulnerability disclosure.
  • Coverage claim: The company reported more than 90% detection coverage across technologies representing 60% to 70% of enterprise vulnerability volume.
  • Platform: The feature is part of Qualys Enterprise TruRisk Management.
  • Availability: Qualys said the capability is available now.

Netskope Unifies Data Security Across Cloud and AI Services
Netskope announced the Netskope One DataSec Command Center, a control plane for discovering, prioritizing and governing sensitive data across cloud, network, endpoint, email, on-premises and AI environments.

  • Discovery: Provides continuing discovery and prioritization of sensitive data and related exposures.
  • Lineage: Tracks how data moves between repositories, applications, users and AI services.
  • Policy: Supports adaptive controls and remediation through a unified interface.
  • Cloud coverage: The announcement names AWS, Google Cloud and Microsoft Azure object stores and databases.
  • SaaS and AI coverage: Supported environments include OneDrive, SharePoint, Google Drive, ChatGPT, Claude, Databricks, Snowflake and vector databases.
  • Availability: Netskope said general availability is planned during the current quarter.

AvePoint Adds Continuous Classification and Entra ID Recovery
AvePoint introduced Kinetic Classification and new Rapid Recovery capabilities for cloud data and identity environments. Kinetic Classification continuously re-evaluates data sensitivity instead of relying on a one-time label, while new recovery tools are intended to help organizations restore their most critical data and identity services first.

  • Cloud coverage: Classification extends across Microsoft 365, Google Workspace, AWS S3 and other business applications.
  • Continuous assessment: Sensitivity can be updated as data, access policies, ownership and AI-agent interactions change.
  • Recovery planning: The Rapid Recovery Wizard lets teams prebuild and sequence recovery plans.
  • Identity recovery: Express Recovery for Entra ID adds identity services to the prioritized restoration process.
  • Data prioritization: Intelligent recommendations identify critical data that should be restored first after an incident.

Horizon3 Extends Autonomous Testing to Web Applications
Horizon3.ai announced NodeZero WebApp Pentesting, an expansion of its autonomous penetration-testing platform for applications in preproduction and production environments. The system is designed to validate exploitability and follow attack paths from application weaknesses into credentials, internal systems, cloud resources and sensitive data.

  • Testing scope: Includes OWASP Top 10 categories and access-control weaknesses.
  • Attack chaining: Attempts to connect application flaws with credential theft, lateral movement, cloud pivots and data exposure.
  • Evidence: Produces proof of exploitability rather than reporting only potential weaknesses.
  • Early access: Horizon3.ai said 95 customers tested hundreds of applications during early access.
  • Vendor finding: The company reported that the beta program identified broken access-control paths missed during human testing.
  • Availability: The release documents the launch and early-access results but does not state a separate general-availability date.

Snyk Makes Continuous Offensive Security Generally Available
Snyk announced the general availability of Evo Continuous Offensive Security, which combines autonomous AI-powered penetration testing with AI-agent red teaming. The system continuously tests applications as they change and returns validated evidence of weaknesses that attackers could exploit.

  • Application context: Testing draws on findings from Snyk Code, Snyk Open Source and Snyk API & Web.
  • Exploit validation: The product tests architectural and business-logic weaknesses and provides proof of exploitability.
  • Agent testing: Agent Red Teaming simulates prompt injection, tool abuse, agent abuse and data exfiltration.
  • Availability: Evo Continuous Offensive Security, Agent Red Teaming and Snyk Secrets are generally available.

Drata Builds Governance Around AI-Agent Intent
Drata's AI Agent Governance product is designed to discover agents, record their owners and permissions, and apply policy before an agent takes an action. The service uses an operating model called the Trust Ladder, which moves agents through Training, Recommendation and Active stages as organizations gain confidence in their behavior.

  • Inventory: Registers agents and maps ownership, identity, permissions and operational scope.
  • Policy enforcement: Evaluates an agent's stated intent before allowing an action.
  • Governance stages: Training observes behavior, Recommendation proposes actions and Active permits approved autonomous execution.
  • Evidence: Drata describes tamper-evident records for audit and compliance workflows.
  • Initial ecosystem: The company said it is shipping first for Anthropic-based agents.
  • Availability: The official page describes limited availability and early access; an exact public release date is not documented.

Tenable Opens an Exchange for Security AI Agents
Tenable launched the CyberAgents Exchange, a free, open source community for publishing and sharing security-focused AI agents, skills, Model Context Protocol servers and multi-agent playbooks. The exchange provides code-level information about each component's creator, creation date and peer-supported status.

  • Launch catalog: More than 50 open source AI components were available at launch.
  • Component types: The catalog includes agents, reusable skills, MCP servers and multi-agent playbooks.
  • Security functions: Initial components cover vulnerability management, exposure analysis, threat hunting and security operations.
  • Founding members: SentinelOne and Recorded Future joined Tenable as founding participants.
  • Availability: The exchange is free to use, with no fees for listing or using agents.

What the Launches Mean for Cloud Security Operations
The product announcements show vendors attempting to connect previously separate security functions. Cloud runtime telemetry is being tied to AI-led investigations. Agent identities are being linked to users, tools and short-lived permissions. Exposure platforms are combining software vulnerabilities with external assets and attack paths. Data-security products are expanding their coverage to AI services, vector databases and Model Context Protocol connections.

The announcements also require careful attention to release status. Qualys describes its scanless detection capability as available now. ServiceNow distinguishes currently available functions from products expected in December. Netskope plans general availability during the current quarter. Drata describes limited availability, while Rubrik and Sysdig do not document a final general-availability date in their announcements. Palo Alto Networks identifies Advanced Virtual Patching as available through a software upgrade but places forward-looking caveats around unreleased functionality.

For cloud and infrastructure teams evaluating these products, the documented differences concern data sources, enforcement points and the degree of autonomy. Some offerings analyze runtime telemetry and recommend remediation. Others issue permissions, enforce intent policies, test applications, map attack paths or govern sensitive data. The common element is an effort to make security decisions with more immediate context from identities, workloads, APIs, software inventories and data flows.

Featured

Subscribe on YouTube