In this analysis from Black Hat 2026, theCUBE's Krista Case and Jon Oltsik recap day one of the conference, unpacking how artificial intelligence is reshaping both attacker and defender strategies across the security landscape. Oltsik pushes back on "hair-on-fire" narratives, noting that while AI-driven threats are unprecedented in scale and speed, the problem remains manageable for organizations that pair strategy and intelligence with the right balance of people, process and technology. He and Case examine how adversaries are largely using AI for automation and velocity rather than generating entirely new malware, while also flagging the rise of novel, AI-assisted attack techniques and less-skilled actors gaining outsized capability through these tools.
The conversation also explores cyber resilience as a board-level mandate, with CISOs increasingly expected to prove not just prevention but the ability to operate through a breach. Case and Oltsik dig into the growing complexity of identity for AI agents, describing the need for dynamic, runtime authorization and a new "security agent orchestrator" role to govern non-human identities. They stress that visibility must come before control, arguing the industry is on the early on-ramp of resilience maturity. The two also raise a provocative question for enterprises: as AI lowers the barrier to building in-house tooling, will organizations increasingly build their own agentic security operations centers rather than buy from vendors? From fear-mongering sales tactics to the promise of customer education, Case and Oltsik close day one with a call for practitioners to think strategically rather than react to hype.
Forgot Password
Almost there!
We just sent you a verification email. Please verify your account to gain access to
Black Hat USA 2026. If you don’t think you received an email check your
spam folder.
In order to sign in, enter the email address you used to registered for the event. Once completed, you will receive an email with a verification link. Open the link to automatically sign into the site.
Register for Black Hat USA 2026
Please fill out the information below. You will receive an email with a verification link confirming your registration. Click the link to automatically sign into the site.
You’re almost there!
We just sent you a verification email. Please click the verification button in the email. Once your email address is verified, you will have full access to all event content for Black Hat USA 2026.
I want my badge and interests to be visible to all attendees.
Checking this box will display your presense on the attendees list, view your profile and allow other attendees to contact you via 1-1 chat. Read the Privacy Policy. At any time, you can choose to disable this preference.
Select your Interests!
add
Upload your photo
Uploading..
OR
Connect via Twitter
Connect via Linkedin
EDIT PASSWORD
Share
Forgot Password
Almost there!
We just sent you a verification email. Please verify your account to gain access to
Black Hat USA 2026. If you don’t think you received an email check your
spam folder.
In order to sign in, enter the email address you used to registered for the event. Once completed, you will receive an email with a verification link. Open the link to automatically sign into the site.
Sign in to gain access to Black Hat USA 2026
Please sign in with LinkedIn to continue to Black Hat USA 2026. Signing in with LinkedIn ensures a professional environment.
Are you sure you want to remove access rights for this user?
Details
Manage Access
email address
Community Invitation
Day 1 Wrap
Krista Case of theCUBE Research is principal analyst and practice lead for cyber resilience and security. Jon Oltsik of theCUBE Research is principal analyst in residence. Case synthesizes Day 1 discussions at Black Hat 2026 and they highlight artificial intelligence AI-driven threat trends, agentic security operations center concepts, identity and runtime controls, shadow AI visibility and the evolving human role in defense.
Oltsik notes that AI amplifies speed and scale but can be managed with strategy, threat intelligence and balanced investments in people process and technology; they call for improved visibility and vendor-led customer education. Case underscores cyber resilience as an operating model and stresses the importance of identity controls and continuous authorization for non-human agents; they advocate careful orchestration of agent guardrails and runtime controls.
This coverage and analysis from Black Hat 2026 Day 1 provides practical strategic guidance for security operations teams and clarifies vendor responsibilities revealed across briefings and vendor sessions.
Principal Analyst and Practice Lead for Cyber Resilience and SecuritytheCUBE Research
Jon Oltsik
Principal Analyst in ResidencetheCUBE Research
In this analysis from Black Hat 2026, theCUBE's Krista Case and Jon Oltsik recap day one of the conference, unpacking how artificial intelligence is reshaping both attacker and defender strategies across the security landscape. Oltsik pushes back on "hair-on-fire" narratives, noting that while AI-driven threats are unprecedented in scale and speed, the problem remains manageable for organizations that pair strategy and intelligence with the right balance of people, process and technology. He and Case examine how adversaries are largely using AI for automation...Read more
exploreKeep Exploring
How should practitioners navigate this rapid, large‑scale technological change with respect to people and processes, and what practical guidance should they take away?add
How will AI affect cybersecurity practitioners' roles, the need for human-in-the-loop, and the nature of adversarial threats?add
How should identity and access management evolve to manage the risks posed by AI/agentic (non‑human) identities, and what controls or roles (e.g., runtime identity controls, continuous authorization, behavior analytics, security agent orchestrator) are needed to secure their behavior?add
>> We're wrapping up day one of our live coverage of Black Hat 2026 here at the Mandalay Bay in scorching Las Vegas. I'm Krista Case. I'm joined here with Jon Oltsik, my partner in crime here at the show. How are you hanging in there, Jon?
Jon Oltsik
>> Hanging in there. Almost done for the day.
Krista Case
>> Almost done. it's at least a little chilly here on the set. They got the AC blasting.
Jon Oltsik
>> You walk outside, it's not chilly.
Krista Case
>> I know, for two seconds. So kind of, I guess, on that line, so you and I chatted this morning, Jon, to kick off the day before we had a number of conversations here at theCUBE, and I know you were taking a number of briefings as well. You said this morning you got a sense that the sky is falling a little bit. I thought I'd get a pulse check and see how you're feeling after the conversations today.
Jon Oltsik
>> Yes, this afternoon I was saying it's a hair -on -fire problem. And I think it's being presented as a hair on fire problem. And certainly it's unprecedented in terms of scale and speed. But I'm starting to hear from people it's a manageable problem.
Krista Case
>> Yes.
Jon Oltsik
>> But you have to go into it with strategy and intelligence and the right balance of people, process and technology. And I don't think a lot of companies are doing that, but those that are are managing.
Krista Case
>> Absolutely. So Jon, what do you think in terms of navigating this from the standpoint of our people and our processes, what are some things that you think practitioners will walk away from in terms of just some guidance there?
Jon Oltsik
>> Well, practitioners will walk away with a couple things. One is that there are tremendous opportunities. So forget the notion of this is going to replace your job. If you understand the technology, you'll thrive, and if you look for new opportunities that the technology will create, you'll thrive. In terms of processes, we have to be much more sensitive to where the human in the loop takes place. And the human in the loop is important. We have to guide this technology. We have to understand this technology. But humans are still necessary to make decisions, and will be. So there's still opportunity, there's still work to be done.
Krista Case
>> Absolutely. So nobody's job is being displaced. And then at the same time, from the adversarial perspective, yes, it can operate at a speed and a scale that we've never seen before. And it is unprecedented. Yes. We do potentially have the tools available to address that. Again, like you say, provided we rethink different roles and responsibilities and provided we really think strategically about where we can integrate AI as part of our processes.
Jon Oltsik
>> Correct. Correct, but also another anti hair on fire notion that I've heard all day is, we're not seeing massive new amounts of malware created. We're seeing adversaries doing what defenders are doing, and that is using the tools for automation and scale and velocity. And so yes, you have to be prepared for that, but it's not Armageddon.
Krista Case
>> I agree, and Jon, I've also had a couple conversations, instances where AI has actually created some novel types of attacks. Have you heard this as well? And I guess what's your barometer in terms of how concerned we should be about that versus the speed and scale piece of the conversation?
Jon Oltsik
>> Yes. So we're going to see these novel attacks. Sometimes they're accidental or negligence, internal negligence. Sometimes they'll be adversary driven. The other thing we'll see is we will see script kiddies using the tools to advance their skills. I heard a term called Claude Kiddies is the new script kiddie. We'll also see less experienced hackers who get really experienced at using the AI tools. So it's sort of a balance of power. So there's all kinds of dynamics on the threat side.
Krista Case
>> Absolutely, absolutely. So building on the conversation about the threats, I know cyber resilience is near and dear to my heart and I know we've had a number of conversations about that and I think what's really solidified for me here at a security show with security practitioners is that cyber resilience is a part of that operating model and that CISOs are being asked by the business to prove not only how many attacks they can stop, but more than that, to prove that in the event an adversary does penetrate the environment, that they have the capabilities in place to be able to operate through that. I'd love to just get your reaction to that. I know you've studied security deeply for so long. Are you hearing that as well?
Jon Oltsik
>> I am. It's certainly a CISO prerogative, but at the same time, the bigger the enterprise, the more complex the business process is. It may involve third parties. It may involve systems that can't go down. It may involve IT or IoT and OT type of technologies. So that's the challenge for security people is to understand the business process end to end and then determine what can't go down, what we have some flexibility on, and then how to make those systems resilient. So it's definitely an initiative. I think it's the future, and I think your study of it is really important. But we're on the on -ramp. There aren't many companies that know how to do this, and that's a priority moving forward.
Krista Case
>> Right, and it goes back to the conversation around the people, right? It's an issue of navigating the CISO and how they're engaging with the board and navigating this together.
Jon Oltsik
>> Yes. And that means understanding what the system is. Is it a revenue producing system? What is it connected to? Who's accessing it? Are they accessing it internally or externally? So you can see the threat model gets more and more complex, but that's what we're up against.
Krista Case
>> Absolutely. And I think part of that conversation is going to lie in the identity space. I've had a number of conversations today around the need to evolve identity controls at runtime to address AI agents, because they really disrupt that paradigm. And I think that's going to be, if we think about how the technology stack is going to evolve for both security and resilience, I think that's going to be a really important control point moving forward.
Jon Oltsik
>> You couldn't be more right, Krista. The thing is that, and we've done UEBA for years, we can do behavior analytics. People have limited ability to do things. And we can also do identity governance to say you can do this, you can't do this, entitlements, et cetera. If you ask an agent to do a task, it's going to do whatever it needs to do or whatever it can do to accomplish that task. And some of that may be rogue behavior. So that's where I think identity, non-human identities, agentic identities, that's the challenge there, and it's not static, it's very dynamic.
Krista Case
>> It is very dynamic, and I had a conversation, actually a couple, around this concept of continuous authorization, and really it's also about understanding the behavior of the agent as well.
Jon Oltsik
>> Yes, and one of the roles I think is evolving is a security agent orchestrator. So that is, what do I want this agent to do, but what don't I want it to do? And putting the right guardrails, but not putting up blocks where it can't get its job done. So that's a real challenge.
Krista Case
>> Absolutely. So I'll get off my little resilience and identity soapbox for a minute. And Jon, I've also been having a number of conversations around the fact that we're really kind of honing in on runtime for these AI agents and how do we establish security controls and guardrails to be able to allow these AI agents to move safely into production. I'm trying to get a sense, are practitioners kind of solving that piece of the equation while they're also solving the visibility and kind of the shadow AI component of it? I'd be interested to get your take on it. Do you think they're trying to do both at the same time?
>> Yeah. Yeah, I agree. So Jon, looking ahead to tomorrow, what are some of the things that you're going to be listening for in your conversations tomorrow?
Jon Oltsik
>> I'd like to hear more about this complexity that I talked about because there's a little bit of a simplistic binary discussion on we can't secure AI, we can secure AI, and that's just not realistic. All of these tools are being instrumented with agents. How do all those tools work together? So does one vendor's agent know about another vendor's agent? Is there some central management of that? The other thing that I find interesting, and we're surrounded by what? I don't know, 500 vendors here or something? AI makes development easier. So one person can do the development work of several, if they're good. What's stopping enterprises from doing the development themselves? And I actually heard that from a company that I've worked with in the past. We were talking about the agentic SOC. And the CEO said, oh yeah, we've done that. I said, oh, did you buy from this vendor, that vendor? He said, no, we did it ourselves. It took one person and they could do the work of three people and that's really increased our velocity and our efficiency. Okay, now their environment isn't that complex, but what if you applied five people to that if you're a big enterprise? So that's a question that I hadn't really considered is, is there an opportunity for smart engineers who understand their environment intimately to do this themselves. And so I'll be looking out for that tomorrow and I'll ask every vendor, are you seeing that? Because that's a threat to this whole industry.
Krista Case
>> The DIY agentic SOC, that's pretty wild. But what are some of the pitfalls there?
Jon Oltsik
>> Well, I think a common pitfall is that if you're a security department, you don't want to be in the software development business. you don't want to be having to maintain that. But that's gotten easier from waterfall to different types of development environments, CICD pipelines, and now you add agents and agent coding, and it gets even easier. And again, who knows their environment better than those people?
Jon Oltsik
>> Absolutely.
Jon Oltsik
>> If you have to bring in a third -party vendor and then customize their solution. Why don't we just do it ourselves? There's certainly plenty of room for some of the vendors in this show to succeed, but I just wonder how prevalent that trend will be.
Krista Case
>> Yes, I definitely agree. All right, well, Jon, I know we're going to be back at it first thing in the morning.
Jon Oltsik
>> Yes, we are.
Krista Case
>> Anything else top of mind for you from the day?
Jon Oltsik
>> It's very crowded here. There's a lot of energy here. So I think it's a very successful Black Hat, but again, I think, I see a lot of fear-mongering and I've said to everyone I've met, every vendor I've met with, take a step back, take a deep breath, think strategically, talk to your customers, educate your customers. So hopefully I'll see more customer education tomorrow.
Krista Case
>> I agree. I think there's a lot of FUD amongst customers, but are they at the level of panicked? I'm not sure.
Jon Oltsik
>> Sometimes. Sometimes.
Krista Case
>> Sometimes, but like you say, I think the roles of the vendors should be to help them to navigate that and to provide some resolution, some potential solutions.
Jon Oltsik
>> That's right, the vendors, yes. The salespeople, no. They shouldn't scare their customers.
Krista Case
>> That's very fair. All right, well, Jon, thank you so much. I look forward to chatting with you in the morning.
Jon Oltsik
>> Talk to you in the morning.
Krista Case
>> Sounds good. And thank you so much for joining our coverage of the first day here at Black Hat 2026. We'll be right back with you tomorrow morning. So join us then. And thank you so much.