Opens in a new tab
vmblog logo 2024 wht (updated)

Ahead of Black Hat 2026: Backslash Security’s Shahar Man on Why the Endpoint Is the New Frontline for Agentic AI Attacks

Share: 

David Marshall | Published: July 24, 2026
vmblog blackhat usa 2026 qa

As Black Hat USA 2026 approaches, one theme keeps surfacing across the security industry: the explosive growth of agentic AI has quietly created a new attack surface that most enterprise security stacks were never designed to see. AI coding agents, MCP servers, plugins, skills, and hooks are proliferating across developer and employee endpoints, often operating with real privileges to source code, credentials, and sensitive systems, all while flying under the radar of cloud AI security tools, AI gateways, and even traditional EDR.

Ahead of the show, VMblog caught up with Shahar Man, Co-Founder and CEO of Backslash Security, to discuss how his company’s Agentic AI Endpoint Security platform is tackling this emerging challenge. Man shares what attendees can expect at booth #4909 in Las Vegas, including live demonstrations of the company’s Agentic Fabric Graph and a VR experience inviting visitors to “confess their AI sins.” He also digs into the specific threat vectors reshaping the landscape, why the endpoint remains the right control point for securing agentic AI, and the foundational step he believes every security leader should prioritize before chasing advanced detection and response capabilities.

++

VMblog: For readers who may not be familiar, give us the elevator pitch. Who are you, what do you do, and what genuinely sets you apart in today’s crowded cybersecurity market?

Shahar Man: Backslash Security is the Agentic AI Endpoint Security platform, built to secure the complex fabric of AI coding agents, MCP servers, IDEs, plugins, skills, and hooks running across enterprise developer and employee endpoints.

These tools are quickly becoming some of the most powerful and privileged software in the organization, with access to source code, credentials, files, and critical systems. Yet much of that activity happens beyond the reach of cloud AI security, AI gateways, EDR and AppSec. Backslash closes that gap by giving security and AI governance teams continuous visibility into the agentic AI running across their environment, the ability to govern which components and configurations are approved, and real-time protection against threats including prompt injection, data and source exfiltration, malicious or compromised MCPs and abuse of AI agent privileges.

What sets us apart is where we operate and what we understand. We do not just scan what the code agents produce or simply monitor AI traffic on the network. We secure the agentic AI itself, directly on the endpoint where it executes, so enterprises can accelerate AI adoption without losing control of this rapidly expanding attack surface.

VMblog: Black Hat attendees are a discerning crowd. What experiences, live demos or hands-on activities are you bringing to Las Vegas?

Shahar Man: At booth #4909, we will bring the agentic AI attack surface to life through live demonstrations of the Backslash Agentic Fabric Graph. Attendees will be able to see how agents, MCP servers, skills, hooks, plugins and models connect across employee endpoints, including the permissions they hold and the risks those relationships can create.

Rather than stopping at discovery, we will demonstrate how security teams can use that visibility to govern which components are permitted, identify unsafe configurations and protect against risky agent activity in real time.

We are also bringing a more interactive experience to the booth, where attendees can step into VR and “confess their AI sins,” from unapproved agents to risky MCPs and shadow AI. Visitors will have the chance to win one of two Meta Quest 3S headsets during the event.

Backslash will also participate in the inaugural CISO Retreat on August 3, joining the event’s vendor showcase and lightning-talk program for an audience of CISOs and deputy CISOs.

Lastly, Backslash is proud to be sponsoring the Black Hat AI Summit, reflecting our commitment to helping security leaders understand and manage the new risks emerging as agentic AI adoption accelerates.

VMblog: If a CISO walks away remembering exactly one thing about Backslash, what do you want it to be?

Shahar Man: Agentic AI has created a new attack surface on every developer and employee endpoint, and the security stack that most enterprises rely on was not built to see it and protect it.

Security teams may have policies governing which AI services employees should use, but those policies remain on paper when users can install new agents, add external skills, connect MCP servers, or access tools through personal accounts. By the time an agent’s activity triggers a conventional endpoint alert, the agent may have already accessed sensitive information or performed an action it should not have been allowed to take.

Enterprises need a way to understand and control the agentic layer itself, not just respond to the operating-system activity underneath it.

VMblog: The threat landscape heading into Black Hat 2026 looks very different from even 18 months ago. Which specific threat vectors is your solution most directly built to address?

Shahar Man: One of the most important differences with agentic AI is that harmful activity may be carried out through legitimate tools and legitimate permissions. An agent can be manipulated by poisoned context, indirect prompt injection, a compromised skill, or an untrusted MCP server. This may then cause a litany of issues like exposing credentials or transferring sensitive data without ever deploying traditional malware. The individual actions may look normal to tools that cannot understand the agent’s instructions or intended purpose.

Backslash is designed to identify those risks across the agentic environment. That includes shadow agents, unsafe configurations, excessive permissions, unvetted components, prompt injection, data exfiltration, and activity that drifts from the organization’s approved policies.

VMblog: Agentic AI is reshaping both offense and defense. What risk are enterprises underestimating most?

Shahar Man: Enterprises are underestimating how quickly the dependencies surrounding each AI agent multiply the attack surface. Every agent relies on a web of external tools, permissions and data sources, and those dependencies are often shared across users and endpoints. A single compromised or overly permissive component can therefore create exposure far beyond one employee or application.

For an organization with 1,000 employees, this can translate into tens of thousands of interconnected assets, configurations and trust relationships that change continuously. The challenge is not simply securing individual agents, but understanding and controlling the broader agentic AI fabric in which they operate.

Model security and prompt filtering remain important, but they address only part of the problem. Enterprises also need continuous visibility, governance and real-time protection across the endpoint environment where agents access data and take action

VMblog: Why is the endpoint the right control point for agentic AI security?

Shahar Man: The endpoint is becoming the center of agentic AI activity. More powerful CPUs, GPUs and NPUs, combined with local inference frameworks, are making it practical for models and agents to run directly on developer and employee devices rather than relying entirely on the cloud. That places increasingly autonomous software close to source code, credentials, sensitive files and enterprise systems, often operating with the user’s privileges.

This shift creates a gap in the existing security stack. AI gateways see traffic that passes through them, while EDR monitors processes, files and binaries. Neither was designed to understand the full context of an agent’s local activity, like who initiated it, which resources it can access, what tools it is invoking, and whether its actions are consistent with enterprise policy.

That is why protection must operate where the agent actually executes. The endpoint provides the visibility and context needed to govern agentic AI continuously and stop threats such as data exfiltration and privilege abuse before they become conventional security incidents. Agentless assessment can help establish an initial inventory, but real-time protection requires a purpose-built control plane on the endpoint that works alongside EDR, not in place of it.

VMblog: What should sit at the top of every security leader’s priority list in the second half of 2026?

Shahar Man: First and foremost, establishing an accurate baseline of agentic AI usage and activity. Before selecting advanced behavioral controls, security leaders should determine what is already running across the organization, who owns it, what it can access, and whether it has been approved. That inventory should include the surrounding components (MCPs, plugins, etc), not only the primary AI agents employees recognize by name.

From there, organizations can define sanctioned assets, enforce practical guardrails, and begin monitoring for drift or risky actions.

There is understandable excitement around intent analysis and autonomous protection. Those capabilities will continue to improve, but they cannot replace the foundational work of understanding the environment and defining what should be allowed.

VMblog: Beyond the product pitch, what is one piece of hard-won, actionable security wisdom you would give every practitioner who stops by?

Shahar Man: Do not treat an AI agent as a single application. Ask what it is connected to, which tools it can invoke, where its instructions come from, what data it can reach, and how its capabilities change when someone installs a new skill or plugin. The most consequential exposure may not exist in the model itself. It may exist in one of the components surrounding it.

The practical first step is to create visibility and governance before trying to create perfect detection and response capabilities. You cannot govern an environment that you have not yet mapped, and focusing on DR when you have no governance will generate too much noise.

##