TLDRocket
Sign in

Three insights you may have missed from theCUBE’s coverage of Black Hat USA

SiliconANGLE Victoria Gayton

Black Hat’s big lesson: AI is speeding up attacks and making “perfect prevention” unrealistic. Now security has to focus on recovery, context and control, not just blocking breaches.

Based on reporting by SiliconANGLE, Victoria Gayton — read the original for the full story.

Summary, retelling and take written by AI under human oversight; images are AI-generated illustrations. How we work · Report an error

Black Hat USA kept circling back to the same uncomfortable idea: security teams should stop pretending they can block every hit. Krista Case of theCUBE Research said disruption is inevitable, even for mature organizations, and the real question is whether companies know their “minimal viable operations” and can get them back to a trusted state fast.

The speed problem is getting worse. Jon Oltsik pointed to Mandiant’s “M-Trends 2026” report, which says the median time from initial access to handoff to a secondary threat group dropped from more than eight hours in 2022 to 22 seconds in 2025. That kind of compression makes human-led response look slow by design, and it puts a premium on context, not just alarms.

It also changes how teams think about identity. Case and Oltsik both argued that autonomous agents create a new oversight problem because their behavior is dynamic. An agent can have legitimate access and still act in ways security teams would call rogue. Static permissions were built for people and servers, not software that improvises to get a job done.

AI is also pushing defense further left and further out. David Weston of Microsoft said safer software construction now includes memory-safe languages and formal verification, and he described catching a catastrophic issue that passed tests and human review. Once software ships, Emilio Escobar of Datadog said security and engineering need shared telemetry so they can see the same activity from different angles and prioritize based on runtime exposure and business importance, not just severity scores.

The governance piece may be the hardest part. Robin Braun of HPE said organizations can’t scale AI without trust in the data underneath it, while Axonius and Rubrik both showed how messy agent-era access control gets once identities, prompts and tool calls enter the picture. And Fortinet’s cybercrime bounty program is a reminder that resilience is no longer only about defending systems; it’s also about helping law enforcement identify the people behind the attacks.

My take — AI-written commentary, not fact-checked reporting

The industry keeps selling AI as if it were mostly a productivity story, but Black Hat made the better case: AI is an operations and governance problem dressed up as a feature. The companies that win won’t be the ones with the prettiest demo; they’ll be the ones that can explain who touched what, why it happened and how to shut it down without a week of spreadsheet theater.

Read more about this at: SiliconANGLE

Related stories

The daily briefing

Every AI story that matters, in your inbox by 8am.

TLDRocket reads all relevant sources, removes duplicate coverage, and summarises the day in two minutes. Follow companies and topics for alerts, or get the briefing in Slack. Free, no spam, unsubscribe anytime.