Particle.news
Download on the App Store

Security Industry Shifts to Guard AI Agents at Black Hat USA 2026

Vendors unveiled runtime sanitization, identity-aware controls, open-source agent exchanges to counter faster AI-driven attacks.

Overview

  • Black Hat USA 2026 saw a concentrated wave of agent-focused launches that aim to find, govern, sanitize and monitor AI assistants and developer agents across cloud and endpoints.
  • Palo Alto Networks announced PAN-OS 12.2 Ceres with six AI security agents, advanced virtual patching and automated blocking for direct-to-IP attacks to protect AI data centers.
  • Tenable introduced the open-source CyberAgents Exchange so security teams can discover, share and build agent code, multi-agent playbooks and provenance for trusted agent workflows.
  • Research from CrowdStrike and Cisco Talos and Dataminr’s mid-year report show threat actors are using LLMs to speed exploit development, expand cloud and supply-chain attacks, and that patch windows and alert volumes have grown.
  • Vendors say the new controls aim to cut SOC overload by automating continuous testing, tying agent actions to identity and telemetry, and creating human-reviewable audit trails to speed response.