惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Microsoft Azure Blog
Microsoft Azure Blog
J
Java Code Geeks
量子位
腾讯CDC
C
Check Point Blog
小众软件
小众软件
IT之家
IT之家
I
InfoQ
Hugging Face - Blog
Hugging Face - Blog
Stack Overflow Blog
Stack Overflow Blog
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
GbyAI
GbyAI
Apple Machine Learning Research
Apple Machine Learning Research
大猫的无限游戏
大猫的无限游戏
博客园_首页
S
SegmentFault 最新的问题
The Cloudflare Blog
阮一峰的网络日志
阮一峰的网络日志
aimingoo的专栏
aimingoo的专栏
P
Proofpoint News Feed
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
Google DeepMind News
Google DeepMind News
T
Tailwind CSS Blog
Martin Fowler
Martin Fowler

The Last Watchdog

News Alert: SpyCloud survey finds machine identity risks outpace defenses, exposing gaps in oversight | The Last Watchdog News Alert: Reflectiz launches AI website testing, uses site context to find and verify flaws | The Last Watchdog News Alert: Link11 reports fewer but stronger DDoS attacks in Europe for the first half of 2026 | The Last Watchdog GUEST ESSAY: AI coding assistants are putting open source in your code without declaring it | The Last Watchdog News alert: OpenMatter adds secure routing for OpenAI, Anthropic and Google models | The Last Watchdog LW ROUNDTABLE: OpenAI’s test agents self-organized into a rogue swarm no one anticipated | The Last Watchdog News alert: Bright Security launches AI PT, AI-powered penetration testing that cuts weeks to hours | The Last Watchdog MY TAKE: ChatGPT’s five-hour outage coincided with a model retirement its incident record omits | The Last Watchdog NEWS ALERT: Lunar Cyber tracks stolen API keys, ties them to infected employer devices | The Last Watchdog NEWS ALERT: SRA makes SOC AI license-free — customers pay only for the Azure compute they use | The Last Watchdog BLACK HAT FIRESIDE CHAT: How linking SOC alerts cuts noise, reveals attacks taking shape | The Last Watchdog News alert: Airlock Digital IRAP assessment bolsters trust for sensitive Australian deployments | The Last Watchdog News alert: OpenMatter Network spotlights AI verification at Belgrade Blockchain Week | The Last Watchdog MY TAKE: Black Hat 2026 Part 3 — Agentic AI can do the work, but somebody has to prove it | The Last Watchdog MY TAKE: Black Hat 2026 Wrap-up Part 1 — AI is forcing security and operations to merge in the SOC | The Last Watchdog News Alert: Pulse Security AI’s research reveals C-suite, board confidence gap on cyber exposures | The Last Watchdog BLACK HAT ROUNDTABLE: Security pros dissect fallout from Hugging Face’s double guardrail failure | The Last Watchdog News alert: Airlock extends endpoint control to govern AI agents and define operating boundaries | The Last Watchdog News alert: Mallory links threat intelligence to governed response as exploit timelines shrink | The Last Watchdog News alert: Community voting shapes 2026 Cybersecurity Excellence Awards | The Last Watchdog BLACK HAT Q&A: The AI agent that clears the human door and slips past the machine gate | The Last Watchdog News alert: Pulse Security launches with $8 million for AI platform to modernize CISO operations | The Last Watchdog News alert: Insignary’s on-demand SBOM verification boosts software supply chain security | The Last Watchdog News alert: Tego AI finds Anthropic’s integration of Claude and Slack can trigger unauthorized actions | The Last Watchdog News alert: OpenMatter joins HOL initiative to shape trust standards for autonomous AI | The Last Watchdog News alert: Insignary tackles SBOM accuracy gap as AI tools intensify software supply-chain risk | The Last Watchdog News alert: Link11 launches faster DDoS mitigation to counter AI-driven, adaptive network attacks | The Last Watchdog News alert: Reflectiz partners with Taboola to host webinar on AI-driven marketing security risks | The Last Watchdog News alert: OpenMatter launches platform to verify AI activity across enterprise systems | The Last Watchdog News alert: SpyCloud report finds phishing surge exposing employee data at Fortune 100 companies | The Last Watchdog
MY TAKE: Black Hat 2026 Part 2 — Security shifts to decid...
bacohido · 2026-08-11 · via The Last Watchdog

By Byron V. Acohido

Humans get identity. That is what MFA and single sign-on are for, and we all understand the bargain: prove you are who you say, then go do your work. Machines get predictability. That is what monitoring is for. A script does the same thing every day. If it deviates, somebody notices.

Related: Part 1: AI is forcing security and operations to merge in the SOC

Agentic AI upsets that arrangement. An agent logs in like a human, with an identity that says who it is. Then it goes to work without a script. It figures out its own steps as it goes. There never is a script. No baseline. Nothing ever amiss.

In part two of my three-part Black Hat USA 2026 wrap-up, the eight vendors I looked at closely are all trying to insert permission where predictability used to be. Predictability was something you watched for after the fact. Permission is something you set in advance. Somebody decides what the agent may reach and what it may not, and the agent runs inside that. Permission can be set in several places.

Radware — Mahwah, N.J. Founded 1997. Application, API and bot defense, extended to the AI agents companies are now deploying.

Sagiv

“Authentication establishes identity,� says Shira Sagiv, vice president of product portfolio. “It does not control what happens next.�

A script that changed behavior was easy to spot. An agent is built to interpret and adapt, using valid credentials and approved tools the whole way. It can reach data it does not need, call the wrong tool, or take a series of individually valid actions that add up to something nobody intended.

Radware’s answer is three stages: discover every agent running, establish what each may access, then watch behavior at runtime with controls that can stop an action in progress.

Suzu Labs — Las Vegas. Founded 2025. Secure AI adoption built on the data layer underneath it.

I spent an hour with founder and CEO Mike Bell at the show, my second sit-down with him this year, reporting for Machines Against Machines.

Bell grants agents no permissions at all. An agent inherits whatever the employee running it could already reach, so there is nothing separate to over-grant and nothing to drift as agents multiply.

Making that work meant rebuilding the plumbing. One client, a $2.5 billion equipment dealer ordered to put AI into more of the business, went looking and could not say where the company’s own data lived. Hundreds of integrations had piled up through acquisitions, some still on an AS/400.

One tier holds material no AI touches, whatever the employee’s rights.

Airlock Digital — Adelaide, Australia. Founded 2013. Application allowlisting, deny by default, now extended to what an agent may do once it is running.

Blocking an agent does not stop it. “AI agents don’t simply stop when an action is blocked,� says CEO and co-founder David Cottingham. They evaluate alternatives and keep working toward the objective.

That is why he separates two decisions. Whether software may execute, which allowlisting has answered since 2013, and what an agent is allowed to do once it already has. Airlock now enforces the second at the command and session level, through the CrowdStrike Falcon sensor.

His conclusion: draw the boundary and let the agent adapt inside it.

Straiker — Mountain View, Calif. Founded 2025. Discovery, adversarial testing and runtime defense for the agents already running inside a company.

You cannot permit what you have not found. In adversarial testing, Straiker’s research arm found 91 percent of successful attacks on productivity agents ended in silent data theft, with no malware and no stolen credentials. Nearly 29 percent of the MCP tools it cataloged carried direct security risk.

“An autonomous attacker takes whichever door is open,� says CTO Sreenath Kurupati. Every agent nobody mapped is a door.

Straiker maps them, red-teams them before deployment, then holds a kill switch that can stop one mid-action.

HERE Enterprise — New York. Founded 2010 as OpenFin. A work-apps browser that keeps a company’s own AI inside its own permissions.

CEO Mazy Dar sat down with me at the show for close to an hour, recording a Fireside Chat podcast. The permission Dar cares about is which AI an employee is allowed to use. Google makes Chrome and Gemini. Microsoft makes Edge and Copilot. Hand an employee one of those browsers and the browser maker decides which AI shows up in it.

HERE is a browser for work apps. An employee opens Salesforce, work email and an internal database in a single secure window supplied by HERE. Those apps share data, so clicking a customer in one updates the others. The company runs its own AI inside that window, with permissions accounted for.

Semperis — Hoboken, N.J. Founded 2014. Identity resilience for Active Directory and Entra ID.

Permissions get granted to a name. Active Directory holds the names, and when an AI agent shows up asking for something, Active Directory matches it to a name and grants whatever that name is permitted.

Semperis researcher Shai Laron showed at Black Hat that the match can go wrong. He found 385 characters that show up as blank spaces on a screen. An attacker can slip an invisible character into his own name and become somebody else.

Laron showed how an attacker can use that to impersonate a domain administrator and take the administrator’s privileges. Microsoft patched it in April.

Semperis also premiered a documentary at the show. Midnight in the War Room runs on more than 50 interviews. Among those on camera are Chris Inglis, David Petraeus, Jen Easterly and Tim Brown, who was CISO of SolarWinds when it happened. The film follows security executives through the worst nights of their careers. Its argument is that complacency is the real adversary.

Token — Rochester, N.Y. Founded 2014. Biometric assured identity, hardware-bound and non-transferable.

Most of the work going into agent permissions aims at acceleration, at letting machines carry more on their own. Token argues that for some tasks the final step still needs a human, however well the agents perform up to that point.

Token sells hardware. An employee wears a ring or carries a stick that reads his fingerprint, and access opens only when the right finger touches the device.

In June, Token introduced a way for companies to attach that same check to what their AI agents do. A company might have agents moving money, deleting records or granting access, with the agents taking over more and more of the steps. But the final step cannot happen until an authorized employee, verified by his device, gives the green light.

Surace

“More AI watching AI is useful, but it is still probabilistic,� CEO Kevin Surace said in announcing the capability. “Biometric assured identity is deterministic.�

Pindrop — Atlanta. Founded 2011. Deepfake detection and identity verification across voice, video and digital channels.

Permissions govern what an agent reaches inside a company. Pindrop works the channel where an attacker calls in and talks a person into granting access.

I spent an hour with co-founder and CTO Vijay Balasubramaniyan a few weeks before the show. “We started off solving, okay, is this the right human,� he said. “And then we’re like, is it even a real human? And that’s the big change.� Pindrop now analyzes the audio for the acoustic anomalies that give a synthetic voice away, sounds no human mouth could have made. AI-generated calls went from one a month across its customer base in late 2023 to 84 a day per customer now.

In March, Pindrop turned agents on its own side of the problem. Protect Fraud Assist puts AI into the fraud analyst’s workflow, summarizing calls and writing case documentation. First National Bank of Omaha cut investigation time 35 to 40 percent.

Acohido

Pulitzer Prize-winning business journalist Byron V. Acohido is dedicated to fostering public awareness about how to make the Internet as private and secure as it ought to be.

(Editor’s note: I used Claude and ChatGPT to assist with research compilation, source discovery, and early draft structuring. All interviews, analysis, fact-checking, and final writing are my own. I remain responsible for every claim and conclusion.)

August 11th, 2026 | Black Hat | Black Hat Podcasts | My Take | Top Stories