Illumio is a Customers’ Choice in the 2026 Gartner Peer Insights for Network Security Microsegmentation.

The Zero Trust Hub Editions

Zero Trust trends, insights, and resources for today’s cybersecurity leaders

Subscribe on LinkedIn
August 3, 2026
Want more Zero Trust trends, insights, and resources?
Explore Past Editions

The Monday Microsegment for the week of 8/3/2026

NEWS

Hugging Face Hack Is the Wake-Up Call for Every Defender

In Axios, Illumio CEO and founder Andrew Rubin warns that OpenAI’s hack of Hugging Face shows AI-powered attacks are arriving faster than defenders can respond. He says security teams must prioritize containment over detection to stop breaches from spreading.

Read more
NEWS

AI Guardrails Won’t Stop Rogue Frontier AI Models Alone

In AI Magazine, Raghu Nandakumara warns that AI guardrails alone can’t stop autonomous agents once they start improvising. He argues security teams must prioritize breach containment over trust as AI systems take on more independent action.

Read more
THE WEEKLY BRIEFING

What Black Hat 2026 Can Tell You About Your Own Network

Michael Adjei
Director, Systems Enginering

There's a 90-second walk at Black Hat I look forward to every year. It runs from the Briefings room, where a researcher has just shown a new way to break something organizations depend on, to the Business Hall, where the industry is selling the answers.  

I think more about a different distance, though: the one an attacker covers between the machine they land on and the systems that matter. Zero Trust is how you shorten it.

That’s why this week is worth your attention, even from your desk. Black Hat USA 2026 is underway at Mandalay Bay through Thursday, and what gets demonstrated on stage in August tends to show up in incident reports by winter.

Instead of asking whether a control will keep attackers out, I assume they're already inside and ask what they can reach. If one of those techniques landed on a laptop in your finance team, what could it reach by lunchtime? Answer that, and a week of talks and demos becomes a practical review of your network.

Seeing Black Hat Briefings sessions through a Zero Trust lens

Briefings are peer-reviewed research, and they show you in fifty minutes how something your organization trusts can be made to behave in ways you never planned for.

That word — trust — is the whole problem.

Every technique on that stage works because something believed something else. So put each talk inside your own environment. What would it reach by lunchtime?

Every "yes, it could reach that" points to implicit trust that was granted years ago and never revisited.

The theme is predictable. Threat actors operate two main phases on the way to their ultimate objectives: the start and the spread phases of their attack plan.

Attackers rarely need a fresh exploit to do the ultimate damage. That just opens the door. They just need an open path to spread, which is where microsegmentation turns Zero Trust from a principle into a control.

The Zero Trust question you should be asking

All of it comes back to that one question: if that landed on a laptop in your finance team, what could it reach by lunchtime?

Ask it about a technique demoed on stage, and it's an interesting exercise. Ask it about the workloads, applications, and identities you already run, and it becomes a worklist.

The answer is rarely about the exploit. That only opens the door. It's about what sits around the machine it landed on — standing permissions, identities nobody has reviewed, and the east-west paths between systems that have talked to each other for years without anyone asking why.

That's where microsegmentation turns Zero Trust from a principle into a control. Least-privilege access decides who can log in. Segmentation decides what they can reach once they're in.

Teams who have already mapped the lateral movement in their environment, can answer in minutes, and the answer doubles as a to-do list. Wherever the reach is widest is where you segment first.

What’s changed since last year’s Black Hat

The Business Hall is full of AI agents this year — Summit Day includes an AI Security Summit.

An AI agent is the newest identity on your network. It never sleeps and never wonders why it's been asked to query a payroll database at 3 a.m.

Twelve months ago, most agent deployments were pilots. Now they're in production, wired into critical systems and data, often with permissions nobody has reviewed since the pilot.

So let’s revisit our original question: If one of those agents went bad, what could it reach by lunchtime?

For most organizations that's a harder question than the one about the finance laptop. The laptop got its reach through drift — permissions granted years ago and never revisited. The agent was handed its access on purpose, last quarter, by someone who could tell you exactly why.

It’s no wonder that board expectations are changing. The issue used to be whether you'd spot an incident. Now it's whether you can contain one — which means knowing what the attacker can reach before they get in, not after.

Detection buys you awareness. Segmentation is what keeps the business running while the incident is still open.

If you’re going to Vegas, come find me at the Illumio at booth 4743. If not, watch the Briefings schedule and run the same review from your desk. Pick three talks, imagine each landing inside your environment, and map where the attacker would stop.

In most environments, that answer is still “nowhere.” Zero Trust is the work of changing it.

Read more
STATSHOT

Enabled Isn’t Enforced

Security controls work only when they’re configured correctly and turned on. Password settings fail most often on both desktops and servers, while Kerberoasting checks also reveal broad gaps in service account protection. Desktops show the largest weakness in LSASS safeguards, which help protect credentials stored in memory. Failures tied to NTDS, brute-force protections, and access token manipulation appear less often. Overall, desktops fail more configuration checks than servers across every category shown.