LIVE · cybersecurity feed
Live wire
Acronis warns of actively exploited flaw in its cPanel backup pluginOracle September 2026 Critical Security Patch Update addresses 672 CVEsCVE-2026-76461 · U.S. CISA adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalogHackers target WordPress sites via third-party WooCommerce pluginCVE-2026-51990 · Hackers exploit Tencent app flaw to deploy GrayRabbit malwareCVE-2026-42016 · CISA Adds 5 Exploited Flaws in Artifactory, ScreenConnect, RouterOS to KEVCVE-2026-85102 · Dutch NCSC: Critical Check Point VPN flaws exploitation is imminentAI Enables Mass Generation of Personalized Fraud EmailsCVE-2026-85706 · Critical GitLab Vulnerability Exploited in Internet-Wide ProbesCVE-2025-66516 · Metasploit Wrap Up: This One Goes to Sixteen!
cloud

Black Hat USA 2026: Building the Agentic SOC, One Live Event at a Time

Cisco is the Security Cloud Provider for the Black Hat conferences. Learn about the latest innovations for the Agentic SOC.

zeroday.news ·

Cisco served as the Official Security Cloud Provider and a long-standing partner for the Black Hat USA 2026 Network Operations Center (NOC) and Security Operations Center (SOC), marking its eleventh year in this role. The company collaborated with other official technology partners, including Palo Alto Networks, Arista, Corelight, Jamf, and Lumen, to ensure the conference network's safe and reliable operation.

The Black Hat environment is distinct, encompassing training sessions, briefings, and a wide array of devices from security researchers, vendors, and attendees. This unique setting makes the Black Hat NOC/SOC a critical testing ground for security operations, where typical corporate network alarms might be expected activity in a training room, while genuine threats can still emerge from the same telemetry.

For Black Hat USA 2026, the Cisco and Splunk team focused on live NOC/SOC visibility, Splunk Enterprise Security (ES) detection engineering, threat hunting, malware and artifact analysis, AI protection, and the advancement of Agentic SOC development. These efforts are intended to carry forward into future events, including Cisco GSX and Splunk .conf26.

Cisco's primary responsibility was to ensure its critical infrastructure systems were operational and integrated with the broader partner environment. Once this foundation was stable, the team shifted focus to hunting, detection engineering, and innovation. The NOC leadership permitted Cisco and other partners to introduce additional pre-approved software and hardware solutions to enhance efficiency and expand visibility. However, Cisco was not the official provider for Extended Detection & Response, Security Event and Incident Management, Firewall, Network Detection & Response, or Collaboration.

The Cisco and Splunk team integrated telemetry and workflows from Cisco Security, Splunk Security, and partner-provided network and security controls. Splunk ingested logs from various sources, including DHCP and DNS from Cisco Secure Access, Jamf, Splunk Attack Analyzer, Cisco Secure Malware Analytics, Arista network data, Corelight, Palo Alto Networks firewall data, Cisco Secure Firewall, Cisco Secure Network Analytics, ThousandEyes, and Duo. Findings were investigated within Splunk Security, utilizing threat intelligence from Cisco Talos and licenses donated by alphaMountain, Pulsedive, and StealthMole, alongside community sources.

This broad telemetry was crucial due to the diverse nature of the Black Hat environment, which includes high-noise training networks, public attendee networks, registration and event infrastructure, sponsor systems, cloud dependencies, and critical operational services. The value of the NOC/SOC stemmed from its ability to quickly consolidate these signals to understand events and determine necessary actions.

A significant focus for the team at Black Hat USA 2026 was the practical application of Splunk Enterprise Security. Splunk Cloud and Splunk ES provided a searchable evidence layer across disparate telemetry sources, and Splunk ES served as a platform to build, tune, test, and operationalize detections based on real event data. The team developed and refined detections drawing from over 100 Black Hat training courses and live NOC/SOC observations. These detections will be applied to protect future events like Cisco GSX and will contribute to the first Agentic SOC at Splunk .conf26, demonstrating the reusability of content developed in this event SOC model.

Black Hat USA 2026 also functioned as a development environment for the Agentic SOC. Building on an operating model introduced at Cisco Live Americas 2026, which uses agentic workflows to reduce repetitive triage, the Black Hat environment provided a different testing ground. The team prepared Cloud Control AI Studio and Agent Builder for testing, along with AI-assisted investigation workflows designed to support summarization, triage, evidence gathering, and handoff. The objective is to enhance human security operations by providing faster context, improved starting points, stronger documentation, and more time for threat hunting and deeper analysis, rather than replacing human analysts.

The Black Hat NOC/SOC was particularly important for testing this model due to its noisy, temporary, and highly collaborative nature, requiring signals to be understood by multiple teams including Cisco, Splunk, Black Hat leadership, and other partners. Agentic workflows are effective only if they preserve evidence, respect operational boundaries, and support human decision-makers.

Attendees in the Business Hall could view live dashboards from the Black Hat NOC/SOC at the NOC Outpost. These dashboards displayed the operational status of the event network, illustrating how telemetry translates into situational awareness. Staff from the NOC/SOC were available to explain the data and provide practical security operations lessons, making the work of the NOC/SOC visible and useful to the broader Black Hat community.

Black Hat is a unique environment where competitors collaborate for a shared mission: ensuring network functionality, event protection, and rapid investigation of unusual occurrences. Cisco and Splunk worked alongside other official network and security providers, each contributing a distinct perspective. The value derived from operationalizing these perspectives quickly and using them collectively under real-world conditions. This collaborative environment also fosters innovation, as integrations, dashboards, escalation paths, and detection logic are tested against actual traffic, constraints, and partner workflows.

cloud
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

The vulnpocalypse rains iBugs down on Apple with record-setting number of patches

September Patch Tuesday part 2?

vulnerabilityhigh

Acronis warns of actively exploited flaw in its cPanel backup plugin

Acronis disclosed a high-severity Linux local privilege escalation vulnerability in its backup plugin for cPanel, WebHost Manager (WHM), and Plesk that may be exploited in the wild. [...]

vulnerabilitycritical

Oracle September 2026 Critical Security Patch Update addresses 672 CVEs

Oracle addresses 672 CVEs in its September 2026 Critical Security Patch Update with 673 patches, including 104 critical updates. Key Takeaways The September 2026 Critical Security Patch Update (CSPU) contains fixes for 672 unique CVEs in 673 security updates 104 issues (15.5% of all patches) were assigned a critical severity rating Oracle E-Business Suite received the highest number of patches at

CVE-2026-76461critical

U.S. CISA adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Cisco Secure Email Gateway flaw, tracked as CVE-2026-76461 (CVSS score of 9,8), to its Known Exploited Vulnerabilities (KEV) catalog. Cisco disclosed a critical zero-day CVE-2026-76

patch

Malcious Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites

Malicious versions of the Admin Menu Editor Pro plugin for WordPress have been distributed to more than 200 customers after a threat actor compromised the maintainer's website and pushed updates that created a hidden user account. [...]

ai

Microsoft Commits to Sweeping AI Privacy Rules for Students. Will Other Tech Giants Follow?

Microsoft agreed to adopt guardrails and privacy standards for its AI in schools, as negotiated with the American Federation of Teachers. The post Microsoft Commits to Sweeping AI Privacy Rules for Students. Will Other Tech Giants Follow? appeared first on SecurityWeek.