Black Hat USA 2026: Cisco's Secure Access Safeguards DNS Amidst Growing Threat Landscape
The Black Hat USA 2026 conference saw Cisco's Secure Access play a crucial role in safeguarding the DNS (Domain Name System) of attendees. Since 2017, Cisco has provided DNS-layer visibility and protection to the Network Operations Center (NOC)/Security Operations Center (SOC) team, giving them an early vantage point into potential threats.
The conference's noisy environment, with security research, demos, and thousands of attendee devices, makes DNS telemetry essential for separating expected activity from suspicious behavior. Building on encrypted DNS controls introduced at Black Hat USA 2025, this visibility remains particularly important as encrypted protocols obscure traditional network telemetry.
Cisco identified 76,331,133 DNS requests across 1.02 million domains and 1,268 identities, with a significant increase in the number of apps accessed compared to previous years. The growth of Generative AI was also visible on the Black Hat network, with nearly twice as many GenAI applications identified compared to last year.
Cisco's Secure Access prevented devices from bypassing organizational DNS inspection through unapproved encrypted resolvers, blocking 79.3% of every blocked DNS request. Mask.icloud.com generated 4.42 million requests, with 99.7% blocked. Apple privacy-relay and encrypted-DNS hostnames collectively accounted for approximately 97.9% of blocks among the top blocked destinations.