AI News HubLIVE
站内改写5 分钟阅读

待翻译:Three insights you may have missed from theCUBE’s coverage of Black Hat USA

AI 服务暂时不可用,以下为来源摘要,待恢复后补全翻译:Cyber resilience is becoming a business imperative as AI accelerates attacks, expands the enterprise attack surface and gives autonomous systems greater access to sensitive data and critical operations. Preventing every disruption is no longer a realistic measure of security success, even for mature organizations. As attack windows contract, enterprises must also understand which operations are […] The post Three insights you may have missed from theCUBE’s coverage of Black Hat USA appeared first on SiliconANGLE.

来源SiliconANGLE AI作者: Victoria Gayton

AI 服务暂时不可用,以下为来源正文,待恢复后补全翻译。

Cyber resilience is becoming a business imperative as AI accelerates attacks, expands the enterprise attack surface and gives autonomous systems greater access to sensitive data and critical operations. Preventing every disruption is no longer a realistic measure of security success, even for mature organizations. As attack windows contract, enterprises must also understand which operations are essential and whether they can restore them quickly to a trusted state, according to Krista Case, principal analyst and practice lead for cyber resilience and security at theCUBE Research. “It is, practically speaking, inevitable … that any even mature security organization might experience some disruption at some point in time,” Case said. “The conversation is becoming, ‘Do we understand what our minimal viable operations look like? Do we have confidence that we’re able to recover them quickly and confidently to that trusted state?’” During Black Hat USA, Case spoke with cybersecurity executives, technology leaders and fellow analysts about how AI is changing attack economics, software construction, security operations and enterprise governance. Their discussions showed cyber resilience expanding beyond breach prevention and recovery to encompass trusted data, shared operational context and controls for autonomous agents. (* Disclosure below.) Here’s theCUBE’s complete video analysis with Krista Case: Here are three insights you may have missed from theCUBE’s coverage of this year’s Black Hat USA: Insight #1: Cyber resilience demands context and dynamic control. AI is widening the gap between the speed of attacks and the ability of human-led security operations to respond, according to Jon Oltsik, analyst in residence at theCUBE Research. The Mandiant “M-Trends 2026” report found that the median interval between an initial access event and the handoff to a secondary threat group had fallen from more than eight hours in 2022 to just 22 seconds in 2025. As that response window contracts beyond what human-only security operations can match, contextual intelligence becomes increasingly important to closing the AI security skills gap, according to Case. “These frontier AI models … are really accelerating the speed and the scale that attackers can move at, which is compressing the window for response for our defenders,” Case said during the event. “One of the big things that defenders need … is context.” That compressed response window is colliding with the emergence of autonomous agents that can access sensitive systems and improvise their way toward assigned goals. Static entitlements are insufficient when agent identities and behaviors are dynamic, making visibility the necessary first step toward agentic AI oversight. “If you ask an agent to do a task, it’s going to do whatever it needs to do or whatever it can do to accomplish that task,” Oltsik said. “Some of that may be rogue behavior. That’s where I think identity — non-human identities, agentic identities — [is] the challenge. And it’s not static; it’s very dynamic.” Here’s theCUBE’s complete video analysis with Krista Case and Jon Oltsik: Insight #2: AI-driven threats broaden cyber defense across development, operations and enforcement. As AI lowers the cost of finding and exploiting vulnerabilities, defenders can no longer depend on faster patching to keep pace. David Weston, corporate vice president of AI security at Microsoft Corp., pointed to safer software construction through memory-safe languages and formal verification. “In Microsoft’s case … we were able to get a massive production increase by using agents to do this,” Weston said during the event. “We found one that would have been pretty catastrophic had we shipped it, and it passed all the tests … all the analysis of human experts. Apple [Inc.] had a similar case.” Once software reaches production, cyber resilience depends on breaking down the data barriers between security and engineering. Shared telemetry lets teams examine the same activity through different lenses, identify common root causes and prioritize vulnerabilities based on runtime exposure and business importance rather than severity scores alone, according to Emilio Escobar, chief information security officer at Datadog Inc. “At Datadog … it has to be a unified context for both teams,” Escobar said. “If both people, both teams can see the same data, but from a different lens … they can solve the problems faster.” Strengthening cyber resilience also requires looking beyond enterprise systems to the criminal networks behind attacks. Fortinet Inc.’s cybercrime bounty program focuses on closing the accountability gap and slowing the growth of the cybercrime industry by helping law enforcement identify and hold attackers accountable. The program extends Crime Stoppers International’s anonymous reporting model to cyber threats for the first time. Fortinet then validates, analyzes and packages that intelligence for law enforcement, according to Derek Manky, chief security strategist and global vice president of threat intelligence at FortiGuard Labs. “The idea on the gaps that we’re trying to solve is to really focus on the human intelligence,” Manky said. “That’s why we launched the cybercrime bounty program with Crimestoppers International: to do the attribution, which is the toughest thing to do in the world of threat intelligence.” Here’s theCUBE’s complete video interview with Derek Manky: Insight #3: Production AI makes cyber resilience a governance challenge. Enterprise AI projects often stall when organizations attempt to scale models without first bringing visibility, protection and policy enforcement to the underlying data. Moving beyond pilots therefore requires coordinated data discovery, encryption and governance across hybrid environments, according to Robin Braun (pictured, left), vice president of AI business development and hybrid cloud at Hewlett Packard Enterprise Co., who was joined by Ian Williamson (center), senior vice president of global alliances at BigID Inc., and Patrick Conte (right), chief revenue officer at Fortanix Inc. “When you think about how do you trust to scale out into production, you have to trust what you’re doing, and at the foundation of all AI is data,” Braun said during the event. “Organizations have [software-as-a-service] applications, they have data in the cloud, they have data on-prem, they have data probably on somebody’s laptop that they’re not sure about. Do they know how a model got trained? Do they know that it has the right parameters, right governance, right guardrails?” Asset discovery now extends beyond servers and laptops to identities, applications and networks, as well as agents and the large language models and prompts behind them. Ahead of Black Hat, Axonius Inc. launched two capabilities that extend the company’s asset intelligence into AI-assisted security and information technology operations, according to Dean Sysman, co-founder and executive chairman of Axonius. “Organizations don’t have a lack of understanding or visibility because they are lacking in data,” Sysman said. “It’s actually the opposite. There’s too much data … all of the assets have relationships to each other, and they influence each other.” Autonomous agents can use legitimate permissions in combinations that traditional identity controls were not designed to evaluate. An agent might be authorized to access both Salesforce Inc. and email, for example, while lacking the judgment to recognize that transferring sensitive information between them would be unsafe. Rubrik Inc. unveiled Rubrik Agent Identity to govern access one tool call at a time, but oversight at machine scale can’t depend on humans manually approving every action, according to Dev Rishi, general manager of AI at Rubrik. “The entire bull case on agents is that they’re doing 10 times as much work as a human in the same amount of time,” Rishi said during the event. “If I’m sitting there and I’m hitting approve, approve, approve, we feel like it’s more security theater than anything else.” Here’s theCUBE’s complete video interview with Dev Rishi: To watch more of theCUBE’s coverage of Black Hat USA, here’s our complete video playlist: (* Disclosure: TheCUBE is a paid media partner for Black Hat USA. Sponsors of theCUBE’s event coverage do not have editorial control over content on theCUBE or SiliconANGLE.) Photo: SiliconANGLE A message from John Furrier, co-founder of SiliconANGLE: Support our mission to keep content open and free by engaging with theCUBE community. Join theCUBE’s Alumni Trust Network, where technology leaders connect, share intelligence and create opportunities. 15M+ viewers of theCUBE videos, powering conversations across AI, cloud, cybersecurity and more 11.4k+ theCUBE alumni — Connect with more than 11,400 tech and business leaders shaping the future through a unique trusted-based network Are you an AWS customer? Support SiliconANGLE financially by buying your AWS services from our Marketplace portal page and links: https://siliconangle.com/aws-marketplace/ About SiliconANGLE Media