Execweb is now part of the CyberRisk Alliance. Click here to Learn More

Black Hat USA 2026: Keynotes, Briefings, Vulnerabilities, Tools & Key Takeaways

  • UserVal Tsanev
  • Updated: August 12, 2026
  • 10 min read
  • Facebook Icon
  • Twitter Icon
  • LinkedIn Icon

Black Hat USA 2026, the cybersecurity industry's most established conference, now in its 29th year, ran August 1–6 at the Mandalay Bay Convention Center in Las Vegas. The six-day program delivered 100+ peer-reviewed Briefings, 100+ Trainings, 80+ Arsenal tool demos, 120+ Sponsored Sessions, six Summits, and a Business Hall with 450+ exhibitors. It was the centerpiece of Hacker Summer Camp 2026, flanked by BSidesLV and DEF CON 34 (August 6–9 at the Las Vegas Convention Center). One theme eclipsed everything: agentic AI is now cybersecurity's biggest attack surface and the industry's most urgent governance gap. Black Hat

For organizations navigating cybersecurity buying decisions in 2026, what happened at Black Hat sets the threat and product landscape for the next twelve months.

Black Hat USA 2026 at a Glance

Component Dates What's Included Cost
Trainings Aug 1–4 Multi-day hands-on expert-led courses $3,000–$5,500+ per course
Summit Day Aug 4 6 summits: Healthcare, CISO, AI, Financial Threat, Innovators & Investors, Omdia Analyst Briefings + Summit pass
Briefings Aug 5–6 100+ peer-reviewed 50-min research talks, 10 AM–5 PM $2,295 early / $2,495+ standard
Arsenal Aug 4–6 80+ open-source tool demos (19 used AI) Included with Briefings pass
Business Hall Aug 4–6 450+ exhibitors, sponsored sessions, demos Free Business Pass available
DEF CON 34 Aug 6–9 Hacker conference at LVCC (separate event) $560–$600 for BH attendees

Registration rates varied by registration period and pass type; the figures above reflect the rates used in the 2026 event materials and registration windows.

Recorded Briefings are available on-demand from August 14–September 14, 2026, via the Black Hat Events App for eligible Briefings, Briefings + Training, and Briefings + Summit passholders. Slides and other presentation materials are posted on the Black Hat website by 6:00 PM PT each day following the live Briefings.

Black Hat 2026 by the Numbers

Metric Value
Days of programming 6
Peer-reviewed Briefings 100+
Arsenal tools (AI-powered) 80+ (19)
Exhibitors promoting AI or agentic capabilities 235 of 450 (52%+)
Machine-to-human identity ratio 109:1
AI patches that failed 54%
Investigations involving identity/privilege 75%
Attacker breakout time Under 30 minutes

Sources: SecurityWeek, TechRepublic

The Dominant Theme: Agentic AI Is the New Attack Surface

An exhibitor analysis by Andy Ellis found that 235 of 450 vendors marketed AI or agentic capabilities, highlighting how prominently AI security featured across the Black Hat 2026 show floor.

  • 109:1 machine-to-human identity ratio (Palo Alto Networks, up from 82:1)
  • 45:1 NHI-to-human ratio, with 78% of organizations lacking formal policies for managing AI identities, according to Cyera/Oasis Security research.
  • 88% of organizations reported a confirmed or suspected AI-agent security incident, according to Gravitee research cited by Okta.
  • Only 22% govern agents as distinct identities
  • 26% of organizations have deployed purpose binding for AI agents; 21% have an AI kill switch; and 28% have AI-specific DLP policies, according to Kiteworks.
  • Every major vendor shipped "agent governance" products in response

The takeaway: Every AI agent is an identity with system access, and the governance layer barely exists. For CISOs evaluating how this shifts priorities, Execweb connects security leaders with vendors addressing this gap.

Keynotes: Cyber Power in the Age of AI

Black Hat USA 2026 featured its major keynote programming across August 4–6, with AI, cyber policy, and vulnerability research at the center of the discussions.

Sean Cairncross: Cyber Power in the Age of AI

Opening Session: Tuesday, August 4 at 4:15 PM

  • Sean Cairncross (White House National Cyber Director) led a fireside chat on U.S. cyber policy in the AI era.
  • The discussion examined how U.S. cyber policy is evolving amid rapid AI adoption, government-industry collaboration, critical infrastructure protection, and the changing role of offensive and defensive cyber operations.

David Weston: Agentic Security

Opening Session: Wednesday, August 5 at 9:15 AM

  • David Weston (Microsoft) presented on agentic security and the changing security environment created by AI-powered vulnerability discovery and exploit generation.
  • The discussion focused on why defenders may need to move from reactive patching toward proactive strategies, including memory-safe languages, formal verification, and automated remediation.

Yan Shoshitaishvili: Vulnerability Research in the Agentic Age

Opening Session: Thursday, August 6 at 9:15 AM

  • Yan Shoshitaishvili (Arizona State University) discussed the scientific foundations of vulnerability research and how automation and AI are changing vulnerability discovery.
  • His research background spans vulnerabilities across IoT, browsers, kernels, and bootloaders.

Black Hat's official 2026 keynote announcement confirms David Weston and Yan Shoshitaishvili as additional keynote speakers.

Key Vulnerabilities & Research Disclosed

Black Hat USA 2026 revealed a wide range of vulnerabilities and research findings, from network-level attacks and critical infrastructure flaws to emerging risks in AI coding agents, cloud platforms, and non-human identities.

NatJack Attack Class (Malcolm Stagg, Synack)

  • New class of attacks exploiting trust assumptions in NAT
  • 4 techniques: TCP connection hijacking, DNS response spoofing, port mapping exposure, NAT table exhaustion
  • Affects Windows, Linux, macOS independently
  • CVE-2026-56181 (CVSS 8.3): Windows NAT / Hyper-V
  • CVE-2026-63913 (CVSS 8.2): Linux Netfilter conntrack

Cisco IMC Vulnerability

  • CVE-2026-20200: Critical vulnerability in Cisco Integrated Management Controller enabling privileged access
  • Proof-of-concept exploit demonstrated

Critical Flaws in AI Coding Agents (Novee)

  • Flaws found in Anthropic, Google, and OpenAI coding agents
  • Attack via a single malicious GitHub issue could enable RCE, credential theft, and supply chain compromise
  • Found in vendors' own repos running default configurations
  • All three vendors released mitigations.

Cloudflare Workers Sandbox Escape (Check Point Research)

  • 5 memory corruption vulnerabilities, 2 rated Critical
  • URLPattern flaw: cross-tenant data access in shared memory
  • Use-after-free in node:zlib: chained to full sandbox escape from prompt injection
  • Fixed in Workers v1.20260619.1

(Check Point Blog)

PleaseFix Vulnerability Class (Zenity)

  • Flaws in agentic browsers that make social engineering easy
  • Exploits weaknesses in cross-origin request handling

AI-Generated Patches Failing (1Password Off-By-1 Labs)

  • 54% of AI-generated security patches failed to fix the original vulnerability
  • Evaluated 6,000+ patches across recent open-source vulnerabilities
  • Some patches introduced new vulnerabilities

Zenity Malicious Skills Campaign

  • Active campaign distributed through Vercel's skills.sh
  • 1.7 million aggregate installs across affected skill family
  • Disrupted by Zenity and Vercel

Dormant Non-Human Identities (Aleksandr Krasnov)

  • Open-source tool released to detect trust paths from dormant NHIs
  • Highlights how inactive machine identities create security blind spots

Unit 42 NOVA Autonomous Vulnerability Research

  • Analyzed 3,915 open-source projects in 2 months
  • Confirmed 14,090 vulnerabilities, 99.4% previously unreported

BeyondTrust Phantom Labs Index

  • 75% of completed investigations involved identity or privilege
  • Root causes: credential/secret exposure (18%), identity relationship exposure (11%), excessive privilege (11%), identity misconfiguration (10%), lateral movement (6%)
  • Coordinated disclosures involving OpenAI Codex and AWS Bedrock AgentCore

CrowdStrike 2026 Threat Hunting Report

  • Attacker breakout times dropping below 30 minutes
  • Widespread malware use of direct-to-IP connections bypassing DNS monitoring

Dataminr Threat Landscape Report

  • Average patch window in H1 2026 grew 11 days longer
  • 69.2% jump in alerts from H2 2025 (TechTarget)

image3

Arsenal Tools & Key Takeaways

Open-Source Tools Showcase

Arsenal showcased 80+ tools across offensive security, defensive tooling, cloud security, AI research, and malware analysis. 19 tools incorporated AI (per Chris Wysopal). New for 2026: Arsenal Lab, offering hands-on practice with tools and targets guided by creators. Black Hat describes Arsenal as a place for researchers to demonstrate open-source tools and interact directly with attendees.

Notable tools released:

FAInd my XPC (XM Cyber) discovers macOS trust flaws enabling unprivileged-to-root code execution

Offensive OCI Toolset (XM Cyber) maps Oracle Cloud permissions, exposing hidden privilege-escalation paths

NHI Trust Path Detector (Aleksandr Krasnov) identifies dormant non-human identity risks

Category to watch: automated adversarial testing for multi-step AI agents not "can I jailbreak the model" but "can I poison one tool result and make the agent exfiltrate data three steps later."

10 Key Takeaways from Black Hat 2026

  1. AI agents are a new identity class; they need governance equal to human users, and almost nobody has it yet.
  2. Offensive AI is outpacing defense; red team agents are now training blue team counterparts.
  3. Identity and privilege are the #1 root cause present in 75% of investigations.
  4. Patch windows are growing 11 days longer while attacker breakout times shrink to under 30 minutes.
  5. AI-generated patches fail 54% of the time and can introduce new vulnerabilities.
  6. Non-human identities are exploding at a 109:1 ratio, with almost no governance.
  7. Supply chain attacks extend to AI tooling; coding agents from major vendors were compromised via GitHub issues.
  8. NAT is no longer a safe assumption; NatJack affects all major operating systems.
  9. Healthcare cybersecurity hit the main stage at Black Hat's inaugural Healthcare Summit with HIMSS.
  10. The industry finds risk faster than it fixes it; governance tools outnumber prevention tools on the show floor.

Top Vendor Announcements

Vendor Announcement
SentinelOne Governed closed-loop response via Purple AI; Wayfinder expansion with Anthropic models
Zero Networks Least Agency Enforcement — microsegmentation + JIT MFA for AI agents
Acalvio Deception Guardrails — decoys and honeytokens protecting AI agents
Zenity AI Total — free threat intelligence for AI agent skill analysis
CrowdStrike Falcon Fund investment in Above Security for insider risk
Salt Security AWS WAF Managed Ruleset for AI agents and API protection
Vectra AI Vectra AI Pro launch
ArmorCode Vulnerability remediation agents

Full coverage: SecurityWeek Part 1, 2, 3 and 4

Summits, New Programs & Extras

Black Hat USA 2026 included six Summits on August 4:

  • Healthcare Summit: Inaugural summit with HIMSS, responding to the surge in healthcare cyberattacks
  • CISO Summit: 12th year, invite-only and focused on confidential strategy conversations
  • AI Summit: 3rd year, focused on practical AI applications and security
  • Financial Threat Summit: Cybersecurity risks specific to the financial sector
  • Innovators & Investors Summit: Founders, investors and CISOs examining how cybersecurity is being redefined
  • Omdia Analyst Summit: Data-driven perspectives on threats, M&A, funding and enterprise security

The summit program brought together executives and experts from organizations including Anthropic, CVS Health, TD Bank and the U.S. Department of Justice. The official Black Hat schedule confirms August 4 as Summit Day.

  • New programs: Cyber War Forum and Black Hat(HER) (diversity in cybersecurity).
  • Books launched: The End of Guessing (Jeremiah Grossman & Robert Hansen) and Code War (Allie Mellen, Forrester).
  • Titanium sponsors: Armis, Cisco, Qualys, ReliaQuest, Safe Security, SentinelOne, ServiceNow, ThreatLocker.

Briefings vs. Training vs. Summits vs. Arsenal

Briefings Trainings Summits Arsenal
Dates Aug 5–6 Aug 1–4 Aug 4 Aug 4–6
Format 50-min research talks Multi-day hands-on courses Full-day sector panels Live tool demos
Focus New vulns, attack/defense research Skill-building Industry strategy Downloadable open-source tools
Cost $2,295–$2,495+ $3,000–$5,500+ Briefings + Summit pass Included with Briefings
Best for Researchers, practitioners Engineers CISOs, executives Tool builders, evaluators

Black Hat's official schedule confirms Trainings ran August 1–4 and Briefings ran August 5–6, while Summit Day took place August 4.

image1

Black Hat 2026: What Were the Biggest Discussion Topics?

Across the Briefings, keynotes, Summits, Arsenal and Business Hall, several discussions consistently stood out:

  • Agentic AI security and governance
  • AI agents as a new identity class
  • Non-human identities and machine identities
  • AI-powered vulnerability discovery
  • AI coding-agent security
  • Identity and privilege management
  • Supply chain security
  • Automated vulnerability research
  • Cloud and container security
  • AI-generated security patches
  • Critical infrastructure protection
  • Healthcare cybersecurity
  • Offensive and defensive AI
  • Autonomous security operations

The official event also introduced an AI Zone in the Business Hall, with live demonstrations, hands-on activities, and scheduled content focused on AI in cybersecurity.

Black Hat USA 2026 and Hacker Summer Camp

Black Hat USA 2026 was part of the broader Las Vegas cybersecurity week commonly referred to as Hacker Summer Camp, bringing together BSidesLV, Black Hat USA, and DEF CON.

Black Hat ran August 1–6 at Mandalay Bay, while DEF CON 34 ran August 6–9 at the Las Vegas Convention Center. This makes August 6 an important transition point for attendees moving between the two events.

Is Black Hat the same as DEF CON? No. Black Hat is more structured around peer-reviewed research, professional training, vendors, and enterprise cybersecurity, while DEF CON is community-driven and known for villages, contests, hands-on hacking, and its broader hacker culture.

What Were the Biggest Outcomes of Black Hat 2026?

The biggest outcome was not a single vulnerability or product announcement. It was a shift in how the cybersecurity industry is thinking about AI agents.

AI agents are moving from experimental assistants toward systems capable of accessing data, using tools, making decisions, and taking actions. That creates a security problem that looks increasingly similar to identity and access management but at machine scale.

The Black Hat 2026 discussions therefore moved beyond traditional AI model security toward:

  • Who owns an AI agent?
  • What permissions should an agent have?
  • How can organizations monitor agent activity?
  • What happens when an agent is compromised?
  • Can an organization immediately stop an autonomous agent?
  • How should organizations govern thousands of non-human identities?
  • How can security teams test multi-step agent workflows for attacks?

For security leaders, this means AI security is no longer only about protecting the model. It is also about controlling what the model can do.

Looking Ahead: Black Hat USA 2027 and DEF CON 35

Black Hat's 2026 event has already set the stage for the next cycle of cybersecurity conversations.

  • Black Hat USA 2027 is scheduled for July 31–August 5, 2027, at the Mandalay Bay Convention Center in Las Vegas.
  • DEF CON 35 is confirmed for August 5–8, 2027, at the Las Vegas Convention Center, and people can check the DEF CON Forums.

If this year's signals hold, agentic AI governance will move from "emerging" to "mandatory," identity-first architectures will dominate vendor roadmaps, and the gap between offensive AI capability and defensive readiness will drive the industry's most critical conversations.

Security leaders planning ahead can benchmark against these trends through Execweb.

FAQ

What is the NatJack attack class from Black Hat 2026?

NatJack is a new attack class exploiting trust assumptions in NAT. It affects Windows, Linux and macOS using four techniques: TCP hijacking, DNS spoofing, port exposure and NAT table exhaustion. CVEs assigned include CVE-2026-56181 and CVE-2026-63913.

What is agentic AI security?

Securing AI agents that autonomously plan, reason and execute actions with system access. At Black Hat 2026, agents were treated as a new identity class requiring governance, access controls, and kill switches.

Where can I access Black Hat 2026 Briefings recordings?

Recorded Briefings are available on-demand August 14–September 14, 2026 through the Black Hat Events app for eligible passholders. Presentation materials are also made available through the Black Hat Briefings site.

What did 1Password find about AI-generated patches?

54% of 6,000+ evaluated patches failed to fix the original vulnerability. Some patches introduced new flaws.

What is Hacker Summer Camp 2026?

The annual convergence of BSidesLV, Black Hat USA and DEF CON in Las Vegas each August drawing tens of thousands of security professionals.

How are non-human identities (NHIs) a security risk?

Enterprises increasingly manage large numbers of machine and non-human identities. Dormant or over-provisioned NHIs create blind spots for privilege escalation, lateral movement and unauthorized access.

What flaws were found in AI coding agents?

Novee disclosed vulnerabilities in Anthropic, Google and OpenAI coding agents. A single malicious GitHub issue could trigger RCE, credential theft and supply chain compromise. All three vendors released mitigations.

Is Black Hat the same as DEF CON?

No. Black Hat (Aug 1–6, Mandalay Bay) is corporate and vendor-heavy with peer-reviewed research, training and professional programming. DEF CON 34 (Aug 6–9, LVCC) is community-driven with villages, CTFs and hands-on hacking. Together they form the core of Hacker Summer Camp.

  • Facebook Icon
  • Twitter Icon
  • LinkedIn Icon
  • 0 views
  • 0 comments

Recent Posts

See All
featured image thumbnail for post How to Sell to CISOs in 2026: Understanding the Modern Buying Process Before You Lose the Deal
featured image thumbnail for post Cybersecurity Buying Trends in 2026: How Cyber-Enabled Fraud Is Changing What Buyers Want
featured image thumbnail for post Top 11 Things CISOs Want From Cybersecurity Vendors in 2026

Comment

Cancel