Check out the Largest Integration Ecosystem in Cybersecurity and IT and request to be included. 

Black Hat USA 2026: The Agent Governance Land Rush, and What Actually Shipped

Black Hat USA 2026 closed on August 6 with more than 23,000 verified attendees, over 15 percent year-over-year growth, and a new product category that did not meaningfully exist five months ago. When you strip away the branding, nearly all of it addressed one problem: an autonomous agent was handed credentials, tools, and permission to act within production systems without a human approving every step.

One theme, roughly 235 ways

CybrSec Media put a number on the messaging problem everyone felt: “235 exhibitors, more than half the show floor, marketed AI or autonomous agents as part of their value proposition.”

Forkast counted the product side more narrowly, reporting “more than 15 vendors launched specialized products in 48 hours” aimed at agent infrastructure security.

That is the shape of the week.

Not AI in general, which has been the headline since 2023, but the specific problem of an autonomous agent handed credentials, tools, and permission to act inside production systems without a human approving every step. That category barely existed at RSAC. By Thursday it had a dozen competing control planes.

The offensive side got uncomfortably real

The most substantive launches were not the governance products. They were the ones proving autonomous offense already works.

Palo Alto Networks published the strongest evidence of the week, and it came from Unit 42 rather than a product team. Unit 42 built an agentic research system it calls NOVA, pointed it at 3,915 open-source projects across six ecosystems over roughly two months, and came back with 14,090 confirmed vulnerabilities, 99.4 percent previously unreported, nearly 40 percent High or Critical under CVSS 4.0. Scoping, discovery, proof-of-concept, and gatekeeper agents ran an iterative loop “requiring no human in the loop until final review,” each finding validated deterministically before disclosure. Read that against the accompanying launch, PAN-OS 12.2 Ceres and its Advanced Virtual Patching, and the pitch clarifies: the industry-average 55-day patch lag is not survivable when discovery costs this little.

Snyk made Evo Continuous Offensive Security generally available on August 4, and the interesting half is Agent Red Teaming, which detects LLMs in the application stack and simulates the full chain from user prompt through prompt injection to tool abuse and data exfiltration against running agents. Manoj Nair, Snyk’s Chief Technology and Innovation Officer, framed it as preparing for the moment “when autonomous AI attacks move from a research breakthrough to a mainstream operating model for attackers.” Snyk also reports prompt injection reports to HackerOne up 540 percent.

Horizon3 extended NodeZero to web applications and raised $250 million in a Series E co-led by NightDragon and NEA at a valuation above $2 billion, roughly tripling its Series D mark from a year earlier. Snehal Antani, co-founder and CEO, took the expected shot at incumbents: “Legacy web application security tools are notoriously noisy. They flood teams with theoretical findings that lack context or business impact.”

Governing the agent, from every direction at once

On the defensive side, Synqly integration partners covered nearly the full surface of the problem, and each picked a different enforcement point.

ServiceNow shipped six unified autonomous security solutions spanning exposure management, continuous vulnerability detection, cyber-physical security, identity and access security, agentic incident response, and cyber risk and compliance. The cyber-physical piece is the Armis capability arriving post-acquisition. Yevgeny Dibrov, SVP and GM of Cybersecurity and Risk, made the consolidation argument directly: “Machine identities double every 18 months. Fragmented security tools can’t match the curve AI is creating.” Roughly half the portfolio is available now, the rest expected in December.

Tanium introduced Atlas alongside an MCP server that exposes governed Tanium data and actions to Claude, Microsoft Security Copilot, and other MCP clients, as well as External Attack Surface Management built on Censys data. Harman Kaur, Tanium’s CTO, positioned it as governance first: “every action is auditable, boundaries are enforced, and everything is grounded in what’s actually happening on the endpoint right now.”

SentinelOne took the trust-boundary angle with a governed, closed-loop response across Singularity, so Purple AI can investigate, reach a verdict, and act autonomously within the limits the security team sets, with every AI-driven action traceable, auditable, and overridable. Wayfinder Frontier AI Services expanded to Anthropic’s latest models and extended threat hunting into Okta and Microsoft Entra ID.

Torq went after institutional memory with SOC Brain, which learns from a customer’s investigation history and past analyst decisions rather than starting cold on every alert. Mimecast put Agent Risk Center into beta, inventorying every AI tool and connection in an organization, sanctioned or not, and surfacing who is behind each one. Tenable did the most unusual thing of the week and gave something away, launching CyberAgents Exchange, a free open-source registry of agents, skills, MCP servers, and playbooks, with SentinelOne and Recorded Future as founding members.

Qualys attacked latency instead of agents. InstaScan ingests newly published vendor advisories and correlates them against live asset inventory, surfacing confidence-scored detections within minutes of publication rather than at the next scheduled scan. Sumedh Thakar, Qualys President and CEO, reduced it to one line: “A slow vulnerability management program is now the biggest vulnerability an organization has.” Given 46,048 CVEs published in the first seven months of 2026, that is hard to wave off.

CrowdStrike supplied the threat data underneath all of it. The 2026 Threat Hunting Report found that 88 percent of observed exploitations with a public proof of concept occurred within 48 hours of that PoC’s release, including DPRK-nexus actor STARDUST CHOLLIMA injecting a malicious npm package into 131 trusted Mastra AI frameworks.

Outside the partner list the pattern repeated at different layers. Delinea shipped runtime authorization evaluating individual agent actions before they execute, and CEO Art Gilliland gave the week its best framing: “You can have perfect credential hygiene and still have an agent tear through your production environment in milliseconds.” Varonis compares an agent’s reasoning against the task it was assigned and blocks the identity or session on drift. Rubrik mints short-lived tokens per tool call. Zero Networks applied microsegmentation and just-in-time MFA under OWASP’s Least Agency principle. Airlock Digital extended endpoint application control into agent behavior, citing a Cloud Security Alliance survey finding 82 percent of organizations had unknown AI agents already running in their environments.

The most underrated launch of the week was Zimperium’s Deep Insights, which automates mobile forensics, cutting investigation time from weeks to minutes. CEO Shridhar Mittal named the real constraint: security teams are being forced to “investigate more incidents with fewer resources.”

The research nobody put on a booth wall

The Briefings were where the agent problem stopped being a product category and became a set of demonstrated attacks.

Zenity Labs laid out the full scope of PleaseFix, a vulnerability class that enables zero-click agent hijacking across leading agentic browsers, in which an attacker takes control via malicious instructions hidden in ordinary content. Separately, Artem Chaikin of Brave Software showed that Opera’s AI browser, Perplexity Comet, and ChatGPT Atlas remain vulnerable to prompt injection despite multiple security guardrails, and concluded that there is “currently no known perfect solution.”

The question the show mostly avoided

Halcyon published the most useful postmortem of the week. By their count, AI or LLM terminology appeared in roughly 50 of the 115 total briefings, but only 6 described attackers already using AI offensively in the wild. Seth Geftic’s conclusion: “very little of it answers the question that we as defenders really care about: what will attackers do now that they have the power of AI at their disposal?”

Chase Cunningham, Chief Strategy Officer at Demo-Force, said the quieter version of the same thing about the floor: “You cannot walk 20 feet without encountering agentic, AI-powered or autonomous attached to a product that, in some cases, was apparently doing just fine without those words last year.”

Anyone who walked that hall recognizes the sentence.

What I take from the week is that roughly a dozen vendors independently found the same real gap and built genuinely different answers to it: the network layer, the identity layer, the tool call, the endpoint, and the intent. Convergence like that is usually a signal rather than a fad. Which layer turns out to be the right place to enforce is a question the teams running agents in production will answer long before the next keynote does.

We can compare notes in Las Vegas next year.

https://www.synqly.com

Richard brings over 15 years of experience in cybersecurity product strategy, threat intelligence, and marketing to Synqly. Drawing on his extensive background, he writes about market trends, enterprise attack surfaces, and the value of seamless security ecosystems. At Synqly, Richard is focused on eliminating "integration debt" and helping vendors effectively communicate the power of a faster, more secure approach to integrations.


  • Platform
  • Integrations
  • Resources
  • About
  • Blog