
Black Hat USA 2026 is a wrap. The Raxis team is packing up booth 6018 at the Mandalay Bay Convention Center, and we are heading home from Las Vegas with tired feet and a much clearer picture of what security teams are worried about right now.
Here’s what we didn’t expect before we arrived: How many visitors opened with some version of the same question: “Thank goodness there’s actually a company here that isn’t just using AI, but is truly testing our systems. I’ve been looking for someone just like you.”
Where Automation Stops and Testers Start
Here is the short version of what we heard all week: Attackers have gotten faster, and everyone knows it.
That came from the keynote stage, where the conversation kept circling back to AI-assisted vulnerability discovery and how cheap it has become to find a flaw and turn it into a working exploit. When offense gets cheaper, defense has to get sharper.

We also witnessed this in the business hall. It felt like every other booth was selling some version of continuous, autonomous, AI-driven penetration testing or vulnerability management. While this is helpful information, it doesn’t tell organizations what a determined human hacker could actually do. When you think of a human hacker who knows how to use those same tools for targeted exploits to save time while they chain a complex attack, it’s easy to see which test gives you a better picture of your actual risks.
This was not lost on the people who stopped at our booth. Several said they had come to Black Hat specifically to find a firm that still puts senior human testers on an engagement, and they were glad to find Raxis leading with that instead of a platform.
That gap is the whole conversation. A tool will find your missing patch and your open misconfiguration faster than any person can. It will not take a weak password policy, chain it to a forgotten VPN account, pivot across a flat network segment, escalate to domain admin, and then sit down with your board to explain what that would have cost you. Raxis engineers do that by hand on every engagement because that is what a real breach looks like.
Several people we spoke with were excited to learn that Raxis specialized in OT systems and onsite physical penetration testing. With AI and automation taking center stage, these critical tests are getting left behind. Few companies offer them, and they told us that finding that Raxis excels at them was refreshing.

Partners Found Us Too
Much of our week went to excellent partner conversations. We met IT service providers who want to add penetration testing to what they already deliver for their clients as well as pentesting firms who do one or two types of assessment well and want a partner who covers the rest, from web applications and APIs to cloud, wireless, OT, IoT and embedded devices, physical, social engineering, and AI systems. These partnerships strengthen both partners and give the end customers a strong set of security options.
Let’s keep the conversation going
If you stopped by booth 6018 this week, thank you. It was a good week of honest conversations with people who take this work seriously.
If we did not get to talk, the offer stands. Raxis has delivered manual, human-led penetration testing since 2011 with U.S.-based senior engineers who think the way attackers do. We are glad to walk through what a properly scoped engagement would look like for your environment.
Reach out to request a quote or schedule a call.

Brad Herring
About The Exploit
The Exploit is written by Raxis penetration testers. Every post is a technical writeup from someone who runs engagements for a living, with code, command output, and the reasoning behind each step. Topics include exploit research, vulnerability disclosure, tool development, and the offensive techniques showing up in current client work.
Raxis Discovered Vulnerabilities
View the CVEs and bugs that Raxis pentesters have uncovered and submitted.
Work With the Pentesters Who Wrote This Blog
The engineers behind these posts run real engagements every week. Put them on your network, web apps, APIs, or cloud and see what an attacker would find first.
Blog Categories
- AI
- Careers
- Choosing a Penetration Testing Company
- Exploits
- How To
- In The News
- Injection Attacks
- Just For Fun
- Meet Our Team
- Mobile Apps
- Networks
- Password Cracking
- Patching
- Penetration Testing
- Phishing
- PTaaS
- Raxis Discovered Vulnerabilities
- Raxis In The Community
- Red Team
- Security Recommendations
- Social Engineering
- Tips For Everyone
- Web Apps
- What People Are Saying
- Wireless