UX Writes

20 New AI and Security Products at Black Hat 2026

 ·  By Ottoline Stanhope
20 New AI and Security Products at Black Hat 2026 - ai and security products
20 New AI and Security Products at Black Hat 2026

Major cybersecurity vendors including Palo Alto Networks, Abnormal AI and SentinelOne unveiled new security tools at Black Hat USA 2026, focusing on the intersection of artificial intelligence and network defense.

AI moves from theory to practice

For Abnormal AI, the shift is unmistakable. The company expanded its Behavioral Security Platform to include Identity Threat Protection, AI Governance and Infiltration Prevention. These tools apply behavioral models to protect against compromised accounts, shadow AI and fraudulent job candidates, including suspected nation-state operatives, according to the company.

“Humans are very pattern-driven—and once you understand what normal looks like, it’s easy to spot” unsanctioned behavior in identity, Abnormal AI CIO Mike Britton told CRN. He added that the vendor has an “eight-year head start” in detecting these patterns.

While vendors race to build defenses, the rapid proliferation of AI agents creates a significant blind spot. Companies deploying autonomous systems often lack visibility into exactly which tools are interacting with sensitive data or how those agents might drift from their intended purpose. This disconnect means that a security team might approve a specific agent for a task, but that agent could access unrelated systems or generate code that bypasses internal controls without anyone noticing until an incident occurs. The risk is compounded when these agents operate across hybrid environments where permissions are distributed across cloud providers, databases and containerized applications.

Related: Microsoft Channel Executive Julie Sanford Joins Stripe

Firewalls and identity protection evolve

Palo Alto Networks unveiled PAN-OS 12.2 Ceres at the conference, introducing more than 55 updates. The focus includes protection against threats from frontier AI, increased network traffic and a looming “cryptographic reset” spurred by quantum computers and shorter certification lifecycles.

Key capabilities include Advanced Virtual Patching, Advanced IP Defense, AI-powered Network Security Agents, quantum-readiness features and new high-performance firewalls, the company said. The updates are critical because attackers are already “weaponizing vulnerabilities before we have official patches available, or before they can be actually applied,” said Anand Oswal, executive vice president at Palo Alto Networks.

1Password launched Privileged Access ahead of the event, bringing just-in-time privilege controls to its Unified Access platform. The tool, based on technology from the company’s acquisition of Apono in June, discovers privileged access paths across cloud and hybrid environments and grants temporary permissions based on identity and context.

  • Cyera debuted Agent Guardian to secure AI agents by connecting their identities to sensitive data.
  • SentinelOne updated Purple AI and Singularity Hyperautomation to connect AI-led investigations with remediation.
  • Arctic Wolf introduced Cyber Resilience, combining managed security operations with endpoint protection.

Check Point introduced its AI Network Firewall, bringing AI security directly into physical and virtual firewalls. This approach avoids the need for additional infrastructure or major re-architecting of systems. The offering provides discovery for sanctioned and shadow AI applications and agents while blocking prompt-injection or adversarial inputs before they impact AI models.

Varonis launched Intent-Based Access Control, which compares an agent’s instructions with its actual reasoning and usage to detect “intent drift.” The tool works with agents like Claude Code, Cursor, GitHub Copilot and Microsoft Copilot Studio.

Related: Model Context Protocol Goes Stateless to Simplify Scaling

Continuous testing and visibility

Cato Networks launched Agentic Threat Prevention, introducing autonomous security agents that model an organization’s environment and predict likely attack paths. The company said the tool “models risk across users, applications, traffic patterns, assets, and exposures” and creates protections tailored to each customer’s environment rather than relying on one-size-fits-all detections.

Huntress unveiled RMM Guard to protect against attacks targeting remote monitoring and management tools. The tool takes an inventory of RMMs across an environment and blocks unauthorized instances—including attacker-controlled deployments of approved products. Nearly a third of incidents observed by Huntress this year “could’ve been prevented by blocking rogue RMM tools from running,” the company said.

Snyk released Evo Continuous Offensive Security, bringing autonomous penetration testing into the software development process. The platform continuously tests changing applications and identifies exploitable flaws before validating whether fixes are still effective.

Cribl launched an AI Observability app to provide security and IT teams with a centralized view of AI tool usage. The app works with existing telemetry to uncover AI usage, cost and risk, helping to identify shadow AI and understand token consumption.

Leave a Comment

Your email address will not be published.