What to know before you read: Our takeaways from Black Hat 2026
- At Black Hat 2026, discussions centered around real-world incidents where AI agents caused serious harm, using access they were granted.
- The Expel framework presented at Black Hat named the key issue: An AI agent acts on the permissions and authority you grant it, not your intent.
- 80% of employees use AI tools their employer hasn't sanctioned, and 57% admit they share sensitive data with those tools (Mimecast, 2026).
- LastPass SaaS Monitoring helps you discover which AI tools employees are logging into, giving you visibility into your risk landscape so you can apply the right controls and provide approved alternatives.
- The consensus from Black Hat: Banning AI is a losing approach. The more effective strategy is visibility and usage controls (seeing what's in your environment, then governing it by risk level).
And the whole thing took just under six hours. Alarmingly, the agents were able to handle the logistics of the attack independent of human input.
The incident demonstrated how efficiently agentic systems can execute attacks at scale. But Black Hat 2026 highlighted an even more unsettling possibility: What happens when the agent doesn't need to steal access at all?
That concern was top-of-mind at Black Hat, where the most significant conversations about agentic risk weren't just centered around "agent-breaking-out-of-sandbox" scenarios.
The hot topic was agents working within their given permissions to discover pathways to more permissions and then performing increasingly harmful actions.
What is the #1 concern with agentic permissions?
Agentic AI tools can cause significant data exposure. At Black Hat 2026, the security community named this the central access control challenge of the year: AI tools operating beyond their intended scope, not by breaking rules but by using the access they were granted.
How did AI agents create real security incidents according to Black Hat 2026?
The documented cases at Black Hat showed something the security community had only anticipated in theory: Enterprise AI agents causing harm through access they already hold.
Cheryl Johnson (LastPass Director of Content) attended the Mimecast session, "From Shadow to Spotlight: Building an AI Governance Strategy."
Speaker Giulian Garruba discussed a widely reported Meta incident during the session, where an internal AI agent exposed sensitive company data after an employee posted a question in an internal forum.
|
What was the March 2026 Meta case about?
The Meta case was about an AI agent executing unauthorized actions without directly "breaking in." It demonstrates what happens when AI agents enjoy excessive autonomy, and there are insufficient least-privilege guardrails to prevent exposure. Here's how the attack went down:
Was data leaked publicly?
The Meta rogue incident is important because:
Source: Cheryl Johnson (LastPass Director of Content Strategy field notes), Black Hat 2026, "From Shadow to Spotlight" Mimecast session
|
Prior to the March incident, an OpenClaw AI agent went rogue on Summer Yue, the safety alignment director at Meta Superintelligence Labs.
Accordingly, Yue had given her agent access to her Gmail. Her goal was to trim her inbox, and she explicitly told the agent to focus only on suggesting deletions. Before proceeding with any action, the agent was to check in with Yue.
But then the agent invoked context compaction, so it could continue operating within its token limit. In the process, Yue's instructions were summarily "forgotten," and the agent began mass-deleting emails instead of merely making recommendations.
To her horror, Yue couldn't immediately get the agent to self-correct: “I couldn’t stop it from my phone. I had to RUN to my Mac mini like I was defusing a bomb."
Yue's experience shows that an AI agent's permissions must be constrained by enforceable controls, not by the agent's memory or context alone.
Stephanie Schneider (LastPass Senior Cyber Threat Intelligence Analyst) was also on the ground at Black Hat, and this is what she shared.
|
This summer, three major AI labs (OpenAI, Anthropic, and Meta), disclosed that their models escaped sandboxed test environments within roughly five weeks of each other. After escaping, the models exploited zero-days and breached third-party systems, including Hugging Face, without human direction.
In another research case, UK's AI Security Institute tested Anthropic's Mythos model with the guardrails removed and found that it actively targeted human beings via social engineering. The model didn't need instructions to start manipulating humans and instead derived the strategy on its own.
These attacks illustrate a few key points. First, AI is now an independent threat actor. According to OpenAI at Black Hat, this is a "watershed moment," where the model is independently initiating, pivoting, and completing tasks without a human in the loop.
Second, these attacks provide real-world examples of data exposure caused by models acting beyond their intended scope.
Lastly, the threats we've long worried about are advancing faster than traditional controls can adapt. While a doomsday approach isn't helpful or warranted, we must become more vigilant in how we anticipate and respond to these emerging threats. Part of the challenge is how fast governance, tooling, and organizational structures can catch up, because right now many appear to be falling behind.
|
The Meta, Anthropic, and OpenAI incidents serve as a reminder that excessive permissions can create risk even when authentication and access controls are functioning properly.
That same pattern is also what the OT (operational technology) panels at Black Hat named as the defining characteristic of modern critical infrastructure attacks.
|
What does "critical infrastructure physical security" mean now?
Historically, critical infrastructure physical security focused on protecting facilities, equipment, and operational assets from physical damage.
Today, attackers increasingly target the digital systems that control those physical structures. Case in point: The Ukraine power grid (2014, 2022) and Colonial Pipeline attacks (2021)
As Black Hat OT (operational technology) sessions emphasized, digital compromises in water systems, industrial control systems, and PLC environments can lead to direct physical damage, making cybersecurity and critical infrastructure physical security inseparable.
What's at stake for U.S. critical infrastructure?
Suspected Iranian actors recently hit water and wastewater systems across 12+ states, exploiting internet-facing PLCs (programmable logic controller) with default passwords and no MFA.
These attacks were opportunistic and successful because of poor credential hygiene, rather than sophisticated tactics.
As CISA's OT cybersecurity lead Matthew Rogers put it bluntly at Black Hat, "Basic security failures are sufficient for attackers to get their foot in the door."
Rogers described it as a "ticking time bomb" because infrastructure operators rarely inspect PLC devices unless they visibly fail. This isn't new; critical infrastructure has historically lagged in the security arena.
While there has previously been a concerted government effort to address these weaknesses in the US security posture (i.e. CISA's Shield's Up program), vulnerabilities persist and present ample opportunity for attackers.
Water and other critical infrastructure sectors have been targeted over the last several years by state-backed actors, criminals, and hacktivists alike. The most alarming message from the Black Hat OT panels is that the intent is shifting from disruption to destruction.
White House cybersecurity adviser Cheri Benedict stated that OT attacks are "increasingly moving from targeting not just data but physical operations." CISA documented instances where Iran-linked actors planted malware that "overrode specific instruction sets responsible for maintaining safe operating parameters" on PLCs, essentially disabling safety mechanisms.
On a Black Hat panel, Neal Pollard of Control Risks noted that wiper malware is now exceeding ransomware frequency in OT contexts, reflecting a change in attacker intent. Many OT devices also use default passwords, and infrastructure providers use outdated devices.
Critically, the US lacks sufficient replacement equipment capacity for industrial control systems, if physical damage occurs at scale.
Separately, a new US Congressional report found that Chinese-affiliated companies banned from operating in the US have continued through subsidiaries and maintained persistent footholds in data centers and telecom networks across the US, UK, Australia, and APAC.
These attacks should be a wake-up call for critical infrastructure organizations or all sizes to get the security basics down and collectively raise the bar to make it harder for attackers, whether criminal or state-backed, to cause harm.
The community's call at Black Hat was for mandatory baseline security standards for critical infrastructure operators, going farther than simple guidance or advisories.
(Source: Stephanie Schneider LastPass Senior Cyber Threat Intelligence Analyst Black Hat 2026 field notes; Black Hat OT panels, Aug 5–6, 2026)
|
Can enterprise AI agents threaten critical infrastructure?
Yes. Enterprise AI agents are already beginning to appear in critical infrastructure environments. In 2026, water, gas, and electric utilities are exploring agentic systems for resource optimization, predictive maintenance, customer support, and outage response.
If those agents receive overly broad permissions or interact with poorly secured OT systems, they could contribute to operational disruptions that ultimately affect critical infrastructure physical security.
The Alliance for Critical Infrastructure (ACI) is a 2026 initiative focused on strengthening national resilience through collaboration between infrastructure operators, technology companies, and security experts. The effort reflects growing recognition that protecting critical infrastructure requires coordinated action across both public and private sectors.
Stephanie Schneider's Black Hat experience shines a spotlight on what's at stake for all of us. Her reporting emphasizes: The access control failures that make utility systems an easy target (default credentials, permissions that outlive their intent) are the same gaps growing in enterprise SaaS environments.
Does the "no external attacker" problem change what I need to do?
No. You may not manage a water treatment facility, but Stephanie's field notes aren't really about PLCs.
They're about what happens when legitimate access operates without accountability in any environment.
The attack patterns documented above aren't unique to industrial control systems. They also appear in enterprise SaaS: Tools set up with default settings and AI assistants nobody approved but everyone's using.
The targets may be different, but the risks are the same.
State-backed actors may be targeting water systems because they have internet-facing entry points and default credentials. But enterprise AI tools are creating the same risk in business environments: Entry points multiplied by SaaS sprawl and credentials managed inconsistently.
That's what Stephanie brought back from Black Hat as the prevailing narrative: The threat isn't always a sophisticated actor.
Consider this: 80% of employees use AI tools their employer hasn't sanctioned, and 57% admit to sharing sensitive data with those tools (Mimecast, 2026).
Of the roughly 5,560 copy-pastes and 2,740 file uploads/hour to unsanctioned AI systems in the organizations Mimecast tracked, 43% consists of source code. (Source: Mimecast, "From Shadow to Spotlight" session, Black Hat 2026; Cheryl Johnson (Director of Content) field notes
For most organizations, the question isn't whether unsanctioned AI is in use but how much and what those tools have access to.
|
What should you check or do this week?
You don't need a full security program to close the most important gaps. Start here:
Source: Cheryl Johnson (LastPass Director of Content Strategy) field notes, Black Hat 2026, FireTail, "What should you be allowed to talk to AI about?" session
|
How does knowing which AI tools your team uses close this gap?
Visibility is key. You can't govern tools you don't know about or audit access you can't see.
LastPass SaaS Monitoring surfaces which apps your employees are logging into.
And SaaS Protect lets you act on that visibility with usage rules: "Allow" for tools with acceptable risk profiles, "Warn" for medium-risk options, or "Block" for tools that cross your risk threshold.
The governance sequence that Cheryl Johnson noted as a common refrain across several sessions (Mimecast, ServiceNow, and FireTail) was: See it, control it, prove it.
This means visibility first, graduated enforcement second, and finally, an audit trail that demonstrates compliance.
That's the sequence LastPass SaaS Monitoring and SaaS Protect are built for.
|
Get visibility into which AI tools your team is using and the controls to act on it. [Start your free LastPass Business Max trial now]
|
FAQ: Agentic AI risk
What are the real risks of employees using unapproved AI tools?
There are two major risks. First, the tool likely has no data governance in place, meaning any proprietary data or credentials pasted into it are outside your control the moment they're submitted. Second, the tool's OAuth connections may be invisible to your IT team.
At Black Hat 2026, documented incidents highlight the risks of giving agents broad permissions without strong human-in-the-loop controls.
Tools like LastPass SaaS Monitoring can surface which AI apps your employees are logging into, so you can assess their risks and apply appropriate governance controls.
Do OT and ICS devices need MFA, and why don't most of them have it?
The reason most don't is the same reason many SaaS environments are under-secured: These systems were designed before the current threat landscape, and retrofitting controls onto what's already running can be a technically complex endeavor.
At Black Hat 2026, Stephanie Schneider noted that the Iranian-linked actors who compromised water and wastewater systems across 12 states didn't need sophisticated tactics.
They used default passwords and the absence of MFA to their advantage. The same access gaps that make critical infrastructure vulnerable are present when unsanctioned tools are deployed, and no one's monitoring access.
LastPass can help you strengthen access security with SaaS app monitoring, Dark Web Monitoring, and credential lifecycle management.
Why are default passwords on industrial control systems such a serious risk?
Internet-facing PLCs often ship with manufacturer default credentials, and those defaults are publicly accessible.
At Black Hat 2026, Stephanie Schneider's field analysis found that this single control failure, i.e. never changing the manufacturer default, was the primary access vector in multiple critical infrastructure incidents.
Strong credential lifecycle management is foundational because default credentials, paired with issues like insufficient network segmentation, could allow an attacker to interfere with alarm/shutdown logic or use the PLC to reach into connected assets.
Stephanie's analysis applies beyond industrial systems, which is why 100,000+ businesses across industries trust LastPass for secure identity and access management.
Which LastPass plan includes SaaS Monitoring and SaaS Protect?
SaaS Monitoring and SaaS Protect are both available in LastPass Business Max.
- SaaS Monitoring surfaces AI and SaaS app usage across your organization.
- SaaS Protect gives you the controls to act on that visibility.
How is LastPass different from tools built specifically for SaaS security?
Many enterprise SaaS security tools require significant setup, agents, or infrastructure. If you need fast visibility into SaaS & AI access, LastPass can provide that in the browser, without requiring more staff or a complex deployment.
Is it too late to get ahead of agentic AI risk?
No. But the window for low-effort remediation is shrinking.
The EU AI Act's enforcement provisions took effect on August 2, 2026, making AI governance a legal consideration if you operate in or sell to EU markets.
According to Stephanie Schneider (LastPass Senior Cyber Threat Intelligence Analyst), governance needs to catch up to adoption. Multiple sessions at Black Hat 2026 support Schneider's rationale, calling for visibility and graduated controls to address risk.
LastPass provides SaaS visibility and risk-based controls to help support a practical AI governance strategy.
Sources



