Black Hat USA 2026, the cybersecurity industry's most established conference, now in its 29th year, ran August 1–6 at the Mandalay Bay Convention Center in Las Vegas. The six-day program delivered 100+ peer-reviewed Briefings, 100+ Trainings, 80+ Arsenal tool demos, 120+ Sponsored Sessions, six Summits, and a Business Hall with 450+ exhibitors. It was the centerpiece of Hacker Summer Camp 2026, flanked by BSidesLV and DEF CON 34 (August 6–9 at the Las Vegas Convention Center). One theme eclipsed everything: agentic AI is now cybersecurity's biggest attack surface and the industry's most urgent governance gap. Black Hat
For organizations navigating cybersecurity buying decisions in 2026, what happened at Black Hat sets the threat and product landscape for the next twelve months.
| Component | Dates | What's Included | Cost |
|---|---|---|---|
| Trainings | Aug 1–4 | Multi-day hands-on expert-led courses | $3,000–$5,500+ per course |
| Summit Day | Aug 4 | 6 summits: Healthcare, CISO, AI, Financial Threat, Innovators & Investors, Omdia Analyst | Briefings + Summit pass |
| Briefings | Aug 5–6 | 100+ peer-reviewed 50-min research talks, 10 AM–5 PM | $2,295 early / $2,495+ standard |
| Arsenal | Aug 4–6 | 80+ open-source tool demos (19 used AI) | Included with Briefings pass |
| Business Hall | Aug 4–6 | 450+ exhibitors, sponsored sessions, demos | Free Business Pass available |
| DEF CON 34 | Aug 6–9 | Hacker conference at LVCC (separate event) | $560–$600 for BH attendees |
Registration rates varied by registration period and pass type; the figures above reflect the rates used in the 2026 event materials and registration windows.
Recorded Briefings are available on-demand from August 14–September 14, 2026, via the Black Hat Events App for eligible Briefings, Briefings + Training, and Briefings + Summit passholders. Slides and other presentation materials are posted on the Black Hat website by 6:00 PM PT each day following the live Briefings.
| Metric | Value |
|---|---|
| Days of programming | 6 |
| Peer-reviewed Briefings | 100+ |
| Arsenal tools (AI-powered) | 80+ (19) |
| Exhibitors promoting AI or agentic capabilities | 235 of 450 (52%+) |
| Machine-to-human identity ratio | 109:1 |
| AI patches that failed | 54% |
| Investigations involving identity/privilege | 75% |
| Attacker breakout time | Under 30 minutes |
Sources: SecurityWeek, TechRepublic
An exhibitor analysis by Andy Ellis found that 235 of 450 vendors marketed AI or agentic capabilities, highlighting how prominently AI security featured across the Black Hat 2026 show floor.
The takeaway: Every AI agent is an identity with system access, and the governance layer barely exists. For CISOs evaluating how this shifts priorities, Execweb connects security leaders with vendors addressing this gap.
Black Hat USA 2026 featured its major keynote programming across August 4–6, with AI, cyber policy, and vulnerability research at the center of the discussions.
Sean Cairncross: Cyber Power in the Age of AI
Opening Session: Tuesday, August 4 at 4:15 PM
David Weston: Agentic Security
Opening Session: Wednesday, August 5 at 9:15 AM
Yan Shoshitaishvili: Vulnerability Research in the Agentic Age
Opening Session: Thursday, August 6 at 9:15 AM
Black Hat's official 2026 keynote announcement confirms David Weston and Yan Shoshitaishvili as additional keynote speakers.
Black Hat USA 2026 revealed a wide range of vulnerabilities and research findings, from network-level attacks and critical infrastructure flaws to emerging risks in AI coding agents, cloud platforms, and non-human identities.
(Check Point Blog)
Open-Source Tools Showcase
Arsenal showcased 80+ tools across offensive security, defensive tooling, cloud security, AI research, and malware analysis. 19 tools incorporated AI (per Chris Wysopal). New for 2026: Arsenal Lab, offering hands-on practice with tools and targets guided by creators. Black Hat describes Arsenal as a place for researchers to demonstrate open-source tools and interact directly with attendees.
Notable tools released:
FAInd my XPC (XM Cyber) discovers macOS trust flaws enabling unprivileged-to-root code execution
Offensive OCI Toolset (XM Cyber) maps Oracle Cloud permissions, exposing hidden privilege-escalation paths
NHI Trust Path Detector (Aleksandr Krasnov) identifies dormant non-human identity risks
Category to watch: automated adversarial testing for multi-step AI agents not "can I jailbreak the model" but "can I poison one tool result and make the agent exfiltrate data three steps later."
| Vendor | Announcement |
|---|---|
| SentinelOne | Governed closed-loop response via Purple AI; Wayfinder expansion with Anthropic models |
| Zero Networks | Least Agency Enforcement — microsegmentation + JIT MFA for AI agents |
| Acalvio | Deception Guardrails — decoys and honeytokens protecting AI agents |
| Zenity | AI Total — free threat intelligence for AI agent skill analysis |
| CrowdStrike | Falcon Fund investment in Above Security for insider risk |
| Salt Security | AWS WAF Managed Ruleset for AI agents and API protection |
| Vectra AI | Vectra AI Pro launch |
| ArmorCode | Vulnerability remediation agents |
Full coverage: SecurityWeek Part 1, 2, 3 and 4
Black Hat USA 2026 included six Summits on August 4:
The summit program brought together executives and experts from organizations including Anthropic, CVS Health, TD Bank and the U.S. Department of Justice. The official Black Hat schedule confirms August 4 as Summit Day.
| Briefings | Trainings | Summits | Arsenal | |
|---|---|---|---|---|
| Dates | Aug 5–6 | Aug 1–4 | Aug 4 | Aug 4–6 |
| Format | 50-min research talks | Multi-day hands-on courses | Full-day sector panels | Live tool demos |
| Focus | New vulns, attack/defense research | Skill-building | Industry strategy | Downloadable open-source tools |
| Cost | $2,295–$2,495+ | $3,000–$5,500+ | Briefings + Summit pass | Included with Briefings |
| Best for | Researchers, practitioners | Engineers | CISOs, executives | Tool builders, evaluators |
Black Hat's official schedule confirms Trainings ran August 1–4 and Briefings ran August 5–6, while Summit Day took place August 4.
Across the Briefings, keynotes, Summits, Arsenal and Business Hall, several discussions consistently stood out:
The official event also introduced an AI Zone in the Business Hall, with live demonstrations, hands-on activities, and scheduled content focused on AI in cybersecurity.
Black Hat USA 2026 was part of the broader Las Vegas cybersecurity week commonly referred to as Hacker Summer Camp, bringing together BSidesLV, Black Hat USA, and DEF CON.
Black Hat ran August 1–6 at Mandalay Bay, while DEF CON 34 ran August 6–9 at the Las Vegas Convention Center. This makes August 6 an important transition point for attendees moving between the two events.
Is Black Hat the same as DEF CON? No. Black Hat is more structured around peer-reviewed research, professional training, vendors, and enterprise cybersecurity, while DEF CON is community-driven and known for villages, contests, hands-on hacking, and its broader hacker culture.
The biggest outcome was not a single vulnerability or product announcement. It was a shift in how the cybersecurity industry is thinking about AI agents.
AI agents are moving from experimental assistants toward systems capable of accessing data, using tools, making decisions, and taking actions. That creates a security problem that looks increasingly similar to identity and access management but at machine scale.
The Black Hat 2026 discussions therefore moved beyond traditional AI model security toward:
For security leaders, this means AI security is no longer only about protecting the model. It is also about controlling what the model can do.
Black Hat's 2026 event has already set the stage for the next cycle of cybersecurity conversations.
If this year's signals hold, agentic AI governance will move from "emerging" to "mandatory," identity-first architectures will dominate vendor roadmaps, and the gap between offensive AI capability and defensive readiness will drive the industry's most critical conversations.
Security leaders planning ahead can benchmark against these trends through Execweb.
What is the NatJack attack class from Black Hat 2026?
NatJack is a new attack class exploiting trust assumptions in NAT. It affects Windows, Linux and macOS using four techniques: TCP hijacking, DNS spoofing, port exposure and NAT table exhaustion. CVEs assigned include CVE-2026-56181 and CVE-2026-63913.
What is agentic AI security?
Securing AI agents that autonomously plan, reason and execute actions with system access. At Black Hat 2026, agents were treated as a new identity class requiring governance, access controls, and kill switches.
Where can I access Black Hat 2026 Briefings recordings?
Recorded Briefings are available on-demand August 14–September 14, 2026 through the Black Hat Events app for eligible passholders. Presentation materials are also made available through the Black Hat Briefings site.
What did 1Password find about AI-generated patches?
54% of 6,000+ evaluated patches failed to fix the original vulnerability. Some patches introduced new flaws.
What is Hacker Summer Camp 2026?
The annual convergence of BSidesLV, Black Hat USA and DEF CON in Las Vegas each August drawing tens of thousands of security professionals.
How are non-human identities (NHIs) a security risk?
Enterprises increasingly manage large numbers of machine and non-human identities. Dormant or over-provisioned NHIs create blind spots for privilege escalation, lateral movement and unauthorized access.
What flaws were found in AI coding agents?
Novee disclosed vulnerabilities in Anthropic, Google and OpenAI coding agents. A single malicious GitHub issue could trigger RCE, credential theft and supply chain compromise. All three vendors released mitigations.
Is Black Hat the same as DEF CON?
No. Black Hat (Aug 1–6, Mandalay Bay) is corporate and vendor-heavy with peer-reviewed research, training and professional programming. DEF CON 34 (Aug 6–9, LVCC) is community-driven with villages, CTFs and hands-on hacking. Together they form the core of Hacker Summer Camp.
Comment