















Security work used to leave a trail without anyone trying. A developer who wanted an open source library went and got it, and the license came along. An analyst who closed a case wrote down why. The record was a byproduct of a person doing the work.
Related: Part 2 — Deciding what an AI agent may reach
An AI agent produces no such byproduct. It works out its own steps, moves faster than anyone watching, and finishes without leaving behind the paper trail a person would have.
Companies have caught on to what is missing, and they are no longer satisfied with a tool that reports a result. They want to see what the result rests on. Vendors have heard that, and a group of them arrived at Mandalay Bay in Las Vegas selling the proof rather than the finding. Ten of the companies I looked at closely are working that ground, and they close out my three-part Black Hat USA 2026 wrap-up.
Command Zero — Austin, Texas. Founded 2021. Documents how a verdict was reached
I sat down with CEO Dov Yoran and CTO Dean De Beer at the show.
An alert lands and somebody has to work out whether anything actually happened. Answering means pulling records from wherever they sit, in the SIEM, on the endpoint, in email, in SharePoint, and reasoning across all of it.
Command Zero does that work and keeps a full account of how it went. Every question asked of the data, every tool call made, every log record collected, every hypothesis proven or disproven. The verdict stops being an assertion and becomes something the company can stand behind.
De Beer likens it to the citations under a research paper. The sources have to be listed for the conclusion to be worth anything.
Throughline, launched at the show, keeps a case alive after it closes. New alerts get matched against prior cases, and a closed verdict can change as evidence arrives.
SubImage — San Francisco. Founded 2024. Maps a company’s infrastructure and its connections
I met CEO Alex Chantavy after a wrong turn looking for a restroom.
A big company runs thousands of servers, databases, cloud accounts and employee logins, and no one person can say how they connect. SubImage maps that and writes it down. Which login can reach which system, where the sensitive data sits, what path leads to it. Most security vendors sell alerts. Chantavy sells the picture underneath them.
Chantavy built the map for security teams to read. His first customer fed a SubImage map to their own AI agents instead. An alert names one machine. The map tells the agent what that machine reaches, what sits downstream of it, and where an attacker would go next. The agent sees the whole shape of the exposure in seconds, not just the piece that set off the alarm.
“The robots love that kind of structure,� Chantavy said.
Nucleus Security — Sarasota, Fla. Founded 2018. Routes each vulnerability to whoever owns the fix
I’ve spoken several times over the past year and a half with co-founder and chief product officer Scott Kuffer about how vulnerability management is evolving.
Security teams have always had more known flaws than they can fix, and AI models that hunt vulnerabilities have made that list grow faster than ever. Kuffer’s position is that finding was never the constraint. Fixing is.
Nucleus sits above the scanners a company already owns, takes in everything they report, ranks each exposure by what it actually threatens, and routes it to whoever can close it. What comes out is a record of what was found, what mattered, who was assigned and what got done.
“Use automation to maintain context and accelerate action, and keep accountability with people,� Kuffer said.
Ridge Security — Milpitas, Calif. Founded 2020. Live payloads show which flaws cause damage
President and co-founder Lydia Zhang sat down with me on short notice as the show was winding down.
Scanners return more findings than any team can act on, each carrying a severity score. Zhang’s argument is that the score is a guess. Ridge tests each finding with a live payload and reports which ones actually cause damage.
“We give you the evidence to prove that,� Zhang said.
At the show the company launched RidgeGen, an agentic platform that chains flaws into complete attack paths and validates each path with reproducible evidence before an analyst ever sees it. Rather than run a fixed script, the agents adapt as they go, the way an intruder would.
Root Evidence — Boise, Idaho. Founded 2025. Uses loss data to decide which flaws matter
CEO and co-founder Jeremiah Grossman argues that security teams have spent years counting the wrong things: CVEs, severity scores and remediation totals.
Root Evidence instead uses cyber insurance claims, actuarial analysis, digital forensics, attack-surface intelligence and breach data to identify the small percentage of vulnerabilities tied to real financial loss.
“The cybersecurity industry has become exceptionally good at finding vulnerabilities, but it has not become significantly better at preventing financial loss,� Grossman said.
Its Mythos Warranty pushes the argument further: cyber insurance underwriters evaluated the methodology and agreed to back covered events resulting from CVEs Root Evidence failed to identify and report, with up to $5 million in protection. The point: fewer guesses, more proof.
Filigran — Paris. Founded 2022. Open-source threat intelligence, plus attack simulation
Another end-of-show meet-and-greet, this one with co-founder and CTO Julien Richard.
The company traces to a report French President Emmanuel Macron demanded on a state-backed actor targeting France. Samuel Hassine, now Filigran’s CEO, ran threat and risk analysis at ANSSI and could not assemble the answer fast enough. Everything he needed existed, scattered across tools that did not talk to each other. He and Richard built OpenCTI to fix that.
A second product, OpenAEV, takes what OpenCTI knows about an attacker and simulates that attack against a customer’s own network. “It’s like a proof,� Richard said. Either the threat finds a way in or it does not.
XTM One, shipped in June, turns a threat report into a live test in minutes.
Finite State — Columbus, Ohio. Founded 2017. Reads device firmware to confirm what shipped
Another on-the-fly conversation, this one over coffee with Doc McConnell, head of policy and compliance.
Finite State works for the manufacturers of internet-connected devices — pacemakers, doorbell cameras, industrial controllers, cars. Each one runs software assembled from parts the manufacturer did not write, and once that code is compiled and loaded onto a device, nobody can see inside it. Finite State scans the finished product, catalogs every component, and reports back before it ships.
The gap between what a manufacturer thinks it built and what actually shipped has widened this year, because AI now writes much of the code. Teams move faster and review less. They no longer have visibility into every line, McConnell said, the way they did when people wrote it by hand.
Which is why an outside reading matters more than it did two years ago.
Companies have to “show their math,� McConnell said.
Insignary — Toronto. Founded 2016. Verifies a company’s software parts list
I published a Q&A with president and CEO Taek Wan Kim the Sunday before the show.
Nearly every company can now produce a software bill of materials, a list of the components inside its product. Almost none can prove the list is right.
AI widened the gap. A developer who wanted a library used to go and get it, and the license came along, so the record wrote itself. An assistant writes the code directly, and some of what it writes belongs to somebody else. Insignary reads the finished binary and reports what is actually in there.
Kim compares it to financial auditing. A company prepares its own statements, and investors still expect somebody independent to check them.
Jscrambler — Porto, Portugal. Founded 2014, roots to 2009. Accounts for outside code on company web pages
I talked with CEO and co-founder Rui Ribeiro in a Fireside Chat that ran as the show was getting underway.
Fifteen years ago a company built its own web page and knew every piece of it. Then rich, dynamic pages got cheap and companies started bolting on components they did not build — payments, retargeting, chat. “All of a sudden you have 100 vendors on your website,� Ribeiro said. Each one got handed more access than its job required, and nobody was keeping track.
Now AI composes the page and decides on its own what to pull in. The supplier list grows without anyone approving it. “AI is going to pull whatever it decides into the supply chain,� Ribeiro said.
Jscrambler watches the page as it runs and reports what each component actually reached for. A company gets to decide what leaves its own site. Proprietary business information stops flowing out unnoticed.
Black Hills Information Security — Spearfish, S.D. Founded 2008. Boutique penetration testing, no outside funding
The other nine companies here sell a way to prove something. Founder John Strand sells the assessment itself.
Black Hills breaks into networks for a living, about a thousand assessments a year, and Strand now runs some of that work continuously, with AI hunting alongside his testers.
When his team finds a security hole, the answer has almost always been the same one: wait for the vendor to issue a patch and install it. That worked because finding a hole and building a working attack against it were separate jobs, and the second one took time. AI agents now do both at once, and a company can face a working attack with no patch coming.
The same tools work for the defense. “AI gives a lot of results,� Strand said, and a skilled human is what turns them into something a company can act on. His testers go through what the AI turns up, throw out what does not matter to that company, and hand the customer a short list of the holes that actually put the business at risk.
Pulitzer Prize-winning business journalist Byron V. Acohido is dedicated to fostering public awareness about how to make the Internet as private and secure as it ought to be.
(Editor’s note: I used Claude and ChatGPT to assist with research compilation, source discovery, and early draft structuring. All interviews, analysis, fact-checking, and final writing are my own. I remain responsible for every claim and conclusion.)
August 12th, 2026 | Black Hat | Black Hat Podcasts | My Take | Top Stories
此内容由惯性聚合(RSS阅读器)自动聚合整理,仅供阅读参考。 原文来自 — 版权归原作者所有。