Home About Black Hat Contact Essays Fireside Chats My Take News Alerts Q&A Reels RSAC Videocasts
 

RSAC

 

FIRESIDE CHAT: Cyber insurers deepen SMB security role as supply chain attacks spread

By Byron V. Acohido

The cyber insurance industry set out to manage financial risk. Along the way, it has quietly became the security operations provider for a significant share of American small businesses. An $11 billion acquisition agreement announced earlier this year suggests it intends to stay in that role.

Related: No easy AI security fixes

I sat down with Tony Anscombe, chief security evangelist at ESET, on the floor at RSAC 2026 to discuss this. Tony has spent years tracking the intersection of cyber insurance and SMB security from inside the insurance ecosystem. Here is what I learned that you should know.

The causality chain is not complicated, but it took about five years to play out. Around 2020, ransomware payouts started overwhelming cyber insurers. Losses mounted. The industry responded the way it always does — by tightening requirements.

FIRESIDE CHAT: Leaked secrets are now the go-to attack vector — and AI is accelerating exposures

By Byron V. Acohido

A consequential shift is underway in how enterprise breaches begin. The leaked credential — once treated as a hygiene problem — has become the primary on-ramp.

Related: No easy fixes for AI risk

Last August’s Salesloft campaign was the pattern in miniature. Stolen OAuth tokens from one chatbot vendor pulled Salesforce data from 760 enterprise instances — Cloudflare, Cisco, Palo Alto Networks, and TransUnion among them, according to Mandiant. Google’s Threat Intelligence Group reported the primary intent: credential harvesting, each stolen key the path into the next victim.

That is the shape of the modern enterprise breach, says Dwayne McDaniel, senior developer advocate at non-human identity security firm GitGuardian, whom I interviewed at RSAC 2026. Each leaked credential, he explained, is a key to a door behind which sit more keys.

Leaks spiking

GitGuardian scans every public GitHub commit — every new batch of developer code published to a shared repository — for hard-coded secrets: credentials typed directly into source code. Its latest report documented 28.6 million such exposures in 2025 alone — a 34 percent year-over-year jump, the largest in five years. Private repositories ran six times worse.

Fireside Chat: PKI has carried digital trust through every tech advance—now comes the hardest one

By Byron V. Acohido

Public key infrastructure — the authentication and encryption framework that has held digital commerce together through every chaotic leap forward in technology — is facing a double whammy.

Related: Achieveing AI security won’t be easy

Autonomous AI agents are flooding enterprise networks, most without verified identities or any meaningful governance. What’s more, quantum computers are just around the corner — and when they arrive, current encryption becomes obsolete overnight.

I sat down with DigiCert CEO Amit Sinha at RSAC 2026 to discuss this. The identity management and encryption communities are not sitting on their hands. Here is what I learned that you should know.

PKI has been the quiet backbone of digital trust for 30 years. E-commerce needed it to authenticate strangers. The cloud and IoT needed it to manage machine identities at scale.

FIRESIDE CHAT: Geopolitical turmoil, rising AI risk add a new layer to enterprise cyber defense

By Byron V. Acohido

As if securing the enterprise against a tidal wave of AI tools wasn’t hard enough, it turns out the geopolitical instability of the moment is making things worse.

That wasn’t the headline at RSAC 2026 last week — agentic AI dominated the agenda — but the stress was visible at the ground level if you knew where to look.

Sanjay Castelino, president of Skyhigh Security, knew where to look. While the Trump White House was pulling federal agencies off the conference floor — fracturing the public-private threat intelligence pipeline RSAC had sustained for three decades — Castelino was tracking a pressure building from the other direction.

He had spent time in Europe roughly a month earlier, meeting with customers across the EU and UK. The message was uniform and pointed: enterprises there were reassessing whether US-controlled cloud infrastructure could be trusted as the foundation of their defenses.

The concern wasn’t technical. It was political — an erosion of confidence in US oversight that had accelerated sharply in recent months. What they wanted was the guaranteed ability to control their own defensive perimeter, on-premises or inside sovereign cloud environments their own governments could reach.

The federal boycott playing out a few hundred yards away at Moscone was, if anything, a live demonstration of exactly what they were worried about. Over the prior three to nine months, Castelino said, that conversation had moved well beyond regulated industries into mainstream enterprise.

That pressure is arriving simultaneously with the challenge that did own the conference: the explosion of unsanctioned AI tools inside enterprise environments. Castelino puts the number at 320 AI cloud applications per enterprise on average, most outside existing data protection policy.

The exposure is concrete — employees are copying patient records, financial data and proprietary product plans into AI prompts, with no visibility into what the tool does with that content afterward.

What’s striking is how fast enterprises are moving from paralysis … more

Fireside Chat: AI agents are reshaping mobile attacks — and exposing weak API trust models

By Byron V. Acohido

SAN FRANCISCO — A new exposure is emerging in mobile security as AI begins to act on behalf of users — and attackers move to exploit that shift.

Related: RSAC wrap-up—no easy fixes for AI exposures

In a Fireside Chat at RSAC 2026, Approov CEO Ted Miracco described how mobile apps are starting to hand control to AI agents that can carry out tasks such as placing orders or accessing services. That upends a core assumption that has held since the rise of smartphones: apps, devices and backend systems were all designed with the expectation that a human is in control, making deliberate, bounded requests through the interface.

When that control shifts to an AI agent, the behavior changes. Actions can be executed faster, repeated continuously, and carried out without the natural limits of human interaction.

At the same time, attackers have quickly recognized how this shift can be manipulated — and are using AI to exploit it.

FIRESIDE CHAT: AI gives rise to a semantic attack surface, forcing a new class of network defense

By Byron V. Acohido

SAN FRANCISCO — Enterprises rushing to deploy AI in their operations are opening a security exposure most of their existing tools were never designed to address. That’s the hard message coming out of RSAC 2026 — and it’s one worth sitting with.

Related: RSAC 2026 recap—no easy AI fixes

Jamison Utter, A10 Networks field CISO, draws a distinction that the industry tends to blur. The problem isn’t that AI has made familiar attacks faster or more powerful — though it has done that too. The deeper issue is that AI deployment creates an entirely new kind of attack surface: one that is semantic and non-deterministic, responsive to language, images, and multimodal input in ways no firewall, WAF, or API security tool was built to govern. “Every other tool we have today — none of them solve the semantic problem,” Utter said, “because that’s not what they were designed to do.”

The good news, he argues, is that the infrastructure layer is largely understood. Cloud security, Kubernetes, API protection, DDoS — enterprises have those tools. The new frontier is what happens when language itself becomes the attack surface.

RSAC 2026: No easy fixes for expanding AI attack surface, but a coordinated response is emerging

By Byron V. Acohido

SAN FRANCISCO — Forty-four thousand cybersecurity practitioners converged on Moscone Center this week with an urgent question: how do you secure a network when everything — the technology, the threats, the tools — is changing faster than anyone can govern it?

Related: Feds pull back on collaboration

Microsoft’s Vasu Jakkal set the scale on day one. She noted that IDC projects 1.3 billion AI agents in operation by 2028 — each one requiring the same governance and protection organizations currently apply to human users. That number puts a concrete frame around both waves: the tools needed to defend AI-native infrastructure, and the tools needed to secure AI systems themselves. Neither problem is theoretical anymore.

The week’s most unexpected signal came not from the vendor floor but from the main stage, where former New Zealand Prime Minister Jacinda Ardern joined new RSAC CEO Jen Easterly for a conversation on leading through crisis.

The message landed differently in this room than it might have elsewhere: the challenge in front of this industry has grown past what any single organization, or any single technology, solves alone. What’s required now is the kind of collective will that Ardern built in the aftermath of Christchurch — clear values, shared purpose, leaders who show up.