Black Hat USA 2026 | Las Vegas | Aug 1st – 6th | Booth 5115

Every year, Black Hat draws the people who take security seriously. This year, the conversation is unavoidable: AI has changed what it means to build, and that means it has changed what it means to secure.

The companies in Las Vegas this week aren’t just defending infrastructure. They’re defending pipelines, agents, models, PaaS platforms, and entire AI-native architectures that didn’t exist two years ago. Their developers ship to cloud environments that outpace any team’s ability to manually track. Their data scientists deploy model endpoints before security has a chance to ask what they connect to. Their analysts spin up agents with access to a dozen internal systems in an afternoon. That doesn’t include other parts of the organization like marketing, finance, sales, etc.

Security that can’t keep up isn’t protecting anyone. It’s like putting on a safety vest while the scaffolding collapses around you — the right instinct, wrong solution.

Orca was built for the companies that build. That means keeping security in step with every team, every environment, every AI workload — not just keeping up, but helping teams move faster, at greater scale, and with greater confidence. At Black Hat this year, we’re announcing the next round of capabilities that make that real.

The theme: Security for the companies that build

Risk now lives everywhere you build. Cloud, PaaS, runtime, AI agents, running models, and everything your team is spinning up next week. The teams building fastest are also expanding their attack surface fastest, and the old answer of deploying more tools and hoping the alerts get triaged isn’t working.

Orca’s approach is different. Complete cloud and AI visibility. Context that actually changes decisions. And security that adapts to how your team already operates, not the other way around.

Here’s what we’re showing at Black Hat.

1. AI-Native Code Security

Securing code wherever AI helps write it, inside the pipeline and beyond it.

AI has changed who writes code and how fast it ships. That means code security has to extend further than the traditional SDLC, both deeper into the developer’s workflow and outward to the tools letting anyone in the company generate an application.

Code Security Auditor

The Code Security Auditor brings reasoning-driven code scanning throughout your full code repository, detecting exploitable vulnerabilities that can’t be traced with traditional AppSec scanners. 

Rather than flagging every pattern match, it delivers reasoning-based risk detection by tracing cross-file data flows and reconstructing attack chains to assess what’s actually exploitable, enriched with the same cloud exposure context that powers Orca’s broader risk prioritization.

AI AppGen Security

AI app builders like Lovable, Replit, and similar platforms have made it possible for anyone, not just developers, to describe an app and ship a working version in minutes. That kind of usage happens entirely off security’s radar today. Orca’s AI AppGen Security is built to close that gap by:

  • Discovering every shadow app in use and who built it
  • Mapping each app’s APIs, integrations, and data access to show what’s actually exposed
  • Flagging high-risk usage, apps touching sensitive data, using risky APIs, or exposed to the internet, scored by severity.

2. Attack Surface Red Agent

On-demand AI-driven discovery and testing of your external attack surface.

Most teams only find out what’s reachable on their external attack surface after a scan cycle, a bug bounty report, a pentest, or an incident. New subdomains, forgotten endpoints, and exposed admin panels can sit undiscovered for months with no attacker’s-eye view of what’s actually there. 

The Attack Surface Red Agent runs on-demand against your external attack surface, enriched with the cloud context Orca already has about the underlying assets, discovering new addresses and exposed endpoints and probing for web vulnerabilities and exposure risks, so findings come with real risk context instead of a raw scan output.

3. AI Agent Pod

Activate and customize AI agents built for security work, all from one place.

Every security team is being asked to do more with the same headcount, and AI agents are becoming central to how that work gets done, but most teams are stuck stitching together scripts, one-off tools, and manual processes to make it happen. Orca’s new AI Agent Pod closes that gap, giving you one home for the agents doing security work across your environment.

Orca’s Core Agents are specialized agents built out of the box by the Orca team, organized into families by function, Red for attacking, Blue for investigation and triage, and Green for remediation, each purpose-built for a specific need. Orca’s Custom Agents add another layer of flexibility, letting you start from templates and frameworks or build entirely from scratch, so you can shape an agent around your own environment, processes, and use cases. Orca fits the way you work, not the other way around.

Come find us at Black Hat

Orca is at booth 5115 all week. AI is changing what it means to build, and that means it’s changing what it means to secure. We want to show you what that actually looks like for your cloud and AI, your team, and the alerts keeping you up at night. 

If you want to go deeper on any of what we covered here, stay tuned. We’ll be publishing a dedicated blog on each next week.

Book a meeting at Black Hat  |  Request a demo