Many companies are showcasing their cybersecurity products and services this week at the 2026 edition of the Black Hat conference in Las Vegas.
To help cut through the clutter, the SecurityWeek team is publishing a digest summarizing vendor announcements at Black Hat USA 2026, including new products and services, updates to existing offerings, reports, and other initiatives.
This is the third part of the series. You can also read Part 1 and Part 2 if you haven’t already.
Above Security’s strategic investment from CrowdStrike Falcon Fund
Above Security announced a strategic investment from the CrowdStrike Falcon Fund and integration with the CrowdStrike Falcon platform. Through the partnership, CrowdStrike customers will be able to extend their Falcon deployment, powering ready-made insider risk investigations with Falcon Next-Gen SIEM telemetry. Above correlates Next-Gen SIEM endpoint, identity, and third-party data into investigation-ready cases and streams completed investigations back into Falcon.
ArmorCode launches vulnerability remediation agents
ArmorCode announced four new Anya agents designed to help security teams analyze cloud risks, assess vulnerability exploitability, identify mitigation strategies, and coordinate patch orchestration. The company also added new Context Risk Graph capabilities for expanded attack path analysis, network reachability, and patch management.
Commvault integrates Threat Scan with Google Threat Intelligence
Enterprise cyber resilience company Commvault announced a new integration that will incorporate Google Threat Intelligence into Commvault Threat Scan workflows. This capability can help organizations identify clean recovery points faster, as well as reduce downtime and speed up recovery following cyberattacks. This announcement adds to Commvault’s ongoing collaboration with Google Cloud, including expanded cyber resilience capabilities for Google Cloud environments via Clumio, and support for Google Cloud workloads.
CrowdStrike announces $100,000 international AI security challenge
CrowdStrike announced AI Unlocked: Agents of Chaos, a global AI red teaming competition created with AWS that challenges participants to exploit rogue AI agents using prompt injection and other techniques to better understand emerging agentic AI security risks. The virtual competition, which begins on August 31 and features a $100,000 prize pool, is designed to give defenders hands-on experience securing AI agents as they become a growing enterprise attack surface.
Dataminr threat landscape report
Dataminr has published its 2026 Mid-Year Threat Landscape Report, finding that the average patch window in H1 2026 got 11 days longer. Meanwhile, attackers can break out in less than 30 minutes, and Dataminr tracked a 69.2% jump in alerts from the second half of 2025.
DataBahn launches Federated Search and Orchestration
DataBahn launched Federated Search and Orchestration, an expansion of its agentic data control plane that moves companies from applying intelligence after data has moved through pipelines to orchestrating it as the data moves. Enterprises can ask one question across every store they own without needing to copy any of the data, and hand it off to an AI agent to complete the investigation.
FireMon integrates with Palo Alto Networks
FireMon announced it has completed its product integration with Palo Alto Networks Strata Cloud Manager to deliver intelligent and interoperable solutions that enable joint customers to innovate faster and solve their most complex cybersecurity challenges.
Intel 471 unveils new AI capabilities
Intel 471 announced two new AI capabilities in the Verity471 platform: MCP471 and Agent471. With the addition of MCP471 and Agent471, Verity471 makes its pre-attack and threat-hunt intelligence more accessible and operationalizes it to help organizations detect and respond rapidly.
Menlo Security extends platform to secure AI assistants and coding agents
Menlo Security expanded its cloud-based Menlo Agent Runtime Security platform to protect AI assistants and coding agents from prompt injection attacks and data exfiltration. The platform routes agent web traffic through a cloud environment to sanitize files and strip hidden instructions before an agent receives the content. Adaptive data loss prevention controls mask sensitive information, while token-based authentication assigns per-agent session identity to enforce specific web access policies.
Mimecast unveils Agent Risk Center and Managed Threat Response
Mimecast announced a new expansion of its Incydr technology that discovers every AI agent and tool operating across an organization and ties each one back to the human who deployed it. The platform will also include a relaunched Managed Threat Response (MTR) service and expanded Google Workspace integrations.
Palo Alto Networks introduces evolution of PAN-OS and publishes research
Palo Alto Networks announced a new PAN-OS purpose-built for the Frontier AI era. PAN-OS 12.2 Ceres introduces Advanced Virtual Patching, automated blocking for direct-to-IP attacks, six AI security agents, and expanded hardware for securing AI data centers and critical infrastructure. Palo Alto Networks Unit 42 has also released new threat research detailing how an AI system built by its researchers uncovered more than 14,000 previously unknown vulnerabilities across nearly 4,000 widely used open source projects; and how analysis of more than 4 million reports found that 45.32% of malware with C&C activity communicates directly with IP addresses.
Prophet Security research on AI in Security Operations
Prophet Security has released its second annual State of AI in Security Operations report. An independent survey of 250 IT and cybersecurity professionals finds that security operations teams are reaching a breaking point as alert overload, AI-powered attacks and staffing shortages force organizations to rethink how SOCs operate. According to the report, 96% of organizations are already using AI or actively evaluating AI for security operations, organizations leave an average of 28% of security alerts uninvestigated, and 56% report an increase in AI-driven attacks over the past year.
Proofpoint announces OEM Program
Proofpoint announced an OEM Program: a portfolio of OEM-ready threat intelligence and detection capabilities available for technology providers, cybersecurity vendors, managed service providers, and platform companies. The program cuts the time, cost, and operational lift of building threat intelligence capabilities from scratch, helping partners accelerate product roadmaps and bring differentiated offerings to market faster.
Rubrik adds agent identity controls to Agent Cloud
Rubrik expanded its Agent Cloud platform with Rubrik Agent Identity to manage autonomous AI agent access permissions at runtime. The solution eliminates standing credentials by generating short-lived, scoped tokens for individual tool calls and integrating with identity providers (including Okta and Microsoft Entra ID). Before execution, tool requests pass through a gateway that conducts semantic behavioral analysis, verifies infrastructure access policies, and authenticates session identities.
ServiceNow announces new security solutions and AI Center for Cyber Defense
ServiceNow launched six unified solutions that deliver prevention-first, AI-native cyber defense across unified exposure management, identity and access security, cyber-physical security, cyber risk and compliance, and agentic incident response. ServiceNow also unveiled its newly formed AI Center for Cyber Defense, a global hub for security innovation.
SOCRadar launches Human Identity Exposure
Threat intelligence company SOCRadar announced the launch of Human Identity Exposure, a new Identity & Access layer for its Extended Threat Intelligence (XTI) platform that gives analysts an instant, comprehensive snapshot of an individual’s identity risk. SOCRadar Human Identity Exposure unifies fragmented identity exposure data, including breach repositories, stealer infections, attacker telemetry, PII, data leaks, and CTI signals into a single, decision-ready record.
Surf AI announces new integration and platform expansion
Surf AI announced an integration with Claude’s Compliance API, alongside the general availability of Exposure Reduction Operations, extending the platform to govern AI model connectivity alongside identity, cloud, and SaaS exposures. The integration pulls activity logs from the Claude environment, maps the connection and access path to an accountable owner inside the Context Graph, and operationalizes remediation, including disabling unsanctioned MCP integrations and lingering Claude access after offboarding.
Tenable debuts open source AI agent exchange and expands AI risk coverage
Tenable launched CyberAgents Exchange, a free, open source AI agent exchange built for cybersecurity teams. It is a vendor-agnostic community where security professionals can discover, share and build trusted AI agents, skills, MCP servers and multi-agent playbooks, backed by code-level transparency into who built what and how it works. Founding members also include SentinelOne and Recorded Future. The company also unveiled new Tenable One AI Exposure capabilities that expand coverage across every major AI platform and key developer tools.
Thales releases Luna 8
Thales released Luna 8, its first in-house designed hardware security module made to secure, store, protect, and manage cryptographic keys against quantum threats. The system features an upgradeable architecture to integrate future cryptographic algorithms while maintaining backward compatibility with existing interfaces and ancillaries. Delivered on a unified hardware platform, the appliance is undergoing independent evaluation for FIPS 140-3 Level 3 and EU Common Criteria standards.
Trustmi announces new AI investigation agent and new payment fraud threats
Trustmi unveiled an AI Investigation Agent that is purpose-built for B2B fraud detection. It introduces agentic workflows that investigate suspicious activity, reasons across business workflows, and connects evidence across systems. The company also announced the discovery of two emerging payment fraud threats: Ghost Executive, an attack in which fraudsters fabricate an executive’s approval so the payment looks like a decision has already been made; and Deadline Deception, which pairs fraudulent paperwork with a false deadline to pressure employees into releasing funds.
VanishID adds AI exploitability management and external identity protection control
VanishID announced AI Exploitability Management and External Identity Protection. Operating externally without internal system credentials or installations, AI Exploitability Management breaks down over 40 attack scenarios to calculate individual risk scores based on public data availability. Complementing this tool, External Identity Protection deploys four categories of autonomous agents (detection, analyst, remediation, and residual risk) to scan data brokers, dark web repositories, and public records. Automated remediation agents submit and verify opt-out requests to erase public profiles.


