Skip to content

Black Hat 2026: Security vendors integrate AI agents into operational workflows

Bottom line: At Black Hat 2026, vendors such as ArmorCode, Cribl, CommVault, SOCRadar and Arctic Wolf are shifting focus from pure AI copilots to agent-based workflows for prioritization, threat analysis and recovery.

At Black Hat 2026, several security vendors are shifting their focus from pure AI copilots toward deeply integrated agents for vulnerability management, threat analysis and recovery. For CISOs, this translates into concrete new tools for prioritizing risk and accelerating investigations without having to replace existing infrastructure.

Several vendors presented product announcements at Black Hat 2026 that embed AI more deeply into operational security processes rather than merely deploying it as an assistive feature. ArmorCode is expanding its Agentic Control Plane with four new Anya AI agents as well as enhanced Context Risk Graph capabilities. These are designed to prioritize vulnerabilities based on actual business risk rather than pure CVE count – through attack path analysis, network reachability mapping, patch management integration, and support for compensating controls such as WAFs and EDR platforms. The agents are intended to assess exploitability, recommend mitigations, evaluate cloud exposures, and orchestrate patch rollouts, with shared security context aimed at reducing redundant AI analyses and operational costs.

Cribl introduced a new AI Observability application designed to provide visibility into AI model usage, token consumption, spending, and potential exposure of sensitive data based on already existing telemetry data. In addition, detection engineering capabilities were expanded through the CardinalOps acquisition: detection rules are mapped to MITRE ATT&CK, coverage gaps are identified, and AI-driven workflows are applied. New stream-native detections are intended to identify high-confidence threats directly from telemetry data in motion, without requiring an additional data platform.

CommVault announced an integration of its Threat Scan with Google Threat Intelligence to identify clean recovery points following cyberattacks. The combination of Google’s threat data and CommVault’s backup validation workflows, along with new inline file hash capture, makes it possible to check recovery points against threat indicators already during backup operations. According to CommVault, this multi-stage approach accelerates the validation of recovery points prior to deeper malware or forensic analysis and strengthens the AI-driven synthetic recovery capability. Availability is announced for the coming months.

SOCRadar is launching People Intelligence, a new identity-focused offering within its Extended Threat Intelligence (XTI) platform. The feature aggregates compromised credentials, stealer logs, personal data, attacker telemetry, and other external identity exposure data into unified analyst profiles – without requiring integration of internal HR and IAM systems. Automated risk scoring and consolidated identity context are intended to reduce manual correlation effort during investigations.

Arctic Wolf presented a new cyber resilience offering that bundles Managed Detection and Response, Exposure Management, endpoint protection, Incident Response, and a guarantee of up to 3 million US dollars into a single package. The offering is available immediately, both directly through Arctic Wolf and via its partner ecosystem.


Source: www.csoonline.com · Published August 4, 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.8.3.

Share on: