Blog

August 10, 2026

Black Hat 2026 Was About Everything Except the Endpoint

Copied to clipboard!

Updated On

August 10, 2026

Illustration of a purple gargoyle crouched at the base of a stone path. An ornate path streams above, led by a star, signifying the gap between discovery and the fix.

At Black Hat USA 2026, Mitiga skipped the show floor and hosted security leaders in our Zero-Impact Suite at Mandalay Bay. The conversations often returned to shadow SaaS sprawl nobody has inventoried, shadow AI agents and copilots operating outside security's view, correlated runtime security across the modern infrastructure, and a widening ask to protect business platforms themselves — including one enterprise that asked Mitiga about covering its SAP deployment. Mitiga CMO John Vecchi on why those threads are one question: who protects everything beyond the endpoint?

We didn't have a booth at Black Hat this year. On purpose.

Instead of scanning badges on the show floor, we spent the week in the Zero-Impact Suite at Mandalay Bay, in 30-minute conversations with security leaders about what's actually keeping them up. We didn’t have badge scanners. We didn’t deliver theater demos. We just answered the questions CISOs ask when there's a door between them and the expo hall.

The room made the week. Across four days we sat down with CISOs and security leaders, close partners we build alongside, and more than a few of the people who saw this market coming before it had a name.

The questions were remarkable, and not because they were new. Because of how far they've moved from the endpoint.

Shadow SaaS stopped being an edge case

So many conversations found their way to this admission. Nobody is fully confident in their SaaS inventory. The problem isn’t generally the sanctioned apps. It’s the tools a team swiped a credit card for three years ago, the integration an admin approved once and forgot, and the OAuth grants that outlived the employees who created them.

That's shadow SaaS, and in 2026 it goes beyond hygiene. It's a standing population of unwatched identities and unwatched data paths. Attackers stopped treating it as an edge case a long time ago because the easiest way into a modern enterprise isn't breaking in. It's logging in to an app you forgot you had.

Shadow AI built the same problem in a tenth of the time

Shadow SaaS took a decade to accumulate. Shadow AI needed about 18 months.

Leaders in the suite described the same pattern in different words. Business units adopt AI agents and copilots ahead of any security review, and each one holds credentials, touches data, and acts at machine speed. An unsanctioned SaaS app mostly sits there until someone uses it. An unsanctioned AI agent does things all day.

And the ceiling here isn't set by what your business units adopt. In July an OpenAI evaluation model, sanctioned and sandboxed, chained vulnerabilities across trust boundaries into Hugging Face's production environment and kept a campaign running there for days, rebuilding its tooling each time the environment was torn down. Hugging Face's postmortem reviewed roughly 17,600 agent actions.

You can't govern, detect, or contain what you haven't found. Discovery is the starting line, and it's why Shadow SaaS and AI Discovery are built into how Mitiga watches an environment.

Third-party services became part of the attack surface

Another theme that surfaced repeatedly was concern over third-party services. Modern enterprises these days depend on a growing web of managed platforms, APIs, integrations, and business services that operate inside the environment every day. Those services increasingly arrive with their own embedded AI. Think Salesforce Agentforce and the growing number of agents and copilots that can access enterprise data, use identities, call APIs, and take action across connected systems.

Most security leaders we spoke with had only partial visibility into what happens after those services and agents are connected. If a third-party platform authenticates into your environment, moves sensitive data, or executes work on your behalf, it has effectively become part of your runtime attack surface.

We heard this question more than a few times. “How do I know if this service, or the AI agent operating inside it, is being abused right now?”

That’s a runtime security problem.

My favorite question: "Can you protect our SAP deployment?"

It came up without a hint of irony. An enterprise looked at the platform running its finance and supply chain and asked the same question it asks about its cloud. Who sees an attacker in here, and who stops them?

Think about what that ask means. A few years ago, ERP security meant patching cadence and access reviews. Now the perimeter of "protect this" includes every system a valid credential can reach. It's why we talk about the modern infrastructure across cloud, SaaS, identity, third-party services, and AI. If it authenticates, exchanges data, or executes work inside your environment, it's no longer adjacent to your infrastructure. It is your infrastructure.

EDR answered this question for the endpoint. The rest of the stack is still raising its hand.

The agentic SOC ran through every conversation

The other thread of the week, in the suite and even in after-hours conversations, was the agentic SOC. AI analysts triaging alerts, agents closing tickets, autonomy edging into the response loop. The energy is real, and so is the pressure behind it.

So, I asked back, “What do the agents reason over?” An AI analyst is only as good as the evidence it can reach, and if you feed agents the same raw, fragmented alerts and 30-day retention you have today, you haven't eliminated the SIEM tax. You've automated it.

The agentic SOC runs on contextualized data. Normalized, correlated, forensic-grade, and going back a lot further than the last month. Data is King, and that layer is why orchestration platforms plug into Mitiga rather than around it.

Posture is handled. The live window isn't.

One more thing. Basically, everyone’s got something to cover their posture. The CNAPP and CSPM boxes are checked. The gap they described is the live window, the misconfiguration that can't close this quarter, or this year, and the identity path nobody has untangled yet. Posture finds the exposure. Someone still has to catch the attacker using it when they’re halfway through the front door.

The market stopped asking whether attackers get in

Four days of those conversations left me more convinced that the market has stopped asking whether attackers will get in. Security leaders are asking what happens next and whether "Zero-Impact" is an achievable answer.

It is. We spent the week showing exactly that. Attackers get in. They walk out empty-handed. That's Zero-Impact Breach Prevention.

Let them come.

Related posts

Mitiga

Let them come

No one can prevent attacks – but we can prevent their impact.Our Zero‑Impact platform unifies security across cloud, SaaS, AI, and identity.

Don't miss these stories