Black Hat USA 2026: Vendor Announcements Roundup, Part 1
At Black Hat USA 2026 in Las Vegas, vendors disclosed products and services on Aug. 3 and before, focusing on AI-agent protections, detection and response, and identity controls.
At Black Hat USA 2026 in Las Vegas, dozens of cybersecurity vendors announced new products and services ahead of and on Aug. 3 that target protections for AI agents, automated detection and response, and identity and privilege controls. A digest compiled pre-event and Aug. 3 disclosures outlining the features and aims of those releases.
Acalvio launched Deception Guardrails inside its ShadowPlex platform. The feature deploys honeytokens, decoy tools and fake infrastructure to attract and reveal malicious activity aimed at agentic AI environments and monitors agent interactions for jailbreak attempts and prompt injection in real time.
Artiphishell introduced Verifiable Remediation within its Automated VulnOps Platform. The capability validates scanner findings, filters duplicates and false positives, tests exploitability and generates evidence that a remediation fixed the underlying issue.
Arctic Wolf packaged managed detection and response, attack surface and vulnerability management, endpoint defense and security awareness training into a Cyber Resilience offering. The bundle includes a security operations warranty that can cover up to $3 million in incident costs.
Several vendors added agentic workflows or autonomous agent functions. Cato Networks released Agentic Threat Prevention to model combined network and security telemetry and predict likely attack paths. Cycode launched Agentic Workflows to let AI agents autonomously triage and remediate application security risks based on triggers, actions and confidence thresholds, with options to require human review. Cyera introduced Agent Guardian and Cyera Endpoint to discover and monitor AI agents, govern agent access and enforce runtime controls across cloud and endpoint tools. Sweet Security announced Agentic AI Blocking to terminate unauthorized tool calls, stop secrets and sensitive data leaving via a running agent, and block prompt injections at runtime.
Telemetry, detection engineering and observability updates focused on mapping detections to source data and reducing false positives. Cribl unveiled the Cribl App for AI Observability, stream-native detections and new detection engineering tools to manage AI usage and identify coverage gaps. Prophet Security added AI Detection Engineer to automate creation and tuning of detection rules, including backtesting and confidence scoring. Realm Security introduced Detection Integrity to map SIEM rules to their log sources and added search to its Data Haven retention layer to let teams query raw, normalized security data without restoring archives first.
Identity and privilege protections featured across multiple announcements and in research results. BeyondTrust’s Phantom Labs Research Index reported that 75% of attacks observed involved identity or privilege issues, with credential exposure, privilege escalation and identity misconfiguration commonly appearing together. Varonis added Agent Intent-Based Access Control to its Atlas platform to compare an AI agent’s actions and tool calls against assigned instructions, flag or block deviations, and quarantine identities when session behavior departs from the intended task. Zero Networks released Least Agency Enforcement to limit agent access and actions using identity-based microsegmentation, automated policy enforcement and just-in-time multifactor authentication.
Other releases addressed vulnerability mitigation, testing and intelligence workflows. Miggo Security demonstrated a defense-in-depth mitigation approach using AI-generated, tested controls at the edge and in applications to block exploits, with tests including mitigations for LiteLLM vulnerabilities. Novee extended its AI pentesting platform to mobile applications to provide continuous testing across mobile, web and APIs. Flashpoint added a Custom Summary Builder to its AI Workspace to let analysts produce tailored investigation reports and trace generated content back to source data. KnowBe4 extended Agent Risk Manager to support Anthropic’s Claude, adding six detection engines and a visual map of connected APIs and credentials in early access.
Tool and open source releases included XM Cyber’s exposure hunting tools for macOS and Oracle Cloud, showing macOS trust flaw hunting and methods to map Oracle Cloud permissions. SentinelOne announced a governed, closed-loop response capability for its Singularity platform and expanded its Wayfinder Frontier service to pair Anthropic models with analysts, add new remediation partnerships and extend threat hunting to identity platforms. Several vendors emphasized linking detections to underlying telemetry and evidence to improve analyst confidence and reduce false positives.
The announcements at Black Hat focused on securing AI agents, automating detection and response and tightening identity and privilege controls through new features for telemetry, remediation and testing.








