Skip to content

I Went to Black Hat 2026 and Only Saw the Expo Floor. Here's What I Learned.

Listen to this article instead
4:58

 

To see what our CEO Ken Carnesi thought of the week at Black Hat, check out his blog here.

Black Hat took over Mandalay Bay this week, and the official theme was impossible to miss: AI, everywhere, all at once. The keynotes covered cyber power in the age of AI, defending when offense is cheap, and vulnerability research in the agentic age. The vendor announcements were wall-to-wall AI agents, autonomous response, and identity security. TechTarget's recap sums up the show floor mood well: Attackers are getting faster and cheaper, and defenders are scrambling to see what their users (and their users' AI tools) are actually doing.

I heard all of that secondhand, though. My Black Hat happened at the DNSFilter booth.

What Missing Every Black Hat Briefing Taught Me About B2B Sales Cybersecurity

Here's the thing about working a booth for a week: You get an unfiltered read on what's keeping people up at night. I missed the keynotes, but I had hundreds of conversations with the people running security day to day.

A few patterns emerged fast.

Remote and hybrid work is still the unsolved problem. The single most common conversation I had was with organizations whose users are everywhere: Home offices, coffee shops, client sites, and airports. They weren't concerned about the network perimeter. Instead, they were asking how to find and rein in their riskiest users, wherever those users happen to be working from. That's exactly the problem CyberSight was built for, so those conversations were fun to have. The ability to surface risky behavior (rather than only blocking categories) resonated with almost everyone who stopped by.

Shadow AI. We did a presentation on shadow AI at the booth that got a lot of people interested in CyberSight’s AI Usage Report. There was a common theme in my conversations around the lack of visibility into AI tools that employees are using and it was exciting to be able to point to a solution.

Clientless Entra came up A LOT. We launched our direct Microsoft Entra ID integration a few weeks before the show (no sync tool, no server, one admin consent), and I lost count of how many people specifically mentioned rolling out filtering through identities. Cloud-first teams and MSPs managing multiple tenants have been waiting on this one for a long time. I know, because I opened the original feature request myself almost six years ago.

Everyone wants their data where they need it. Data export came up constantly, for both CyberSight insights and standard DNS filtering logs. Security teams want DNS and user-risk data flowing into their SIEM and reporting workflows alongside everything else.

And then there's SecureTransit. It’s our upcoming release that does privacy and encryption, with the ability to block ads and trackers beyond what we already do at the DNS level. It came up in a striking number of conversations as encryption is clearly on people’s minds.

Attendees got a sneak peek at LUMINATE by DNSFilter. Booth visitors and existing customers got an early look at what's coming in October: A new DNS-first platform that brings advanced filtering, behavior analytics, AI governance controls, threat intelligence, and encryption together into the most upstream control point in cybersecurity. It's in closed beta right now, but we're excited to show it off when the time is right.

The Briefings Came To Us Anyway

Even without setting foot in a session, the themes of the keynotes found their way to our booth. People would come straight from a briefing on AI agent security or identity blind spots and ask us the practical version of the same question: "How do I see and control this in my environment today?"

That gap between research-stage threats and Tuesday-morning operations is where DNS keeps proving its value. When offense gets cheaper (David Weston's keynote called this "the end of rare"), the defensive layers that are fast, universal, and hard to route around matter more and more. DNS is one of the few control points that touches every user, every device, and increasingly every AI agent making requests on a user's behalf.

Being Booth-Bound Was Actually Fun

Our racing jerseys were a hit. The slot car race was a huge hit. Please do not ask me about my lap times.

If you raced us, grabbed a jersey, or just came by to talk shop: Thank you! You made a long week in the booth the best part of my year so far.

What's Next

DNSFilter’s building something great, and Black Hat confirmed we're building it for the right problems: Risky users scattered across hundreds of devices, AI reshaping both sides of the fight, and security teams who need visibility and control without another agent to deploy.

If you didn't make it to the booth (or you did, and you want the longer version), book a personalized demo or start a free trial and we'll show you CyberSight, clientless Entra, and Data Export. And keep an eye out for SecureTransit 👀

See you at booth whatever-number-we-get next year!

Search
  • There are no suggestions because the search field is empty.
Latest posts
SecureTransit for MSPs: Digital Privacy Without Another Tool to Manage SecureTransit for MSPs: Digital Privacy Without Another Tool to Manage

MSPs need to boost client security without sacrificing efficiency or margin. Every extra tool, console, or license just adds overhead and slows down service delivery.

Privacy is a classic example. Clients want their remote and hybrid users protected from the networks they connect through and the trackers profiling them, but most solutions add another siloed tool and more operational work.

How Black Hat Proved DNSFilter is on the Right Expansion Path How Black Hat Proved DNSFilter is on the Right Expansion Path

By Ken Carnesi, CEO & Co-Founder, DNSFilter

I've been going to Black Hat for years, and I can tell you plainly: This year was different.

Shadow AI and AI governance are top of mind now, an evolution from what we were hearing at RSA earlier this year. In an AI era, taking a DNS First approach to cybersecurity isn't optional, and we're built to solve exactly that problem.

Explore More Content

Ready to brush up on something new? We've got even more for you to discover.