AI in Security

Black Hat Told Us What Patch Tuesday Already Knew

by Brad Hibbert, COO & CSO//11 min read/

Every August, Black Hat rolls into Las Vegas and the industry spends a week arguing about the future. Every month, Patch Tuesday rolls around and the industry spends a day dealing with the present. This year the two are saying the same thing, just at different speeds.

Patch Tuesday is the reminder that the work never stops. A new batch of CVEs lands, some critical, most not, and every security team has to figure out which ones actually matter before attackers do. Black Hat is the reminder that the gap between “vulnerability disclosed” and “vulnerability weaponized” keeps shrinking. Put them together and you get the real story of 2026. The calendar-driven patch cycle was built for a slower attacker, and that attacker no longer exists. For those of you reading our monthly Patch Tuesday posts, none of this will come as a surprise.

The keynote said what we’ve all been seeing

Microsoft’s Black Hat keynote this year is called “The End of Rare: Defending When Offense Is Cheap.” David Weston, who leads Agentic Security at Microsoft, is using that stage to make a simple point. AI is making vulnerability discovery and exploit generation fast and cheap. Defenders who are still running on monthly patch cycles and manual triage are defending at the wrong speed.

That is not a controversial idea inside security teams. It is the reason risk-based prioritization exists in the first place. What is new is that it is now the headline of the industry’s biggest conference, delivered by one of the platform vendors every enterprise already depends on. The old model of patch on a schedule is running out of runway, and the industry needs to move from reactive patching toward continuous, automated remediation. From where I sit, that shift shines a light on two things that don’t get enough attention: validating a fix before it goes out, and verifying it actually held after it did.

The opening keynote backs this up from a different angle. For the first time, the White House Cyber Director shares the opening session with CISA, the FBI, and the Department of War. It’s a fireside chat followed by a joint panel. Cyber risk has always had a national security dimension, but having this many federal agencies keynote together at a practitioner conference is new, and it’s a signal of how central AI has become to that conversation.

It starts with the high-fidelity data

Walk the Black Hat show floor this year and you’ll see the same pattern repeated by dozens of vendors. Pair an AI agent with an existing product, call it agentic, and ship it. Exposure management specifically has become the category everyone wants a piece of. Attack path analysis is replacing raw vulnerability counts as the pitch. External threat intelligence is getting stitched directly into remediation workflows. Purpose-built agents are showing up to accelerate investigation without asking customers to rip out what they already have.

However, almost none of these announcements are coming from a single platform. They’re coming from point products bolted onto other point products. A vulnerability scanner adds a risk graph. An MDR vendor adds exposure management and wraps it in a warranty. A SOC platform adds agent governance as a separate module. Every one of these is a real capability. None of them is the same thing as a single system that ingests the data, makes the decision, and orchestrates the action. That takes one confidence model and one audit trail running through all three.

The reason I am pointing this out is that data and AI aren’t add-ons, and it’s not specific to any one vendor. An agent is only as good as what it’s reading. Layering a new agent onto an existing product is the easy part. Making sure the data underneath it is normalized, deduplicated, and trustworthy enough to support a decision, not just a dashboard, is the part that actually takes years. For what it’s worth, this is the same reasoning behind Brinqa’s own Q2 2026 releases, the AI Attribution Agent and AI Deduplication Agent. Both run inside the same CyberRisk Graph as everything else in the platform, rather than a separate bolt-on layer. We also used Black Hat this week to preview the next piece we’re building, an Exploitability Agent that will layer real-time exploit intelligence and environmental context onto that same data foundation. It’s early, but we’re doing it in that order on purpose. If the data underneath isn’t right, nothing you build on top of it is worth trusting.

Agents are now an attack surface, and the industry is finally saying so

The most useful quote out of Black Hat this year didn’t come from a keynote. It came from Tanium’s CTO: “What fewer will acknowledge is that ungoverned agents are themselves an emerging attack surface.” A whole new sub-category showed up this week just to deal with that problem. KnowBe4 added Claude support to its agent governance tool so it can flag prompt injection and privilege escalation. Acalvio launched deception infrastructure built specifically to lure attacks on AI agents. Sweet Security shipped real-time blocking for rogue agents in production.

That raises a fair question for any platform selling its own AI: what happens when a security team wants to use a different model, or an agent they built in-house, instead? Most teams already are, across multiple copilots and multiple in-house tools, and that isn’t going to consolidate down to one anytime soon. So the governance problem can’t really be solved by picking a single vendor’s AI. It has to sit at the point where any AI, regardless of who built it, tries to take an action in the environment. That’s the role SmartFlows plays in Brinqa’s platform. It’s a no-code automation and workflow engine that sits between a recommendation and an action, and checks it against policy before anything executes. That holds whether the recommendation came from Brinqa’s own agents or an outside tool plugged in on top.

Identity keeps showing up as the root cause, because it is

BeyondTrust’s annual research, also out this week, found that 75% of attacks involved some form of identity or privilege issue. Standing privilege and escalation showed up together often enough that the report calls them compounding, not coincidental.

That’s not a new finding to anyone who has worked an incident, but it’s a good data point to have in hand. A critical CVE on an unreachable, isolated asset and the same CVE on a system tied to a privileged service account are not the same risk. Treating them the same is how noisy backlogs happen in the first place. Again, the takeaway is that more attack vectors, more data, and more threat feeds all put pressure on teams to have a data foundation that can scale and evolve with their continuous threat exposure management (CTEM) program. That’s different from simply absorbing one more feed.

It’s also important, although perhaps obvious, that identity shows up multiple times on the same attack path. First on the way in, then again for lateral movement. Most breaches begin with a compromised credential or an over-permissioned account that walks an attacker through the front door without tripping an alarm, not a zero day. Once inside, identity is also what determines how far that attacker can actually get. A service account with broad access, a stale admin credential, or a trust relationship between systems nobody’s reviewed in a year can each turn a single compromised asset into a dozen. That’s why blast radius can’t be measured by network segmentation alone. Two assets can sit on the exact same segment and carry very different risk, depending on the identities and privileges that connect them to everything else. For this reason, additional identity intelligence connectors are one of the higher priority requests we’ve started getting at Brinqa. We’re expanding our connector marketplace for CTEM to meet that demand.

What we’re hearing on the floor

A few voices from the team on what this week is confirming:

“Customers want flexibility in choice when it comes to AI. They don’t want to be locked into one vendor’s model or one vendor’s agents. Our BYOAI Marketplace announcement has really resonated this week, and I think that’s because it matches how security teams actually operate today.”

— Dan Pagel, CEO

“We launched the BYOAI Marketplace this week, and the reaction from customers and prospects has been fantastic. People immediately see how they can plug in their own AI and start getting value using the data in Brinqa that they already trust. We’re also spending time with other vendors here talking through how we can orchestrate broader, end-to-end use cases together, not point solutions in isolation.”

— Ron Dovich, Chief AI & Automation Officer

What this means going into next month’s Patch Tuesday

None of this changes what shows up in next Tuesday’s release. It changes how fast the distance between disclosure and exploitation is shrinking, and how much less margin there is for triaging that release by CVSS score alone. The vendors at Black Hat this year mostly agree on the diagnosis: raw vulnerability counts don’t tell you what matters, the gap between discovery and remediation is growing, agentic automation only works if it’s governed, and identity context changes the math on almost every finding.

Where the market is still catching up is the cure. Most of what launched this week is a capability added to an existing tool, not a system built around the decision from the ground up. For us, it still starts with the data. The exposure management market is moving fast, but no matter how fast it moves, AI still comes down to garbage in, garbage out. I’ll pick this thread back up in next month’s Patch Tuesday post.

See what changes when identity, exploitability, and business context are part of the decision instead of an afterthought.

Meet with a Brinqa ExpertMeet with a Brinqa Expert

FAQs

Most 2026 Black Hat AI security launches pair a new agent with an existing point product, a scanner adds a risk graph, an MDR vendor adds exposure management, rather than building a single system with one data foundation, one confidence model, and one audit trail. The distinction matters because an agent bolted onto disconnected data can only be as reliable as that data.

AI is making both vulnerability discovery and exploit generation faster and cheaper for attackers, which compresses the window defenders have to patch before a CVE is weaponized. This is the core theme of Microsoft's 2026 Black Hat keynote and the reason risk-based prioritization has moved from best practice to necessity.

Ungoverned AI agents can be manipulated through prompt injection or privilege escalation the same way traditional software can be exploited, which is why agent governance has emerged as its own security sub-category. Effective governance has to check any agent's proposed action against policy before it executes, regardless of which vendor or model produced the recommendation.

Most security teams are already running multiple copilots and in-house AI tools, and that isn't likely to consolidate to a single vendor. Because of that, governance needs to sit at the point where any AI tries to take an action in the environment, not be tied to picking one vendor's AI stack.

No. Two assets on the same network segment can carry very different risk levels depending on the identities and privileges connecting them to the rest of the environment, so blast radius has to account for identity relationships, not just network topology.

B
Brad Hibbert
Chief Operating Officer & Chief Strategy Officer
Brad Hibbert brings over 30 years of executive experience in the software industry, with a proven track record of aligning business and technical teams to drive growth and customer success.
See all of Brad's posts

Focus on the Exposures That Matter Most

Request a DemoRequest a Demo