"One of the best things about Black Hat is having the ability to listen to the community and have conversations with the cybersecurity professionals that are on the front lines. As conversations progressed, it became clear that adopting Zero Trust principles and sticking to fundamentally sound practices was the best way to keep organizations secure while allowing them to implement and explore advances in AI." - Danny Jenkins
What's happening: Attacks exploiting the relationship between organizations and their third-party partners are becoming more common. Attackers can steal API keys or OAuth tokens, abuse excessive permissions, or inject malicious code into software updates. Organizations that rely on vendor assessments or security certifications alone are finding out the hard way that these measures are not enough.
Why it matters: The damage from a supply chain compromise ultimately depends on how much freedom the affected technology already has. If a SaaS application's update process is compromised, but policies prevent unauthorized code or installers from running, you can contain the attack.
The big picture: You cannot control which security controls your partners enforce, but you can control how third-party tools behave in your own environment. Assume that trusted vendors can be compromised and limit how far that compromise can spread.
What's happening: While EDR remains an important part of defense in depth, it has limits. Modern attacks don't always begin with an obvious malicious executable. They blend into normal activity. At the same time, AI is increasing the speed and scale of attacks, and simply adding more analysts to your response team is not sustainable. The strategy needs to shift toward pairing visibility with proactive containment.
Why it matters: Responding to an alert takes time, and every second matters when attacks move at machine speed. The longer the gap between seeing a potential threat and stopping it, the greater the risk.
The big picture: Detection and containment are not competing strategies. Instead, each one strengthens the other. Organizations still need EDR for visibility into suspicious activity, but it should be paired with proactive controls that limit what attackers can do in the first place. The goal is to stop an attempted malicious action rather than detect the damage after it's done.
Build your environment so one breach can't become many
What's happening: Cyber resilience is often associated with recovering from an attack. In reality, a resilient company should be able to contain a threat before significant damage occurs. That means assuming attackers will eventually gain access and enforcing default-deny controls to restrict what they can do.
Why it matters: Many organizations put most of their effort into preventing initial access. This is becoming less feasible. With the right controls in place, however, initial access doesn't have to become a widespread compromise.
The big picture: Cyber resilience shouldn't be measured only by how quickly you restore systems after an attack. The better measure is how difficult you've made it for an attacker to inflict damage in the first place.
NightmareEclipse claims Microsoft failed to properly patch RoguePlanet
What's happening: RoguePlanet, CVE-2026-50656, was reportedly patched in June 2026, but researcher NightmareEclipse has released a new proof of concept (PoC) exploiting the same weakness. Dubbed ShieldBreak, it deploys similar tactics to RoguePlanet and shares the ultimate goal of providing an unprivileged user with SYSTEM-level rights. The path replacement and locking mechanisms are different, however, supporting the researcher's claim that ShieldBreak is a patch bypass for RoguePlanet.
Why it matters: This is the ninth PoC released by NightmareEclipse this year, and while the public reaction to the technical details has been mixed, they have highlighted the frustration many professionals have with responsible disclosure practices.
The big picture:Patching is an important part of a security strategy, but as this PoC shows, your security cannot stop once you've deployed the patch. Patching fixes known vulnerabilities, but it shouldn't become a new point of implicit trust. Continue enforcing least privilege and default-deny controls even after a fix is deployed.
Does MFA stop credential theft? Can you trust a signed application? We'll draw from real attack scenarios to examine the security assumptions too many believe to be true.
ThreatLocker events
Meet the Cyber Hero Team in person at these upcoming events
GRC Conference | Aug. 17–19 Chula Vista, CA
Secure Carolinas | Aug. 26–27 Greenville, SC
Blue Team Con | Sept. 10–13 Chicago, IL
Gartner IT Symposium | Sept. 14–16 Broadbeach, AU
Insider Risk Symposium | Sept. 15–16 Washington D.C.