Cybersecurity vendors introduced a wave of AI-driven tools at Black Hat USA 2026, targeting threat detection, exposure management, security operations, and emerging attack risks. Tanium, Prophet Security, VanishID, Flashpoint, Arctic Wolf, and Vectra AI were among the companies unveiling new capabilities during the Aug. 1–6 conference in Las Vegas.
The announcements reflected the industry’s shift toward agentic and automated security workflows, while creating new opportunities for partners to deliver assessment, consulting, remediation, and managed security services around the technology.
- Tanium: Extending autonomous security from exposure to response
- Prophet Security: Bringing agentic AI to detection engineering
- VanishID: Measuring AI exploitability from public data
- Flashpoint brings customizable AI summaries to investigations
- Arctic Wolf creates new opportunities for channel partners
- Vectra AI brings behavioral intelligence to AI-powered SOCs
Tanium: Extending autonomous security from exposure to response
Tanium, an autonomous IT company, unveiled new capabilities across its Tanium Autonomous IT Platform at Black Hat USA 2026, spanning agentic AI, exposure management, and security operations.
“At Black Hat USA 2026, vendors will be talking about AI agents and tools. What fewer will acknowledge is that ungoverned agents are themselves an emerging attack surface,” said Harman Kaur, chief technology officer at Tanium.
“Tanium is the platform that governs and manages them with Tanium Atlas — where every action is auditable, boundaries are enforced, and everything is grounded in what’s actually happening on the endpoint right now,” Kaur added.
The new capabilities announced across the three areas include:
- Agentic AI and Tanium Atlas: Tanium Atlas is an autonomous operating system built on the Tanium Autonomous IT Platform that takes IT and security operators from question to resolution in a single experience. It operates within operator-defined limits through a governance model designed to make its actions auditable and reviewable.
- Exposure Management: Tanium introduced External Attack Surface Management and Attack Path Mapping to address visibility gaps beyond the firewall and help organizations identify and prioritize risks across their external and internal attack surfaces.
- Security Operations: Tanium debuted Agent-Guided Threat Hunting and an integration with Google Threat Intelligence. The former allows threat hunters to describe a hypothesis in plain language and have Tanium Atlas autonomously conduct the hunt using live endpoint data, select the appropriate tools, and map its findings to MITRE ATT&CK.
Prophet Security: Bringing agentic AI to detection engineering
Prophet Security announced the general availability of AI Detection Engineer, a new addition to its Agentic AI SOC Platform that automates detection engineering to help security teams adapt their detection capabilities to rapidly evolving threats.
“Security teams have known for years that detection engineering is essential, but they haven’t had the people or the time to do it continuously,” said Grant Oviatt, co-founder and vice president of product at Prophet Security.
“AI Detection Engineer turns detection engineering from an occasional project into a continuous operational capability. Because Prophet AI performs the investigations, it understands which detections matter most, which gaps create the greatest risk, and where teams can make the biggest improvements. Organizations remain in complete control while AI handles the work that never seems to fit into the day.”
According to Prophet Security, AI Detection Engineer can:
- Builds a live MITRE ATT&CK coverage map based on investigation outcomes rather than static rule inventories.
- Identifies detection coverage gaps and telemetry blind spots across the environment.
- Authors new detections using the organization’s existing security stack.
- Tunes existing detection rules to reduce false positives and analyst fatigue.
AI Detection Engineer is available immediately as part of the company’s Agentic AI SOC Platform for security operations teams.
VanishID: Measuring AI exploitability from public data
External identity security provider VanishID announced AI Exploitability Management, a new capability that measures what AI-enabled attacks could be created from employees’ publicly available information. The company demonstrated the capability publicly for the first time at Black Hat USA 2026.
According to VanishID CEO Matt Polak, the capability is intended to address a blind spot for security teams: understanding how publicly available employee information could be assembled by AI into viable attacks.
“Most security teams can quote their patch rate to a decimal point. Almost none can tell you what AI could assemble from their CFO’s public exposure this afternoon, and that blind spot is where the attacks now start,” Polak said.
“We built AI Exploitability Management to make it measurable, attack by attack and person by person, from the attacker’s side of the fence,” he added.
According to VanishID, the solution:
- Measures AI exploitability risk by evaluating more than 40 AI-powered attack scenarios, including executive impersonation, real-time deepfakes, voice cloning, and other AI-driven social engineering techniques.
- Calculates an AI Exploitability Score for every individual assessed, helping security teams prioritize mitigation based on the attacks most likely to succeed.
- Runs entirely from the outside, the same vantage point an attacker has, with nothing installed, no integrations, and no credentials.
Black Hat USA 2026 attendees were also able to sign up for a complimentary private scan of their own AI exploitability, with findings reports to be delivered after the event.
Flashpoint brings customizable AI summaries to investigations
Threat intelligence provider Flashpoint announced the launch of its new Custom Summary Builder within its AI Workspace for Investigations Management.
Built into Flashpoint Ignite, the new capability allows security and intelligence teams to tailor AI-generated investigation findings for different audiences while standardizing how intelligence is delivered across an organization.
Analysts can select from sections including Executive Summary, Key Observations, Actors and Entities, Tactics, Techniques, and Procedures (TTPs), Industry Threat Landscape, and Recommendations, then save those configurations as reusable templates for future investigations.
“As organizations operationalize AI in their intelligence operations, they’re also looking for ways to extend capabilities across adjacent teams,” said Josh Lefkowitz, co-founder and chief executive officer at Flashpoint.
“To do that, analysts need the flexibility to adapt intelligence for different audiences, but organizations also need consistency in how that intelligence is communicated. Bringing those two requirements together is what allows AI to become part of an operational workflow rather than a point solution.”
The custom summary templates are available now to Flashpoint Ignite customers with access to Investigations Management.
Arctic Wolf creates new opportunities for channel partners
Arctic Wolf made three major announcements at Black Hat USA 2026, spanning its partner ecosystem, cyber resilience portfolio, and AI-powered security operations.
The announcements include:
- Cyber AI Readiness Accelerator: A new route to market that allows partners to combine Arctic Wolf’s Aurora Attack Surface Management with their own consulting, advisory, and remediation services through a 30-day assessment designed to identify and prioritize cyber risks.
- Cyber Resilience offering: A suite of products and services combining Arctic Wolf security operations, Aurora Incident Response 360 (IR360), and up to $3 million in warranty coverage to help organizations prepare for, respond to, and recover from cyber incidents.
- Aurora Agentic SOC: New advancements include updates to Arctic Wolf’s Swarm of Experts architecture and the introduction of Mean Time to Trusted Action (MTTA), a metric for measuring how quickly organizations receive security guidance they can act on.
The announcements also build on Arctic Wolf’s broader investments in its channel and MSP ecosystem.
Vectra AI brings behavioral intelligence to AI-powered SOCs
Finally, Vectra AI launched Vectra AI Pro at Black Hat USA 2026, a new offering designed to provide what the company calls “trusted signal intelligence” for SOCs adopting AI-powered workflows.
The platform continuously correlates network, identity, cloud, SaaS, SASE, and endpoint telemetry to build a unified view of attacker behavior and provide AI systems and security analysts with additional context for detection and response.
Channel Insider spoke with Mark Wojtasiak, vice president of product strategy and research at Vectra AI, about the launch and how AI is changing security operations.
In our conversation, Wojtasiak argued that behavioral intelligence is becoming increasingly important as AI allows attackers to operate faster than defenders can respond using traditional approaches.
“The only true defense is behavioral,” Wojtasiak said. “You can’t write signatures fast enough, you can’t patch fast enough. The SOC has to work at the speed of the attack.”





