In brief: At Black Hat 2026, vendors such as ArmorCode, Cribl, CommVault, SOCRadar and Arctic Wolf are shifting AI capabilities from pure copilots toward operationally integrated agents for attack path analysis, recovery validation, identity risk management and bundled cyber resilience offerings.
At Black Hat 2026, the focus is shifting away from pure AI assistants toward operationally embedded agents that prioritize attack paths, harden recovery processes and consolidate identity risk. Several vendors unveiled concrete new product capabilities to this end.
According to CSO Online, this year’s Black Hat shows a shift away from pure AI copilots toward agents deeply embedded in operational security workflows. ArmorCode is expanding its Agentic Control Plane with four new Anya AI agents as well as enhanced Context Risk Graph capabilities. These are designed to prioritize vulnerabilities not by raw CVE count but by actual business risk — via attack path analysis, network reachability mapping, patch management integration, and support for compensating controls such as WAFs and EDR platforms. The agents are meant to assess exploitability, recommend mitigations, evaluate cloud exposures and orchestrate patch rollouts, with shared security context intended to reduce redundant AI analysis and operational costs.
Cribl introduced a new AI observability application that provides visibility into AI model usage, token consumption, spend and potential exposure of sensitive data — based on telemetry data already available. Through the acquisition of CardinalOps, detection engineering capabilities have also been expanded: detection rules are mapped to MITRE ATT&CK, coverage gaps are identified, and AI-powered workflows are applied. New stream-native detections are designed to identify high-confidence threats directly within data in motion, without requiring an additional data platform.
CommVault announced an integration between its Threat Scan and Google Threat Intelligence to identify clean recovery points after cyberattacks. Google threat intelligence data is combined with CommVault’s backup validation workflows; a new inline file hash capture allows recovery points to be matched against threat indicators already during backup. According to the vendor, this multi-stage approach is designed to enable customers to validate recovery points faster before deeper malware or forensic analysis takes place, and to strengthen the AI-powered synthetic recovery feature. Availability is expected in the coming months.
SOCRadar is introducing People Intelligence, an identity-focused offering within its Extended Threat Intelligence (XTI) platform. The feature aggregates compromised credentials, stealer logs, personal data, attacker telemetry and other external identity exposure data into unified analyst profiles — allowing investigators to prioritize identity risk without needing to connect internal HR and IAM systems. Automated risk scoring and consolidated identity context are intended to reduce the manual correlation effort involved in investigations.
Arctic Wolf introduced Cyber Resilience, a bundled offering that combines Managed Detection and Response, Exposure Management, Endpoint Protection, Incident Response and a warranty of up to 3 million US dollars in a single package. The offering is available immediately through Arctic Wolf and its partner ecosystem.
Source: www.csoonline.com · Published August 4, 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.8.3.