20 Cool New AI And Security Products At Black Hat 2026

Top vendors including Palo Alto Networks, Abnormal AI and SentinelOne have unveiled new security tools in fast-growing categories of security and AI at the Black Hat USA conference.

For Abnormal AI—one of the numerous cybersecurity vendors launching new security products at Black Hat 2026—it’s clear that something has shifted when it comes to leveraging AI for cyber defense, according to Mike Britton, CIO of Abnormal AI. “We’re getting to that point where AI is not new. It’s no longer the talk of ‘what if’—but now we have experience with it. Now we’re starting to refine and hone in on the use cases—where it makes sense, where it doesn’t,” Britton told CRN. “This is now the mainstay.”

[Related: The 10 Hottest Cybersecurity Tools And Products Of 2026 (So Far)]

Thus, the Black Hat USA 2026 conference—taking place this week in Las Vegas—is undoubtedly a “continuing sharpening of that focus [on the fact that] AI is not going away,” he said. “It’s clearly got applicable use cases from an attacker and a defender’s perspective. And so [for] defenders, how do we make sure that we’re raising the bar? And how do we also make sure that we’re addressing the new threats from attackers?”

Black Hat 2026 has already seen a wide array of product launches from vendors ranging from startups, to fast-growing emerging vendors, to top industry players such as Palo Alto Networks and SentinelOne. Black Hat USA 2026 takes place this week through Thursday, Aug. 6.

What follows are the key details on 20 cool new AI and security products at Black Hat 2026.

Abnormal AI: Identity Threat Protection

In the lead up to Black Hat 2026, Abnormal AI announced it is expanding its Behavioral Security Platform to include Identity Threat Protection, AI Governance and Infiltration Prevention. The products utilize Abnormal’s behavioral models for protecting against compromised accounts and shadow AI as well as fraudulent job candidates—including suspected nation-state operatives, according to the company. The launch represents “the extension of [Abnormal’s] knowledge and learning over the last eight years of behavior” into pivotal new use cases, Abnormal AI CIO Mike Britton told CRN. When it comes to Identity Threat Protection specifically, Abnormal AI is bringing a highly differentiated approach by applying behavioral and pattern analysis to identity, Britton said. “Humans are very pattern-driven—and once you understand what normal looks like, it’s easy to spot” unsanctioned behavior in identity, he said. “I feel like we have an eight-year head start, and we have a proven commodity in being able to detect these anomalistic behavior patterns. That I think that makes us unique.”

Palo Alto Networks: PAN-OS 12.2 Ceres

Unveiled Tuesday at Black Hat, Palo Alto Networks’ PAN-OS 12.2 Ceres introduces more than 55 updates aimed at helping security teams to protect against threats from frontier AI and increased network traffic as well as a looming “cryptographic reset” spurred by quantum computers and shorter certification lifecycles. Key capabilities include Advanced Virtual Patching, Advanced IP Defense, AI-powered Network Security Agents, quantum-readiness features and new high-performance firewalls, the company said. The PAN-OS 12.2 Ceres updates are critical as a result of the fact that attackers are already “weaponizing vulnerabilities before we have official patches available, or before they can be actually applied,” said Anand Oswal, executive vice president at Palo Alto Networks, during a briefing with media.

1Password Privileged Access

Launched just ahead of Black Hat, 1Password Privileged Access brings just-in-time privilege controls into the company’s Unified Access platform, targeting standing access held by employees and contractors as well as AI agents. The offering is based on technology from the company’s acquisition of Apono in June, and it discovers privileged access paths across cloud and hybrid environments, databases and Kubernetes, according to 1Password. The tool then grants temporary permissions based on identity and context along with policy, the company said.

Cyera: Agent Guardian

Debuted Monday at Black Hat, Cyera Agent Guardian is designed to secure AI agents by connecting their identities and permissions to the sensitive data they can reach. The product is aimed at discovery of shadow agents, MCP servers and agent-related—spanning activity across endpoints, SaaS and cloud environments, according to Cyera. The tool maps each agent’s data access and evaluates intent and risk, while intervening when an agent attempts an unauthorized or risky action, the company said.

SentinelOne: Purple AI, Singularity Hyperautomation Updates

Announced at Black Hat Monday, SentinelOne’s latest Purple AI and Singularity Hyperautomation updates bring AI-led investigations into a tighter connection with governed remediation, the company said. Purple AI Agentic Investigation can collect evidence and perform reasoning across telemetry while building an attack narrative and recommending responses, according to SentinelOne. Enhancements to Singularity Hyperautomation then turn those findings into repeatable workflows for containment and remediation, SentinelOne said.

Bugcrowd: Savant Pathseeker

Announced just ahead of Black Hat, Bugcrowd Savant Pathseeker brings together continuous agentic penetration testing with on-demand human validation across external web applications and APIs, the company said. The platform autonomously tests and validates findings while providing proof of exploitability—even as human researchers focus on flaws, exploit chains and zero-day threats, according to the company. The goal is to “take the best of AI” without “replacing the crowd,” Bugcrowd CEO Dave Gerry told CRN. Ultimately, Bugcrowd can “leverage the machine speed of AI combined with the human intel—and be able to say, ‘Now we can test across all of the assets on an at least somewhat continuous basis, and really laser focus the humans on the pieces of the architecture that matter the most,” Gerry said.

Arctic Wolf Cyber Resilience

Unveiled at Black Hat Monday, Arctic Wolf Cyber Resilience brings together managed security operations and exposure management with endpoint protection, incident response and protection in to a single offering aimed at helping organizations protect against AI-powered attacks. The offering includes Aurora MDR, Attack Surface Management and Vulnerability Management with patch management—as well as Managed Endpoint Defense, security awareness and Aurora Incident Response 360 for containment and recovery, according to the company. Eligible customers can also receive up to $3 million in coverage through Arctic Wolf’s Security Operations Warranty. The offering is available now through Arctic Wolf and its partners, the company said.

Rubrik Agent Identity

At Black Hat on Tuesday, Rubrik launched its new Agent Identity capability, expanding the Rubrik Agent Cloud platform with new controls aimed at securing AI agents in real time. The offering provides discovery and inventories for all agents and MCP servers—as well as skills and plugins—and then implements least-privilege access for the MCP servers and tools, according to Rubrik. Meanwhile, integrations with Okta and Microsoft Entra ID extend existing identities to autonomous systems, the company said, while its Agent Rewind capability can also undo harmful actions.

Mimecast Agent Risk Center

The latest move in Mimecast’s evolution was the Monday launch of Mimecast Agent Risk Center, a new capability for discovery, monitoring and governance of AI agents. “We’ll be able to surface all of the agentic risk in a customer’s environment—on their desktop, in their browser—and associate it with the user risk,” Mimecast CEO Ranjan Singh told CRN. “So that’s combining your AI and your user risk into a single score, visualizing all the agentic activity that’s taking place in your environment.” Agent Risk Center is initially being offered in beta to customers of Mimecast’s Incydr data protection platform, with early access expected to begin in September and general availability targeted for January 2027.

SailPoint Identity Security

Debuted Tuesday at Black Hat, SailPoint Identity Security brings together protection for human users, non-human identities and AI agents, the company said. Key advantages of the platform include continuous discovery of identities and governance of access as well as remediation of risk in real time, according to SailPoint. The platform leverages SailPoint’s Human Fabric technology, which delivers just-in-time provisioning and detection of unnecessary privileges, as well as the vendor’s Agentic Fabric that provides browser and endpoint sensors to expose “hidden” AI agents, credentials and MCP servers, the company said in a news release.

Cato Networks: Agentic Threat Prevention

Launched Monday at Black Hat, Cato Networks’ Agentic Threat Prevention introduces autonomous security agents that can perform modeling on an organization’s environment and predict likely attack paths, the company said. The offering brings together network and security telemetry with threat intelligence to “model risk across users, applications, traffic patterns, assets, and exposures,” Cato said in a news release. “It then predicts how agentic attackers might chain techniques, exploit gaps, and evade controls, then creates protections tailored to each customer’s environment rather than relying on one-size-fits-all detections.”

Huntress: RMM Guard

Unveiled Monday, Huntress RMM Guard is aimed at protecting against the growing attacks looking to compromise remote monitoring and management (RMM) tools. Rather than requiring MSPs and lean IT teams to build complex allowlists, the tool takes an inventory of RMMs across an environment and then blocks unauthorized RMM instances—including attacker-controlled deployments of approved products, Huntress said. Nearly a third of incidents observed by Huntress this year “could’ve been prevented by blocking rogue RMM tools from running,” the company said in a blog post.

Check Point: AI Network Firewall

Introduced just ahead of Black Hat 2026, Check Point said that its AI Network Firewall brings AI security directly into the physical and virtual firewalls customers already use—avoiding the need for additional infrastructure or major re-architecting of systems. The offering provides discovery for sanctioned and shadow AI applications as well as agents and MCP communications, while also giving security teams enhanced visibility into prompts and data movement, according to Check Point. The AI Network Firewall can also enforce access policies and prevent sensitive information from leaving the network, while blocking prompt-injection or adversarial inputs before they impact AI models, the company said.

Snyk: Evo Continuous Offensive Security

Introduced Tuesday, Snyk Evo Continuous Offensive Security brings autonomous penetration testing and agent red teaming into the software development process, according to the company. The platform continuously tests changing applications and identifies exploitable flaws, before then validating whether fixes are still effective, Snyk said. The offering combines AI-powered pentesting and DAST (dynamic application security testing) with context from Snyk Code, Snyk Open Source and Snyk API & Web findings to help security teams to “prioritize real risk, not just manage more alerts,” the vendor said in a news release.

Cribl: AI Observability App

Launched Monday, Cribl’s AI Observability app provides security and IT teams with a centralized view of how AI tools and models are being used across an organization. The app works with existing telemetry—flowing through Cribl and third-party platforms—to uncover AI usage, cost and risk, the company said. This can help to identify shadow AI as well as to understand token consumption and “identify workloads better served by a smaller, less expensive model,” the company said in a news release.

Qualys InstaScan

Introduced at Black Hat Monday, Qualys InstaScan is a new capability within Enterprise TruRisk Management that aims to rapidly identify vulnerabilities—“within minutes of disclosure,” the company said in a news release. That allows organizations to avoid waiting for a scheduled scan, the company said. The tool works by monitoring vendor advisories and threat intelligence and then correlating that information with asset inventory and endpoint telemetry, according to Qualys. The “scanless scanning” approach can determine likely exposure using available data instead of launching a full assessment every time a vulnerability appears, the company said in the release.

Sectigo: Orchestration Gateway

Unveiled Tuesday at Black Hat, Sectigo Orchestration Gateway automates the process of certificate discovery and issuance—as well as certificate renewal and deployment—across complex environments “from one lightweight install,” the company said in a news release. The capability, built into Sectigo Certificate Manager, “replaces fragmented connectors and manual workflows with end-to-end automation, centralized policy and distributed execution, reducing operational complexity and improving scalability,” the company said.

Varonis: Agent Intent-Based Access Control

Debuted Monday, Varonis’ Intent-Based Access Control provides enhanced safeguards for AI agents accessing corporate data, the company said. Built into Varonis Atlas, the capability compares the instructions assigned to an agent with its actual reasoning, usage and access to detect “intent drift,” Varonis said in a news release. The offering also works with tools such as Claude Code, Cursor, GitHub Copilot and Microsoft Copilot Studio, the company said.

Command Zero: Throughline

Debuted just ahead of Black Hat, Command Zero Throughline enables “living investigations” for security teams by connecting related alerts into existing cases. Crucially, the offering “re-examines its verdict as new evidence arrives,” the vendor said in a news release. Key advantages of the approach include improved prioritization and reduced repetitive work as well as a shared, auditable investigation record, Command Zero said.

Contrast Security: CVE Shield

Introduced in late July, Contrast Security’s CVE Shield provides protection from exploitation of known vulnerabilities while security teams test and deploy patches, the company said. Operating inside the running application, the capability uses runtime micro-sandboxes to block remote code execution and other threats without disrupting legitimate functions, according to Contrast Security. The platform also inventories vulnerable libraries and provides teams with evidence to prioritize remediation efforts, the company said.