Many companies are showcasing their cybersecurity products and services this week at the 2026 edition of the Black Hat conference in Las Vegas.
To help cut through the clutter, the SecurityWeek team is publishing a digest summarizing vendor announcements at Black Hat USA 2026, including new products and services, updates to existing offerings, reports, and other initiatives.
The first part of this roundup was published on August 3.
Astelia unveils agentic AI exposure management capabilities
Astelia launched its new agentic AI capabilities for its exposure management platform, automating reachability analysis and remediation workflows across the entire vulnerability lifecycle. By adding this new agentic layer, the platform now evaluates newly disclosed vulnerabilities and their reachability, assesses operational impact, coordinates remediation across security and IT teams, and helps drive each issue toward resolution. Human approval remains built into key decision points, with every action logged and auditable.
AvePoint adds continuous data sensitivity classification to Confidence Platform
AvePoint has introduced Kinetic Classification, a capability that continuously re-evaluates data sensitivity across Microsoft 365, Google Workspace, and other business applications, replacing static, one-time labeling. AvePoint also added new tools to its Rapid Recovery system, including a Rapid Recovery Wizard and Express Recovery for Entra ID, meant to help teams prioritize restoration of critical data after an incident.
CrowdStrike publishes 2026 Threat Hunting Report
CrowdStrike’s 2026 Threat Hunting Report finds that AI is now embedded across modern adversary operations, with threat actors using AI to accelerate attacks, exploit vulnerabilities within hours of public disclosure, and target enterprise AI systems and software supply chains. The report also highlights a sharp rise in cloud-focused attacks, AI supply chain compromises, and abuse of trusted authentication workflows, underscoring the need for organizations to secure AI environments while using AI to defend against increasingly automated threats.
Cisco Talos research shows how threat actors are weaponizing AI
Cisco Talos released new research detailing how threat actors are using AI and LLMs in real-world cyberattacks. Drawing on recovered prompt logs, attack tooling and threat actor conversations, the research documents how AI is being used to develop malicious code, build fraud infrastructure, and accelerate vulnerability research and exploitation. The research found that threat actors rarely need sophisticated jailbreaks; sophisticated threat groups are leveraging AI as a development assistant to rapidly build exploits; and that adversaries use AI across various steps of the attack lifecycle and operations.
Drata extends trust management platform to AI agents
Drata has extended its Trust Management Platform, announcing the limited availability of AI Agent Governance, which is designed to help enterprises discover, monitor, govern, and prove traceability of the AI agents running inside the organization. The product ships first for Anthropic, with early access customers already running it end-to-end in production.
Horizon3 extends production-safe autonomous pentesting to web applications
Horizon3.ai announced NodeZero WebApp Pentesting, an expansion that enables the NodeZero platform to autonomously and safely test web applications the way attackers operate. It proves what is actually exploitable, quantifies the business consequence of each attack path, and maps those paths to the tactics of known threat actors. The announcement comes just as the company raised $250 million in funding.
Huntress expands Managed ESPM with free RMM Guard
Huntress announced that its RMM Guard is now available for free to all customers with an agent deployed, as part of its broader Managed ESPM effort. This release is focused on detecting and blocking rogue remote monitoring and management tools that attackers increasingly abuse to gain and maintain access. RMM Guard identifies and blocks unauthorized RMM software on endpoints before it can be used for persistence or remote control, lets teams define which RMM tools are approved and which should be blocked, and adds extra protection for isolated machines so approved remote access tools do not get blanket access. The announcement comes in light of a new N-central RMM vulnerability being exploited in the wild.
Legit Security releases VibeGuard 2.0 for coding agent endpoint security
Legit Security has released VibeGuard 2.0, an endpoint-based tool that discovers and secures AI coding agents such as Claude Code, Cursor, and GitHub Copilot. It operates at the endpoint level, applying policy enforcement and granular controls over specific agent commands and tools. New features include guardrails for skill discovery, blocking of risky operations, MCP security controls, command monitoring against built-in or custom policies, and anti-tampering protections meant to stop agents or users from disabling the tool.
Netskope announces DataSec Command Center
Netskope announced its Netskope One DataSec Command Center, a unified control plane that discovers, understands, tracks, and protects sensitive data of any kind wherever it lives and moves, from AI environments to the network. With Netskope One DataSec Command Center, security teams gain full visibility into their sensitive data and a seamless path from discovery to remediation across their entire data landscape.
ProjectDiscovery announces general availability of Neo
ProjectDiscovery announced the general availability of Neo v1, and a new Pay-as-you-go model. After six months of private beta testing with enterprise customers, ProjectDiscovery is making Neo available to everyone to help teams move from periodic, manual testing toward continuous security that runs alongside development. Teams of all sizes can access autonomous security testing across code, applications, APIs, cloud and networks with this new pay-as-you-go model, without traditional procurement and budget barriers.
Qualys adds scanless vulnerability detection to ETM platform
Qualys has introduced InstaScan, a scanless detection capability inside its Enterprise TruRisk Management (ETM) platform. The feature is powered by Agent Insta, an AI agent that continuously matches newly published vendor advisories against an organization’s existing asset inventory and telemetry rather than relying on scheduled scans. It normalizes software identities into standard identifiers (such as CPEs and PURLs) to build a consolidated inventory, then flags affected assets and issues confidence-scored findings.
SailPoint unveils SailPoint Identity Security
SailPoint has unveiled SailPoint Identity Security, a combination of SailPoint Agentic Fabric and SailPoint Human Fabric designed to deliver a continuous, real-time loop to discover, govern, and protect digital environments across human, non-human and agentic identities.
Sectigo launches automation gateway for certificate lifecycle management
Sectigo has released Sectigo Orchestration Gateway (SOG), a new automation layer inside its Sectigo Certificate Manager (SCM) platform. The gateway lets IT teams automate certificate discovery, issuance, renewal, and deployment across servers, load balancers, CDNs, WAFs, and access systems from a single install. It includes native support for platforms such as IIS, Apache, F5, NGINX, and Citrix, along with direct integrations with credential managers CyberArk, Delinea, HashiCorp, and BeyondTrust for just-in-time credential retrieval.
Sevii expands ADR platform with autonomous preemptive security module
Sevii announced a major expansion of the Sevii Autonomous Defense & Remediation (ADR) platform with the general availability of an Autonomous Preemptive Security (APS) module. The new module extends the platform to continuously transform external global and internal environmental cyber intelligence into autonomous hypothesis hunting, exposure validation, compromise detection, and autonomous remediation.
Sysdig launches AI-native offering for cloud runtime defense
Sysdig has launched Sysdig Secure AI, an AI-native addition to its Sysdig Secure cloud-native application protection platform (CNAPP). The offering provides three ways to apply AI to cloud defense: autonomous agents that prioritize risks and issue remediations, a “headless” mode that integrates with AI coding agents such as Claude, Cursor, and Codex, and a GenAI assistant (formerly Sysdig Sage) that explains risks and recommends fixes in plain language.
Tanium expands Autonomous IT Platform with new agentic and exposure tools
Tanium added new capabilities across its Autonomous IT Platform in three areas. Tanium Atlas now includes Agentic Performance Analysis for root-cause tracing, Background AI Agents that run alert-to-resolution workflows autonomously, and an MCP Server that exposes Tanium data to clients like Claude and Microsoft Security Copilot. New exposure management tools add External Attack Surface Management and Attack Path Mapping, while a new Agent-Guided Threat Hunting feature runs hypothesis-driven hunts mapped to MITRE ATT&CK, paired with a private-preview integration with Google Threat Intelligence.
Torq unveils SOC Brain
Torq has introduced Torq SOC Brain, a new self-learning layer of its AI SOC Platform that continuously learns from historical investigations, analyst decisions, and organization-specific security operations to create a personalized intelligence engine. By utilizing its Recall, Reflex, and Retrospect capabilities, the system reasons from precedent and organizational history to adapt to each team’s unique risk logic and deliver increasingly accurate threat classifications over time.
Viakoo adds configuration drift remediation module for OT and IoT devices
Viakoo has introduced Device Configuration Manager (DXM), a new module for its Viakoo Action Platform aimed at correcting configuration drift in OT and IoT environments. The agentless tool continuously audits device settings against defined baselines, flags unauthorized changes, and automatically restores devices to a compliant state. Viakoo also expanded its integrations to include Armis, Forescout, Nozomi Networks, Claroty, and Tenable. DXM is expected to become available in Q4 2026.
Vicarius publishes state of vulnerability remediation report
Vicarius released its “Exposed and Unfixed: The 2026 State of Vulnerability Remediation” report, which shows that siloed workflows and manual administrative handoffs leave 79% of organizations vulnerable to known exploits they already knew about. The report data found that 75% of critical vulnerability responses simply trigger an administrative workflow rather than actually resolving the threat, 50% of organizations consider a vulnerability “closed” based on pure risk acceptance or ticket generation rather than running a verified rescan to ensure the patch worked, and 79% of organizations experienced a security incident in the past 12 months involving a vulnerability that was already sitting in their inventory.
Zimperium releases automated mobile forensic investigation tool
Zimperium has introduced Deep Insights, a mobile forensic investigation tool built to automate analysis of mobile device attacks. The tool reconstructs full attack timelines from collected evidence, allowing tier-one SOC analysts to investigate incidents without specialized mobile forensics expertise. It also runs automated pre- and post-travel comparisons to flag suspicious changes in device state. Deep Insights is expected to become generally available in September 2026.