At Black Hat USA 2026 in Las Vegas, vendor announcements underscored a major architectural shift across enterprise security tools: defending against and managing autonomous AI agents. As threat actors collapse the window between vulnerability disclosure and exploit execution, security platforms are pivoting toward continuous, autonomous, and scanless capabilities across identity, vulnerability management, runtime protection, and software development workflows.
AI Agent Governance and Coding Assistant Security
The rapid rollout of AI coding agents and autonomous AI workflows across enterprise environments has introduced severe visibility and policy enforcement gaps at the endpoint and operational levels.
- Legit Security released VibeGuard 2.0, targeting AI coding agents such as Claude Code, Cursor, and GitHub Copilot. Operating at the endpoint level, the tool introduces granular command filtering and Model Context Protocol (MCP) security controls. MCP controls are critical because coding tools that integrate directly with developers’ local shells and repositories can be tricked or directed into running unauthorized system commands; VibeGuard 2.0 enforces policy guardrails, skill discovery limits, and anti-tampering protections to prevent tools or users from disabling security controls.
- Drata expanded its Trust Management Platform into limited availability for AI Agent Governance, starting with native support for Anthropic. The solution provides discovery, runtime monitoring, and auditability for AI agents operating within enterprise boundaries, giving compliance and security teams trace logs to prove governance.
- Sysdig launched Sysdig Secure AI, adding autonomous agentic capabilities to its Sysdig Secure cloud-native application protection platform (CNAPP). Crucially, it includes a “headless” integration mode designed to interface directly with AI coding assistants like Claude and Cursor during development and runtime remediation loops.
Continuous Exposure Management and Scanless Detection
Traditional scheduled vulnerability scanning is increasingly unviable given the speed of modern exploitation. Vendor updates at Black Hat reflect a broader migration toward continuous telemetry analysis, graph-based reachability, and autonomous testing.
- Qualys introduced InstaScan within its Enterprise TruRisk Management (ETM) platform. Powered by an AI agent called Agent Insta, the scanless detection engine normalizes software identities into standard identifiers—specifically Common Platform Enumeration (CPE) and Package URL (PURL) formats—and continuously matches them against new vendor advisories without sending active network probes or scheduled scan jobs.
- Astelia launched new agentic AI capabilities for its exposure management platform, automating reachability analysis and remediation workflows across vulnerability lifecycles while retaining mandatory human approval gates for critical decisions.
- Horizon3.ai expanded its autonomous pentesting platform with NodeZero WebApp Pentesting, designed to safely execute web application attacks in production environments to validate actual exploitable paths and map them directly to known threat actor tactics. The release follows Horizon3.ai’s $250 million funding round.
- ProjectDiscovery moved Neo v1 to general availability under a pay-as-you-go pricing model, bringing continuous security testing across code, application interfaces, APIs, cloud assets, and network boundaries without requiring legacy procurement processes.
Threat Research and Adversary Weaponization of AI
Multiple threat intelligence releases at the conference highlighted how adversaries are integrating generative models directly into their attack chains to increase speed and precision.
- CrowdStrike published its 2026 Threat Hunting Report, pointing out that threat actors are exploiting newly disclosed vulnerabilities within hours of public release by leveraging AI assistants. The report detailed an uptick in cloud-focused intrusions, AI supply chain compromises, and the abuse of trusted authentication workflows.
- Cisco Talos released research based on recovered adversary prompt logs, attack tooling, and operator chat logs demonstrating how cybercriminals use LLMs as development assistants. Rather than relying on sophisticated jailbreaks, threat groups use standard LLM capabilities to draft malware modules, establish fraud infrastructure, and perform rapid vulnerability research.
- Huntress made its RMM Guard feature free to all customers with an active agent deployment. Remote Monitoring and Management (RMM) tools remain a primary target for initial access and persistence because security software typically trusts them by default. Huntress highlighted this risk in light of ongoing exploitation of an N-central RMM vulnerability in the wild, noting that RMM Guard blocks unauthorized remote management binaries from executing on endpoints.
Data Sensitivity, Identity, and PKI Automation
Data loss prevention and identity security tools are also moving away from static point-in-time classifications toward dynamic evaluation across hybrid cloud and agentic environments.
- AvePoint launched Kinetic Classification within its Confidence Platform, replacing static tags with continuous data sensitivity re-evaluation across Microsoft 365, Google Workspace, and enterprise SaaS apps. The company also updated its Rapid Recovery system with a dedicated recovery wizard and express restoration tools for Microsoft Entra ID.
- Netskope introduced the Netskope One DataSec Command Center, offering a unified plane to track and safeguard sensitive data across enterprise networks and AI model interactions.
- SailPoint unveiled SailPoint Identity Security, merging its Agentic Fabric and Human Fabric modules to establish continuous identity governance loops across human users, machine accounts, and autonomous AI agents.
- Sectigo released the Sectigo Orchestration Gateway (SOG) within Sectigo Certificate Manager (SCM). SOG centralizes discovery, issuance, and renewal automation across IIS, Apache, F5, NGINX, and Citrix deployments, pulling credentials dynamically via integrations with CyberArk, Delinea, HashiCorp, and BeyondTrust.
- Sevii rolled out an Autonomous Preemptive Security (APS) module for its Sevii Autonomous Defense & Remediation platform, continuously translating global threat feeds and internal environmental context into automated hypothesis hunting and risk remediation.
Related content
Black Hat USA 2026 Vendor Wrap-Up: Focus Turns to Agentic AI and Virtual Patching
Security NewsFrontier AI Models Favor Offense Over Defense in New Cyber Benchmark
Security NewsGhostJacking Technique Exploits Identity Governance Gaps in AI Agents
Security NewsOkta Acquires Permiso to Expand Into Identity Threat Detection and SecOps
Found something similar in your stack?
Let's find out before it becomes an incident.
Book an advisory call