Black Hat USA 2026: Key Vendor Announcements, Part 4
At Black Hat USA 2026 in Las Vegas, vendors announced new security products and research, including 1Password’s AI-patch findings, its Privileged Access product, Cogent’s VR-1 model and Synack’s NatJack discovery.
At Black Hat USA 2026 in Las Vegas, multiple vendors revealed new security tools and research across endpoint, runtime, AI and network domains. Announcements included results from 1Password’s new research group, a frontier AI model from Cogent Security, and Synack Red Team’s NatJack network findings.
1Password’s Off-By-1 Labs evaluated more than 6,000 AI-generated patches for recently disclosed, complex open-source vulnerabilities. Researchers found 54% of the patches did not fully remediate the targeted vulnerability, either leaving the original flaw, introducing a new flaw, or both. Twenty-six percent of patches fully resolved the vulnerability without changing application behavior, and 20% fixed the issue but changed behavior. At the conference, 1Password introduced 1Password Privileged Access, an extension of its Unified Access platform into privileged access management. The product creates accounts on demand scoped to a task and deletes them automatically when the task is complete rather than maintaining standing privileged accounts.
Cogent Security announced VR-1, a frontier AI model the company positions as comparable to other large reasoning models. Cogent described VR-1 as a model that correlates business context, identities and runtime controls into a machine-readable view of an organization’s security posture. The company said the model is paired with a “security harness” designed to align model reasoning with live environment data.
Synack Red Team researcher Malcolm Stagg presented NatJack, a set of network address translation (NAT) attack techniques developed over several years. Testing found weaknesses in independently developed NAT implementations on Windows, Linux and macOS. Stagg described four attacker techniques: hijacking active TCP connections, poisoning DNS responses, identifying ports assigned to other connections, and exhausting NAT tables to cause denial of service. Two CVEs were assigned: CVE-2026-56181 affecting Microsoft Windows NAT in Hyper-V, and CVE-2026-63913 affecting the Linux netfilter conntrack subsystem.
Cyble updated its Titan endpoint security platform to include silicon-rooted attestation and integrated automated attack reconstruction driven by BlazeAI. The company said the update links endpoint telemetry with threat intelligence and behavioral analytics and provides a single interface for device controls, exposure management and auditable response workflows.
RapidFort launched RapidFort Runtime, a continuous threat elimination product that runs in live production environments. The product monitors deployed software for unauthorized changes, keeps a curated inventory of open-source components and tracks new CVEs in real time.
NeuralTrust introduced a runtime security mesh that inspects agentic AI traffic through an Agent Gateway. The system monitors agent reasoning to detect drift, enforces tool authentication policies and flags malicious payloads such as prompt injections or exposed credentials, and can forward alerts and logs to enterprise SIEMs. Optiv introduced Optiv Agentic Security Operations, a managed service that pairs Google Security Operations with Wiz products to triage alerts using agentic AI and enrich findings with cloud, identity and exposure telemetry from Wiz Cloud, Wiz Code and Wiz Defend.
Vectra AI launched Vectra AI Pro, which correlates network, identity, cloud, SaaS, EDR and SASE signals to provide contextual inputs for AI agents and SOC workflows. Zenity disclosed a malicious skills campaign distributed via Vercel’s skills.sh that reached roughly 1.7 million installs before disruption and released AI Total, a free service that executes AI agent skills inside a contained environment to analyze runtime behavior.
CyberProof published research on a browser-downloaded installer disguised as a free utility. The analysis showed the attack relied on user interaction, convincing landing pages, valid code-signing certificates and server-side control rather than exploiting software vulnerabilities, and mapped the delivery chain and potential downstream impact if prevention failed.
KnowBe4 announced enhanced Real-Time Coaching that delivers short SecurityTips when risky behavior is detected and factors those interventions into organizational Risk Scores. The announcements at Black Hat covered AI-generated patch safety, runtime protection for agentic systems, privileged access workflows, endpoint attestation, supply-chain delivery risks and NAT-level network vulnerabilities.








