DNS Filtering Blog: Latest Trends and Updates | DNSFilter

I Went to Black Hat 2026 and Only Saw the Expo Floor. Here's What I Learned.

Written by Serena Raymond | Aug 7, 2026, 5:05:22 PM

 

Black Hat took over Mandalay Bay this week, and the official theme was impossible to miss: AI, everywhere, all at once. The keynotes covered cyber power in the age of AI, defending when offense is cheap, and vulnerability research in the agentic age. The vendor announcements were wall-to-wall AI agents, autonomous response, and identity security. TechTarget's recap sums up the show floor mood well: Attackers are getting faster and cheaper, and defenders are scrambling to see what their users (and their users' AI tools) are actually doing.

I heard all of that secondhand, though. My Black Hat happened at the DNSFilter booth.

What Missing Every Black Hat Briefing Taught Me About B2B Sales Cybersecurity

Here's the thing about working a booth for a week: You get an unfiltered read on what's keeping people up at night. I missed the keynotes, but I had hundreds of conversations with the people running security day to day.

A few patterns emerged fast.

Remote and hybrid work is still the unsolved problem. The single most common conversation I had was with organizations whose users are everywhere: Home offices, coffee shops, client sites, and airports. They weren't concerned about the network perimeter. Instead, they were asking how to find and rein in their riskiest users, wherever those users happen to be working from. That's exactly the problem CyberSight was built for, so those conversations were fun to have. The ability to surface risky behavior (rather than only blocking categories) resonated with almost everyone who stopped by.

Shadow AI. We did a presentation on shadow AI at the booth that got a lot of people interested in CyberSight’s AI Usage Report. There was a common theme in my conversations around the lack of visibility into AI tools that employees are using and it was exciting to be able to point to a solution.

Clientless Entra came up A LOT. We launched our direct Microsoft Entra ID integration a few weeks before the show (no sync tool, no server, one admin consent), and I lost count of how many people specifically mentioned rolling out filtering through identities. Cloud-first teams and MSPs managing multiple tenants have been waiting on this one for a long time. I know, because I opened the original feature request myself almost six years ago.

Everyone wants their data where they need it. Data export came up constantly, for both CyberSight insights and standard DNS filtering logs. Security teams want DNS and user-risk data flowing into their SIEM and reporting workflows alongside everything else.

And then there's SecureTransit. One of the most titillating things that I got to talk about all week was our upcoming SecureTransit launch, and the reactions made the sore feet worth it. It’s privacy and encryption, with the ability to block ads and trackers beyond what we already do at the DNS level. But more on that later.

The Briefings Came To Us Anyway

Even without setting foot in a session, the themes of the keynotes found their way to our booth. People would come straight from a briefing on AI agent security or identity blind spots and ask us the practical version of the same question: "How do I see and control this in my environment today?"

That gap between research-stage threats and Tuesday-morning operations is where DNS keeps proving its value. When offense gets cheaper (David Weston's keynote called this "the end of rare"), the defensive layers that are fast, universal, and hard to route around matter more and more. DNS is one of the few control points that touches every user, every device, and increasingly every AI agent making requests on a user's behalf.

Being Booth-Bound Was Actually Fun

Our racing jerseys were a hit. The slot car race was a huge hit. Please do not ask me about my lap times.

If you raced us, grabbed a jersey, or just came by to talk shop: Thank you! You made a long week in the booth the best part of my year so far.

What's Next

DNSFilter’s building something great, and Black Hat confirmed we're building it for the right problems: Risky users scattered across hundreds of devices, AI reshaping both sides of the fight, and security teams who need visibility and control without another agent to deploy.

If you didn't make it to the booth (or you did, and you want the longer version), book a personalized demo or start a free trial and we'll show you CyberSight, clientless Entra, and Data Export. And keep an eye out for SecureTransit 👀

See you at booth whatever-number-we-get next year!