Black Hat State of Security Vendors

Andy Ellis has a roundup of the security vendors at Black Hat this year.

Key Takeaways: We have entered into an AI world. While nearly half of booths didn’t directly mention AI or agents in their taglines, the effects of AI are everywhere. Multiple spaces (Identity, SaaS, AppSec, Data) have almost every vendor leading with AI; existing unsolved problem areas just got worse.

At the same time, there’s a clear trichotomy in the market: tools that tell you how bad things are; tools that stop adversaries, and tools that prevent problems from occurring. While you’d suspect that the tools that fix things would dominate, the tools that merely tell you how bad things are seem to be frustratingly plentiful.

Posted on August 25, 2026 at 6:54 AM12 Comments

Comments

For Profit August 25, 2026 7:29 AM

Of course there’s dominance by tools that say how bad things are, that’s to motivate people to buy the tools that fix things. It’s a marketing strategy, IMHO.

KC August 25, 2026 8:43 AM

Andy Ellis posts some helpful analysis and running thoughts on his BHUSA 2026 sec vendor report.

450 booths, a dozen hours, and hopefully some good support in those magenta shoes 🙂

Kevin August 25, 2026 11:24 AM

Chrome Security doesn’t like the embedded link

This server could not prove that it is http://www.duha.co; its security certificate is from wordpress.com. This may be caused by a misconfiguration or an attacker intercepting your connection.

Proceed to http://www.duha.co (unsafe)

Anonymous August 25, 2026 12:04 PM

https://www.cnn.com/2026/08/25/politics/cia-director-visits-moscow

A big plane for what? Am I allowed to guess?
Gold from the USA, whose owner will be following soon, or after the unsuccessful third term attempt, ’cause when ya gotta leave in a hurry it’s quite soothing to know your gold is there, safe, waiting for you among your comrades.

Nooo-they did not meddle in our elections – you’re all delusional.
Down the road, when the USA is owned by Russia, you’ll remember this event, and a few other events, and say – oh wow, so that’s what this was about….
Effin sh33ple – you don’t deserve a country!

AI Video Detector August 25, 2026 12:20 PM

Interesting take on the shift toward AI-driven security solutions at Black Hat. It’s striking how many vendors focus on highlighting problems rather than fixing them—feels like a symptom of an industry still catching up with real solutions. This resonates with challenges in detecting synthetic media, where awareness is growing but effective tools are scarce. For those exploring deeper into media authenticity, checking out resources like AI Video Detector might offer useful insights.

Bob August 25, 2026 1:49 PM

While you’d suspect that the tools that fix things would dominate, the tools that merely tell you how bad things are seem to be frustratingly plentiful

Is this talking about SIEMs, vuln scanners and the like? There’s a lot of bizarrely loaded language here, and I’m not clicking through the cert mismatch to make it make sense.

lurker August 25, 2026 1:54 PM

@ALL

“An error occurred during a connection to http://www.duha.co. SSL received a malformed Server Hello handshake message. (Error code: SSL_ERROR_RX_MALFORMED_SERVER_HELLO)”

There is what purports to be a nearly verbatim rewrite of Andy’s reports at

https://www.cybrsecmedia.com/black-hat-2026-ai-security-trends-andy-ellis-finds-an-industry-better-at-finding-risk-than-fixing-it/

which also contains a fancy graphic version of the link @Bruce gave at the top, also returning the same error message in a different browser. WordPress and Letsencrypt, could be such fun together …

WishyWashy Kismet-AirCrack-Magnets Now in Your Hood August 25, 2026 4:03 PM

Considering how $t00p1d and rude (too many) people are, there actually aren’t that many shootings in the USA at all. Seriously – I know what I’m talking about.
THE NERVE to move into my neighborhood and fire up a Packet-Sniffer, ya gotta be soooooo $t00p1d…..and how did that magnet thing work out for ya?
Keep jerkin’ my chain and you’ll see how old ya get.

ResearcherZero August 26, 2026 12:16 AM

Companies are playing a dangerous game by including automatic installers that are installing software that displays advertising every time the computer boots. By turning monitors into “smart” monitors and including internet connectivity, a security gap opens.

https://www.tomshardware.com/software/windows/companies-are-now-using-automatic-windows-installers-to-display-adware-through-the-microsoft-store-when-you-install-new-hardware-customer-immediately-gets-mcafee-ads-on-their-pc-after-connecting-new-lg-monitor-heres-how-to-block-the-new-ads

Alienware and LG monitors can both trigger automatic software installers on setup.
https://www.techspot.com/news/113031-lg-alienware-monitors-caught-auto-installing-windows-adware.html

Leave a comment

Blog moderation policy

Login

Allowed HTML <a href="URL"> • <em> <cite> <i> • <strong> <b> • <sub> <sup> • <ul> <ol> <li> • <blockquote> <pre> Markdown Extra syntax via https://michelf.ca/projects/php-markdown/extra/

Sidebar photo of Bruce Schneier by Joe MacInnis.