惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

罗磊的独立博客
小众软件
小众软件
The Cloudflare Blog
博客园 - 【当耐特】
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
酷 壳 – CoolShell
酷 壳 – CoolShell
WordPress大学
WordPress大学
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
V
Visual Studio Blog
量子位
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
美团技术团队
S
SegmentFault 最新的问题
宝玉的分享
宝玉的分享
博客园 - 叶小钗
月光博客
月光博客
Apple Machine Learning Research
Apple Machine Learning Research
T
Tailwind CSS Blog
博客园 - 聂微东
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
J
Java Code Geeks
Y
Y Combinator Blog
D
Docker
Microsoft Azure Blog
Microsoft Azure Blog

The Last Watchdog

News Alert: SpyCloud survey finds machine identity risks outpace defenses, exposing gaps in oversight | The Last Watchdog News Alert: Reflectiz launches AI website testing, uses site context to find and verify flaws | The Last Watchdog News Alert: Link11 reports fewer but stronger DDoS attacks in Europe for the first half of 2026 | The Last Watchdog GUEST ESSAY: AI coding assistants are putting open source in your code without declaring it | The Last Watchdog News alert: OpenMatter adds secure routing for OpenAI, Anthropic and Google models | The Last Watchdog LW ROUNDTABLE: OpenAI’s test agents self-organized into a rogue swarm no one anticipated | The Last Watchdog News alert: Bright Security launches AI PT, AI-powered penetration testing that cuts weeks to hours | The Last Watchdog MY TAKE: ChatGPT’s five-hour outage coincided with a model retirement its incident record omits | The Last Watchdog NEWS ALERT: Lunar Cyber tracks stolen API keys, ties them to infected employer devices | The Last Watchdog NEWS ALERT: SRA makes SOC AI license-free — customers pay only for the Azure compute they use | The Last Watchdog BLACK HAT FIRESIDE CHAT: How linking SOC alerts cuts noise, reveals attacks taking shape | The Last Watchdog News alert: Airlock Digital IRAP assessment bolsters trust for sensitive Australian deployments | The Last Watchdog News alert: OpenMatter Network spotlights AI verification at Belgrade Blockchain Week | The Last Watchdog MY TAKE: Black Hat 2026 Part 3 — Agentic AI can do the work, but somebody has to prove it | The Last Watchdog MY TAKE: Black Hat 2026 Part 2 — Security shifts to deciding in advance what an AI agent may reach | The Last Watchdog News Alert: Pulse Security AI’s research reveals C-suite, board confidence gap on cyber exposures | The Last Watchdog BLACK HAT ROUNDTABLE: Security pros dissect fallout from Hugging Face’s double guardrail failure | The Last Watchdog News alert: Airlock extends endpoint control to govern AI agents and define operating boundaries | The Last Watchdog News alert: Mallory links threat intelligence to governed response as exploit timelines shrink | The Last Watchdog News alert: Community voting shapes 2026 Cybersecurity Excellence Awards | The Last Watchdog BLACK HAT Q&A: The AI agent that clears the human door and slips past the machine gate | The Last Watchdog News alert: Pulse Security launches with $8 million for AI platform to modernize CISO operations | The Last Watchdog News alert: Insignary’s on-demand SBOM verification boosts software supply chain security | The Last Watchdog News alert: Tego AI finds Anthropic’s integration of Claude and Slack can trigger unauthorized actions | The Last Watchdog News alert: OpenMatter joins HOL initiative to shape trust standards for autonomous AI | The Last Watchdog News alert: Insignary tackles SBOM accuracy gap as AI tools intensify software supply-chain risk | The Last Watchdog News alert: Link11 launches faster DDoS mitigation to counter AI-driven, adaptive network attacks | The Last Watchdog News alert: Reflectiz partners with Taboola to host webinar on AI-driven marketing security risks | The Last Watchdog News alert: OpenMatter launches platform to verify AI activity across enterprise systems | The Last Watchdog News alert: SpyCloud report finds phishing surge exposing employee data at Fortune 100 companies | The Last Watchdog
MY TAKE: Black Hat 2026 Wrap-up Part 1 — AI is forcing se...
bacohido · 2026-08-10 · via The Last Watchdog

By Byron V. Acohido

Companies have kept security in one silo and operations in another for as long as both have existed.

Related:Part 2 — deciding what AI can reach

Agentic AI is collapsing the divide. That is what a week at Black Hat USA 2026 made plain to me.

Here’s what I’m driving at: Network security and IT operations grew up in separate silos. Security watched for intruders and cleaned up after them. Operations provisioned the accounts, pushed the updates and kept the systems running.

Now both sides are absorbing hits from the same technology. Adversaries are using AI agents to intensify everything they already do, which lands on security. At the same time, companies are deploying AI agents into production faster than anyone can track what those agents can reach, creating unprecedented exposures, which lands on operations.

On July 21, OpenAI disclosed that two of its own models broke out of a sandboxed evaluation, reached the open internet and compromised Hugging Face’s production infrastructure to get a benchmark’s answer key. No human picked that target. The models did.

Dual use for AI security tools

Security is answering by putting AI agents of its own into the fight, and that is where the silo starts coming apart. An agent built to watch for a hostile agent has to know what the company’s own agents are provisioned to do, which was always an operations question. The tooling that defends against the first problem turns out to be the tooling that can corral the second.

Spiteri

That convergence showed up in the conversations vendors were having on the floor. I caught up with James Spiteri, a product manager at Elastic Security, at his company’s booth. He told me that roughly 95 percent of his conversations all week ran on both problems at once.

Visitors wanted attackers’ AI agents kept out of their networks. They also wanted to keep deploying agents of their own at a breakneck pace, fully aware they are absorbing risk they cannot yet measure.

The instinct at that point is to try to cover everything at once. “Don’t try and boil the ocean,� Spiteri counsels. Take a single lane, whichever one is worst, and stay there until you know what you have.

LW’s show coverage

I plan coverage of a gathering like Black Hat months out. I book sit-down interviews with executives from a couple dozen vendors, back to back, and I schedule blocks to walk the exhibits floor. The floor time is where the discovery happens.

This year it produced booth talks at random stops, hallway pulls, and one wrong turn looking for a restroom that put me in front of a mapping company for an hour, learning how location data has become security telemetry. Whatever minutes I save between appointments go to wrangling notes. That is usually when somebody taps me on the shoulder, and that conversation goes in the notebook too.

A show like this normally gets one wrap-up column from me. This year it gets three. There was too much on the floor to fit in a single column, so I am running a three-part Black Hat USA 2026 wrap-up series: Part 1 today, Part 2 Tuesday, Part 3 Wednesday. Part 1 covers the biggest thing I saw. The security operations center is where the two sides are merging first.

Eight SOC innovators

Eight of the vendors I looked at closely are building for the SOC, and what pulled them there is the staffing. A SOC is staffed in tiers. Analysts work shifts around the clock, and the lower tiers repeat the same steps all day. Hiring cannot keep up, and now the pressure is arriving from the attackers and from the company’s own deployments at the same time.

That gap is where the innovation has rushed in. More money, more founders and more shipping product went at the SOC this year than at any other corner of the enterprise.

Eight vendors, eight different roads to the SOC. Here is what I took from each.

TENEX.AI — Sarasota, Fla. Founded 2025. Automated triage on every alert, human-led response.

An old contact I had not seen in a decade, Mike Haro, tapped me on the shoulder as I was wrangling notes at a hallway side table and walked me into the TENEX customer suite, where a product manager gave me a full briefing.

He was eager to talk about the Agentic SOC Alliance, a fifteen-company coalition ExtraHop convened in July. TENEX is a founding member. The members are writing a shared blueprint for autonomous defense, organized in three layers: the context an agent reasons over, the orchestration that governs what it may do, and the model itself, which they treat as interchangeable.

The premise is that no single vendor can cover this alone. An attacker can now point tens of thousands of agents at one company, and answering that takes threat intelligence, orchestration and reasoning that no one company owns end to end.

TENEX comes at it from Google. CTO Venkata Koppaka and CRO Edwin Solis helped build Chronicle, now Google SecOps; CEO Eric Foster co-founded Cyderes. The product is an overlay on that stack rather than a platform of its own.

Mate Security — Tel Aviv. Founded 2025. A relationship graph that supplies the context alerts are missing.

Mate was handing out free massages in a white-shag lounge on level three. I looked the company up while waiting for a chair and got the briefing at their booth later that day.

CEO Asaf Wiener was a product leader at Wiz and Microsoft, and the first Wiz alumnus to leave and found a startup. Oren Saban ran product for Microsoft Defender XDR and Security Copilot. Guy Pergal came out of Microsoft’s threat intelligence center and later ran engineering at Axonius.

The bet is that an alert means nothing without knowing how the business runs. Mate’s patent-pending Security Context Graph maps assets, business processes, users and data for each customer, then builds detections and triages incidents against that map.

Simbian — Mountain View, Calif. Founded 2023. AI agents for alert triage, threat hunting and pentesting.

I have interviewed Simbian CEO Ambuj Kumar numerous times, most recently for his read on the Hugging Face breach in the roundtable that ran mid-show.

Kumar

Kumar came to security from silicon: lead designer on multiple NVIDIA GPU generations, then co-founder of Fortanix, which raised more than $135 million and established confidential computing as a category. He started Simbian in 2023 with Alankrit Chona, a former Twitter engineer.

The bet is that reasoning was never the scarce part. Simbian runs four agents, for the SOC, threat hunting, pentesting and the network, and all four reason against one shared store called the Context Lake. Every alert triaged and every analyst correction flows back into it. Swap the underlying model and the agents keep their footing, because what they know about the customer sits outside the model.

Legion Security — New York. Founded 2024. Automation learned by watching analysts work in their own tools.

Abramovitch

Legion came to me sideways. I went to a PR rep chasing one client and he brought two more along, which is how a hustling rep earns his keep. CEO Ely Abramovitch’s commentary landed in time for Wednesday’s roundtable.

Abramovitch is a former jazz musician who came back to Israel, studied math and went into security. He founded Legion in 2024 with Michael Gladishev, out of Microsoft and Sentinel, and CTO Eyal Fisher, out of Cambridge AI research.

Abramovitch locates the danger in what the agent did not know. The agent that hit Hugging Face, he noted, had no sense that this was a real company, a real production system, or that finding an answer and breaching infrastructure were different acts. Lacking context, “it filled the gap with its best guess, and it guessed wrong.” So Legion trains inside the customer’s environment. A browser extension watches analysts work, learns the judgment calls that never reach a runbook, and replays them.

Gurucul — Los Angeles. Founded 2010. SIEM incumbent extending entity modeling to AI agents.

I have covered Founder and CEO Saryu Nayyar for years and her read on behavior analytics has held up better than most, which is why she was the voice I wanted for the Hugging Face roundtable. I missed her at the booth. Her commentary came by email in time to run Wednesday.

Nayyar

She co-founded Gurucul in 2010 with CTO Nilesh Dherange and has run it since, making her the longest-tenured founder in this group by more than a decade. She holds patents pending in behavior analytics, anomaly detection and dynamic risk scoring. Gartner named Gurucul a Leader in its 2025 Magic Quadrant for SIEM, after three straight years as the most visionary provider.

The bet is that context belongs to the customer. Gurucul models every user, device and workload as an entity with a baseline and a blast radius. The Open AI SOC platform, launched in March, runs that model against a customer’s own data lake, in Snowflake or Databricks rather than in vendor storage.

On August 4 Gurucul added AI agents, copilots, tools, plugins and MCP servers as entities alongside humans and machines. It is the only product in this group watching a company’s own agents and the agents attacking it, in one model.

SecurityBridge — Ingolstadt, Germany. Founded 2012. Cybersecurity built natively inside the SAP environment.

A scheduling conflict cost me my sit-down, so what follows comes from the public record.

Christoph Nagy ran the company as CEO from January 2012 until this year, when Jesper Zerlang moved up from chairman. Zerlang spent fifteen years building Logpoint into one of Europe’s larger security companies. Nagy and co-founder Ivan Mans stepped into strategic and product roles.

The bet is depth in one system instead of breadth across many. SecurityBridge builds threat monitoring, vulnerability management and compliance inside SAP rather than alongside it, and secures more than 5,000 SAP systems worldwide. Other vendors ask what is normal and what an entity can reach across a whole enterprise. SecurityBridge asks the same questions where the financials live.

Varist — Reykjavik, Iceland. Founded 2012, roots to 1993. OEM detection engine trained on a three-petabyte malware archive.

Bjornsson

Varist CEO Halli Bjornsson made the point in my Hugging Face roundtable that nobody else did. Morris, Stuxnet and SolarWinds were built to infect thousands of independent targets. This attack had one. Built to spread, he observed, it could have produced self-evolving malware more dangerous than all three. With millions of open-weight users coming, defenders will have to account for attacks by goal-seeking agents working for people with no malicious intent.

A coherent position for him to hold. Varist traces to Frisk Software, one of Iceland’s original antivirus houses, and Bjornsson has worked on malware at machine scale since before most of this week’s exhibitors existed. Decades of accumulated samples nearly got deleted as a storage cost before becoming the company’s training asset.

The Hybrid Detection Engine, launched in February, scans every file rather than sampling, and simulates suspicious code roughly 1,000 times faster than a conventional sandbox. Verdicts come back in under nine milliseconds. It runs inside the customer’s own infrastructure and ships as an OEM component, already sitting in front of more than five billion mailboxes.

Varist sits upstream of everyone else here. The others work the alert queue. Varist is trying to keep the alert from being generated.

HPE Networking — Houston. Founded 2002 (as Aruba Networks). Network telemetry at scale, repurposed for behavioral baselining.

David Hughes and I sat down at the show for a Fireside Chat. Hughes has been building networks since founding Silver Peak in 2004, and his story is that the network became a security platform sideways. HPE collects session telemetry from millions of network-managed devices and more than a billion customer endpoints on Aruba Central. It started collecting that data to answer help-desk tickets about bad video calls. The same data turned out to baseline behavior.

The bet is that scale produces signal nobody can manufacture. Hughes calls the payoff fleet learning. Take an electronic door lock that normally talks to four IP addresses. It starts calling a fifth. Inside one customer’s network, that means something is wrong. Across a thousand customers at once, it means the manufacturer pushed an update. Neither read is available to a company looking only at its own network.

Agents are where the machinery pays off twice. An agent authenticates correctly, so nothing stops it at the door. Then it gives itself away by tempo. “It’s going to type faster than a human,” Hughes said.

Acohido

Pulitzer Prize-winning business journalist Byron V. Acohido is dedicated to fostering public awareness about how to make the Internet as private and secure as it ought to be.

(Editor’s note: I used Claude and ChatGPT to assist with research compilation, source discovery, and early draft structuring. All interviews, analysis, fact-checking, and final writing are my own. I remain responsible for every claim and conclusion.)

August 10th, 2026 | Black Hat | Black Hat Podcasts | My Take | Top Stories