Black Hat 2026 brought a lot of new security promises to the table this week in Las Vegas. Still, the sheer range makes it hard to quickly see what really changes: which tools go further with AI, what automation is being added, and where the emphasis is placed on governance, recovery, and protection of sensitive data. Below you’ll find a compact, substantive summary of the key vendor announcements SecurityWeek highlighted during Black Hat 2026.
Agentic AI for exposure and vulnerabilities
A striking common thread is the shift from “manual testing” to continuous, agent-driven workflows. Astelia launched agentic AI exposure management for its platform. This includes automated reachability analysis and remediation processes across the entire vulnerability lifecycle.
What sets this apart is that the platform can evaluate new alerts based on reachability and operational impact. It can then align remediation between security and IT teams. Crucially: human approval remains in place at key decision moments, and all actions are logged so they are controllable and auditable.
Continuous data classification instead of one-off labels
AvePoint introduced a new approach to data classification. With Kinetic Classification, data insights are no longer treated as a one-time task, but as something that is continuously re-assessed. The goal is to revisit sensitivity levels inside Microsoft 365, Google Workspace, and other business applications.
In addition, AvePoint expanded its Rapid Recovery system with extra tooling. This should help teams prioritize restoring critical data after incidents faster and more precisely, including a wizard and a faster recovery step for Entra ID.
Threats with AI: from exploit development to the supply chain
CrowdStrike published its 2026 Threat Hunting Report and leans heavily on one idea: AI is now embedded in modern attacks. According to the report, attackers use AI to execute attacks faster, to exploit vulnerabilities within hours of public disclosure, and to specifically target enterprise AI systems and parts of the software supply chain.
Alongside this automation, the report also notes an increase in cloud-focused attacks and incidents involving AI-supply-chain compromises. Misuse of trusted authentication flows also gets attention, giving organizations extra reason to not only use AI environments, but to secure them properly.
Cisco Talos: how AI and LLMs accelerate real-world attack tactics
Cisco Talos also shared new research on how AI and LLMs are used in real cyberattacks. The team bases its findings on, among other things, recovered prompt logs, attack tools, and communications from threat actors.
The core takeaway: in many cases, attackers don’t need “sophisticated jailbreaks.” Strong groups more often use AI as development assistance to shape malicious code and exploit development faster. Also, AI is deployed across multiple stages of the attack chain, from development to operational execution.
Governance for AI agents: discover, monitor, and prove
While one group builds tools to automate more, other vendors try to manage the risk of autonomy. Drata expanded its Trust Management Platform with a component for AI Agent Governance, available via limited availability.
The goal of this module is to discover, monitor, and govern AI agents within organizations—and make their traceability demonstrable. The first rollout starts with Anthropic, with early-access customers that, according to the announcement, are already running end-to-end in production.
Autonomous pentesting that “actually exploits”
Horizon3 announced an expansion for its NodeZero platform. With NodeZero WebApp Pentesting, the platform can autonomously and “safely” test web applications in the same way attackers would.
The claim is that the output isn’t just about theoretical weaknesses, but about what is truly exploitable. For each attack path, it also quantifies business impact and maps routes to tactics used by known threat actors. The announcement comes shortly after a $250 million investment.
RMM Guard: limit remote monitoring against misuse
Huntress expanded its Managed ESPM approach with a free component: RMM Guard. This applies to customers who have an agent installed. The focus is on detecting and blocking rogue remote monitoring and management tools that attackers use to gain access—and to maintain it.
According to the announcement, RMM Guard identifies and blocks unauthorized RMM software on endpoints before it can be used for persistence or remote control. Teams can also specify which RMM tools are allowed and which are not. There are also additional protection measures for isolated machines, so approved remote access tools don’t automatically get unlimited access.
This release also comes against the backdrop of a newly reported N-central RMM vulnerability being actively exploited in the wild.
Secure coding agents at endpoint level
Legit Security released VibeGuard 2.0, an endpoint-based solution that supports AI coding agents while protecting them. It focuses on discovering and securing agents such as Claude Code, Cursor, and GitHub Copilot.
The approach is concrete: policy enforcement and granular controls are applied on the endpoint to specific agent commands and tools. New features include guardrails around skill discovery, blocking risky actions, and security controls around MCP.
In addition, the update includes command monitoring for built-in or custom policies, plus anti-tampering protection. The idea is clear: prevent an agent or user from disabling a security layer.
Make sensitive data visible and route it to remediation
Netskope announced DataSec Command Center. Part of Netskope One, it positions itself as a unified control plane: the system discovers, understands, and tracks sensitive data regardless of where it resides or moves—from AI environments to the network.
For security teams, this should provide end-to-end visibility. Even more importantly, it claims a “seamless path” from discovery to actual remediation across the entire data landscape.
Test security continuously with a pay-as-you-go model
ProjectDiscovery made its platform Neo v1 generally available and introduced a pay-as-you-go model. After six months of private beta with enterprise customers, ProjectDiscovery wants to help teams move from periodic, manual testing to continuous security running in parallel with development.
With Neo, teams can deploy autonomous security testing for code, applications, APIs, cloud, and networks. The biggest change for organizations is said to be easier access: fewer traditional procurement and budget barriers, according to the announcement.
Scanless vulnerability detection with advisories as the starting point
Qualys added scanless detection to its Enterprise TruRisk Management (ETM) platform with InstaScan. Behind the scenes, this runs on an AI agent (Agent Insta) that continuously maps newly published vendor advisories to an organization’s asset inventory and telemetry.
The platform normalizes software identities into standard identifiers, such as CPEs and PURLs. It then flags affected assets and provides findings with confidence scoring. Instead of waiting for scheduled scans, the risk is therefore linked sooner as soon as the information becomes available.
Automate certificate management with integrations
Sectigo launched Sectigo Orchestration Gateway (SOG), an automation layer within its Sectigo Certificate Manager. With it, IT teams can—according to the announcement—automate certificate discovery, issuance, renewal, and deployment through a single installation.
It involves multiple components—such as servers, load balancers, CDNs, WAFs, and access systems—with native support for, among others, IIS, Apache, F5, NGINX, and Citrix. There are also direct integrations with credential managers such as CyberArk, Delinea, HashiCorp, and BeyondTrust for just-in-time retrieval of credentials.
Autonomous defense, “headless,” and cloud runtime protection
Sevii expanded its Sevii Autonomous Defense & Remediation (ADR) platform with an Autonomous Preemptive Security module. This module converts continuous external and internal cyber intelligence into autonomous hypothesis hunting, exposure validation, compromise detection, and autonomous remediation.
Sysdig also introduced Sysdig Secure AI, an AI-native addition to its CNAPP platform. How AI is used comes in three forms: autonomous agents that set priorities and perform remediations, a “headless” mode that integrates with AI coding agents, and a GenAI assistant that explains risks and fixes in understandable language.
Autonomous IT and exposure mapping
Tanium expanded its Autonomous IT Platform with agentic and exposure tools. Within Tanium Atlas, Agentic Performance Analysis was introduced for root-cause tracing. In addition, background AI agents can autonomously carry out alert-to-resolution workflows.
It also added an MCP Server that exposes Tanium data to customers, such as Claude and Microsoft Security Copilot. For exposure management, Tanium added External Attack Surface Management and Attack Path Mapping, according to the announcement. It also announced agent-guided threat hunting, where hunts are hypothesis-driven and mapped to MITRE ATT&CK.
A SOC “brain” that learns from previous investigations
Torq introduced Torq SOC Brain as a self-learning layer on top of its AI SOC Platform. The system learns from historical investigations, analyst decisions, and organization-specific security operations to build a personalized intelligence engine.
The operation is described via capabilities such as Recall, Reflex, and Retrospect. With this, the platform aims to reason from precedent and the organization’s security history, so that threat classifications increasingly align over time with the team’s risk logic.
Config drift remediation for OT and IoT
Viakoo announced Device Configuration Manager (DXM). This module sits on top of the Viakoo Action Platform and focuses on correcting configuration deviations (configuration drift) in OT and IoT environments.
DXM is “agentless” and continuously checks device settings against predefined baselines. When there are unauthorized changes, they are flagged and devices are automatically rolled back to a compliant state. Integrations are being expanded with, among others, Armis, Forescout, Nozomi Networks, Claroty, and Tenable. Availability is expected in Q4 2026.
Status of vulnerability remediation: 79% still exposes risks
Vicarius published “Exposed and Unfixed: The 2026 State of Vulnerability Remediation”. The report states that siloed workflows and manual administrative handoffs cause 79% of organizations to keep exposing vulnerabilities to known exploits—even though they already know about them.
It also reports that 75% of critical responses mainly result in starting an administrative workflow, without the threat actually being resolved. Further, half of the organizations consider a vulnerability “closed” based on risk acceptance or creating tickets, without a validated re-scan to confirm that the patch truly works. In the past 12 months, 79% also experienced a security incident tied to a vulnerability that was already present in inventory.
Automate mobile forensics for faster incident analysis
Zimperium released Deep Insights, a mobile forensic investigation tool designed to automate the analysis of mobile device attacks. The system reconstructs complete attack timelines from collected evidence, so tier-one SOC analysts can investigate incidents without specialist mobile forensics knowledge.
Deep Insights also performs automated comparisons of before-and-after travel data to detect suspicious changes in a device’s state. General availability is expected in September 2026.
What does this mean for organizations?
The announcements during Black Hat 2026 show that security is increasingly built around three moves: (1) more AI-driven automation in exposure, testing, and defense, (2) increased focus on governance and control—especially for AI agents—and (3) bringing detection and recovery closer, with less reliance on scheduled scans or manual handoffs.
At the same time, the research claims that attacks are accelerating too make it important not only to look at new tools, but also to re-evaluate your processes around traceability, fix validation, and safe operation of remote or agentic components.
If you also want to see how attackers misuse AI and authentication in practice, that connects to earlier reporting on modern hijacking techniques, such as weaponized email AI and account hijacking.
Source: https://www.securityweek.com/black-hat-usa-2026-summary-of-vendor-announcements-part-2/
