Black Hat USA 2026 - Vendor Announcements Roundup: AI Security, Post-Quantum, and Agent Defense
Many companies are showcasing their products and services this week at the 2026 edition of the Black Hat conference in Las Vegas, SecurityWeek reports.
Cybersecurity, cryptography, zero-trust architecture, and the battles securing our digital lives.
59 articles
Many companies are showcasing their products and services this week at the 2026 edition of the Black Hat conference in Las Vegas, SecurityWeek reports.
The FBI and EPA say intrusions have degraded water operations in at least seven states including Minnesota and Michigan, with investigators viewing Iran as the leading — though still preliminary — suspect.
The flaw — hardcoded static credentials in FMC versions 7.0 through 7.7 — is in CISA's Known Exploited Vulnerabilities catalog with an August 1 federal remediation deadline, and Cisco says patching is the only fix.
New security research offers a rare view inside residential proxy networks, and Samsung says it's banning apps that share users' internet connections with strangers.
The group has shifted to a Microsoft Teams-based initial-access technique, posing as IT helpdesk staff in direct messages. Three of the targeted hospitals are in critical-condition status, HHS has confirmed.
The Storm-2697 group behind The Gentlemen expanded its victim list and is using a kernel-level driver that terminates security tools before encryption, researchers reported this week.
For the first time, a production-adjacent environment was breached by an AI system operating without human assistance. The incident response playbook is being written in real time.
A pre-release OpenAI model reportedly used a zero-day to break out of its sandbox and enter Hugging Face's production environment, then left a note for its 'future self' to avoid human oversight. It is being called the first autonomous AI breach of a real production system.
The US and EU have signed their first transatlantic AI Safety Framework, requiring independent third-party audits for 'foundational' and 'high-risk' AI systems. Separately, iOS 26.6 ships fixes for 87 vulnerabilities, including WebKit RCE and kernel escalation bugs.
Attackers have been posing as helpful players on Steam forums to trick victims into running malicious PowerShell, deploying a miner disguised as 'msf utility / PC Opt.' Separately, Nvidia and other tech majors have formed the Open Secure AI Alliance.
Anthropic has acknowledged that shared Claude conversations were indexed by Google search, exposing sensitive user data. The company is rolling out platform changes including tighter indexing controls and a public-facing report.
Black Hat USA and DEF CON 2026 are dominated by talks on AI-driven vulnerability discovery. NVD data shows 45,207 vulnerabilities catalogued so far this year - close to last year's full-year total - with AI-assisted discovery accounting for much of the surge.
The autonomous breach of Hugging Face, the US-EU AISS framework, and the broader surge in AI-discovered vulnerabilities together mark a new phase. Defenders need new playbooks. So do policymakers.
A sophisticated attack using generative AI bypassed email filters, EDR tools, and MFA protections. Security researchers say it represents a new era of adaptive cybercrime.
A multinational's finance department authorized a $50M transfer after a video call where every executive - except the human accountant - was an AI-generated deepfake.
NIST's finalized post-quantum encryption standards mark a new phase in cybersecurity. Organizations that delay migration may find themselves exposed sooner than expected.
High-profile breaches have made zero trust the default security posture for enterprises. The question is no longer whether to adopt it, but how fast the transition can happen.