Black Hat 2026: Time for an AI Chill Pill?
Sandbox escapes and “patch storms” are cause for concern, not panic, experts say. Plus: Securing open source AI, partner programs invest in personas, and Sophos partners with OpenAI.
Does the progress AI’s making in security these days bother you as much as it does me?
I should probably put “progress” in air quotes, come to think of it, because it’s hard to characterize recent evidence from OpenAI, Anthropic, Meta, Kimi maker Moonshot, and even the U.K.’s AI Security Institute that cutting-edge LLMs can’t be contained in sandboxes and will happily smash through guardrails as steps in the right direction.
Same goes for the observation by Thomas Wolf, co-founder and chief science officer of AI hacking victim Hugging Face, that Anthropic’s Claude engaged in repeated acts of deception to perpetrate its three break-ins even though the constitution supposedly governing its every action explicitly says it “should basically never directly lie or actively deceive anyone it’s interacting with.”
I used the word “perpetrate” advisedly in that last sentence, by the way, because frontier AI models have been perps in enough unlawful entries lately to inspire the launch of a brand new, chillingly funny performance benchmark.
So yes, I’m a touch nervous about where things might be headed next, and I’m not alone. The folks at cyber insurer Beazley are a little worried that AI might be about to wreck their entire risk model.
“They have a whole effort and project underway with people assigned to it who are just focused on this AI question,” said Alton Kizziah, CEO of the insurance company’s Beazley Security subsidiary, during a conversation at the recent Black Hat conference in Las Vegas. “What is it going to be like? What’s the risk? How does this change cyber?”
You know who isn’t terribly worried about any of that? Pretty much all of the experts I spoke with at Black Hat week before last. AI’s latest exploits, most said, are potentially dangerous, but not in some radically new way or to some radically new degree.
That was the conclusion Brendan Griffin, director of threat research at N-able, reached anyway after attending a session (scheduled quietly at the last minute and not listed on the official event agenda) in which OpenAI staffers offered a blow-by-blow account of the Hugging Face hack. The most striking takeaway, he says, is that ChatGPT did pretty much exactly what a smart human attacker would, and the same applies to the other felonious models.
“It’s not magic,” Griffin says. “They’re still exploiting the same types of vulnerabilities and misconfigurations that we defenders have been trying to warn against and defend against for years and years.”
Albeit with one critical difference, he adds. “They’re doing it at machine speed, they don’t get tired, and they don’t run out of ideas.”
They work cheap too. Autonomous pentest vendor FireCompass recently made the top three in HackerOne’s U.S. country leaderboard on a budget of $5,000 a month. I could probably afford that kind of spending if I wanted a life of crime and I write for a living.
Which brings up another emerging change to the threat landscape: AI is democratizing access to tactics, techniques, and procedures once limited to skilled threat actors.
“You can now host your own dark flavor of an LLM or use maybe one of the Chinese models that don’t have the same safety guardrails,” notes Ben Bernstein (pictured), manager of the Cybersecurity Advisors team at Huntress. “So someone who hasn’t had deep experience in being a super hacker or being really good at their tradecraft is now able to be way more successful through the power of AI.”
In a manner of speaking, then, AI is empowering humans to commit cybercrime by removing them from the cybercrime loop. And in doing so, it’s giving humans in the defensive security loop one more demanding yet critical responsibility to shoulder: monitoring and controlling the often inscrutable actions of their agent swarms.
That’s a responsibility OpenAI failed to fulfill. One of the more mystifying aspects of the Hugging Face story, from where I sit, is that the LLM OpenAI was testing executed over 17,000 autonomous actions days before anyone at OpenAI realized their software was up to no good. Tony Anscombe, chief security evangelist at ESET, finds that a little mystifying too.
“Agents create logs. They use message boards to talk to each other. Who’s monitoring the message boards? Who’s looking at the logs?” he asks. Frontier lab operators have a responsibility to “do things more slowly, more thoughtfully, and in a structured way,” he adds, and with much, much more oversight.
Andy Syrewicze, principal security advocate for MSPs at Proofpoint, agrees. “You have these AI tools being put in place a lot faster and more rapidly than maybe they should be, and then the governance and the security often comes after the fact, usually after damage has been done already,” he says. “We seem to be in one of those phases right now where it’s let’s innovate, and then we’ll secure later.”
Storm watch
Mythos-grade models may not be inventing whole new schools of hackery, but they sure are good at exposing long-hidden vulnerabilities.
Anyone responsible for managing Microsoft environments is painfully aware of it too. This month’s Patch Tuesday included a mere 421 CVEs, which I guess you’d have to call an improvement over the prior month’s record 622.
Kizziah and his analysts are feeling the strain. “We’re getting into a situation where we don’t have enough people to keep up with the vulnerabilities to be able to write the research on it,” he says.
Same goes for NIST, which recently reduced the number of CVEs it will add context to going forward following a 263% increase in submissions and which even more recently requested suggestions for modernizing the badly overburdened National Vulnerability Database.
There’s a lot more of the same coming too, enough to constitute what Jon France (pictured), ISC2’s CISO, calls a “patch storm,” to distinguish it from a mere patch wave.
“We live in an age of rapid vulnerability discovery,” France says. “That causes rapid patching, and then for security practitioners and for IT infrastructure folks, that means the application of said patches.” Which is followed, inevitably, by post-patch cleanup.
“Some patches are going to break stuff,” France says. “That’s an absolute given.”
One would like to think AI itself could help automate the problem away. Recent evidence from 1Password, however, suggests otherwise, for now at least. Which means the imperfect strategy security teams have long used to deal with patching remains the most effective if even more imperfect one today.
“The vulnerability management problem has always been one of prioritization,” Griffin says. “That doesn’t necessarily change.” There’s just a lot more volume and velocity to deal with.
But maybe not forever, at least as far as the volume part is concerned. The thing about storms, including patch storms, is that they blow in, shake a lot of things up, and then blow out. France expects this one to last 18 to 24 months while we hunt down years’ worth of undetected gaps.
“We’ve all heard of tech debt,” he says. “We’re actually paying down vulnerability debt now.”
And when we’re done, ESET’s Anscombe presumes, vuln counts will return to more manageable levels. Or that’s what should happen, anyway.
“I’ve got no data,” he says. “That’s just logic.”
Want a hype-free take on agentic AI?
Tune in to the latest episode of MSP Chat, the podcast I co-host, which features a frank, specific, experience-driven conversation with Hexi Xiao of Bumblebee about when to use agents and, just as importantly, when not to.
It was recorded during GTIA’s recent ChannelCon event, by the way, and you’ll find another episode from the show featuring interviews with top execs about GTIA’s regulation and standards initiatives right here.
More AI in security means more platform in security
Further common sense: MSPs inundated with novel threats and new vulnerabilities will eagerly embrace anything that makes dealing with them easier. Which, in turn, implies even more momentum up ahead for security platforms.
“Consolidation is the key,” says Doni Brass (pictured), SVP of product strategy and community at Guardz. “I think everyone has tool fatigue and workflow overload and alert fatigue, and there’s just so many things coming from so many different places. Any kind of simplification of that is a success.”
Consolidation of the old kind won’t get the job done, though. Thanks largely to the AI-era threatscape, per a recent story here, businesses and their IT partners increasingly want platforms that fuse security functions, with each other and a unified data layer, rather than loosely integrate them behind a single pane of glass.
Make that so-called single pane of glass, adds Carlson Choi, COO of BCDR vendor Slide. “In the industry in general, single pane of glass merely means single sign-on,” he says. “You take all these different products and strap them together with a single sign-on and duct tape and expect to deliver value.” The better approach is a single product in which everything works together seamlessly.
Or close to seamlessly. No one in security really expects people to buy everything from one supplier.
“We have over 500 third-party integrations, and we’re going to keep on leaning into integrations,” says Chris Bell, Sophos’s SVP & GM of global partner ecosystem and corporate development.
So is Guardz, according to Brass, via APIs and an MCP server the vendor’s currently building. “We’re also developing new log ingestion capabilities to bring more data from third-party sources,” he adds. The goal is to create something bigger than a unified platform.
“Everyone will have a unified platform in the future, built with MCPs and some kind of centralized management,” Brass says. “That’s not going to be a differentiator.” Context—about an MSP’s operating procedures, employees, customers, and more—will.
“Being able to understand all of that and pull that into that identity-centric decision making, that’s the power I think Guardz will have,” Brass says.
Put differently, the platform of the future Guardz is constructing, along with Sophos and others, is a system of record like the one Lexful is attempting to build, except for security. “We’re thinking about ourselves as a center rather than a contributor,” Brass says.
Which feels like a strategic, commoditization-resistant place for vendors inside or outside security to be these days.
Over on The Business of Tech
Speaking of Lexful, if you enjoyed my thoughts on that company’s SaaSpocalypse insurance strategy last week, you’ll also enjoy hearing Lexful CEO Pinar Ormeci discuss that same strategy herself with host Dave Sobel in a recent Business of Tech episode.
The biggest key to open source AI safety is also the biggest gap in security
New data from Ramp’s Ara Kharazian offers concrete evidence of something much discussed in the media lately: Open source AI models, like the one NVIDIA just released, really are making headway with corporate AI buyers. 6.1% of them were using one as of July, up from 5.9% in June and 4.5% in January.
Modest numbers to be sure, but rising, which is not true of OpenAI and Anthropic, Kharazian says:
“That’s not because new AI spenders are switching to open source / Chinese models (they most definitely are not doing that — first-time buyers on AI are still using the American model companies). But it means more of their growth will have to come from existing businesses spending on AI, particularly the advanced spenders, and those businesses are increasingly spending on open source.”
Cost is an important reason why, the post continues, noting that Anthropic’s performant but pricey Fable 5 model accounted for only 6% of tokens purchased from Anthropic last month. But ISC2’s France, perhaps with Fable 5 in mind, suggests that a second issue he calls the “AI kill switch” might have been a contributing factor too.
“If you’re relying on one of the big vendors for their hosted model, they can turn it off,” he observes. “They can be instructed to turn it off as well, and that may be a big problem for your business.”
Installing an open source model locally is an effective way to mitigate that risk, but it poses risks of its own if you don’t know where that model came from and whether or not it’s safe. No one would start uploading IP to a conventional business application without vetting it first, France notes.
“You should do the same for models and look at their lineage,” he says.
Sounds easy enough, but there’s a caveat. “Skilling to do that might be a bit of a challenge,” France says. Meaning that just as cyber skills generally are in short supply, so too are the skills required to confirm the safety of the same open source AI models rapidly gaining popularity in IT environments.
Security partners want one program for many personas
I recently shared some theories as to why partner satisfaction with vendors has been slipping recently, and especially in the last year. One was that companies juggling 2.8 business models like MSP, reseller, and developer on average, according to IDC, dislike partner programs tuned to just one of those identities. Another was that partners notice when vendors replace human relationships with AI ones, and resent it.
Two recent conversations with channel chiefs at major security vendors have added some nuance to the picture.
Yes, says Michelle Hodges, SVP of global channels and alliances at Barracuda, most partners make money multiple ways these days, and Barracuda’s Partner Success Program recognizes it. “We don’t say this is a reseller and this is an MSP,” she notes. “We view them as a single entity.”
But not without variation. Partners want different things from vendors when they’re wearing their MSP hat than when they’re wearing their reseller hat, just as their salespeople need different things from those vendors than their technicians do. The partner program Barracuda modernized in March and updated last month reflects that fact by embedding resources for multiple user “personas.”
So does the program Sophos introduced last summer to support its 25,000 hugely varied global partners. “The way you enable an MSP looks very different than the way you enable a reseller, and the way you enable a very large partner like a CDW looks very different than the way you enable a smaller partner,” Bell (pictured) says, “so we do much more persona segmentation than we used to.”
Barracuda emphasizes differentiation not just in how it interacts with partners, moreover, but in how it markets them to end users as well. The newest iteration of its certification program features a deeper set of technical and sales badges that will help members distinguish themselves from similar peers and inform how a forthcoming partner locator tool farms out sales leads.
“That partner locator can really help customers and salespeople find the right partner for the right task in the right location, right vertical, etc.,” Hodges says.
Bell, meanwhile, pushes back a little on the idea that partners want more contact from a vendor’s people and less from their agents.
“Actually, what we hear is, ‘I want to hear less from you. I want more self-service tools. I want to be able to leverage AI to do more things on my own,’” he says. “We’re trying to put more control in our partners’ hands because that’s what they’re telling us.”
So is Barracuda, which plans to extend Bailey, the omnipresent AI assistant on the company’s website, to its partner portal as well. The results, according to Hodges, will be faster answers to basic questions and more time for the deeper business conversations that she, Bell, and the experts I consulted for my recent vendor sat story all say partners want more of.
“We get a chance to talk to 5,500 MSPs,” Hodges notes. “What do we know? What are we learning? Where do we see growth opportunities?” That kind of thought leadership and innovation advice more than anything else, she contends, is the remedy to vendor and partner program satisfaction issues.
Sophos and OpenAI double down
News worth exploring breaks shortly before my vendor interviews all the time. It’s rare for news to break during an interview, however.
And yet that’s very close to what happened during my Black Hat conversation with Bell, which took place roughly an hour after Sophos revealed a newly inked alliance pact with OpenAI designed to … Well, neither Bell nor Sophos, in its press release about the deal, went too deep into specifics except to suggest that the new agreement adds a dedicated focus on MSPs to a relationship initiated when Sophos joined the OpenAI Daybreak Cyber partner program two months ago. How that focus expresses itself in the marketplace is TBD.
“Is it a bundle that we meet in the channel with? Is it areas where we can embed [their large language models] into our products or areas where we can embed our products into their large language models?” Bell asks. “We’re still early in that infancy, but in our conversations we recognize that we’re both trying to solve the same use cases and outcomes for our end customers.”
The upshot of that recognition appears headed to include (my words, not Bell’s) some combination of deeper integration of OpenAI models within Sophos products, stronger protection of those models via Sophos’s recently introduced AI Defense solution, and joint go-to-market efforts aimed at helping both companies grow enterprise market share, something Sophos has been keen to do since its acquisition of Secureworks and OpenAI has been pushing hard on this year.
“You are going to hear a lot more,” Bell says.
Also worth noting
Just two months after I told you that a16z-backed Treeline is in the market for MSPs, it’s acquired one, Los Angeles-based SugarShot.
Shield Technology Partners parent Thrive Holdings has raised more than $2 billion of additional capital at a $12 billion valuation, bringing its total funds raised above $3 billion.
Multi-tenant agent management is now available in the Microsoft 365 admin center.
Just in time for the patch storm, CrowdStrike has expanded its Project QuiltWorks vulnerability discovery, prioritization, and remediation initiative to SMBs.
SonicWall has launched SonicWall Endpoint Security, an endpoint protection offering for SMBs available either as a standalone product or as a fully managed MDR service.
Blumira has launched Hearth, a vendor-agnostic AI command center that reasons across an organization’s existing security stack, logs, and external attack surface.
ConnectSecure has added Microsoft 365 auto remediation and AI-powered training assessments to its platform.
Nutanix has joined the MCP club. The hybrid cloud leader now has an open source MCP server for its Nutanix Cloud Platform.
Auvik has promoted Daniel Ochoa from head of global sales to CRO.
Channelscaler has launched Scaler Index, a benchmarking initiative designed to let partner leaders compare program performance and maturity.









