Events & industry
What just happened, and what the companies did about it
Conference coverage and vendor developments — acquisitions, funding, product launches
and original research — with a short, plain assessment of why each one matters. Newest first.
Just happened
3–6 August 2026 · Las Vegas
Black Hat USA 2026
The defining security conference of the year, and this year it was almost entirely about agents. Three coding-agent harnesses broken, the first voluntary AI incident-disclosure framework tabled, and vendor after vendor shipping autonomous offence and defence. The through-line: AI is accelerating familiar attacks rather than inventing new ones.
Highlights
Coding agents broken in default configuration
Novee's Elad Meged showed a single unprivileged GitHub issue reaching RCE on CI runners behind Claude Code, Gemini CLI and Codex. CVE-2026-54316 for Anthropic; CVSS 10.0 from Google.
Source: Novee
SAFE: first voluntary AI incident-disclosure framework
The Linux Foundation published the Shared AI Findings Exchange RFC with the Open Secure AI Alliance — 72 hours to notify exposed customers, 30 days to a preliminary public report.
Source: Cybersecurity Dive
OpenAI calls autonomous hacks a 'watershed moment'
OpenAI debriefed on the Hugging Face incident, with leadership framing autonomous intrusion as a watershed moment for computer security.
Source: Cybersecurity Dive
Attackers grow willing to destroy, not just disrupt, OT
Sessions on critical infrastructure reported a shift from disruption toward destructive intent against operational technology.
Source: Cybersecurity Dive
Governments push resilience over AI hype
Western government leaders on the policy panel called for a focus on infrastructure resilience rather than AI capability narratives.
Source: Cybersecurity Dive
Research: AI accelerates familiar attacks
The recurring research finding across the week — AI is compressing the timeline of known attack patterns rather than producing novel ones.
Source: Redmond
August 2026 · Las Vegas
Ai4 2026
Ran alongside Black Hat, with an overlapping AI-security track. Coverage of the two events together produced the clearest current picture of where enterprise AI security spending is heading.
Highlights
15 AI security lessons from Black Hat and Ai4
TechRepublic's combined round-up of the practical takeaways from both events.
Source: TechRepublic
Company watch
Vendor moves on the AI-security beat. We note the commercial interest behind every announcement:
research published by a company selling a product in that category is still research, and still
marketing-adjacent. We have no commercial interest of our own here — we sell subscriptions, not
placements.
August 2026
NewResearch
Palo Alto Networks (Unit 42)
5 August 2026
NOVA autonomous vulnerability research: 14,090 confirmed bugs across 3,915 projects
Unit 42 published results from NOVA, an autonomous vulnerability research system. Over two months it analysed 3,915 open source projects and confirmed 14,090 vulnerabilities — 99.4% previously unreported, and 39.7% rated High or Critical under CVSS 4.0.
Why it mattersThe most concrete evidence yet that autonomous vulnerability discovery works at scale. If these numbers hold, the disclosure and patching pipeline is about to be the bottleneck, not discovery.
Source: SecurityWeek
NewResearch
CrowdStrike
5 August 2026
2026 Threat Hunting Report: adversaries exploiting disclosures within hours
CrowdStrike found AI now embedded across adversary operations, with actors exploiting vulnerabilities within hours of public disclosure. The report flags a sharp rise in cloud-focused attacks, AI supply chain compromise and abuse of trusted authentication workflows. CrowdStrike also launched 'AI Unlocked: Agents of Chaos', a global AI red-teaming competition with AWS and a $100,000 prize pool.
Why it mattersHours-to-exploit changes patch SLAs from a policy question into an operational one.
Source: SecurityWeek
NewProduct
SentinelOne
5 August 2026
Purple AI gets closed-loop response; Wayfinder Frontier pairs Anthropic models with analysts
Two Singularity Platform updates: governed closed-loop response letting Purple AI investigate alerts and execute response actions, and expanded Wayfinder Frontier AI Services pairing Anthropic's latest models with SentinelOne analysts to find and validate exploitable vulnerabilities.
Why it matters'Governed' is the operative word. Agents that can act, not just advise, are the current frontier of SOC tooling — and the current frontier of SOC risk.
Source: SecurityWeek
NewProduct
Tenable
5 August 2026
CyberAgents Exchange: a free open-source agent marketplace for security teams
An open source exchange where security professionals can discover, share and build trusted AI agents and multi-agent playbooks.
Why it mattersWorth watching against the Black Hat harness findings — a shared agent marketplace is also a shared supply chain.
Source: SecurityWeek
NewProduct
Menlo Security
5 August 2026
Prompt-injection protection for AI assistants and coding agents
Menlo extended its platform to route agent web traffic through a cloud environment that sanitises files and strips hidden instructions before the agent sees them.
Why it mattersDirectly addresses the untrusted-input problem behind the coding-agent disclosures, though at the input layer rather than the harness layer where those bugs actually lived.
Source: SecurityWeek
February 2026
M&A
Arctic Wolf
23 February 2026
Arctic Wolf acquires Sevco Security
Arctic Wolf acquired Austin-based Sevco Security for an undisclosed sum. Sevco, founded in 2020 by J.J. Guy and Greg Fitzgerald with roughly 50 staff, had raised $38.7 million across multiple rounds led primarily by SYN Ventures. Its cloud-native CAASM platform aggregates asset inventory and vulnerability metadata without endpoint agents. Arctic Wolf plans to integrate it natively into the Aurora Platform to strengthen Managed Risk.
Why it mattersArctic Wolf has raised $879M over 8 rounds and is consolidating around a single claim: an authoritative real-time system of record for corporate assets. Asset truth is the unglamorous prerequisite for every AI-driven detection story being sold this year — you cannot reason about an estate you cannot enumerate.
Source: GlobeNewswire
Disclosure. AI Perimeter takes no
advertising, no sponsored content and no vendor money. None of the companies on this page has paid
us anything, and none of them saw this coverage before publication. See our
editorial standards.