Skip to content
Beveiligingsnieuws

Black Hat USA 2026: Vendor Announcements Recap (Part 4)

Black Hat USA 2026

The 2026 edition of Black Hat USA 2026 in Las Vegas is again a busy stage for cybersecurity vendors and research teams. To help you sift through new launches, product updates, and notable findings, we summarize the vendor announcements from Part 4 of the series. Below, you’ll find the most important themes—from AI-assisted defense that doesn’t always land correctly to runtime controls designed for today’s AI-driven workflows.

This recap focuses on announcements made during the conference week, highlighting what changed, what was introduced, and why the developments matter for security teams.

AI patching: not every fix actually fixes

1Password’s newly formed research team, Off-By-1 Labs, published its first study on AI-generated vulnerability patches. The headline finding: AI-generated fixes often don’t fully remediate the underlying issue. In some cases, the patch process can even create new vulnerabilities along the way.

In an evaluation covering more than 6,000 patches tied to recently disclosed, complex open-source vulnerabilities, the researchers reported that 54% of the analyzed patches did not remove the target vulnerability. According to the study, patches either failed to resolve the original problem, introduced a different vulnerability, or did both.

Only 26% of patches resolved the vulnerability without significantly changing application behavior. Another 20% resolved the issue but altered application behavior in a material way. The overall message for practitioners is clear: treat AI-generated patches as a starting point, not as an automatic guarantee of correctness.

Privileged access without standing access

In the same announcement set, 1Password also launched 1Password Privileged Access. The offering extends its Unified Access approach into the PAM (privileged access management) market, with a different model than many traditional PAM tools.

Rather than continuously safeguarding standing access, the account is created when access is requested. It’s scoped to the task at hand and then automatically removed when the work is finished. For organizations trying to reduce the risks that come with persistent privilege, this time-bound access concept is a practical shift.

Frontier AI model claims and the missing context problem

Cogent Security announced a model it describes as a frontier AI approach designed to align with Anthropic’s Mythos. The company’s core argument is that frontier models can reason about security at a high level, but may not understand the real-world environment they are meant to protect—especially details like business context, identity structure, and runtime control boundaries.

To address this, Cogent positions its VR-1 model as a way to correlate relevant environment data into a machine-readable representation of an organization’s security posture. Cogent also describes a “security harness” intended to keep reasoning anchored in the organization’s actual setup, rather than floating in abstraction.

Real-world delivery chains in browser-downloaded attacks

CyberProof published threat research focused on an attack involving a browser-downloaded software installer that masquerades as a free utility. Unlike exploit-driven malware chains, this attack relies on user interaction and deception—specifically the way attackers craft their landing pages and the delivery steps that follow.

The researchers emphasize that the campaign uses convincing landing pages, valid code-signing certificates, and server-side control rather than depending on client-side software vulnerabilities. CyberProof’s analysis outlines the complete delivery chain and also discusses possible downstream impacts if defenses had not prevented the attack from succeeding.

For security teams, this is a reminder that “no vulnerability exploited” doesn’t mean “low risk.” Social engineering, trust signals, and operational control can still lead to serious outcomes.

Endpoint security update: silicon-rooted attestation and automation

Cyble announced an update to its Cyble Titan endpoint security platform. The upgrade adds silicon-rooted attestation, aiming to strengthen trust signals around what’s happening on endpoints.

Cyble describes the platform as combining endpoint activity with threat intelligence, behavioral analytics, and automated attack reconstruction powered by BlazeAI. The goal is to produce complete “Indicators of Attack” and support faster investigation cycles.

Cyble also says the solution consolidates device controls, exposure management, and auditable response workflows into a single interface. This kind of consolidation is often intended to reduce the friction between detecting activity, deciding what it means, and then acting in a governed manner.

KnowBe4 expands Real-Time Coaching for risky behavior

Training and workforce security provider KnowBe4 rolled out enhanced Real-Time Coaching capabilities. The enhancement delivers an instant, short SecurityTip when risky behavior is detected.

KnowBe4 frames the product improvements around habit formation: by intervening at the moment risky actions occur, organizations can help reduce repeat incidents. The company also notes that the coaching outcomes are meant to be reflected in an organization’s Risk Score.

For teams balancing technical controls and human behavior, this kind of real-time training integration is an approach to close the loop quickly rather than waiting for periodic awareness programs.

Runtime security mesh for AI agents

NeuralTrust introduced a runtime security mesh intended to protect AI agents without requiring custom integrations. The platform operates via its Agent Gateway, where it inspects agentic traffic across the lifecycle of an interaction.

NeuralTrust’s described capabilities include active monitoring of agent reasoning to detect drift, validation of tool authentication policies, and flagging of malicious payloads such as prompt injections and exposed credentials. It also supports operational visibility, with alerts, audit logs, and analytics that can sync directly to an enterprise SIEM.

In practice, this is aimed at bridging a gap many organizations face with AI: even when models are “safe,” the surrounding agent workflow can still be manipulated. Runtime controls focus on what the agent does and how it reasons, not just which model it uses.

Agentic Security Operations as a managed service

Optiv announced Optiv Agentic Security Operations, described as a managed service model that integrates Google Security Operations and Wiz.

The platform uses agentic AI to analyze incoming alerts and identify environment-wide risks. Those risks are then enriched contextually using telemetry from Wiz across areas such as cloud, identity, and exposure. Optiv specifically points to Wiz Cloud, Wiz Code, and Wiz Defend as sources for this additional context.

This announcement aligns with a broader industry direction: instead of treating alerts as isolated events, systems should interpret them with identity, cloud configuration, and exposure details to help analysts act faster and more accurately.

Continuous threat elimination in production environments

Software supply chain security firm RapidFort launched RapidFort Runtime, a real-time solution positioned as part of continuous threat elimination. The company describes the service as extending its platform into an end-to-end approach that includes curated open source software, continuous CVE monitoring, and tamper detection in live production environments.

RapidFort Runtime operates inside an organization’s production environment. It continuously monitors deployed software, detects unauthorized or unexpected changes, and tracks newly discovered CVEs proactively.

For teams that struggle with the time gap between CVE disclosure and real-world exposure validation, continuous monitoring of what is actually running can be a major operational advantage.

NatJack: exploiting assumptions in NAT

Synack researcher Malcolm Stagg presented research on NatJack, a new class of attacks that leverages trust assumptions embedded in network address translation (NAT).

The testing reportedly showed the weakness across independently developed NAT implementations in Windows, Linux, and macOS. The research describes four techniques attackers can use against NAT devices:

  • Hijacking active TCP connections
  • Poisoning DNS responses
  • Identifying the ports assigned to other connections
  • Forcing denial of service by exhausting a device’s NAT table

Synack notes that two CVEs have already been assigned: CVE-2026-56181, affecting Microsoft Windows NAT in Hyper-V, and CVE-2026-63913, affecting the Linux netfilter conntrack subsystem.

For defenders, the key takeaway is that NAT is often treated as infrastructure plumbing—but it can still become an attack surface when assumptions about trust and behavior are wrong.

Vectra AI Pro: trusted signal intelligence for SOC AI

Vectra AI launched Vectra AI Pro, designed to help organizations adopt AI safely across the SOC. The offering emphasizes “trusted signal intelligence,” aiming to give AI agents the context they need to reason accurately and act with confidence.

Vectra AI Pro continuously correlates signals across network, identity, cloud, SaaS, EDR, and SASE. By consolidating these sources into a unified view of attacker behavior, the product seeks to reduce the risk of AI operating without enough operational context.

Zenity: malicious skills campaign and a free threat intelligence service

Zenity shared details from its PleaseFix research and also described an active malicious “skills” campaign distributed through Vercel’s skills.sh.

The affected skill family amassed over 1.7 million aggregate installs. Zenity says the campaign was disrupted by Zenity and Vercel, and that the investigation used AI Total—a new free threat intelligence service that dynamically executes AI agent skills in a contained environment and analyzes their runtime behavior.

For security teams, this combines two useful angles: (1) real-world distribution mechanisms for malicious agent capabilities, and (2) a practical way to observe what those capabilities do during execution.

What these announcements have in common

Across the announcements, several shared themes stand out at Black Hat USA 2026. First, vendors are pushing AI forward, but the research side is also showing where AI can fail—such as patch generation that doesn’t fully remediate vulnerabilities. Second, there’s a strong push toward runtime visibility, whether for endpoint activity, NAT-related behaviors, or the lifecycle of AI agents. Third, many updates focus on operationalizing security: faster triage, enriched context, automation, and tighter feedback loops between detection and action.

If you’re planning what to evaluate next—tools, services, or process updates—consider starting with areas where the biggest gaps are visible in your own environment: patch validation quality, agent and automation safety, endpoint trust signals, and the ability to connect alerts to identity, exposure, and cloud context.

Conclusion: Part 4 of the Black Hat USA 2026 vendor announcement digest shows a clear direction for cybersecurity in 2026: smarter AI is emerging, but it’s paired with stronger runtime controls and deeper investigation methods. The result is a more connected defense approach—one that aims to improve both prevention and response when the real world refuses to behave like a lab test.

Source: https://www.securityweek.com/black-hat-usa-2026-summary-of-vendor-announcements-part-4/