Home About Black Hat Contact Essays Fireside Chats My Take News Alerts Q&A Reels RSAC Videocasts
 

Podcasts

 

BLACK HAT FIRESIDE CHAT: How linking SOC alerts cuts noise, reveals attacks taking shape

By Byron V. Acohido

The modern SOC is getting better at closing alerts. It is still bad at remembering them.

Alerts are multiplying. Innovation has been focused on machines that can triage, correlate, and recommend a response at a much elevated scale. The queue indeed is moving faster than ever. Alert in, verdict out, case closed.

Attackers do not work case by case. A scan on Tuesday, an exploit attempt on Thursday and an unfamiliar login the following week may, in fact, be pieces of the same campaign. But once the SOC closes a case, what it learned does not carry forward to the next investigation.

That gap is becoming more consequential as attackers blend into legitimate activity. CrowdStrike found that 82 percent of detections in 2025 were malware-free, with adversaries relying on valid credentials, trusted identity flows and approved SaaS integrations. In that environment, history is not background. It is evidence.

What is absent is not more detection or faster triage. It is a way to keep an investigation alive—to carry its subjects, evidence and reasoning forward so that what arrives tomorrow can change what yesterday meant.

That is the argument Command Zero brought to Black Hat USA 2026. I sat down in Las Vegas with CEO Dov Yoran and CTO Dean De Beer to talk about Throughline, the capability the Austin company launched at the show. For a full drill-down, please give the accompanying podcast a listen. Here is what I took away from it.

Five alerts, one attack

It starts routinely enough. Five phishing emails arrive at one company over five days. Each targets a different employee. Each is tailored to the department where it lands.

Handled one at a time, each message opens its own investigation. No single case carries enough evidence to change the verdict, so the analyst closes it and moves on.

The SOC does its job five times and still misses what happened once.

Read together, … more

BLACK HAT FIRESIDE CHAT: Websites now leak sensitive data by design – AI is making it worse

By Byron V. Acohido

Public-facing web pages aren’t built in-house anymore. They’re composed from components supplied by outsiders, and the advertising platforms have had their run of them. The exposure is enormous, and AI is accelerating it all.

Related: No easy fixes for AI risk

The bill for all of it is arriving now. Since 2023, hospitals and health systems have paid more than $100 million to settle claims that tracking pixels on their websites leaked patient data to advertising platforms. A court approved $21.5 million against Sutter Health in February. Inova settled for $3.1 million in April. Atrium settled for $1.8 million this month. In each of these cases the pixels came from Meta or Google, and the health system paid the settlement.

Those numbers have teeth. On July 14 a federal judge refused to dismiss claims against Google and Meta over prescription data collected by pixels on a telehealth site, rejecting the argument that users had consented, and pushing both companies into discovery.

Fireside Chat: PKI has carried digital trust through every tech advance—now comes the hardest one

By Byron V. Acohido

Public key infrastructure — the authentication and encryption framework that has held digital commerce together through every chaotic leap forward in technology — is facing a double whammy.

Related: Achieveing AI security won’t be easy

Autonomous AI agents are flooding enterprise networks, most without verified identities or any meaningful governance. What’s more, quantum computers are just around the corner — and when they arrive, current encryption becomes obsolete overnight.

I sat down with DigiCert CEO Amit Sinha at RSAC 2026 to discuss this. The identity management and encryption communities are not sitting on their hands. Here is what I learned that you should know.

PKI has been the quiet backbone of digital trust for 30 years. E-commerce needed it to authenticate strangers. The cloud and IoT needed it to manage machine identities at scale.

FIRESIDE CHAT: Geopolitical turmoil, rising AI risk add a new layer to enterprise cyber defense

By Byron V. Acohido

As if securing the enterprise against a tidal wave of AI tools wasn’t hard enough, it turns out the geopolitical instability of the moment is making things worse.

That wasn’t the headline at RSAC 2026 last week — agentic AI dominated the agenda — but the stress was visible at the ground level if you knew where to look.

Sanjay Castelino, president of Skyhigh Security, knew where to look. While the Trump White House was pulling federal agencies off the conference floor — fracturing the public-private threat intelligence pipeline RSAC had sustained for three decades — Castelino was tracking a pressure building from the other direction.

He had spent time in Europe roughly a month earlier, meeting with customers across the EU and UK. The message was uniform and pointed: enterprises there were reassessing whether US-controlled cloud infrastructure could be trusted as the foundation of their defenses.

The concern wasn’t technical. It was political — an erosion of confidence in US oversight that had accelerated sharply in recent months. What they wanted was the guaranteed ability to control their own defensive perimeter, on-premises or inside sovereign cloud environments their own governments could reach.

The federal boycott playing out a few hundred yards away at Moscone was, if anything, a live demonstration of exactly what they were worried about. Over the prior three to nine months, Castelino said, that conversation had moved well beyond regulated industries into mainstream enterprise.

That pressure is arriving simultaneously with the challenge that did own the conference: the explosion of unsanctioned AI tools inside enterprise environments. Castelino puts the number at 320 AI cloud applications per enterprise on average, most outside existing data protection policy.

The exposure is concrete — employees are copying patient records, financial data and proprietary product plans into AI prompts, with no visibility into what the tool does with that content afterward.

What’s striking is how fast enterprises are moving from paralysis … more

BLACK HAT FIRESIDE CHAT: Inside the ‘Mind of a Hacker’ — A10’s plan for unified threat detection

By Byron V. Acohido

In today’s threat landscape, attackers are no longer just exploiting technical flaws — they’re exploiting business logic.

Think gaps in workflows, permissions, and overlooked assumptions in how applications behave. This subtle shift is creating powerful new footholds for cybercriminals and evading traditional defenses.

A10 Networks’ Field CISO Jamison Utter calls this the new front in cybersecurity: stopping attackers who use your own processes against you.

I sat down with Utter to unpack how forward-looking companies are moving beyond static perimeter defenses to more adaptive, behavioral systems. A10’s strategy centers on deploying AI-enhanced observability and automation to detect—and respond to—subtle indicators of attack. This includes analyzing normal vs. anomalous behavior in encrypted web traffic, API interactions, and even traffic flow between legacy systems.

Fireside Chat: Enterprise browsers arise to align security with the modern flow of work

By Byron V. Acohido

A quiet but consequential shift is underway in enterprise workspace security. The browser has effectively become the new operating system of business.

Related: Gartner’s enterprise browser review

It didn’t happen all at once. But as SaaS took over, remote work went mainstream, and generative AI entered the picture, the browser quietly assumed a central role.

Today, it’s where employees access cloud data, navigate core workflows, and — increasingly — interact with powerful AI agents. Traditional file systems are fading. The endpoint is scattered. And the network perimeter, once the centerpiece of security strategy, has become an afterthought.

The security implications are significant. Endpoint tools can’t see what’s happening inside encrypted browser sessions. Identity platforms validate who you are — but they don’t follow what you do next. And network defenses often miss the fact that sensitive data is now exchanged entirely outside the corporate WAN.

At RSAC 2025, I spoke with Amir Ben-Efraim, CEO of , about this shift and how it’s forcing a rethink of control strategies. Menlo’s view is clear: if the browser is now the front door to everything, it needs to be treated as a first-class security layer.

Fireside Chat: Shift left, think forward — why MDR is emerging as cyber’s silver bullet

By Byron V. Acohido

With RSAC kicking off next week, the conversation is shifting—literally. Cybersecurity pros are rethinking how “shift left” applies not just to code, but to enterprise risk.

Related: Making sense of threat detection

In this Fireside Chat, I spoke with John DiLullo, CEO of Deepwatch, who makes a compelling case for how Managed Detection and Response (MDR) is filling that role.

DiLullo frames MDR as a three-part continuum. First, there’s proactive risk reduction—identifying configuration gaps, dormant tools, and soft spots in your stack before they’re exploited. Second is real-time detection and mitigation when something slips through. And third, when it hits the fan—full-scale incident response, already trained and ready.

This layered approach has broad appeal. DiLullo notes that roughly 25% of companies currently use MDR, and that number is expected to climb to 75–90% by 2030. Why? Because MDR delivers something rare: sharper visibility, reduced staffing strain, and—in his view—“instant ROI.”