Black Hat State of Security Vendors

Andy Ellis has a roundup of the security vendors at Black Hat this year.

Key Takeaways: We have entered into an AI world. While nearly half of booths didn’t directly mention AI or agents in their taglines, the effects of AI are everywhere. Multiple spaces (Identity, SaaS, AppSec, Data) have almost every vendor leading with AI; existing unsolved problem areas just got worse.

At the same time, there’s a clear trichotomy in the market: tools that tell you how bad things are; tools that stop adversaries, and tools that prevent problems from occurring. While you’d suspect that the tools that fix things would dominate, the tools that merely tell you how bad things are seem to be frustratingly plentiful.

Posted on August 25, 2026 at 6:54 AM11 Comments

Comments

For Profit August 25, 2026 7:29 AM

Of course there’s dominance by tools that say how bad things are, that’s to motivate people to buy the tools that fix things. It’s a marketing strategy, IMHO.

KC August 25, 2026 8:43 AM

Andy Ellis posts some helpful analysis and running thoughts on his BHUSA 2026 sec vendor report.

450 booths, a dozen hours, and hopefully some good support in those magenta shoes 🙂

Anonymous August 25, 2026 12:04 PM

https://www.cnn.com/2026/08/25/politics/cia-director-visits-moscow

A big plane for what? Am I allowed to guess?
Gold from the USA, whose owner will be following soon, or after the unsuccessful third term attempt, ’cause when ya gotta leave in a hurry it’s quite soothing to know your gold is there, safe, waiting for you among your comrades.

Nooo-they did not meddle in our elections – you’re all delusional.
Down the road, when the USA is owned by Russia, you’ll remember this event, and a few other events, and say – oh wow, so that’s what this was about….
Effin sh33ple – you don’t deserve a country!

Bob August 25, 2026 1:49 PM

While you’d suspect that the tools that fix things would dominate, the tools that merely tell you how bad things are seem to be frustratingly plentiful

Is this talking about SIEMs, vuln scanners and the like? There’s a lot of bizarrely loaded language here, and I’m not clicking through the cert mismatch to make it make sense.

lurker August 25, 2026 1:54 PM

@ALL

“An error occurred during a connection to http://www.duha.co. SSL received a malformed Server Hello handshake message. (Error code: SSL_ERROR_RX_MALFORMED_SERVER_HELLO)”

There is what purports to be a nearly verbatim rewrite of Andy’s reports at

https://www.cybrsecmedia.com/black-hat-2026-ai-security-trends-andy-ellis-finds-an-industry-better-at-finding-risk-than-fixing-it/

which also contains a fancy graphic version of the link @Bruce gave at the top, also returning the same error message in a different browser. WordPress and Letsencrypt, could be such fun together …

ResearcherZero August 26, 2026 12:16 AM

Companies are playing a dangerous game by including automatic installers that are installing software that displays advertising every time the computer boots. By turning monitors into “smart” monitors and including internet connectivity, a security gap opens.

https://www.tomshardware.com/software/windows/companies-are-now-using-automatic-windows-installers-to-display-adware-through-the-microsoft-store-when-you-install-new-hardware-customer-immediately-gets-mcafee-ads-on-their-pc-after-connecting-new-lg-monitor-heres-how-to-block-the-new-ads

Alienware and LG monitors can both trigger automatic software installers on setup.
https://www.techspot.com/news/113031-lg-alienware-monitors-caught-auto-installing-windows-adware.html

GregW August 30, 2026 7:49 AM

Regarding “the tools that merely tell you how bad things are seem to be frustratingly plentiful”.

I have additional observations and a diagnostic/corrective.

The benefit is not just a tool-marketing one as pointed out by @ForProfit.

There is a second reason this flourishes. Showing a bunch of (often false positive) security concerns also helps the CISO internally market that there is a big problem here that needs more budget.

Internal technical teams who recognize this are disincentivised to say the emperor has no clothes because the three departments whose antagonism can be career-ending are HR, Finance, and Cyber.

Instead internal technical teams are incentivized to fix the vast number of false positives (when they are easy to fix) and only argue about bad information from the tooling when it is extremely difficult to fix. The feedback loop needed for good decisions is limited. And the winning move for certain types of leaders is to use a SaaS tool whose security structure is opaque.

You can know whether the tool vendor cares about the problem “for real”, not just for marketing, by their feature set. If the tool enables and incentivizes downstream non-cyber teams (who have much richer context) to report+track on perceived false positives vs perceived true positives, preferably with a confidence rating, then the rational feedback loops and prioritization can occur, and the centralized cyber team can be more aware of how well the tool itself is generating meaningful warnings for the organization. Anything less is just a cheap sales job.

Leave a comment

Blog moderation policy

Login

Allowed HTML <a href="URL"> • <em> <cite> <i> • <strong> <b> • <sub> <sup> • <ul> <ol> <li> • <blockquote> <pre> Markdown Extra syntax via https://michelf.ca/projects/php-markdown/extra/

Sidebar photo of Bruce Schneier by Joe MacInnis.