In brief: At Black Hat 2026, vendors such as ArmorCode, Cribl, CommVault, SOCRadar and Arctic Wolf are shifting AI capabilities from pure copilots toward operationally integrated agents for attack path analysis, recovery validation, identity risk management, and bundled cyber resilience offerings.
At Black Hat 2026, the focus is shifting from pure AI assistants to operationally embedded agents that prioritize attack paths, harden recovery processes, and consolidate identity risks. Several vendors unveiled concrete new product capabilities to that end.
According to CSO Online, this year’s Black Hat shows a shift away from pure AI copilots toward agents deeply embedded in operational security workflows. ArmorCode is expanding its Agentic Control Plane with four new Anya AI agents as well as enhanced Context Risk Graph capabilities. These are designed to prioritize vulnerabilities not by raw CVE count but by actual business risk — via attack path analysis, network reachability mapping, patch management integration, and support for compensating controls such as WAFs and EDR platforms. The agents are meant to check exploitability, recommend mitigations, assess cloud exposures, and orchestrate patch rollouts, with shared security context intended to reduce redundant AI analyses and operating costs.
Cribl introduced a new AI observability application that provides visibility into AI model usage, token consumption, spend, and potential exposure of sensitive data — based on already existing telemetry data. Through the acquisition of CardinalOps, detection engineering capabilities have also been expanded: detection rules are mapped to MITRE ATT&CK, coverage gaps are identified, and AI-driven workflows are applied. New stream-native detections are designed to identify high-confidence threats directly in data in motion, without requiring an additional data platform.
CommVault announced an integration between its Threat Scan and Google Threat Intelligence to identify clean recovery points after cyberattacks. Google threat data is combined with CommVault’s backup validation workflows; a new inline file hash capture allows recovery points to be matched against threat indicators already during backup. According to the vendor, this multi-stage approach is meant to enable customers to validate recovery points faster before deeper malware or forensic analyses are performed, and to strengthen the AI-driven synthetic recovery capability. Availability is expected in the coming months.
SOCRadar is introducing People Intelligence, an identity-focused offering within its Extended Threat Intelligence (XTI) platform. The feature aggregates compromised credentials, stealer logs, personal data, attacker telemetry, and other external identity exposure data into unified analyst profiles — allowing investigators to prioritize identity risks without needing to connect internal HR and IAM systems. Automated risk scoring and consolidated identity context are intended to reduce manual correlation effort during investigations.
Arctic Wolf introduced Cyber Resilience, a bundled offering that combines Managed Detection and Response, Exposure Management, Endpoint Protection, Incident Response, and a warranty of up to US$3 million in a single package. The offering is available immediately through Arctic Wolf and its partner ecosystem.
Source: www.csoonline.com · Published August 4, 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.8.3.