SecurityWeek

Black Hat USA 2026 – Summary of Vendor Announcements (Part 1)


Many companies are showcasing their cybersecurity products and services this week at the 2026 edition of the Black Hat conference in Las Vegas.

To help cut through the clutter, the SecurityWeek team is publishing a digest summarizing vendor announcements at Black Hat USA 2026, including new products and services, updates to existing offerings, reports, and other initiatives. 

The first part of this roundup covers announcements made in the days leading up to the event, as well as some of the announcements made on Monday, August 3.

Acalvio launches Deception Guardrails for AI agents

Acalvio has launched Deception Guardrails, a new capability within its ShadowPlex platform aimed at protecting AI agents from compromise. The feature deploys honeytokens, decoy tools, and fake infrastructure to lure and expose malicious activity targeting agentic AI environments. It also monitors agent interactions to flag jailbreak attempts, prompt injection, and other manipulation in real time. 

Artiphishell introduces Verifiable Remediation

Advertisement. Scroll to continue reading.

Artiphishell, a DARPA-backed company, launched Verifiable Remediation as part of its Automated VulnOps Platform, aimed at helping teams cut through scanner noise and confirm that fixes actually work. The feature validates whether flagged vulnerabilities are real, filters out duplicates and false positives, and checks for exploitability before generating automated remediation. It then produces evidence-backed proof that a fix has addressed the underlying issue.

Arctic Wolf launches cyber resilience offering

Arctic Wolf has introduced a new Cyber Resilience offering that packages several of its existing products and services into one bundle. The suite combines managed detection and response, attack surface and vulnerability management, endpoint defense, and security awareness training. Customers using the offering are also eligible for the company’s security operations warranty, which covers up to $3 million in costs tied to a security incident.

BeyondTrust report ties majority of attacks to identity and privilege gaps

BeyondTrust’s Phantom Labs research team released its annual Research Index, drawing on the group’s offensive security work over the past year. The report found that 75% of attacks involved some form of identity or privilege issue, with credential exposure, privilege escalation, and identity misconfiguration among the leading root causes. These issues often compounded each other rather than appearing in isolation, with standing privilege and escalation frequently occurring together. 

Cato Networks adds agentic capability to predict AI-driven attacks

Cato Networks has launched Cato Agentic Threat Prevention, a new capability that uses autonomous agents to anticipate likely attack paths and tailor defenses to each customer’s environment. The feature draws on combined network and security telemetry from Cato’s platform to model risk across users, applications, and traffic patterns, then predicts how attackers might chain techniques or evade controls.

Cribl adds new AI security and observability capabilities to platform

Telemetry platform provider Cribl has unveiled new tools to help enterprises manage AI security and observability through their own telemetry data. The new tools include the Cribl App for AI Observability, which manages AI usage and risk; new detection engineering capabilities that identify coverage gaps; and stream-native detections in Cribl Stream that pinpoint high-confidence threats earlier.

Cycode adds agentic workflows to automate risk response

Cycode has launched Agentic Workflows, a new capability that lets AI agents autonomously triage, remediate, and manage security risks as they emerge across the application development lifecycle. Security teams define a workflow’s triggers, agent actions, and confidence thresholds, then let agents act automatically once a matching event occurs (such as a new critical CVE or a missed SLA on an exploitable finding). Teams can also set which actions require human review versus running autonomously. The feature is currently in early access.

Cyera launches Agent Guardian, new AI agent risk product

Cyera has introduced Agent Guardian and Cyera Endpoint, new capabilities designed to secure enterprise AI agents by providing visibility into agent activity, governing what agents can access, and enforcing runtime controls across cloud and endpoint environments. Agent Guardian continuously discovers, monitors, and protects AI agents from threats like prompt injection and unauthorized data access, while Cyera Endpoint extends those guardrails to local AI tools running directly on employee devices.

Flashpoint adds custom summary builder to threat intelligence platform

Flashpoint has launched a Custom Summary Builder within its AI Workspace for Investigations Management, part of the Flashpoint Ignite platform. The tool lets analysts choose from a set of report sections (such as executive summary, actors and entities, and TTPs) to tailor AI-generated investigation findings for different audiences, and save those configurations as reusable templates. Generated content can be traced back to the underlying Ignite data for review, and analysts can also query the investigation material through an AI chat function for follow-up questions. 

KnowBe4 extends Agent Risk Manager to cover Claude

KnowBe4 has added support for Anthropic’s Claude to its Agent Risk Manager, extending the tool’s governance layer beyond its existing support for Microsoft Copilot. The tool monitors agent behavior without altering the underlying model, using six detection engines to flag prompt injection, sensitive data leaks, privilege escalation, and unapproved tool access. It also includes a visual map of connected APIs and credentials to help security teams identify high-risk points if an agent is compromised. The feature is currently in early access for SAT Advanced customers on US-tenant accounts.

Miggo Security launches defense-in-depth mitigation solution

Miggo Security launched a defense-in-depth mitigation solution that closes the gap between vulnerability disclosure and patching. It uses AI-generated, tested controls at the edge and inside the application to quickly stop exploits and cut exposure windows. Miggo demonstrated the approach against two recent LiteLLM vulnerabilities, blocking one at the WAF and the other at runtime based on how each exploit actually worked.

Novee expands AI pentesting platform to mobile applications

Novee has expanded its AI pentesting platform to mobile applications, bringing continuous testing across mobile, web and the APIs connecting them into one platform. Customers can upload an Android app and receive proven findings within hours, combining reverse engineering with live runtime testing.

Prophet Security adds AI-driven detection engineering to SOC platform

Prophet Security has released AI Detection Engineer, a new addition to its Agentic AI SOC Platform that automates the process of building and maintaining detection rules. The tool analyzes an organization’s past investigations and threat hunting results to identify coverage gaps, author new detections, and tune existing rules to cut down on false positives. Each recommendation is backtested against historical data and comes with supporting evidence and a confidence score before being applied.

Realm Security adds detection integrity and search features to data platform

Realm Security has introduced two new capabilities, Detection Integrity and search in Data Haven. Detection Integrity maps SIEM detection rules to the log sources they depend on, letting teams reduce log volume while confirming existing detections still work. Data Haven, the platform’s retention layer, keeps a raw, OCSF-normalized copy of security data and now allows teams to search that history directly rather than restoring archived logs first. Both features are aimed at letting organizations lower SIEM ingestion costs without losing detection coverage.

SentinelOne expands autonomous SOC and Wayfinder AI services

SentinelOne unveiled two updates at Black Hat USA 2026. The first adds governed, closed-loop response to its Singularity Platform, letting Purple AI investigate alerts, reach verdicts, and execute response actions within limits set by security teams, with every action traceable and reversible (expected generally available later this quarter). The second expands Wayfinder Frontier AI Services, its managed offering that now pairs Anthropic’s latest models with SentinelOne analysts to find and validate exploitable vulnerabilities, backed by a new remediation partnership with LevelBlue, customizable MDR workflows, and threat hunting extended to identity platforms like Okta and Microsoft Entra ID.

Sweet Security announces new blocking capabilities

Sweet Security announced Agentic AI Blocking, the ability to stop rogue AI agents in live production, in real time. The new capabilities enable organizations to terminate unauthorized tool calls and sessions at runtime, stop secrets, PII, and sensitive data from leaving through an agent, and block prompt injections before they steer an agent off course. 

Varonis adds intent-based access control to Atlas platform

Varonis has introduced Agent Intent-Based Access Control (IBAC), a new capability in its Atlas platform that monitors whether an AI agent’s actions match its assigned instructions. The feature compares an agent’s reasoning, tool calls, and data access against its original task, with adjustable sensitivity settings, and can flag or block actions that fall outside that scope. It evaluates entire sessions to catch risks that build up over multiple turns, such as gradual jailbreak attempts. When a violation occurs, Atlas can quarantine the associated identity for a set period, while flagged actions can also be routed to a human for approval.

XM Cyber released open source exposure hunting tools

XM Cyber has released open source exposure hunting tools for macOS and Oracle Cloud. At Black Hat Arsenal, it will demonstrate FAInd my XPC, which uncovers macOS trust flaws that could let unprivileged attackers invoke privileged services, including paths to root code execution. At DEF CON, XM Cyber will unveil its Offensive OCI toolset, which maps effective Oracle Cloud permissions and exposes hidden privilege-escalation paths.

Zero Networks launches new tool for enterprise AI

Zero trust security firm Zero Networks has launched Least Agency Enforcement, a new AI security capability that allows enterprises to limit what AI agents can access, what actions they can perform, and when human approval is required, preventing agents from exceeding their intended authority. Least Agency Enforcement applies identity-based microsegmentation, automated policy enforcement, and just-in-time MFA to ensure AI agents communicate only with authorized systems, access only approved resources, and are contained if they’re manipulated, over-permissioned, or compromised. 

Related: RSAC 2026 Conference Announcements Summary (Day 1)

Related: RSAC 2026 Conference Announcements Summary (Days 3-4)



Source link