Skip to content
Beveiligingsnieuws

Black Hat USA 2026: Vendor Updates Roundup (Part 3)

Black Hat 2026

Black Hat USA 2026 in Las Vegas continues to deliver a steady stream of cybersecurity product and service announcements—many focused on AI, detection, and how organizations operationalize risk across expanding attack surfaces. This roundup is Part 3 of a vendor digest, designed to help you cut through the noise and quickly understand what’s new, what’s changed, and what may impact your security strategy.

Below you’ll find highlights ranging from SIEM telemetry integrations and vulnerability remediation agents to agent risk visibility and identity controls for autonomous AI tools.

Strategic platform moves and SIEM integrations

Several vendors used Black Hat USA 2026 to emphasize that “connected” tooling is becoming the baseline. That includes linking endpoint and identity signals into investigator-ready workflows, as well as integrating external threat intelligence to speed up recovery decisions.

Above Security and Falcon telemetry for insider risk investigations

Above Security announced a strategic investment from CrowdStrike Falcon Fund, alongside integration with the CrowdStrike Falcon platform. The partnership aims to let Falcon customers extend deployments and run ready-made insider risk investigations powered by Falcon Next-Gen SIEM telemetry. Above correlates endpoint, identity, and third-party data into case-ready investigations, then streams completed investigation results back into Falcon.

Commvault adds Google Threat Intelligence to Threat Scan

Commvault introduced an integration that brings Google Threat Intelligence into Commvault Threat Scan workflows. The stated goal is to help organizations locate cleaner recovery points faster, reduce downtime, and accelerate recovery after cyberattacks. This development builds on Commvault’s broader collaboration with Google Cloud, including expansion via Clumio and support for Google Cloud workloads.

FireMon integration with Palo Alto Networks Strata Cloud Manager

FireMon said it completed its integration with Palo Alto Networks Strata Cloud Manager. The announcement centers on delivering intelligent and interoperable solutions that support joint customers—helping them innovate faster while addressing complex security challenges.

Agentic security tooling expands: remediation, orchestration, and visibility

A recurring theme at Black Hat USA 2026 was the push toward agentic capabilities—systems that can analyze, coordinate, and respond while maintaining oversight. In practice, these updates focus on vulnerability remediation, risk investigation workflows, and discovery of AI tools operating across an organization.

ArmorCode launches Anya vulnerability remediation agents

ArmorCode unveiled four new Anya agents intended to help security teams tackle cloud risk analysis end to end. The agents are positioned to analyze cloud risks, evaluate vulnerability exploitability, identify mitigation approaches, and coordinate patch orchestration. ArmorCode also added Context Risk Graph capabilities to support broader attack path analysis, network reachability, and patch management.

DataBahn introduces Federated Search and Orchestration

DataBahn launched Federated Search and Orchestration as an expansion of its agentic data control plane. Instead of applying intelligence after data has already moved through pipelines, the company claims the platform can orchestrate intelligence as data moves. The pitch is that enterprises can answer one question across every datastore they own without copying the data, and then hand the investigation to an AI agent to complete.

Mimecast expands Incydr with Agent Risk Center and Managed Threat Response

Mimecast announced an expansion of its Incydr technology aimed at discovering AI agents and tools operating across an organization. It also ties each agent or tool back to the human who deployed it. Alongside this capability, Mimecast said it will include a relaunched Managed Threat Response (MTR) service and expanded Google Workspace integrations.

Rubrik adds runtime agent identity controls to Agent Cloud

Rubrik expanded its Agent Cloud platform with Rubrik Agent Identity, focused on controlling autonomous AI agent access permissions at runtime. The solution aims to reduce reliance on standing credentials by generating short-lived, scoped tokens for individual tool calls, integrating with identity providers such as Okta and Microsoft Entra ID. Before execution, tool requests pass through a gateway that performs semantic behavioral analysis, verifies infrastructure access policies, and authenticates session identities.

AI security initiatives: competitions, SOC pressure, and operational readiness

Black Hat USA 2026 also highlighted how quickly defenders are being pulled into securing AI-driven behaviors—especially as AI agents become a larger part of the enterprise attack surface. Several announcements directly address the need for hands-on security work and improved security operations workflows.

CrowdStrike launches an international AI security challenge

CrowdStrike announced an AI red teaming competition called AI Unlocked: Agents of Chaos, created with AWS. The competition challenges participants to exploit rogue AI agents using techniques such as prompt injection, with the goal of understanding emerging agentic AI security risks. The virtual event begins on August 31, includes a $100,000 prize pool, and is designed to give defenders practical experience securing AI agents as they expand across enterprises.

Prophet Security: AI in security operations meets alert overload

Prophet Security released its second annual State of AI in Security Operations report. Based on an independent survey of 250 IT and cybersecurity professionals, the report describes SOC teams reaching a “breaking point” due to alert overload, AI-powered attacks, and staffing shortages. It also reports that 96% of organizations are already using AI or actively evaluating it for security operations, organizations leave an average of 28% of security alerts uninvestigated, and 56% report increased AI-driven attacks over the past year.

Intel 471 adds new Verity471 AI capabilities

Intel 471 announced two new AI capabilities in its Verity471 platform: MCP471 and Agent471. With these additions, Verity471 reportedly makes pre-attack and threat-hunt intelligence more accessible and more operational, aiming to help organizations detect and respond rapidly.

Threat intelligence and exposure management: faster decisions and fuller coverage

Another set of announcements at Black Hat USA 2026 focused on threat intelligence and exposure management—specifically how quickly organizations can identify where risk resides and how to act on it. Several vendors also aimed to broaden coverage across cloud, identity, and AI ecosystems.

Dataminr updates the threat landscape picture

Dataminr published its 2026 Mid-Year Threat Landscape Report. Among the findings shared, the average patch window in H1 2026 increased by 11 days. The report also indicates that attackers can break out in under 30 minutes, and that Dataminr tracked a 69.2% jump in alerts from the second half of 2025.

SOCRadar launches Human Identity Exposure

SOCRadar announced Human Identity Exposure, an Identity & Access layer for its Extended Threat Intelligence (XTI) platform. The company claims it provides analysts with an instant, comprehensive snapshot of an individual’s identity risk. It brings together fragmented identity exposure data—including breach repositories, stealer infections, attacker telemetry, PII, data leaks, and CTI signals—into a single record intended to be decision-ready.

Tenable broadens AI exposure coverage and opens a community exchange

Tenable debuted CyberAgents Exchange, a free open source AI agent exchange built for cybersecurity teams. The exchange is positioned as vendor-agnostic, enabling professionals to discover, share, and build trusted AI agents, skills, MCP servers, and multi-agent playbooks. Tenable also says the exchange includes code-level transparency about who built what and how it works, with founding members including SentinelOne and Recorded Future. Alongside this, Tenable announced Tenable One AI Exposure capabilities designed to expand coverage across major AI platforms and key developer tools.

Securing AI assistants, coding agents, and agent connectivity

Many organizations are deploying AI assistants and coding agents, and that creates new risks—from prompt injection to unwanted data exfiltration and persistent tool access. Several Black Hat USA 2026 announcements addressed these issues by inserting controls around agent connectivity and runtime execution.

Menlo Security protects AI assistants with runtime security

Menlo Security extended its cloud-based Menlo Agent Runtime Security platform to protect AI assistants and coding agents from prompt injection attacks and data exfiltration. The platform routes agent web traffic through a cloud environment that sanitizes files and strips hidden instructions before an agent receives content. It also uses adaptive data loss prevention controls to mask sensitive information, and token-based authentication to assign per-agent session identity and enforce specific web access policies.

Surf AI integrates with Claude’s Compliance API

Surf AI announced an integration with Claude’s Compliance API. The company also introduced general availability of Exposure Reduction Operations, extending the platform to govern AI model connectivity in relation to identity, cloud, and SaaS exposures. Surf AI says the integration pulls activity logs from the Claude environment, maps connection and access paths to an accountable owner within a Context Graph, and operationalizes remediation—such as disabling unsanctioned MCP integrations and removing lingering Claude access after offboarding.

VanishID adds AI exploitability management and external identity protection

VanishID announced AI Exploitability Management and External Identity Protection. AI Exploitability Management operates externally without internal system credentials or installations, and it breaks down more than 40 attack scenarios to compute individual risk scores based on public data availability. External Identity Protection introduces four categories of autonomous agents—detection, analyst, remediation, and residual risk—to scan data brokers, dark web repositories, and public records. It also includes automated remediation agents that submit and verify opt-out requests to erase public profiles.

New research and platform evolution in the cloud security stack

Beyond new tools, vendors also used Black Hat USA 2026 to share platform evolution and research outputs. These announcements can be useful for teams evaluating vendor roadmaps or planning platform upgrades.

Palo Alto Networks evolves PAN-OS for the AI era

Palo Alto Networks announced a purpose-built evolution of PAN-OS for what it called the Frontier AI era. PAN-OS 12.2 Ceres introduces Advanced Virtual Patching, automated blocking for direct-to-IP attacks, six AI security agents, and expanded hardware for securing AI data centers and critical infrastructure.

In addition, Palo Alto Networks Unit 42 released new threat research. It described how an AI system built by Unit 42 researchers uncovered more than 14,000 previously unknown vulnerabilities across nearly 4,000 widely used open source projects. The research also states that analysis of more than 4 million reports found that 45.32% of malware with command-and-control activity communicates directly with IP addresses.

Thales releases Luna 8 for quantum threat key protection

Thales released Luna 8, its first in-house designed hardware security module. The system is built to secure, store, protect, and manage cryptographic keys against quantum threats, with an upgradeable architecture intended to integrate future cryptographic algorithms while maintaining backward compatibility with existing interfaces. Thales also said Luna 8 is undergoing independent evaluation for FIPS 140-3 Level 3 and EU Common Criteria standards.

Security operations modernization: unified solutions and cyber-defense innovation

Some announcements at Black Hat USA 2026 focused less on a single capability and more on how organizations can consolidate defenses across exposure, identity, and response.

ServiceNow launches unified prevention-first security solutions

ServiceNow announced six unified solutions aimed at prevention-first, AI-native cyber defense across unified exposure management, identity and access security, cyber-physical security, cyber risk and compliance, and agentic incident response. The company also unveiled a newly formed AI Center for Cyber Defense, described as a global hub for security innovation.

Proofpoint announces an OEM program for threat intelligence

Proofpoint announced an OEM Program offering OEM-ready threat intelligence and detection capabilities for technology providers, cybersecurity vendors, managed service providers, and platform companies. The program is positioned to reduce the time, cost, and operational effort of building threat intelligence from scratch—helping partners accelerate product roadmaps and bring differentiated offerings to market faster.

Trustmi targets B2B fraud with an AI investigation agent

Trustmi unveiled an AI Investigation Agent designed for B2B fraud detection. It introduces agentic workflows that investigate suspicious activity, reason across business workflows, and connect evidence across systems. Trustmi also announced two emerging payment fraud threats: Ghost Executive and Deadline Deception. The former involves fabricating an executive’s approval so payment appears already decided, while the latter pairs fraudulent paperwork with a false deadline to pressure employees into releasing funds.

Key takeaways from Part 3

Across these announcements, Black Hat USA 2026 points to three practical directions: tighter integration between security data sources, more agentic security workflows (with stronger identity and runtime controls), and broader coverage for AI-related risk. Whether you’re evaluating SIEM extensions, recovery acceleration, exposure reduction, or SOC modernization, these vendor updates offer concrete signals about where security products are heading next.

If you’re comparing options, it helps to map each announcement to a business outcome—like faster investigation case-building, reduced recovery time, fewer uninvestigated alerts, or safer execution of AI agent actions.

Source: https://www.securityweek.com/black-hat-usa-2026-summary-of-vendor-announcements-part-3/