Cisco Talos to Showcase AI Security Research and Ransomware Analysis at Black Hat USA 2026
Cisco Talos will present cutting-edge research on AI's role in cybersecurity, including threat actor prompt usage and AI-driven SOC workflows, alongside an analysis of the Warlock ransomware group at Black Hat USA 2026.

Cisco Talos is set to make a significant presence at Black Hat USA 2026, offering attendees a deep dive into critical cybersecurity topics. The team will host discussions and demonstrations covering the evolving landscape of threat actor tactics, the intricacies of ransomware operations, and the implementation of zero trust principles for agent identity management.
Central to their presentations will be the burgeoning use of Artificial Intelligence in cyberattacks. Talos researchers will detail how threat actors are leveraging AI prompts and agents to enhance their efficiency and sophistication. This includes exploring the development of AI-powered tools and skills that adversaries are integrating into their operational frameworks, presenting a new frontier in cyber defense challenges.
The Warlock ransomware group will also be a focal point of Talos's research. Unlike typical ransomware-as-a-service (RaaS) operations or state-sponsored attacks, Warlock presents a unique profile that defies easy categorization. Talos's analysis aims to shed light on the group's motivations, operational methods, and its distinct position within the broader ransomware ecosystem.
In addition to these specific research areas, Talos will also host lightning talks throughout Wednesday and Thursday at the Cisco and Splunk booth (2633). These sessions will cover a range of topics, including the creation of a "second brain" for security professionals, predictions for cybersecurity fraud, and emerging trends in vulnerability discovery, all designed to provide actionable insights for attendees.
Cisco's David Dalling and Rick Miles will deliver a Main Stage keynote titled "Security at agentic scale." This session will address the profound security implications of increasingly capable and privileged AI agents operating within enterprise environments. The keynote will draw upon extensive research from across Cisco to outline the necessary strategies for securing organizations as autonomous systems become integral to business operations.
Furthermore, Talos will conduct a hands-on workshop, "When AI finds vulnerabilities faster than humans can patch." This interactive session, led by Nick Biasini and Omar Santos, will demonstrate how security teams can integrate AI into Security Operations Center (SOC) workflows for advanced threat hunting. Participants will learn best practices for identifying adversarial AI tactics and gain insights into how Cisco Talos utilizes AI for defense.
The workshop will also feature a segment on the Foundry Security Spec and Project CodeGuard, illustrating how to deploy agent roles and convert autonomous testing findings into secure-coding rules. Complementing this, a Splunk workshop will explore the emerging threat of autonomous agents acting as insider threats, moving sensitive data and manipulating systems without triggering traditional alerts.
Talos emphasizes that its intelligence is not a separate product but is embedded across the Cisco security portfolio. Their presence at Black Hat USA 2026 aims to foster conversations about how this integrated intelligence helps reduce uncertainty and enhance defenses in modern SOC environments.