Preview: Cisco Talos at Black Hat USA 2026
We’re looking forward to having some great conversations with those of you heading to the desert for Hacker Summer Camp 2026. We have a presence within the Cisco and Splunk booth (2633) during Black Hat where you can chat to us about our latest threat research, incident response, and how Talos powers the Cisco portfolio with our intelligence. Or, feel free to pretend to want to talk to us about those things while grabbing a new multicolored Snorty. That’s fine, too. Here’s some of the ways we’ll be showing up at Black Hat, alongside our friends at Cisco and Splunk: Meet the researchers: Booth lightning talks Our Talosians have spent a lot of time over the last few months putting together some truly... well, enlightening lightning talks. Throughout Wednesday and Thursday at Black Hat, you can expect to see such topics as: Threat actor prompting and the emerging ways adversaries are using prompts, agents, skills, and tools to improve efficiency Warlock ransomware, and why this group does not fit neatly into a simple RaaS or state-linked label. Zero trust for agent identity Building a "second brain" for your second brain Predicting cybersecurity fraud Vulnerability discovery trends ... and much more Lightning talks are 15 minutes. That’s less than 9% of The Odyssey. Don’t worry, we cut the bit where everyone gets turned into Snorty pigs. Talos workshop: When AI finds vulnerabilities faster than humans can patch Date/Time: Wednesday, August 5 | 1:30 p.m. – 3:00 p.m. (Oceanside E, Level 2) If you're looking for something hands-on and interactive, don't miss our workshop with Talos’ Nick Biasini and Cisco’s Omar Santos . In two parts, they’ll demonstrate practical ways security teams can incorporate AI into SOC workflows to identify sophisticated adversary behavior. In Part 1, Omar will discuss the Foundry Security Spec. He’ll walk through how to deploy, build testing harnesses around its core agent roles, and integrate Project CodeGuard so that findings from autonomous testing can be converted into reusable secure-coding rules and future prevention. In Part 2, Nick will demonstrate how Talos leverages AI to transform threat hunting. We will explore best practices for identifying adversarial AI tactics and provide attendees with insights into how Cisco Talos is leveraging AI for defense. Participants will learn how to integrate these defensive AI strategies into their own SOC workflows. Splunk workshop: When agents become insider threats Date/Time: Wednesday, August 5 | 10:15 a.m. – 11:00 a.m. (Mandalay Bay I) The Splunk workshop considers the fact that the next insider threat may not be a person; it may be an autonomous agent using valid credentials and delegated authority. Attendees will see real-world attack paths in which agents move sensitive data across tools, distribute brute-force attempts under a single delegation, and manipulate internal systems without triggering traditional SIEM or UEBA alerts. It was Talos all along One of the questions we hear often is: "How do I buy Talos?" The answer… is that you probably already did. Throughout the Cisco booth you'll see our “ It was Talos all along” campaign, highlighting the fact that Talos isn't a standalone product or a threat intelligence feed you bolt onto your security stack. Talos is already embedded across the Cisco security portfolio, which continually benefits from our threat research and intelligence. To build your curiosity, take a look at our new video, “Where Protection Starts,” to see how Cisco Talos Intelligence Integrations help reduce uncertainty in the SOC: See you in Las Vegas.
AI Analysis
Technical Summary
The provided information is a preview blog post from Cisco Talos about their participation at Black Hat USA 2026. It outlines various sessions including lightning talks, keynotes, and workshops focusing on AI in cybersecurity, threat actor behaviors, ransomware, zero trust, and vulnerability discovery trends. The content is informational and promotional, describing planned events and research topics rather than disclosing any specific vulnerability or security threat.
Potential Impact
No direct security impact or vulnerability is described in the provided content. It does not disclose any exploitable security flaw or threat vector.
Mitigation Recommendations
No mitigation or remediation actions are applicable as no vulnerability or threat is described. This is promotional content about upcoming events and research presentations.
Preview: Cisco Talos at Black Hat USA 2026
Description
We’re looking forward to having some great conversations with those of you heading to the desert for Hacker Summer Camp 2026. We have a presence within the Cisco and Splunk booth (2633) during Black Hat where you can chat to us about our latest threat research, incident response, and how Talos powers the Cisco portfolio with our intelligence. Or, feel free to pretend to want to talk to us about those things while grabbing a new multicolored Snorty. That’s fine, too. Here’s some of the ways we’ll be showing up at Black Hat, alongside our friends at Cisco and Splunk: Meet the researchers: Booth lightning talks Our Talosians have spent a lot of time over the last few months putting together some truly... well, enlightening lightning talks. Throughout Wednesday and Thursday at Black Hat, you can expect to see such topics as: Threat actor prompting and the emerging ways adversaries are using prompts, agents, skills, and tools to improve efficiency Warlock ransomware, and why this group does not fit neatly into a simple RaaS or state-linked label. Zero trust for agent identity Building a "second brain" for your second brain Predicting cybersecurity fraud Vulnerability discovery trends ... and much more Lightning talks are 15 minutes. That’s less than 9% of The Odyssey. Don’t worry, we cut the bit where everyone gets turned into Snorty pigs. Talos workshop: When AI finds vulnerabilities faster than humans can patch Date/Time: Wednesday, August 5 | 1:30 p.m. – 3:00 p.m. (Oceanside E, Level 2) If you're looking for something hands-on and interactive, don't miss our workshop with Talos’ Nick Biasini and Cisco’s Omar Santos . In two parts, they’ll demonstrate practical ways security teams can incorporate AI into SOC workflows to identify sophisticated adversary behavior. In Part 1, Omar will discuss the Foundry Security Spec. He’ll walk through how to deploy, build testing harnesses around its core agent roles, and integrate Project CodeGuard so that findings from autonomous testing can be converted into reusable secure-coding rules and future prevention. In Part 2, Nick will demonstrate how Talos leverages AI to transform threat hunting. We will explore best practices for identifying adversarial AI tactics and provide attendees with insights into how Cisco Talos is leveraging AI for defense. Participants will learn how to integrate these defensive AI strategies into their own SOC workflows. Splunk workshop: When agents become insider threats Date/Time: Wednesday, August 5 | 10:15 a.m. – 11:00 a.m. (Mandalay Bay I) The Splunk workshop considers the fact that the next insider threat may not be a person; it may be an autonomous agent using valid credentials and delegated authority. Attendees will see real-world attack paths in which agents move sensitive data across tools, distribute brute-force attempts under a single delegation, and manipulate internal systems without triggering traditional SIEM or UEBA alerts. It was Talos all along One of the questions we hear often is: "How do I buy Talos?" The answer… is that you probably already did. Throughout the Cisco booth you'll see our “ It was Talos all along” campaign, highlighting the fact that Talos isn't a standalone product or a threat intelligence feed you bolt onto your security stack. Talos is already embedded across the Cisco security portfolio, which continually benefits from our threat research and intelligence. To build your curiosity, take a look at our new video, “Where Protection Starts,” to see how Cisco Talos Intelligence Integrations help reduce uncertainty in the SOC: See you in Las Vegas.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The provided information is a preview blog post from Cisco Talos about their participation at Black Hat USA 2026. It outlines various sessions including lightning talks, keynotes, and workshops focusing on AI in cybersecurity, threat actor behaviors, ransomware, zero trust, and vulnerability discovery trends. The content is informational and promotional, describing planned events and research topics rather than disclosing any specific vulnerability or security threat.
Potential Impact
No direct security impact or vulnerability is described in the provided content. It does not disclose any exploitable security flaw or threat vector.
Defensive Guidance
No mitigation or remediation actions are applicable as no vulnerability or threat is described. This is promotional content about upcoming events and research presentations.
Technical Details
- Article Source
- {"url":"https://blog.talosintelligence.com/preview-cisco-talos-at-black-hat-usa-2026/","fetched":true,"fetchedAt":"2026-07-23T10:02:47.378Z","wordCount":664}
- Classification
- {"confidence":0.63,"severitySource":"heuristic","classifier":"rss-v2"}
Threat ID: 6a61e6c79c2644c7f8d7caf8
Added to database: 07/23/2026, 10:02:47 UTC
Last enriched: 07/23/2026, 10:02:56 UTC
Last updated: 09/06/2026, 05:47:19 UTC
Views: 147
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.