惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Microsoft Azure Blog
Microsoft Azure Blog
aimingoo的专栏
aimingoo的专栏
F
Fortinet All Blogs
Blog — PlanetScale
Blog — PlanetScale
GbyAI
GbyAI
MongoDB | Blog
MongoDB | Blog
月光博客
月光博客
The Cloudflare Blog
量子位
T
Tailwind CSS Blog
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
B
Blog
MyScale Blog
MyScale Blog
T
The Blog of Author Tim Ferriss
The GitHub Blog
The GitHub Blog
G
Google Developers Blog
D
DataBreaches.Net
V
Visual Studio Blog
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
Last Week in AI
Last Week in AI
U
Unit 42
博客园 - 聂微东
有赞技术团队
有赞技术团队
A
About on SuperTechFans

Security @ Cisco Blogs

Black Hat USA 2026: Building the Agentic SOC, One Live Event at a Time Thrown into the SOC: A Black Hat First-Timer’s Story Troubleshooting Wi-Fi at Black Hat USA 2026 with ThousandEyes Distributed Latency Monitoring at Black Hat Building a Risk-Based Secure Network Analytics Detection with Splunk Detection Editor (Alpha) Frontier AI just raised the stakes, and the old playbook won’t hold up Crypto Agility: Why PQC Is Not a One-Time Upgrade From Isolated Agents to Collective Intelligence: Why A2A Is the Protocol the Agentic SOC Has Been Waiting For Microsegmentation’s Moment Is Now: Cisco Named a Leader in The Forrester Wave™: Microsegmentation Solutions Identity Everywhere: Bringing Infrastructure Identity to Agentic IT Cisco Named a Leader in the 2026 IDC MarketScape for Worldwide SASE Meet Instant Attack Verification: Agentic AI for Tier-1 and Tier-2 SOC investigation Elevating Federal Cybersecurity: Cisco’s Path from FedRAMP Certified Class C (Moderate) to Certified Class D (High) Elevating Trust: Email Threat Defense Achieves FedRAMP Class D (High) Certification Is your SD-WAN ready for AI-powered operations? The Zero Trust Imperative for the Frontier AI Era Assuming Failure: The Mindset Shift That Actually Improves Your Defensive Outcomes The Journey towards Logically Air-Gapped Deployment Cisco Firewall Migration Manager: A Faster, Simpler, More Confident Path to Secure Firewall We third-party tested our firewall built for AI-scale. The test tools hit their limit first. SharpHound Recon Attack - How AI enhanced the threat hunt Machine Speed, Human Judgement: How AI Changed the SOC in 2026 Elevating Expertise in the SOC Educate at Event Speed: Cisco Live Security Operations Center What Working the Cisco Live SOC Taught Me About AI, Detection, and Response Cable to Cloud - A Product Engineer's Journey Through the Cisco Live AMER 2026 SOC The Experience Dividend: How Better Digital Experience Protects Revenue, Trust, and Growth AIM: Building an Agentic Tier-2 SOC Analyst at Cisco Live AMER 2026 Building the Agentic SOC at Cisco Live Americas 2026 Ten Years in the SOC at RSAC: What We Learned in 2026
Black Hat USA 2026: Safeguarding DNS with Secure Access
Steve Vida · 2026-09-07 · via Security @ Cisco Blogs

DNS continues to provide one of the clearest windows into activity across the Black Hat network. Since 2017, Cisco has helped secure Black Hat through DNS-layer visibility and protection, providing the Network Operations Center (NOC) / Security Operations Center (SOC) team with an early vantage point into where devices are attempting to connect.

At Black Hat, however, the value of DNS goes well beyond traditional threat blocking. The conference creates a uniquely noisy environment where security research, demos, pen-testing tools, malware analysis and thousands of attendee devices all generate activity that might look suspicious on a typical enterprise network. DNS telemetry gives analysts an important starting point for separating this expected activity from events that deserve further investigation, while also revealing broader trends in how the network is being used.

Building on the encrypted DNS controls introduced at Black Hat USA 2025, this visibility remains particularly important as encrypted protocols and privacy technologies increasingly obscure traditional network telemetry.

Continuing from last year’s priorities to monitor and block resolutions for domains related to the ApateWeb Potentially Unwanted Program (PUP) delivery and phishing campaign, which uses ‘two/three-name’ domain pattern, we did see some of these destinations blocked to protect attendees.

Fig. 1: Blocked resolution requests

DNS Year-Over-Year Statistics

This year, we identified 76,331,133 DNS requests across 1.02 million domains and 1,268 identities, as more attendees connected to the conference network vs recent years. With the increase in DNS requests, we also identified an increase in number of apps:

2019: ~3,600 2023: ~7,500 2026: ~10,800
2021: ~2,600 2024: ~9,300
2022: ~6,300 2025: ~9,300
Fig. 2: Black Hat DNS queries, visualized year-over-year

Key findings

Secure Access was not merely resolving DNS—it was preventing devices from bypassing organizational DNS inspection through unapproved encrypted resolvers

  • mask.icloud.com generated 4.42 million requests, of which 99.7% were blocked.
  • Its 4.42 million blocks represented 79.3% of every blocked DNS request.
  • Apple privacy-relay and encrypted-DNS hostnames collectively accounted for approximately 97.9% of blocks among the top blocked destinations.
  • Other blocked encrypted resolvers include Google DNS, Cloudflare DNS, AdGuard, NextDNS and Quad9.

Cisco classified 8,695 DNS requests as “Hacking.”

  • Volume began with 47 requests on July 31, rose to 2,341 on August 3, remained high through August 5, then dropped to 325 on August 6.
  • Leading destinations strongly suggest labs and education:
    • Cyfinoid.training — 1,458
    • kali.darklab.sh and its service records — 1,380
    • hackerai.co — 542
    • exploit-db.com/www.exploit-db.com — 462
    • ctf.icanhack.nl — 192
    • downloads.metasploit.com — 118
    • interact.sh and app.interact.sh — 101

Tool and research-site footprint

A focused set of penetration-testing and research domains generated approximately 5,137 requests, including:

  • OffSec: 1,436
  • PortSwigger: 1,009
  • HackerOne: 726
  • URLScan: 457
  • TryHackMe: 430
  • VirusTotal: 302
  • Webhook.site: 302
  • Nmap: 130
  • Ngrok: 127
  • Shodan: 42
  • Censys: 23
  • Kali: 5

This view highlights the most visited destinations observed through Cisco Secure Access that were classified under security-related categories, including Command & Control (C2C), Cryptomining, Malware, Phishing, and Potentially Harmful content.

Given the security research, demos, training and testing taking place at Black Hat, traffic to many of these destinations was expected and not necessarily indicative of malicious activity.

Fig. 3: Black Hat 2026 top security-related destinations

Growth of Gen AI

The growth of Generative AI was clearly visible on the Black Hat network, with Cisco Secure Access identifying nearly twice as many GenAI applications compared to last year. This increase highlights how quickly AI-powered tools are becoming part of the everyday application landscape and reinforces the growing need for visibility and governance around their use.

Fig. 4: Cisco App Discovery GenAI

With so many talks incorporating AI subjects, the real-world usage of attendees serves as a metric to measure the increase of adoption and the proliferation of AI tools.

Fig. 5: Top 1-5 GenAI DNS Requests
Fig. 6: Top 6-10 GenAI DNS Requests

Notable observations:

  • Claude exceeded ChatGPT in DNS volume. Together they represented 53.5% of GenAI-associated DNS traffic.
  • The top three apps—Claude, ChatGPT and Cursor—accounted for 67.6% of the GenAI total.
  • GenAI was not limited to chatbots. Application development and testing tools generated 257,321 requests (22.9%), led by Cursor, GitHub Copilot, Windsurf and Cline.
  • Search and conversational applications represented 58.5% of requests; office-productivity AI contributed another 12.5%.
  • Cisco marked 14 apps as high risk, but those apps generated 55% of GenAI DNS volume. “High risk” is Cisco’s application-risk classification, not evidence that the traffic was malicious.

Top DNS Categories

Each year, the NOC leaders give awards for the top requested websites by category. In 2026 we saw Slack hold serve for the top chat app, along with clashes of big names like Apple vs. Google and Tinder vs. Hinge. We’ll present the last matchup with no comment.

Fig. 7: Top DNS Categories

Importance of DNS in Your NOC/SOC

DNS is one of the clearest signals a SOC has, especially in an event environment where endpoints are transient, unmanaged, or only briefly connected. Every device needs DNS to find services, reach applications, and communicate outward, which makes DNS visibility a powerful way to identify suspicious domains, command-and-control patterns, newly observed infrastructure, phishing activity, malware callbacks, and policy violations before they become larger incidents.

For the Black Hat NOC/SOC, Secure Access DNS telemetry gives analysts a high-value control point and an investigative starting point. It helps the team protect attendees while preserving the open nature of the network, enrich detections, and support faster human validation with evidence that is easy to correlate across firewall, Zeek, packet capture, malware analysis, and identity context. In modern Security Operations, DNS is not just a network service. It is a security sensor, an enforcement layer, and one of the fastest paths from “something looks suspicious” to “we understand what happened.”

Check out the other blogs from our team at Black Hat USA 2026.

About Black Hat

Black Hat is the cybersecurity industry’s most established and in-depth security event series. Founded in 1997, these annual, multi-day events provide attendees with the latest in cybersecurity research, development, and trends. Driven by the needs of the community, Black Hat events showcase content directly from the community through Briefings presentations, Trainings courses, Summits, and more. As the event series where all career levels and academic disciplines convene to collaborate, network, and discuss the cybersecurity topics that matter most to them, attendees can find Black Hat events in the United States, Canada, Europe, Middle East and Africa, and Asia. For more information, please visit www.BlackHat.com.