Submind YouTube summaries
Thumbnail for Black Hat 2026 Day 1 Wrap | Black Hat 2026

Black Hat 2026 Day 1 Wrap | Black Hat 2026

Watch on YouTube

Video summary

The opening segment of Day One at Black Hat 2026 in Las Vegas focused on dispelling the pervasive fear that artificial intelligence will render cybersecurity jobs obsolete or trigger an immediate digital apocalypse. Host Christa Casease and her partner John Ull discussed how, while AI is indeed causing problems unprecedented in their scale and speed, these challenges are manageable rather than catastrophic if approached with a balanced strategy involving people, processes, and technology. A key takeaway for practitioners was that understanding the underlying technology allows professionals to thrive by identifying new opportunities it creates, ensuring that human decision-making remains essential within the loop. The conversation emphasized that while adversaries can leverage AI tools for automation at velocities never seen before, defenders are not facing Armageddon but rather a shift in dynamics where strategic integration of AI is crucial for maintaining security posture. The dialogue then shifted to the critical concept of cyber resilience as a core component of modern operating models, particularly within complex enterprise environments involving third parties and interconnected systems like IoT and OT technologies. Security leaders such as CISOs are increasingly being asked by business stakeholders not just to prevent attacks but to prove their capability to operate effectively even after an adversary penetrates the environment. This requirement drives a deeper understanding of end-to-end business processes, helping organizations identify which systems cannot go down versus those with some flexibility, thereby focusing resilience efforts where they matter most. The discussion highlighted that navigating this landscape requires CISOs to engage closely with boards and understand specific system attributes like revenue generation, connectivity, and access points to build a robust threat model against evolving complexities. A significant portion of the day's insights revolved around identity management as it evolves to address AI agents operating at runtime. Since AI agents can perform tasks autonomously based on their capabilities, there is a risk that they may exhibit rogue behavior if not properly constrained by dynamic identity controls and continuous authorization mechanisms. Experts noted the emergence of new roles like security agent orchestrators who must define guardrails for what an agent should or should not do without blocking its ability to function effectively. Furthermore, while visibility into shadow AI remains the foundational first step before any intelligent decision-making can occur, there is a growing trend toward "DIY agentic stacks" where enterprises build their own solutions using internal teams rather than relying solely on third-party vendors, challenging traditional industry models and raising questions about who best understands an organization's specific environment. As the day concluded with wrap-up remarks, both hosts agreed that much of the current discourse surrounding AI in cybersecurity is overly simplistic or driven by fear-mongering among customers and even some vendors. The consensus was clear: stakeholders need to take a step back, breathe deeply, and adopt a strategic mindset rather than succumbing to panic fueled by FUD (fear, uncertainty, and doubt). Vendors are urged to move away from merely scaring clients with worst-case scenarios and instead focus on educating their customers about how to navigate these changes safely. Looking ahead to the next day of coverage, John expressed interest in exploring vendor strategies regarding multi-agent ecosystems and whether enterprises will continue developing internal AI capabilities or revert to buying solutions, underscoring that the industry must evolve from a binary debate into nuanced discussions about integration, management, and practical implementation.
Read the full video transcript
Welcome back to the Cube. We're wrapping up day one of our live coverage of Black Hat 2026 here at the Mandalay Bay in Scorching Las Vegas. I'm Christa Casease. I'm joined here with John Ult, my uh my partner in crime here at the show. How you hanging in there, John? >> Hanging in there. Almost done for the day. >> Almost done. You know, it's at least a little chilly here on the set. They got the AC blast in. >> Don't walk outside. It's that >> I know for two seconds. So, kind of I guess on that line. So, you know, you and I chatted this morning, John, to kick off the day before we had a number of conversations here at the cube and I know you were taking another a number of briefings as well. You said this morning you got a sense that the sky is falling a little bit. I thought I'd get a pulse check and see how you're feeling after the conversations today. Yes, this afternoon I was saying it's a hair on fire problem [laughter] and I think it's being presented as a haironfire problem and certainly it's unprecedented in terms of scale and speed but uh I'm starting to hear from people it's uh it's a manageable problem. Yes, >> but you have to go into it with strategy and intelligence and the right balance of people, process and technology and um I don't think a lot of companies are doing that but those that are are managing. >> Absolutely. So John, what do you think in terms of you know navigating this from the standpoint of our pol our people and our processes? What are some things that you think you know practitioners will walk away from in terms of just some guidance there? Well, practitioners will walk away with a couple things. One is that there are tremendous opportunities. >> So, forget the notion of this is going to replace your job. >> If you understand the technology, you'll thrive. And if you look for new opportunities that the technology will create, you'll thrive. >> In terms of processes, um, we have to be much more sensitive to where the human in the loop takes place. And the human in the loop is important. Uh we have to guide this technology. We have to understand this technology. Um but humans are still necessary to make decisions and will be. So there's still opportunity. There's still work to be done. >> Absolutely. So nobody's job is being displaced and then at the same time from the adversarial perspective yes it can operate at a speed and a scale that we've never seen before and it is unprecedented. We do potentially have the tools available to address that. Again, like you say, provided we rethink different roles and responsibilities and provided we really think strategically about where we can integrate AI as part of our processes. >> Correct. But also another anti-hair on fire notion that I've heard all day is um we're not seeing massive new amounts of malware created. We're seeing adversaries doing what uh defenders are doing and that is using the tools for automation and scale and velocity and so yes you have to be prepared for that but it's not Armageddon. >> I agree and John I've also had a couple conversations instances where AI has actually created some novel types of attacks. Have you heard this as well? And I guess kind of what's your barometer in terms of how concerned we should be about that versus the speed and scale piece of the conversation? >> Yes. So, we're going to see these novel attacks. Sometimes they're accidental uh or negligence, internal negligence. Sometimes they'll be adversarydriven. The other thing we'll see is um we will see script kitties using the tools to advance your skills. I heard a a a term called uh u claude cadetses is the new script kitty. We'll also see less experienced hackers who get really experienced at using the AI tools. So it's sort of a balance of power. So there's all kinds of dynamics on the threat side. >> Absolutely. Absolutely. So building on the the conversation about the threats, um I know you know you know cyber resilience is near and dear to my heart and I know we've we've had a number of conversations about that and I think what I'm what's really solidified for me here at a security show with security practitioners is that cyber resilience is a part of that operating model and that CISOs are being asked by the business to prove not only how many attacks they can stop but more than that to prove that in the event an adversary does penetrate the environment that they have the capabilities in place to be able to operate through that. I'd love to just get your reaction to that. I know you've studied security deeply for so long. Are you hearing that as well? >> I am. Uh it's certainly a CIO CISO prerogative, >> but at the same time, the bigger the enterprise, the more complex the business process is. It may involve third parties. It may involve systems that can't go down. It may involve uh IT or IoT and OT type of technologies. So that's the challenge for security people is to understand the business process end to end and then determine what can't go down, what we have some flexibility on and then how to make those systems resilient. So it's it's definitely an is an initiative. Uh, I think it's the future and I think your study of it is really important, but we're on the on-ramp. There aren't many companies that know how to do this and that's uh that's a prerogative moving forward, >> right? And it goes back to the conversation around the people, right? It's a it's an issue of, you know, navigating the CS the CISO and how they're engaging with the board um and kind of navigating this together. >> Yes. And that that means understanding what the system is. um is it a revenue producing system? What it's connected to? Who's accessing it? Are they accessing it internally or externally? So that's you can see the threat model gets more and more complex, but that's what we're up against. >> Absolutely. And I think part of that conversation is going to lie in the identity space. You know, I've had a number of conversations today around the need to kind of evolve identity controls at runtime to address AI agents. Um because, you know, they they really disrupt that paradigm. And I think that's going to be if we think about how the technology stack is going to evolve for both security and resilience. I think that's going to be a really important um control point moving forward. >> You couldn't be more right, Christa. Um the thing is that uh and we've done UEIBA for years. We can do behavior analytics. People have limited ability to do things and we can also do identity governance to say you can do this, you can't you can't do this. entitlements, etc. If you ask an agent to do a task, it's going to do whatever it needs to do orever what it can do to accomplish that task. And some of that may be rogue behavior. So that's where I think identity, non-human identities, gentic identities, that's the challenge there. And it's not static. It's very dynamic. >> It is very dynamic. And I had a conversation actually a couple around this concept of you know continuous authorization um and really it's also about understanding you know the behavior of the agent as well. >> Yes. And uh there is one of the roles I think is evolving is an a security agent orchestrator. So that is what does this what do I want this agent to do but what don't I want it to do and putting the right guard rails but not putting up blocks where it can't get its job done. So that that's a real challenge. >> Absolutely. So, I'll get off my little resilience and identity soap box for a minute. And John, I've also been having a number of conversations around the fact that we're really kind of honing in at, you know, runtime for these AI agents and how do we establish security controls and guard rails to be able to allow these AI agents to move safely into production. Um, I'm trying to get a sense, you know, are practitioners kind of solving that piece of the equation while they're also solving the visibility and kind of the shadow AI component of it. Um, I'd be interested to get your take on it. Do you think they're trying to do both at the same time? >> Um, well, they'd like to do both at the same time, but I think you've had several guests on today. I've had several conversations. The first thing everyone says is we need visibility. So what's out there? What's it doing? Who owns it? What's it connected to? Uh that's you can't move on. You can't what? You can't secure what you don't know or whatever that cliche is. So visibility is the start. Once you have visibility, then you can make intelligent decisions. So I think it's sequential more than um simultaneous. >> Yeah. Yeah. I agree. So, John, looking ahead to tomorrow, you know, I guess what are some of the things that you're going to be listening listening for in your conversations tomorrow? >> I'd like to hear more about this complexity that I talked about because >> there's a little bit of a simplistic [snorts] binary discussion on uh we can't secure AI, we can secure AI, and that's just not realistic. All of these tools are being instrumented with agents. How do all those tools work together? I mean, so do the does one vendor's agent know about another's vendor vendor's agent? Is there some central management of that? >> The other thing that I find interesting and and uh you know, we're surrounded by what I don't know 500 vendors here or something. >> AI makes development easier. So, one person can do the development work of several if they're good. what's stopping enterprises from doing the development themselves and I actually heard that from a company that I've worked with in the past. He we were talking about the agentic sock and the CEO said oh yeah we've done that I said oh did you buy from this vendor that vendor said no we did it ourselves it took one person and uh they could do the work of three people and that's really increased our velocity and our efficiency okay now their environment isn't that complex but what if you applied five people to that if you're a big enterprise so that's a question that I hadn't really considered is >> is there an opportunity for smart engineers who understand their environment, you know, uh intimately >> to do this themselves. And so I'll be looking out for that tomorrow and I'll ask every vendor, are you seeing that? Because that's a a threat to this whole industry. >> The DIY agentic sock, that's that's pretty wild. But what I mean, what are some of the pitfalls there? Well, I think it's a common pitfall is that if you're a security department, you don't want to be in the software development business. You don't want to um be having to maintain that. But that's gotten easier from waterfall to um to different types of development environments, CI/CD pipelines, and now you add agents and agent coding, and it gets even easier. And again, who knows their environment better than those people? >> Absolutely. you have to bring in a third party vendor and then customize their solution. Why don't we just do it ourselves? Now, there's certainly plenty of room for some of the vendors in this in this show to succeed, but I just wonder how um how prevalent that trend will be. >> Yes. Yeah, I definitely agree. All right. Well, John, I know we're going to be back on first thing in the morning. Um >> Yes, we are. >> Yeah. [gasps and laughter] >> Anything else top of mind for you from the day? Um, it's very crowded here. >> Yes, >> there's a lot of energy here. So, I think it's a very successful black hat. But again, I think I I I see a lot of fear-mongering. And I I've said to everyone I've met, every vendor I've met with, take a step back, take a deep breath, >> think strategically, talk to your customers, educate your customers. So hopefully I'll see more customer education tomorrow. >> I agree. I think there's a lot of FUD amongst customers, but are they at the level of panicked? >> I'm not sometimes. >> Sometimes, but like you say, I think the roles of the vendors should be to help them to navigate that and to kind of provide actually some resolution, some potential. >> The vendors, yes, the salespeople, no, they should scare the their [laughter] customers. >> That's very fair. All right. Well, John, thank you so much. I look forward to chatting with you in the morning. >> Talk to you in the morning. >> Sounds good. And thank you so much for joining our coverage of the first day here at Black Hat 2026. We'll be right back with you tomorrow morning. So, uh, join us then. And thank you so much.