Latest Security Vendor Updates | Black Hat & More

August 4, 2026·9 min read·
By
DTDevesh Taneja

Black Hat pre-show wires carried heavy volume today even though the Business Hall does not open until tomorrow. Two themes dominate: governed autonomy in the SOC (SentinelOne and Securonix shipped near-identical "AI acts inside human-set boundaries" stories within hours of each other), and capital flowing hard into AI-agent security and autonomous validation, with $375m announced across two rounds in one morning. CrowdStrike's annual threat hunting report landed the same day and supplies the threat-side justification both trends lean on.

AI SOC & Security Operations

SentinelOne - Adds governed, closed-loop response to Purple AI and Singularity Hyperautomation

Source: BusinessWire | 3 Aug 2026

  • Purple AI can now investigate an alert, reach a verdict, and execute a response inside boundaries the security team defines in advance, with every action traceable and reversible.

  • SentinelOne says Purple AI Agentic Investigation has run in customer environments since June and now handles more than 8,500 critical autonomous investigations daily across roughly a third of its eligible customer base.

  • Chris Corde, Chief Product Officer, said security teams need AI they can trust to act within boundaries they set. The Hyperautomation workflow capabilities are expected to reach general availability later this quarter, with demos at booth #2933.

Why it matters: The production numbers are the substantive part. Most agentic SOC claims this week are roadmap; a daily investigation count and a stated adoption share are checkable. Note the capability is previewing, not shipping, which is the gap worth watching.

Securonix - Adds governed AI agent detection and response, expands Sentinel threat analytics

Source: HelpNet Security | 3 Aug 2026

  • Securonix extended its Unified Defense SIEM with governed AI agent detection and response, expanded Threat Analytics for Microsoft Sentinel, and ingestion cost reduction features.

Why it matters: Incremental, Securonix has been running a human-in-the-loop governance message since at least March, so this reads as restating an existing position for the show rather than opening new ground. Only the wire summary was reachable, so treat product specifics as preliminary.

Cribl - Adds AI observability app and detection engineering to its telemetry platform

Source: GlobeNewswire | 3 Aug 2026

New capabilities include the Cribl App for AI Observability for managing AI usage and risk, detection engineering that identifies coverage gaps, and stream-native detections that flag high-confidence threats earlier in the pipeline.

Why it matters: Pipeline vendors moving detection upstream is the quieter trend of the week — same cost-reduction argument Securonix and Realm Security ran on 3 Aug. Three vendors making the same pitch on one day means the SIEM ingestion-cost fight is now a category, not a differentiator. SecurityWeek 

Exposure Management & Vulnerability

SentinelOne - Expands Wayfinder Frontier AI Services, names LevelBlue premier remediation partner

Source: BusinessWire | 3 Aug 2026

  • SentinelOne expanded the Wayfinder Frontier AI Services line, first announced on 30 April 2026, pairing newer Anthropic models with its own offensive and defensive experts and adding LevelBlue as the premier remediation partner.

  • LevelBlue's own Black Hat page confirms the partner designation and describes turning Wayfinder findings into prioritized remediation programs.

  • The "Wayfinder MDR Workflows" and "Wayfinder Threat Hunting for Identity" (Okta and Microsoft Entra ID) sub-features are consistent with existing Wayfinder naming, but full release text verification is pending.

Why it matters: Second Wayfinder expansion in roughly three months. The remediation-partner layer is the newer idea: discovery has become cheap, so the pitch is shifting to who is accountable for closing findings.

Offensive Security & Pentesting

Horizon3 - Raises $250m Series E at more than $2bn valuation

Source: TechCrunch, SecurityWeek | 3 Aug 2026

  • Co-led by existing investors NightDragon and NEA, with new investors including Acrew, Blue Cloud Ventures, Demeter Group, EDBI (Singapore), PSG, SAIC, and Sapphire.

  • Valuation triples from $650m at the June 2025 Series D; total funding now around $428m.

  • Customer metrics: 310,000 tests run in production; reported customer base between 6,500 and 7,300 with 120% ARR growth.

Why it matters: A 3x valuation step in 14 months says buyers now treat continuous validation as a standing budget line rather than a pilot. The customer-count spread across outlets is worth flagging before anyone quotes a figure.


AI & LLM Security

Zenity - Raises $125m Series C led by Norwest

Source: Fortune, CTech | 3 Aug 2026

  • New investors Qumra Capital, SoftBank Vision Fund 2, Hitachi Ventures and LG Technology Ventures joined existing backers; total funding reaches $185m.

  • Zenity Labs has produced notable disclosures including AgentFlayer zero-click agent hijacking and Copilot Studio research.

Why it matters: Zenity Labs has produced real disclosures, which distinguishes this from the AI-agent-security companies raising on positioning alone. The undisclosed valuation is the one gap.

Pillar Security - Demonstrates one AI agent escalating privilege through another in Google's ADK

Source: The Register, SC Media | 3 Aug 2026

A prompt injection filed as a public GitHub issue manipulated a low-privilege triage agent in the gemini-cli repository, which then invoked a maintainer-only agent. The chain leaked CI environment variables including a long-lived personal access token and a GCP service account key, and allowed tampering with pull request comments to fabricate an approval trail. Google confirmed a fix on 21 July but declined a bounty, saying reports requiring social engineering for supply chain compromise fall outside criteria.

Why it matters: This is the strongest item of the day and it isn't a product. Every vendor below is selling agent governance; this is the concrete attack that justifies the category. The Google bounty refusal is the detail worth using — it says the industry hasn't agreed that agent-to-agent escalation counts as a vulnerability yet.

Zero Networks - Adds enforcement of OWASP's least-agency principle for enterprise AI

Source: BusinessWire | 3 Aug 2026

Least Agency Enforcement limits what agents can access and do, and when human approval is required, using identity-based microsegmentation, automated policy enforcement, and just-in-time MFA.

Why it matters: The most architecturally distinct approach in the group — it treats agents as network identities rather than adding a monitoring layer. Anchoring to an OWASP principle is a category-definition play.

KnowBe4 - Extends Agent Risk Manager to cover Anthropic's Claude

Source: BusinessWire | 3 Aug 2026

Adds Claude support alongside existing Microsoft Copilot coverage, using six detection engines for prompt injection, data leaks, privilege escalation, and unapproved tool access, plus a map of connected APIs and credentials. Currently in early access for SAT Advanced customers on US-tenant accounts.

Why it matters: Incremental — a second model provider on an existing product, gated to early access on one tenant type. Notable mainly as a marker that agent governance tools are going multi-vendor.

Threat Intelligence

CrowdStrike - Publishes 2026 Threat Hunting Report on adversary AI adoption

Source: CrowdStrike | 3 Aug 2026

  • 88% of exploitation of vulnerabilities with a public PoC occurred within 48 hours of release in 1H 2026.

  • Cloud-conscious eCrime activity rose 171%, vishing intrusions doubled, and device code phishing attempts rose 15x.

  • DPRK-nexus STARDUST CHOLLIMA injected a malicious npm package into 131 Mastra AI frameworks.

Why it matters: This is the empirical backing for the whole AI-SOC pitch running at the show, from a vendor selling into it. The 48-hour exploitation figure is the number most likely to end up in slide decks this quarter.

Check Point Research - Weekly threat intelligence report

Source: Check Point Research | 3 Aug 2026

  • Phishing campaign abusing Microsoft login flow to grant access to mailboxes, Teams, and SharePoint.

  • CaptiveCrunch (Storm-2945) compromising hotel and conference captive portals to deliver malware.

  • npm supply chain campaign imitating private Alibaba modules.

Why it matters: The captive-portal vector is timely given 20,000-plus attendees on hotel networks in Las Vegas this week.

Identity & Access

BeyondTrust - Ships first native Pathfinder capabilities, adds Workload Credentials

Source: GlobeNewswire | 3 Aug 2026

Four capabilities on the Pathfinder platform: PathfinderAI and MCP Server, AI Agent Security, NHI Governance, and newly announced Workload Credentials, extending privilege management beyond human administrators to any identity holding privileged access.

Why it matters: "First wave of native capabilities" is the tell — Pathfinder was a platform announcement before it was a product, and this is the fill-in. Worth watching whether Workload Credentials ships separately or only as a bundle.

Data Security

Cyera - Launches Agent Guardian and Cyera Endpoint

Source: BusinessWire | 3 Aug 2026

Agent Guardian discovers, monitors, and protects enterprise AI agents against prompt injection and unauthorized data access with runtime controls; Cyera Endpoint extends the same guardrails to local AI tools running on employee devices.

Why it matters: The endpoint piece is the interesting half — most agent-security products assume agents run in cloud or SaaS. Extending to locally-run AI tooling addresses shadow AI on laptops, which nobody else announced this day.

Email & Managed Services

Mimecast - Opens beta of Agent Risk Center, redesigns managed response service

Source: GlobeNewswire | 3 Aug 2026

Agent Risk Center provides a real-time inventory of AI tools and connections, policy classification by department, and response controls including desktop app blocking and browser upload/paste blocking. It is a free opt-in beta for active Incydr subscribers, with early access in September 2026 and general availability planned for January 2027.

Why it matters: The dates are the story: a January 2027 GA announced at an August 2026 show is a roadmap, not a product. Free-and-opt-in for existing customers also reads as data collection ahead of a paid tier.

Endpoint & XDR

ESET - Extends AI capabilities across detection, investigation, and agent protection

Source: GlobeNewswire | 3 Aug 2026

ESET is expanding AI across threat detection, investigations, protection, and security operations, extending coverage to AI agents, behaviors, and conversations, delivered as a built-in capability at no additional cost rather than a separate add-on.

Why it matters: Thin on named products and availability dates — this is closer to positioning than a launch. The no-extra-cost framing is a channel play aimed at partners, and it's the pricing counter-argument to every standalone agent-security startup on this list.

Tanium - Extends Autonomous IT Platform across agentic AI, exposure management, and SecOps

Source: BusinessWire | 3 Aug 2026

Tanium Atlas is positioned as an autonomous operating system on the Tanium platform, running under a governance model the company describes as auditable and bounded by operator-defined limits, reviewable after the fact. New Atlas capabilities include Agentic Performance Analysis, which traces a slow machine to root cause instead of manual log correlation. Two new exposure management capabilities were also introduced, including External Attack Surface Management built on real-time internet visibility from Censys.

Why it matters: SecurityWeek's digest missed this one entirely, and it's a bigger vendor than most on that list. Note the framing — "governed, auditable, operator-defined limits" is word-for-word the same positioning SentinelOne and Securonix ran the same morning. Three vendors independently landing on identical language on day one means "governed autonomy" is now the agreed category vocabulary, which is a genuinely useful finding for the newsletter. The Censys dependency is worth flagging separately: Tanium is renting its EASM data rather than building discovery.

Also worth adding detail to the BeyondTrust item from yesterday's brief — the four Pathfinder capabilities are PathfinderAI & MCP Server, AI Agent Security, NHI Governance, and the newly announced Workload Credentials. NHI Governance extends privileged access management to service accounts, API keys, OAuth clients, workload identities, and AI agents, moving from discovering non-human identities to governing the privilege they hold.









Did you find this article helpful?

Let the authors know by leaving a like or comment.

0
Leave a Comment
Share your thoughts on this article. We'd love to hear from you!

No comments yet

Be the first to share your thoughts!