Blog
Recent
Cybersecurity

From Disruption to Destruction: What Black Hat 2026 Revealed About AI Agents and Critical Infrastructure

Shireen StephensonPublishedSeptember 21, 2026
What to know before you read: Our takeaways from Black Hat 2026
  • At Black Hat 2026, discussions centered around real-world incidents where AI agents caused serious harm, using access they were granted. 
  • The Expel framework presented at Black Hat named the key issue: An AI agent acts on the permissions and authority you grant it, not your intent. 
  • 80% of employees use AI tools their employer hasn't sanctioned, and 57% admit they share sensitive data with those tools (Mimecast, 2026). 
  • LastPass SaaS Monitoring helps you discover which AI tools employees are logging into, giving you visibility into your risk landscape so you can apply the right controls and provide approved alternatives. 
  • The consensus from Black Hat: Banning AI is a losing approach. The more effective strategy is visibility and usage controls (seeing what's in your environment, then governing it by risk level). 
In September 2026, Google Threat Intelligence reported that financially motivated threat actors used AI agents to execute a sophisticated credential harvesting campaign.
And the whole thing took just under six hours. Alarmingly, the agents were able to handle the logistics of the attack independent of human input.
The incident demonstrated how efficiently agentic systems can execute attacks at scale. But Black Hat 2026 highlighted an even more unsettling possibility: What happens when the agent doesn't need to steal access at all?
That concern was top-of-mind at Black Hat, where the most significant conversations about agentic risk weren't just centered around "agent-breaking-out-of-sandbox" scenarios.
The hot topic was agents working within their given permissions to discover pathways to more permissions and then performing increasingly harmful actions.

What is the #1 concern with agentic permissions?
Agentic AI tools can cause significant data exposure. At Black Hat 2026, the security community named this the central access control challenge of the year: AI tools operating beyond their intended scope, not by breaking rules but by using the access they were granted.

 

How did AI agents create real security incidents according to Black Hat 2026?

The documented cases at Black Hat showed something the security community had only anticipated in theory: Enterprise AI agents causing harm through access they already hold.
Cheryl Johnson (LastPass Director of Content) attended the Mimecast session, "From Shadow to Spotlight: Building an AI Governance Strategy."
Speaker Giulian Garruba discussed a widely reported Meta incident during the session, where an internal AI agent exposed sensitive company data after an employee posted a question in an internal forum.
What was the March 2026 Meta case about?
The Meta case was about an AI agent executing unauthorized actions without directly "breaking in." It demonstrates what happens when AI agents enjoy excessive autonomy, and there are insufficient least-privilege guardrails to prevent exposure. Here's how the attack went down:
  • A Meta engineer posted a question in an internal dev forum.
  • Another engineer asked one of Meta's in-house AI agents to help generate a response.
  • The AI agent, acting with authorized credentials, posted guidance in the forum.
  • The first employee followed the AI-generated guidance to the letter, which unintentionally changed access settings and exposed backend analytics tables and user metrics to a wider group of engineers who had no access privileges.
  • Internal monitoring tools flagged the abnormal volume of queries into restricted datasets nine minutes in. But full containment took about two hours. Meta slapped a second-highest severity rating on the incident ("Sev 1").

Was data leaked publicly?
  • No. All reporting on the case suggests that the data exposure was internal only. Meta has maintained there was no evidence data had been leaked or accessed by outsiders.
  • Why is the Meta rogue AI agent incident important?
The Meta rogue incident is important because:
  • The AI agent had access to internal systems and sensitive corporate data.
  • The agent’s guidance appeared plausible enough that an engineer trusted and implemented it (in reality, the guidance was technically flawed).
  • The failure wasn’t caused by a zero-day, malware, or external threat actor.
  • The incident demonstrated how an enterprise AI agent can trigger a significant security event through legitimate access and insufficient data-centric guardrails.
Source: Cheryl Johnson (LastPass Director of Content Strategy field notes), Black Hat 2026, "From Shadow to Spotlight" Mimecast session
Prior to the March incident, an OpenClaw AI agent went rogue on Summer Yue, the safety alignment director at Meta Superintelligence Labs.
Accordingly, Yue had given her agent access to her Gmail. Her goal was to trim her inbox, and she explicitly told the agent to focus only on suggesting deletions. Before proceeding with any action, the agent was to check in with Yue.
But then the agent invoked context compaction, so it could continue operating within its token limit. In the process, Yue's instructions were summarily "forgotten," and the agent began mass-deleting emails instead of merely making recommendations.
To her horror, Yue couldn't immediately get the agent to self-correct: “I couldn’t stop it from my phone. I had to RUN to my Mac mini like I was defusing a bomb."
Yue's experience shows that an AI agent's permissions must be constrained by enforceable controls, not by the agent's memory or context alone. 
Stephanie Schneider (LastPass Senior Cyber Threat Intelligence Analyst) was also on the ground at Black Hat, and this is what she shared.
This summer, three major AI labs (OpenAI, Anthropic, and Meta), disclosed that their models escaped sandboxed test environments within roughly five weeks of each other. After escaping, the models exploited zero-days and breached third-party systems, including Hugging Face, without human direction.
In another research case, UK's AI Security Institute tested Anthropic's Mythos model with the guardrails removed and found that it actively targeted human beings via social engineering. The model didn't need instructions to start manipulating humans and instead derived the strategy on its own.
These attacks illustrate a few key points. First, AI is now an independent threat actor. According to OpenAI at Black Hat, this is a "watershed moment," where the model is independently initiating, pivoting, and completing tasks without a human in the loop.
Second, these attacks provide real-world examples of data exposure caused by models acting beyond their intended scope.
Lastly, the threats we've long worried about are advancing faster than traditional controls can adapt. While a doomsday approach isn't helpful or warranted, we must become more vigilant in how we anticipate and respond to these emerging threats. Part of the challenge is how fast governance, tooling, and organizational structures can catch up, because right now many appear to be falling behind.
(Source: Stephanie Schneider, LastPass Senior Cyber Threat Intelligence Analyst)
The Meta, Anthropic, and OpenAI incidents serve as a reminder that excessive permissions can create risk even when authentication and access controls are functioning properly.
That same pattern is also what the OT (operational technology) panels at Black Hat named as the defining characteristic of modern critical infrastructure attacks.
What does "critical infrastructure physical security" mean now?

 

Historically, critical infrastructure physical security focused on protecting facilities, equipment, and operational assets from physical damage.

 

Today, attackers increasingly target the digital systems that control those physical structures. Case in point: The Ukraine power grid (2014, 2022) and Colonial Pipeline attacks (2021)

 

As Black Hat OT (operational technology) sessions emphasized, digital compromises in water systems, industrial control systems, and PLC environments can lead to direct physical damage, making cybersecurity and critical infrastructure physical security inseparable.

 

What's at stake for U.S. critical infrastructure?
Suspected Iranian actors recently hit water and wastewater systems across 12+ states, exploiting internet-facing PLCs (programmable logic controller) with default passwords and no MFA.
These attacks were opportunistic and successful because of poor credential hygiene, rather than sophisticated tactics.
As CISA's OT cybersecurity lead Matthew Rogers put it bluntly at Black Hat, "Basic security failures are sufficient for attackers to get their foot in the door."
Rogers described it as a "ticking time bomb" because infrastructure operators rarely inspect PLC devices unless they visibly fail. This isn't new; critical infrastructure has historically lagged in the security arena.
While there has previously been a concerted government effort to address these weaknesses in the US security posture (i.e. CISA's Shield's Up program), vulnerabilities persist and present ample opportunity for attackers.
Water and other critical infrastructure sectors have been targeted over the last several years by state-backed actors, criminals, and hacktivists alike. The most alarming message from the Black Hat OT panels is that the intent is shifting from disruption to destruction.
White House cybersecurity adviser Cheri Benedict stated that OT attacks are "increasingly moving from targeting not just data but physical operations." CISA documented instances where Iran-linked actors planted malware that "overrode specific instruction sets responsible for maintaining safe operating parameters" on PLCs, essentially disabling safety mechanisms.
On a Black Hat panel, Neal Pollard of Control Risks noted that wiper malware is now exceeding ransomware frequency in OT contexts, reflecting a change in attacker intent. Many OT devices also use default passwords, and infrastructure providers use outdated devices.
Critically, the US lacks sufficient replacement equipment capacity for industrial control systems, if physical damage occurs at scale.
Separately, a new US Congressional report found that Chinese-affiliated companies banned from operating in the US have continued through subsidiaries and maintained persistent footholds in data centers and telecom networks across the US, UK, Australia, and APAC.
These attacks should be a wake-up call for critical infrastructure organizations or all sizes to get the security basics down and collectively raise the bar to make it harder for attackers, whether criminal or state-backed, to cause harm.
The community's call at Black Hat was for mandatory baseline security standards for critical infrastructure operators, going farther than simple guidance or advisories.
(Source: Stephanie Schneider LastPass Senior Cyber Threat Intelligence Analyst Black Hat 2026 field notes; Black Hat OT panels, Aug 5–6, 2026)

Can enterprise AI agents threaten critical infrastructure?

Yes. Enterprise AI agents are already beginning to appear in critical infrastructure environments. In 2026, water, gas, and electric utilities are exploring agentic systems for resource optimization, predictive maintenance, customer support, and outage response.
If those agents receive overly broad permissions or interact with poorly secured OT systems, they could contribute to operational disruptions that ultimately affect critical infrastructure physical security.
The Alliance for Critical Infrastructure (ACI) is a 2026 initiative focused on strengthening national resilience through collaboration between infrastructure operators, technology companies, and security experts. The effort reflects growing recognition that protecting critical infrastructure requires coordinated action across both public and private sectors.
Stephanie Schneider's Black Hat experience shines a spotlight on what's at stake for all of us. Her reporting emphasizes: The access control failures that make utility systems an easy target (default credentials, permissions that outlive their intent) are the same gaps growing in enterprise SaaS environments.

Does the "no external attacker" problem change what I need to do?

No. You may not manage a water treatment facility, but Stephanie's field notes aren't really about PLCs.
They're about what happens when legitimate access operates without accountability in any environment.
The attack patterns documented above aren't unique to industrial control systems. They also appear in enterprise SaaS: Tools set up with default settings and AI assistants nobody approved but everyone's using.
The targets may be different, but the risks are the same.
State-backed actors may be targeting water systems because they have internet-facing entry points and default credentials. But enterprise AI tools are creating the same risk in business environments: Entry points multiplied by SaaS sprawl and credentials managed inconsistently.
That's what Stephanie brought back from Black Hat as the prevailing narrative: The threat isn't always a sophisticated actor.
Consider this: 80% of employees use AI tools their employer hasn't sanctioned, and 57% admit to sharing sensitive data with those tools (Mimecast, 2026).
Of the roughly 5,560 copy-pastes and 2,740 file uploads/hour to unsanctioned AI systems in the organizations Mimecast tracked, 43% consists of source code. (Source: Mimecast, "From Shadow to Spotlight" session, Black Hat 2026; Cheryl Johnson (Director of Content) field notes
For most organizations, the question isn't whether unsanctioned AI is in use but how much and what those tools have access to.
What should you check or do this week?
You don't need a full security program to close the most important gaps. Start here:
  • Find out which AI tools your team is actually using. Many IT teams struggle to name the apps employees are accessing daily. Visibility into SaaS and AI logins is foundational to any governance effort.
  • Audit what access those tools have been granted. AI tools frequently request broad permissions such as read-write access to email, calendars, and documents. A review of OAuth permissions shows you what's connected and what data they can touch.
  • Check what data your team is pasting into AI tools. You don't need to ban AI. But you need to know whether proprietary data, client records, or credentials are flowing into consumer-grade AI tools.
  • Set at least one risk-tiered usage rule. "Block everything" was named at Black Hat as a losing near-term strategy. Identify your highest-risk tools and set a warning or approval requirement for those, while allowing lower-risk usage to continue.
Source: Cheryl Johnson (LastPass Director of Content Strategy) field notes, Black Hat 2026, FireTail, "What should you be allowed to talk to AI about?" session

How does knowing which AI tools your team uses close this gap?

Visibility is key. You can't govern tools you don't know about or audit access you can't see.
LastPass SaaS Monitoring surfaces which apps your employees are logging into.
And SaaS Protect lets you act on that visibility with usage rules: "Allow" for tools with acceptable risk profiles, "Warn" for medium-risk options, or "Block" for tools that cross your risk threshold.
The governance sequence that Cheryl Johnson noted as a common refrain across several sessions (Mimecast, ServiceNow, and FireTail) was: See it, control it, prove it.
This means visibility first, graduated enforcement second, and finally, an audit trail that demonstrates compliance.
That's the sequence LastPass SaaS Monitoring and SaaS Protect are built for.
Get visibility into which AI tools your team is using and the controls to act on it. [Start your free LastPass Business Max trial now]

FAQ: Agentic AI risk

What are the real risks of employees using unapproved AI tools?

There are two major risks. First, the tool likely has no data governance in place, meaning any proprietary data or credentials pasted into it are outside your control the moment they're submitted. Second, the tool's OAuth connections may be invisible to your IT team.
At Black Hat 2026, documented incidents highlight the risks of giving agents broad permissions without strong human-in-the-loop controls.
Tools like LastPass SaaS Monitoring can surface which AI apps your employees are logging into, so you can assess their risks and apply appropriate governance controls.

Do OT and ICS devices need MFA, and why don't most of them have it?

Yes, OT and ICS devices need MFA.
The reason most don't is the same reason many SaaS environments are under-secured: These systems were designed before the current threat landscape, and retrofitting controls onto what's already running can be a technically complex endeavor.
At Black Hat 2026, Stephanie Schneider noted that the Iranian-linked actors who compromised water and wastewater systems across 12 states didn't need sophisticated tactics.
They used default passwords and the absence of MFA to their advantage. The same access gaps that make critical infrastructure vulnerable are present when unsanctioned tools are deployed, and no one's monitoring access.
LastPass can help you strengthen access security with SaaS app monitoring, Dark Web Monitoring, and credential lifecycle management.

Why are default passwords on industrial control systems such a serious risk?

Internet-facing PLCs often ship with manufacturer default credentials, and those defaults are publicly accessible.
At Black Hat 2026, Stephanie Schneider's field analysis found that this single control failure, i.e. never changing the manufacturer default, was the primary access vector in multiple critical infrastructure incidents.
Strong credential lifecycle management is foundational because default credentials, paired with issues like insufficient network segmentation, could allow an attacker to interfere with alarm/shutdown logic or use the PLC to reach into connected assets.
Stephanie's analysis applies beyond industrial systems, which is why 100,000+ businesses across industries trust LastPass for secure identity and access management.

Which LastPass plan includes SaaS Monitoring and SaaS Protect?

SaaS Monitoring and SaaS Protect are both available in LastPass Business Max.
  • SaaS Monitoring surfaces AI and SaaS app usage across your organization.
  • SaaS Protect gives you the controls to act on that visibility.

How is LastPass different from tools built specifically for SaaS security?

Many enterprise SaaS security tools require significant setup, agents, or infrastructure. If you need fast visibility into SaaS & AI access, LastPass can provide that in the browser, without requiring more staff or a complex deployment.

Is it too late to get ahead of agentic AI risk?

No. But the window for low-effort remediation is shrinking.
The EU AI Act's enforcement provisions took effect on August 2, 2026, making AI governance a legal consideration if you operate in or sell to EU markets.
According to Stephanie Schneider (LastPass Senior Cyber Threat Intelligence Analyst), governance needs to catch up to adoption. Multiple sessions at Black Hat 2026 support Schneider's rationale, calling for visibility and graduated controls to address risk.
LastPass provides SaaS visibility and risk-based controls to help support a practical AI governance strategy.
Sources
Share this post via:share on linkedinshare on xshare on facebooksend an email