
Episode #226
Episode 149: Black Hat 2026 - Everything Had an AI Agent. Nothing Stopped the Phishing Email.
AI was in every booth, every keynote, and nearly every conversation at Black Hat 2026. Which makes the most useful takeaway from the show a slightly awkward one: the fundamentals still decide who gets compromised. Host Kim Coombes is joined by Connection security experts John Chirillo and Rob Di Girolamo, along with penetration tester and lead systems engineer Joe Chmielewski, to work through what actually mattered this year. The conversation covers: Why AI found hundreds of real vulnerabilities when a human guided the methodology, and performed worse running on its own Attacker velocity, and why AI lets adversaries cover more ground in the time they have inside an environment AI agents as a new class of privileged identity, and the machine identity lifecycle gap most organizations haven't closed What "the end of rare" means when AI makes offense cheap, and why monthly scanning with 30-day patch windows is getting harder to defend How to tell AI-enabled from AI-washed when a vendor claims an autonomous SOC The attacks that still work, from a phishing email to an unpatched server, and why a pen tester rarely needs anything exotic to get in They close with what security teams should do differently on Monday morning. Inventory before innovation, and stop assuming, start validating.

