black-hat-usa-2026-blog

When Visibility Becomes the Target: Bitdefender at Black Hat USA 2026

Share this Share on email Share on twitter Share on linkedin Share on facebook

For more than a decade, the cybersecurity industry has invested heavily in improving detection.

More telemetry. More visibility. More alerts. Faster response. 

Those investments have helped organizations identify threats that would have once gone unnoticed. However, high detection rates are also the reason today's attackers increasingly focus on degrading, bypassing, or manipulating the very security tooling organizations depend on. Living-off-the-Land (LOTL) techniques, identity abuse, telemetry tampering, trusted process abuse, and sensor deception all point to the same trend:

Visibility has become a target.

This shift is changing how cyber defenders think about cyber resilience—and it's one of the key conversations Bitdefender is bringing to Black Hat USA 2026 at space #5135 and beyond.

Can't-Miss Session: Why Detection-First Security Has Blind Spots

On Wednesday, August 5, Nicholas Jackson, Bitdefender Director of Cyber Security Services, and I will present a thought-provoking session at Black Hat around detection.

You Can't Detect What You Can't See: Why Detection-First Security Has Blind Spots by Design

Screenshot 2026-07-23 085537

The session explores a challenge facing every modern security team: attackers increasingly understand how endpoint security tools work—and how to manipulate, evade, or disable them.

Rather than focusing on the latest collection of EDR bypass techniques, we're going to examine the underlying principles behind these attacks. You will learn why many security architectures implicitly trust operating system telemetry, how attackers exploit those assumptions, and what security teams can do to build more resilient defenses.

The session concludes with practical guidance for strengthening endpoint resilience through prevention, attack surface reduction, anti-tampering, least privilege, telemetry validation, and continuous security verification—helping organizations think beyond detection alone.

Rethinking the Threat Lifecycle

The presentation reflects a broader shift taking place across the cybersecurity industry.

For years, organizations measured security success by how quickly they could detect and respond to attacks. While detection remains essential, today's threat landscape demands a broader strategy.

According to Bitdefender Labs, 84% of the attacks investigated relied on legitimate tools already present inside victim environments. Attackers increasingly avoid malware altogether and instead abuse trusted applications, credentials, and native operating system capabilities to blend into normal activity.

This is why prevention and attack surface reduction have become critical components of modern cyber resilience. The less opportunity attackers have to establish a foothold or abuse legitimate tools, the fewer opportunities they have to evade detection in the first place.

Let us show you how this prevention first approach works. Stop by our space (#5135) at Black Hat 2026. Catch a presentation, see a demo, or see threats unfold in a virtual reality (VR) experience.

AI That Empowers Analysts—Not Replaces Them

Artificial intelligence will undoubtedly be one of the hottest topics throughout Black Hat. But technical audiences have grown skeptical of exaggerated AI claims.

Bitdefender's approach is grounded in a simple principle for defenders: AI should make security analysts faster and more effective—not remove them from the decision-making process.

For example, within Bitdefender MDR, AI helps accelerate investigations, correlate signals across the environment, prioritize incidents, and automate appropriate low-risk actions. Experienced security professionals remain responsible for validation, judgment, and arbitration, ensuring critical response decisions continue to benefit from human expertise.

As attackers increasingly leverage AI to move faster and adapt more quickly, organizations need security operations that can match that speed—without sacrificing trust or accountability.

The Bitdefender Virtual Reality Experience at Black Hat USA

Visit Bitdefender at Booth #5135 for a virtual reality experience in which attacks unfold while the GravityZone unified security platform disables them before your eyes. In this VR experience, you can choose your own adventure:

  • Stop a LOTL (Living off the Land) attack & lateral movement.
  • Stop a Supply Chain attack.
  • Stop a ClickFix technique.

GravityZone secures organizations across the complete threat lifecycle—from prevention and protection to detection and response—while simplifying security operations rather than adding complexity.

Whether you're exploring prevention-first security, looking to simplify operations for a lean security team, or evaluating how AI can responsibly strengthen your SOC, our experts are available at space #5135.

And don't miss our presentation at Mandalay Bay.

You Can't Detect What You Can't See: Why Detection-First Security Has Blind Spots by Design

📅 Wednesday, August 5
🕜 1:30–2:15 PM
📍 Pulse Stage 3, Mandalay Bay Convention Center, Las Vegas

The conversation around cybersecurity is evolving. Join us at Black Hat USA 2026 as we explore what comes next.