Close Menu

    Subscribe to Updates

    Get the latest creative news from infofortech

    What's Hot

    Most popular stories on GeekWire for the week of Aug. 2, 2026 – GeekWire

    August 9, 2026

    New CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokens

    August 9, 2026

    Finding big money for AI and a smaller world for security at Black Hat USA 2026

    August 9, 2026
    Facebook X (Twitter) Instagram
    InfoForTech
    • Home
    • Latest in Tech
    • Artificial Intelligence
    • Cybersecurity
    • Innovation
    Facebook X (Twitter) Instagram
    InfoForTech
    Home»Innovation»Finding big money for AI and a smaller world for security at Black Hat USA 2026
    Innovation

    Finding big money for AI and a smaller world for security at Black Hat USA 2026

    InfoForTechBy InfoForTechAugust 9, 2026No Comments12 Mins Read
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr WhatsApp Email
    Finding big money for AI and a smaller world for security at Black Hat USA 2026
    Share
    Facebook Twitter LinkedIn Pinterest Telegram Email



    Las Vegas was hotter than hell last week, but not as hot as the market for artificial intelligence-enabled security at Black Hat USA 2026. A bandwagon of million-dollar booths for overfunded agentic security startups arose like mirages from the desert. Fortunately, there was also real value to be found amidst the AI hallucinations.

    AI supply chain challenges were the topics du jour for chief information security officers and researchers comparing each other’s level of preparedness for agentic AI disruptions such as the on-off introduction of Anthropic PBC Mythos-class escape exploits, and the recent OpenAI/Hugging Face attack, and even Meta Platforms Inc. saying it did one too, just to not get left out.

    “I think this incident was a really good example of exploiting the nondeterministic capabilities we already know about AI, where there’s just a lot more code and traffic generated within a quicker time period, which can hide abuses,” said Patrick Duffy, head of product at Dropzone AI Inc., which announced its new AI Threat Hunter product at the show. “Human teams could not launch a thousand investigations at the same time to respond.”

    One thing that has been thoroughly disproven since last year’s autonomous security operations center craze? AI automation is still not replacing professional security expertise. The ungovernable AI cat is already out of the bag, so we’ll need AI agents to work alongside us to stop it, because we’ll always have a shortage of skilled security professionals to follow up on the unknowns of an ever-expanding threat surface.

    Here were some interesting new brain wrinkles I picked up at my first Black Hat:

    Orchestrating the agentic SOC

    Agents in the SOC, if governed, trained and employed correctly, can take a lot of work off the human security analyst’s plate, freeing up more time for critical investigations and strategic security architecture thinking, but there are many ways to get there.

    Rather than keying off of alerts and incidents, Nebulock Inc. builds a behavioral world-model graph of an enterprise that overlays existing security information event management, information technology security management and alerting tools to conduct “hunt-first” agentic detections and investigations. Agent fleets can be triggered to respond autonomously to events such as patches or new CVEs, or a security analyst’s natural language request to follow up on a hypothesis informed by coverage gaps they are seeing in their security posture command center.

    Huntress Labs Inc. provides a 24/7 managed platform used by hundreds of thousands of individual jacks-of-all-trades, service providers and mid-sized companies. Their in-context training, support experts and SOC workflow automation help customers that would have a difficult time covering every aspect of security.

    “We try not to overuse AI buzzwords here,” said Aimee Simpson, director of product marketing at Huntress. “We do have Athena, an agentic investigator made of different subagents that are doing different tasks, compiling signals, investigations, writing incident reports, to take some of the workload from our SOC, but our customers care about results. If the agent is not confident in its findings, that still goes straight to our expert human analysts – and we’re definitely still hiring them.”

    For a newer vendor on the market, Strike 48 brings a surprisingly broad agentic SecOps platform with multi-platform SOC, network operations center and DevOps connectivity. It has more than 300 MCPs under the hood, allowing its agents to resolve security issues alongside network and development engineering work. Larger companies can lean on their forward-deployed expert teams to build out specialized agents and further bespoke integrations.

    Enabling agentic co-workers with less risk

    Zero-trust policies with least privilege access controls, hardened containers, and microsegmentation have been around for years. These practices started gaining traction for securing containers and ephemeral workloads as cloud native architectures emerged. Now, the “IP-wandering” nature of nondeterministic AI agents makes setting boundaries – without becoming a blocker – more critical than ever.

    “With microsegmentation, we’re narrowing down every asset in your ecosystem to put a protective bubble around it – workstations, servers, operational technology and cloud assets, and now we want to extend beyond infrastructure-as-code to cloud infrastructure itself, using native APIs built into the system of Azure, AWS or GCP,” said Chris Boehm, field chief technology officer at Zero Networks Inc., an identity and microsegmentation vendor that announced its enforcement of Open Worldwide Application Security Project Least Agency Principle for enterprise AI at the show.

    “Agents can be your best worker, and your worst worker, and your adversary, all at the same time. You really need to take the perspective of agents to understand their intent, wherever they run,” said Jason Needham, CEO of Certiv Inc., an agent assurance firm that provides behavioral and intent monitoring to human agent owners, with judgments, policies and technical controls for agents, including local models.

    Geordie AI Ltd. discovers agents wherever they exist across the enterprise, learns what they do and who is responsible for them, and helps security teams help their own organizations successfully adopt agents with less risk. Its Beam solution directly tests for exposure and operates agents, and acts as a control plane for managing work activities, with a light touch, so autonomy and adoption is not as inhibited as a typical security-oriented solution. 

    “The trend for giving more autonomy to agents is only increasing this year,” said CTO Benji Weber. “You even have nontechnical sales and marketing teams adopting agents. Are these teams truly successful with agents, or are they just burning tokens?”

    Enriching and optimizing SOC data estates for shared knowledge

    AI SOC vendor Stairwell was there demonstrating its new Backstory threat intelligence data discovery and knowledge base that can pull multiple petabytes of contextual threat data in seconds into an all-hot live and historical data lake. It captures full-stack activity for multiple systems using parallel agents, without a time-consuming or costly search and ingest process.

    “Rather than try to record every behavior, I want to find the thing that made the behavior, not just a bunch of logs,” said founder and CEO Mike Wiacek. “It changes the way teams think about security. If you were a bank that got robbed, would you want to replay the CCTV footage of the robber, or would you rather already have the guy in handcuffs?”

    “We’ve seen this train coming for a while,” said Monzy Merza, founder and CEO and founder of Crogl Inc. The firm was at Black Hat promoting a free single-user download of its complete enterprise AI SOC platform to accompany its recent sovereign AI agent. “Sovereign data and private AI capabilities are becoming very important to customers who want to control their own data, and that’s why we have always been available on-prem as a customer-managed product.”

    Endpoints are still the leakiest attack surface

    On day three, I was going to record an interview, and my iPhone’s audio recording app said, “Cannot record audio during a phone call.” There was clearly no call going on, and the phone seemed kinda hot, so I rebooted it. Maybe some agent there at Black Hat was demonstrating a cool hack on my endpoint!

    The most devastating attacks in play today are often insider threats on an employee’s desktop or phone, which are particularly difficult to recognize when the signature and intent of an agent’s actions on an endpoint are unknown.

    Ent Security (Athena Formation Inc.) was there with a big presence just out of stealth, combining elements of user and entity behavior analytics, endpoint detection and response, application control, data and endpoint protection, user interface monitoring and remote access analytics, all of which together form an “intent-aware protection” layer for humans, AI and applications.

    “You need to capture high-fidelity telemetry within the user’s workspace, everything from mouse clicks and opening files, screen shots, application focus changes and even remote workers and agents that might log in and take control of your desktop,” said Janani Nagarajan, VP of product marketing at Ent. “For instance, on day 1 of a customer install, they saw an employee invite a user in North Korea to a Zoom, and then hand over remote access to that user, and they were able to make an intervention.”

    For mobile apps, which represent the majority of human user internet traffic, Appdome Inc. introduced new mobile test engineering capabilities and a remote management agent solution. It can make publisher-controlled live configuration and security updates to the application after build, packaging and deployment to an app store, in order to shrink the exploit window for live users if a new threat is discovered between major releases.

    Improving DevSecOps collaboration

    No, DevSecOps is not dead; it is just not as popular as it used to be. But security teams still need to collaborate with development and ops teams in order to realize the value the company expected from AI initiatives.

    RevEng.AI (Binary AI Ltd.) built a machine code verification layer that explores production software, including binaries, for threats or risks. Rather than imitating static or dynamic application security testing scans, or building another large language model like OpenAI or Claude that understands English, it trained a large model that understands binary computer code at a root level.

    “If AI is writing the majority of code today, In the future, why should AI write code that’s easy for human beings to understand? Why should it write Python, when it could go to compiled languages or even straight to binary at a 100-times or 1000-times quicker rate?” said CEO James-Patrick Evans. “But the problem is we’ve got to secure this code, and make sure that its output is actually correct.”

    Software supply chain player RapidFort Inc. was demonstrating a new capability for monitoring an software bill of materials not just for approved software packages in builds, but within container deployments at runtime, in order to protect against drift in production environments. With agents writing infra code and introducing packages at an unprecedented rate, there are always new vectors to account for.

    “We’ve seen developer credentials being compromised so what looks like a legitimate npm package gets pushed up to GitHub,” said Chief Marketing Officer Mike Wood. “People and agents think the update is OK to download, but it has malware. So we don’t make any of our images available to our customers unless they’ve been baked for two weeks and cooled off for two weeks, which guarantees that any issue will already have been discovered by the vendor community and thousands of developers and end users.”

    I met with AISLE Inc., a deep-thinking startup focused on remediation in the AI-enabled software delivery lifecycle, that ended up exposing and publishing common vulnerabilities and extensions for several new zero-day vulnerabilties and topping research leaderboards, including 16 OpenSSL exploits and previously unknown vectors that Mythos-class models could generate. 

    “These aren’t just rogue models, we’re talking about major AI companies that deliberately lowered the guardrails on their flagship models to see what they are capable of – when they weren’t supposed to be accessing the internet,” said Chief Operating Officer and CISO Jaya Baloo. “We want to verify them and prioritize remediation with a fix that doesn’t break anything new.”

    When all else fails… kill the agent

    Straiker Inc. was there with a futuristic cyberpunk presence for its multi-agent attack and defense solutions, and revealed a brand-new game with just one button, under glass: the Agentic Kill Switch. I couldn’t help but press the button, like I was the last man standing in a gas station with a leaking token pump.

    ‘We have tuned models that do detection, looking for remote code execution, indirect prompt injection, and fine-grained blocks, but sometimes, you actually need to just kill misbehaving agents with the push of a button,” said Parth Shah, Straiker’s head of product. “Ultimately, anyone that’s putting AI in their software needs to stay in the driver’s seat. They can’t have someone else in their supply chain that owns that kill switch.”

    The Intellyx take

    If there’s one thing that has been thoroughly disproved since last year’s agentic SOC craze, it’s that AI agents could replace human security professionals.

    There will never be enough skilled SecOps team members with the insight to stay ahead of the rate of change AI is bringing to us, much less the chaotic behavior of fellow employees who trust AI with sensitive work.

    Fortunately, at Black Hat it was impossible to ignore just how fast these vendors are moving forward with AI in their own products, and using AI to augment human awareness, in order to secure AI-driven applications that are appearing everywhere. The value AI and agents can offer human security teams is not a mirage.

    The fact that new startups can build several enterprise-grade security solutions in less than a year is a testament to the incredible acceleration AI development can provide. But only working together as a community to improve the security awareness and expertise of builders and practitioners can save us from an uncertain future.

    Jason English is a principal analyst and chief marketing officer at Intellyx. He wrote this article for SiliconANGLE. At the time of writing, Appdome, Dropzone AI and Straiker are current Intellyx customers, and Crogl and Zero Networks are former Intellyx customers. The event covered the analyst’s attendance cost, a standard industry practice. ©2026 Intellyx B.V.

    Photo: Jason English

    Support our mission to keep content open and free by engaging with theCUBE community. Join theCUBE’s Alumni Trust Network, where technology leaders connect, share intelligence and create opportunities.

    • 15M+ viewers of theCUBE videos, powering conversations across AI, cloud, cybersecurity and more
    • 11.4k+ theCUBE alumni — Connect with more than 11,400 tech and business leaders shaping the future through a unique trusted-based network.

    About SiliconANGLE Media

    SiliconANGLE Media is a recognized leader in digital media innovation, uniting breakthrough technology, strategic insights and real-time audience engagement. As the parent company of SiliconANGLE, theCUBE Network, theCUBE Research, CUBE365, theCUBE AI and theCUBE SuperStudios — with flagship locations in Silicon Valley and the New York Stock Exchange — SiliconANGLE Media operates at the intersection of media, technology and AI.

    Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a dynamic ecosystem of industry-leading digital media brands that reach 15+ million elite tech professionals. Our new proprietary theCUBE AI Video Cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    InfoForTech
    • Website

    Related Posts

    Cloudflare Stock Soars 17% As AI Agents Rewrite The Internet

    August 9, 2026

    My smart home experiment has reached its natural limit

    August 9, 2026

    Census Proposal Would Stop Counting Undocumented Immigrants—and Ignore Race and Sexual Orientation

    August 9, 2026

    Forecasting the AI bubble: When scarcity turns to surplus

    August 9, 2026

    ByteDance’s 10-Trillion Parameter Push Proves Scale Still Rules AI

    August 8, 2026

    Another Googlebook just surfaced online, and this one is from Asus

    August 8, 2026
    Leave A Reply Cancel Reply

    Advertisement
    Top Posts

    A Billionaire-Backed Startup Wants to Grow ‘Organ Sacks’ to Replace Animal Testing

    March 23, 2026204 Views

    DoJ Disrupts 3 Million-Device IoT Botnets Behind Record 31.4 Tbps Global DDoS Attacks

    March 20, 202638 Views

    Microsoft is bringing an AI helper to Xbox consoles

    March 14, 202619 Views

    Why Security Validation Is Becoming Agentic

    March 16, 202616 Views
    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo
    Advertisement
    About Us
    About Us

    Our mission is to deliver clear, reliable, and up-to-date information about the technologies shaping the modern world. We focus on breaking down complex topics into easy-to-understand insights for professionals, enthusiasts, and everyday readers alike.

    We're accepting new partnerships right now.

    Facebook X (Twitter) YouTube
    Most Popular

    A Billionaire-Backed Startup Wants to Grow ‘Organ Sacks’ to Replace Animal Testing

    March 23, 2026204 Views

    DoJ Disrupts 3 Million-Device IoT Botnets Behind Record 31.4 Tbps Global DDoS Attacks

    March 20, 202638 Views

    Microsoft is bringing an AI helper to Xbox consoles

    March 14, 202619 Views
    Categories
    • Artificial Intelligence
    • Cybersecurity
    • Innovation
    • Latest in Tech
    © 2026 All Rights Reserved InfoForTech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy

    Type above and press Enter to search. Press Esc to cancel.

    Ad Blocker Enabled!
    Ad Blocker Enabled!
    Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.