BLACKHAT 2026
2026 BLACKHAT 2026 Black Hat Briefings (běžně označované jako Black Hat ) je konference o počítačové bezpečnosti , která poskytuje bezpečnostní konzultace, školení a instruktáže hackerům, korporacím a vládním agenturám po celém světě.    

DATE

NAME

INFO

CATEGORY

SUBCATE

2026

Beyond Seccomp: Breaking and Rebuilding Syscall Filtering for Microservices

In cloud-native environments, system calls serve as both the primary attack surface and the last line of defense for containers. However, widely deployed commercial container security tools still inherit structural design limitations that create critical blind spots when protecting microservices.

CONGRESS

BLACKHAT 2026 USA

2026 Bye Bye AI: How We Hacked the AI Shopping Assistant of a Top 3 US Retailer AI agents have become powerful digital touchpoints in retail, guiding product discovery, influencing purchases, and acting as the front door to the customer experience. For major retailers, these assistants are a core marketing and sales channel used by millions of shoppers daily. Unfortunately, they are also far easier to compromise than most organizations realize.

CONGRESS

BLACKHAT 2026 USA

2026

Detection Engineering Beyond the Inbox Email gateways fail to detect 63% of targeted phishing in operationally-constrained environments, from our 18-month deployment processing 2.3M+ daily emails. Every industry has structural operational requirements creating email security blind spots gateways cannot solve.

CONGRESS

BLACKHAT 2026 USA

2026 GitHub Can Tell You're Being Hacked. You're Just Not Listening: Building EDR for GitHub from Its Own Event Stream Open-source repositories are critical infrastructure, yet GitHub - where supply chain attacks often originate - remains largely unmonitored. We studied dozens of real-world supply chain attacks spanning 2018–2026 and built a behavioral anomaly scoring model to determine what defenders can detect from GitHub platform telemetry combined with direct Git object-level inspection.

CONGRESS

BLACKHAT 2026 USA

2026

Hunting LANDFALL: From Overlooked Images to State-Linked Mobile Spyware In mid-2024, a set of malformed DNG image files carrying a fully-featured Android spyware were uploaded to VirusTotal from Iraq, Iran, and Morocco. They sat there, undetected, for over a year. Inside was LANDFALL, a previously unknown commercial-grade Android spyware framework exploiting a zero-day in Samsung's image processing library, to achieve zero-click compromise of Galaxy devices, likely via weaponized images delivered through WhatsApp.

CONGRESS

BLACKHAT 2026 USA

2026 LANJack: Turning Ads into IoT Recon Tools You visit a legitimate website. A trusted brand advertisement loads. Nothing looks suspicious. No phishing page, no exploit kit, no visible signs of an attack. Meanwhile, your browser is silently scanning your internal network, mapping your LAN and identifying connected devices.

CONGRESS

BLACKHAT 2026 USA

2026

Policy Meetup: Government Panel Discussion on AI and the New Era of Cyber Resilience Agentic AI has moved the security conversation past scale and speed. These systems reason across multiple steps, write and execute code, and take consequential actions in live environments. A failure, a manipulation, or a compromise no longer stays a model problem. It becomes an operational security incident. Governments are weighing that risk as they connect agentic systems to networks supporting critical national functions.

CONGRESS

BLACKHAT 2026 USA

2026 Thinking Beyond the Code: Contrarian Thinking to AI and Lessons From a Life in Discovery In an era increasingly defined by the algorithmic logic of Large Language Models, the true frontier of security isn't just about better code—it's about seeing the world differently.

CONGRESS

BLACKHAT 2026 USA

2026

Turning Enterprise Update Servers Into Backdoor Factories (0_o) Windows Server Update Services (WSUS) sits at the heart of enterprise patch management, responsible for distributing updates across thousands of endpoints. Its privileged position in the network makes it a high-value target. A compromised WSUS server enables lateral movement, persistent footholds, and organization-wide implant deployment at scale.

CONGRESS

BLACKHAT 2026 USA

2026 When Queues Become Vulnerabilities: Reverse Engineering GCD, XPC Races, and macOS Detection Engineering While many macOS services rely on Grand Central Dispatch (GCD) for concurrency, the underlying kernel integration is often treated as a black box, even by experienced engineers. This Briefing opens that box. From the perspective of a detection engineer and macOS security researcher, this Briefing will map how libdispatch interfaces with the XNU kernel's scheduling infrastructure, focusing on pthread work queues, Mach ports, and quality of service (QoS) propagation.

CONGRESS

BLACKHAT 2026 USA

2026

A Front-Row Seat to APT Operations: How OPSEC Failures Exposed a Malware Supplier We have spent years tracking adversaries across the Asia-Pacific region. This Briefing presents what may be our most revealing case: a single OPSEC failure by a malware supplier that didn't just expose one campaign — it exposed an entire ecosystem.

CONGRESS

BLACKHAT 2026 USA

2026 AI and the Future of Cyber Defense Panel AI and Cyber from Frontier AI models are crossing capability thresholds that reshape both the offensive and defensive sides of cybersecurity. They can now meaningfully accelerate vulnerability discovery, exploit development, and attack execution — compressing timelines for attackers targeting critical infrastructure. At the same time, these capabilities offer defenders an asymmetric advantage if deployed responsibly and at scale.

CONGRESS

BLACKHAT 2026 USA

2026

Burning Tears of PHP's Memory Hardening PHP introduced new heap hardening measures for its heap allocator, ZendMM, in April 2024. This Briefing asks a simple question: how much protection do these latest mitigations really buy against a determined attacker?

CONGRESS

BLACKHAT 2026 USA

2026 C and Its Consequences: The Source Is Just a Suggestion int x = k; if (x == 1 && x == 2) { printf("this is possible"); } Modern compilers don't mindlessly translate your code - they entirely rewrite it. By the time C reaches machine code, it's been reshaped by frontend lowering, IR optimizations, register allocation, and backend codegen - a deep, multi-stage pipeline making decisions you can't see.

CONGRESS

BLACKHAT 2026 USA

2026

Defensive V Offensive? - How Do We Balance The Needs Of The Many The UK like many countries must balance the offensive and the defensive. Since 2016, the NCSC has worked to make the UK the safest place to live and work online, where we counter cyber threats from adversaries planning to do us harm.

CONGRESS

BLACKHAT 2026 USA

2026 From Prompts to Pipelines: Building Agentic Detection Engineering and Threat Hunting Detection engineering and threat hunting remain bottlenecked by the gap between threat intelligence and deployed defenses.

CONGRESS

BLACKHAT 2026 USA

2026

Managing Security Culture Half Life This Briefing pairs two consecutive CSOs from the same high-profile organization — the Democratic National Committee, breached by two Russian intelligence services in 2016 — to examine what the security industry almost never gets to see: an honest succession.

CONGRESS

BLACKHAT 2026 USA

2026 Pre-auth RCE in Enterprise Java: When Middleware Becomes the Exploit Enterprise Java platforms still expose critical pre-authentication attack paths through middleware features that were never designed to handle untrusted input.

CONGRESS

BLACKHAT 2026 USA

2026

Threat Modeling LLMs: The PHANTOM-B model Security engineers shipping LLM products face a painful mismatch: the threat landscape is complex and evolving, the boss wants it deployed yesterday, and existing resources — MITRE ATLAS, NIST AI RMF, hundreds of academic papers — are built for thoroughness, not speed.

CONGRESS

BLACKHAT 2026 USA

2026 Attacking and Defending AI Browsers Implementing Kubernetes namespace-based multi-tenancy is challenging, and its isolation is generally considered less effective than control-plane isolation. That's why the latter is often recommended ... and also implemented? Not really, as workloads such as machine learning, pipelines, and scripting capabilities are increasingly common in enterprise environments. And they can introduce unobvious multi-tenancy in clusters.

CONGRESS

BLACKHAT 2026 USA

2026

BTR Reforged: Weaponizing Defender's Remediation Driver as a Kernel Operation Primitive What if a trusted security component could be repurposed into an attacker-controlled kernel primitive? What if a signed Microsoft remediation driver could be instructed to execute arbitrary file and registry operations from Ring 0—without exploits, vulnerabilities, or memory corruption?

CONGRESS

BLACKHAT 2026 USA

2026 Can AI Do Novel Security Research? Meet the HTTP Terminator We all know AI can find bugs. After a decade of research, I asked a harder question: can an autonomous system invent new attack techniques, and use them to hack live websites at scale? Building this sounded like a bad idea, so I did it.

CONGRESS

BLACKHAT 2026 USA

2026

GPUBreach: Privilege Escalation Attacks on GPUs Using Rowhammer Rowhammer attacks have been extensively studied on CPUs, where they have enabled powerful exploits, including privilege escalation. In contrast, Rowhammer on NVIDIA GPUs, despite recently demonstrated by GPUHammer attacks, has largely been viewed as low impact, limited to inducing random bit flips that merely degrade machine learning accuracy. In this Briefing, we will overturn that assumption and show that GPU Rowhammer can be weaponized into a full-system compromise.

CONGRESS

BLACKHAT 2026 USA

2026 One Click to System: Exploiting Bixby's Trust Model for Full Device Compromise During the 2025 Mobile Pwn2Own competition, we identified a series of vulnerabilities affecting Samsung devices. Chained together, these issues resulted in remote system-level compromise triggered by a single user interaction.

CONGRESS

BLACKHAT 2026 USA

2026

Scambuster: Social Engineering Scammers at Scale Most security teams get a scam email and delete it. That's the standard move. Block it, move on, forget it.

CONGRESS

BLACKHAT 2026 USA

2026

The CoreBreak Attack: Turning AI Agents into Credentials Exfiltration Vectors Building an AI agent? We all do.Struggling to figure out how to make it secure? You're not alone.
Counting on your cloud provider's AI agent platform to handle security for you? It's time to think again.

CONGRESS

BLACKHAT 2026 USA

2026 The Good, the Bad, and the Ugly of AI Security Artificial intelligence is fundamentally reshaping cybersecurity for both attackers and defenders, but the uplifts in capabilities are asymmetrical. Our research presents a comprehensive analysis of how AI is removing long-standing operational bottlenecks across offensive and defensive cyber operations, revealing where the resulting capability gains are greatest and why they are inherently asymmetric.

CONGRESS

BLACKHAT 2026 USA

2026 The 'Breaking' News: The OpenAI–Hugging Face Incident - A Technical Reconstruction and Its Implications for AI In this talk, OpenAI security engineers and researchers will reconstruct the OpenAI-Hugging Face incident and examine its implications for AI security, cyber resilience, and alignment.

CONGRESS

BLACKHAT 2026 USA

2026

Anatomy of a Takedown: Inside the Operation That Broke LockBit LockBit was the most prolific ransomware-as-a-service operation the world has seen. For four years, it operated as if law enforcement could not touch it. It accounted for one in four ransomware attacks globally, victimized over 2,500 organizations across 120 countries, collected more than $500 million in ransom payments, and built a 194-affiliate operation whose leader went out of his way to project invincibility.

CONGRESS

BLACKHAT 2026 USA

2026 Apple macOS Kernel Exploitation with MIE: Building on the Ashes of 100 Vulnerabilities On modern Apple systems, the AI-powered flood of vulnerabilities does not immediately lead to a flood of Apple exploits. This Briefing walks through a modern XNU kernel chain targeting macOS with MIE, showing how kalloc_type, MTE, PAC, and SPTM reshape every step from memory disclosure to read/write to privilege escalation.

CONGRESS

BLACKHAT 2026 USA

2026

gpwn: Wiretapping Fiber ISP Deployments From the Comfort of Your Home GPON is the fiber-to-home protocol that carries traffic for hundreds of millions of subscribers worldwide (and climbing). Although actively updated, the threat model in the ITU-T's Recommendation has remained nearly unchanged since original publication in 2004, and no longer reflects the realities of real world deployment by ISPs.

CONGRESS

BLACKHAT 2026 USA

2026 No Tools Required: Post-Injection Exploitation Across AI Agent Frameworks Prompt injection was first understood as a behavioral problem: make the agent misbehave, leak hidden context, or bypass guardrails. Then came tool abuse, where injected content caused agents to misuse APIs, shells, browsers, databases, and file systems.

CONGRESS

BLACKHAT 2026 USA

2026

Privacy at Scale: Roblox's Infrastructure for Honoring User Privacy Rights Modern online platforms operate complex distributed systems that store user data across hundreds of services and datastores. At the scale of platforms such as Roblox, serving over 100 million daily active users, honoring user privacy rights under regulations requires infrastructure capable of orchestrating data access and erasure requests across highly heterogeneous storages and service layers.

CONGRESS

BLACKHAT 2026 USA

2026

Rules for Neural Traffic: A New Defensive Layer for LLMs For decades, defenders have used rule-based systems like Snort and YARA to express, share, and enforce precise security logic over network and file activity. LLM security, by contrast, is still dominated by opaque safeguards such as RLHF, moderation APIs, and judge models that monitor mostly surface-level text and are brittle against obfuscation, jailbreaks, and prompt injection.

CONGRESS

BLACKHAT 2026 USA

2026 The Cost of Obscurity: Exploiting the ATM Supply Chain ATMs represent a critical, high-stakes target within the global financial infrastructure. While manufacturers like Diebold Nixdorf employ security measures, their reliance on a proprietary software supply chain introduces systemic risk that remains an under examined attack surface.

CONGRESS

BLACKHAT 2026 USA

2026 Transformers: Dark Side of the Type - Weaponizing the Conversion Layer In 2017, we presented "Friday the 13th: JSON Attacks" and forced the industry to confront Insecure Deserialization. We demonstrated that Java and .NET serialization libraries are vulnerable to Remote Code Execution (RCE) when an attacker can control the type of object being instantiated.

CONGRESS

BLACKHAT 2026 USA

2026

Zero-Day Provisioning: Chaining TP-Link ZTP Vulnerabilities for Infiltrating Networks An increasing number of network vendors offer Zero-Touch Provisioning (ZTP) to conveniently provision and configure devices with little-to-no manual intervention. A ZTP ecosystem includes provisioning servers (local or cloud-based controllers) that push configurations and updates to client devices: routers, switches, gateways and wireless access points.

CONGRESS

BLACKHAT 2026 USA

2026 A Billion-User Blast Radius: Owning ChatGPT's Secure Sandbox OpenAI designed ChatGPT's container sandbox as a secure runtime environment, enforcing full network isolation, strict execution timeouts, and an AI supervisor to filter every command. Under this model, owning the container and extracting sensitive data seemed impossible.

CONGRESS

BLACKHAT 2026 USA

2026

Breaking the Seal: Static Deobfuscation of Compiled V8 JavaScript Bytecode Malware Compiled V8 JavaScript bytecode (.jsc) is an emerging format that gives attackers an unusual advantage. Threat actors can assemble capable malware using the rich Node.js ecosystem, apply an off-the-shelf JavaScript obfuscator, and then compile the prepared code. While the payload is relatively easy to build, it is much harder to analyze. From the defender's perspective, it falls in an uncomfortable gap: above the native-level instrumentation, but below the standard JavaScript analysis tooling.

CONGRESS

BLACKHAT 2026 USA

2026 Identity Crisis: Novel Vulnerabilities Leading to Kerberos Downgrade, DoS, and Full Domain Takeover Active Directory remains the crown jewel of enterprise infrastructure, and for threat actors, the holy grail is clear: gaining Domain Admin privileges. This level of privilege effectively grants full control over the environment.

CONGRESS

BLACKHAT 2026 USA

2026

Lights Out: BMCs Are Still Broken and Now We Have the Receipts Baseboard management controllers (BMCs) are embedded into every modern enterprise server. These devices run their own OS, have their own network interfaces, and are network-reachable even when the server is powered off. The devices speak a protocol called IPMI that was thoroughly trashed by Dan Farmer's ground-breaking research in 2013.

CONGRESS

BLACKHAT 2026 USA

2026

Pass-the-Passkey Family of Attacks Coming from the field of enterprise security, performing privilege escalation and lateral movement by attacking Windows Integrated Authentication is our bread and butter. But as more and more companies are adopting cloud services, we decided to shift our attention to Passkeys, which are slowly but steadily becoming the norm.

CONGRESS

BLACKHAT 2026 USA

2026 Policy Meetup: Fireside Chat with Kirsten Davies, CIO at DOW This exclusive fireside chat with the Hon. Kirsten Davies, the Department of War CIO, explores the military's shifting IT landscape, efforts to create an enduring digital foundation, hardened cybersecurity capabilities, and essential partnerships. The session provides firsthand insights into tackling legacy technical debt, accelerating modern software delivery, and operationalizing systems for warfighter dominance.

CONGRESS

BLACKHAT 2026 USA

2026

Surveillance as a Service: LightSpy's 72 Servers, Router Implants, and Operators Eating Out for Fried Chicken Forensics LightSpy is an actively developed surveillance framework with 70+ plugins targeting iOS, Android, macOS, Windows, Linux, and routers. While previous reporting focused on individual platform variants, no research has mapped the full operational scope of LightSpy's infrastructure, its live operator workflows, or its router infection capabilities.

CONGRESS

BLACKHAT 2026 USA

2026

Time for ACKrobatics: Abusing TCP Timestamps to Improve Remote Timing Attacks Exploiting timing side-channel leaks over the Internet is known to be challenging due to variations in the round-trip time, i.e., network jitter. Timing attacks have become especially challenging as processors become faster, resulting in smaller timing differences, systems become more complex, making it more difficult to collect consistent measurements, and networks become more congested, amplifying the network jitter.

CONGRESS

BLACKHAT 2026 USA

2026 Trusted Enough to Run: Breaking AI Agents in Official Workflows Official AI-agent workflows increasingly run as trusted, unattended automation. These workflows are not a single decision point: they are built from internal stages that decide what is approved, sanitized, and safe to reuse during execution. Our research identifies a distinct failure class inside those official workflow paths: the product marks state as safe, and a later component in the same workflow interprets or consumes that state more powerfully than the earlier decision accounted for.

CONGRESS

BLACKHAT 2026 USA

2026 Vulnerabilities Assembled! The Vulnerability Factory Inside the Windows Kernel As a fundamental part of the Windows networking stack, AFD (Ancillary Function Driver) has undergone years of security hardening and is often considered a well-investigated target whose attack surface would be expected to steadily reduce over time. But is that actually true? Actually, vulnerabilities are not just found, but assembled.

CONGRESS

BLACKHAT 2026 USA

2026

Beam Me Up, Luke: A Review of Teleport Attack Scenarios Traditional network perimeters are disappearing with the increased adoption of cloud infrastructure, SaaS applications, and remote workforces. As a result, solutions such as Teleport have emerged to provide secure access to distributed infrastructure and services, including emerging AI-driven access patterns. But what happens when a threat actor targets the very technology responsible for guarding remote access?

CONGRESS

BLACKHAT 2026 USA

2026

CRLF-Powered Desync Attacks: Beheading HTTP Streams Have you ever discovered a header injection vulnerability and settled for little more than an open redirect or XSS? In this Briefing, we will introduce a battle-tested "header injection" powered desync methodology, enabling you to perform HTTP request smuggling attacks against even strictly RFC-compliant proxy chains.

CONGRESS

BLACKHAT 2026 USA

2026 Deny. Disrupt. Dismantle. Breaking the Business Model of Cybercrime in the Gray Zone Ransomware networks and cyber-enabled fraud syndicates, from ransomware-as-a-service (RaaS) ecosystems to pig-butchering scam compounds - are not separate problems requiring separate policy responses.

CONGRESS

BLACKHAT 2026 USA

2026

Forgotten but Not Gone: Unauthenticated RCEs and LPEs in Legacy Linux Services The cybersecurity industry constantly chases the greatest risks in the latest tech, while old components developed with outdated security principles gather dust. Companies rush to secure their latest AI-based product, while their network remains the same.

CONGRESS

BLACKHAT 2026 USA

2026

Handle With Care: Chaining Azure Automation Flaws for Cross-Tenant Identity Takeover In modern cloud architecture, the integrity of tenant isolation is the ultimate safeguard. However, when the very logic intended to manage identity and automation is flawed, those boundaries become transparent.

CONGRESS

BLACKHAT 2026 USA

2026 PLaTypus: Eliminating Code-Reuse at the Module Boundary Numerous techniques have been proposed to thwart code reuse attacks, yet practical adoption remains limited due to compatibility and deployment challenges. In the current and foreseeable Intel architecture landscape, the main line of defense against such attacks is Intel CET, a hardware-enforced control-flow integrity (CFI) mechanism integrated into recent Intel x86-64 CPUs.

CONGRESS

BLACKHAT 2026 USA

2026

Prompt2Own: Real-World Kernel Exploit Development with LLMs Operating system kernel exploit development is a high-effort, expert-driven process: beyond identifying a memory corruption flaw, developers must build a bug-triggering proof-of-concept (PoC), tame non-determinism from races and allocator noise, determine which exploit primitives are available from the crash context, and compose them into an end-to-end exploit, achieving local privilege escalation (LPE) while overcoming modern mitigations.

CONGRESS

BLACKHAT 2026 USA

2026

Pwning Agentic Browsers with PleaseFix: A New Vulnerability Class for 0-Click Takeover Atlas breaks Same-Origin Policy (SOP). Gemini and Edge add untethered localhost access. Comet opens up your filesystem. Claude executes scripts on any website, giving you XSS as a service. Their main mitigation is model safety training. These are design choices, not vulnerabilities. Subsequently, XSS, sandbox escapes, and drive-by exploitation are making a comeback!

CONGRESS

BLACKHAT 2026 USA

2026 Running Untrusted Code: An Empirical Study of Developer Compromise and Its Blast Radius Developer-targeted attacks, particularly those using trojanized coding assessments, are a known threat vector. What has been missing is empirical data on what these attacks actually yield at scale, and how far downstream the impact extends.

CONGRESS

BLACKHAT 2026 USA

2026

Breaking Trust Boundaries: Exploiting Design Assumptions in Network Infrastructure Most modern network infrastructure relies on design assumptions that have remained unchallenged for decades since their original development. While these assumptions historically held under cooperative network environments, some no longer withstand adversarial conditions.

CONGRESS

BLACKHAT 2026 USA

2026

Cracking the Chains: Accelerating Ransomware Recovery via LLM-Assisted Engineering and Verification In the high-stakes world of ransomware incident response, organizations are often forced into a binary choice: pay the ransom or face permanent data loss. However, even the most aggressive threat actors make fatal implementation errors.

CONGRESS

BLACKHAT 2026 USA

2026

Bring Your Own COM - Session Pivoting and Lateral Movement via Ephemeral COM Registration Modern Endpoint Detection and Response (EDR) systems heavily rely on process lineage and telemetry tracking to identify malicious behavior. To bypass these checks, advanced threat actors have historically turned to Component Object Model (COM) hijacking — specifically Living off the Land (LotL) techniques that abuse known, trusted binaries like MMC20.Application.

CONGRESS

BLACKHAT 2026 USA

2026 Cost-Effective, Private, Frontier-Grade: AI Agent Exploitation with a Fine-Tuned OSS Model Large Language Models (LLMs) have transitioned from isolated chat interfaces to autonomous agents, shifting the attack surface from output generation to active, multi-step execution.

CONGRESS

BLACKHAT 2026 USA

2026

Cracking the Chains: Accelerating Ransomware Recovery via LLM-Assisted Engineering and Verification In the high-stakes world of ransomware incident response, organizations are often forced into a binary choice: pay the ransom or face permanent data loss. However, even the most aggressive threat actors make fatal implementation errors.

CONGRESS

BLACKHAT 2026 USA

2026

Cyberspace Pirates: Outsourcing Cyberwar in the Age of AI and Ransomware Four days ago, the White House publicly declared it is "not interested in fighting pirates with pirates." Congress disagrees. H.R. 4988 - the Scam Farms Marque and Reprisal Authorization Act - would invoke one of the Constitution's oldest war powers to deputize private actors to hack foreign criminal enterprises, disrupt infrastructure, and seize illicit cryptocurrency.

CONGRESS

BLACKHAT 2026 USA

2026 Kinetic Prompt Injection: Agent Compromise With a Physical Blast Radius Prompt injection is usually treated as a text problem contained on a screen: a bad output, leaked data, a rogue tool call. This one isn't. A live jailbreak of a stock Unitree Go2 robot dog running Gemini Robotics-ER 1.6, reached through its own camera and mic and driven to physical movement, no human in the loop.

CONGRESS

BLACKHAT 2026 USA

2026

Sift or Get Off the PoC: Applying Information Retrieval to Vulnerability Research You bought an IoT device, extracted the firmware, and dropped the main runtime binary into your favorite reverse engineering tool. Now you're staring at thousands of decompiled functions with no source, no symbols, and no obvious place to start bug hunting.

CONGRESS

BLACKHAT 2026 USA

2026

Tractor ECU RE: When a Noise Triggered Recall is Also a Security Patch Tractor brake controllers are assumed to be isolated from the trailer's noisy powerline network. This research proves that assumption false. In 2024, a major North American recall was issued for Bendix EC80 brake controllers, citing "memory corruption from power-line noise" as the cause.

CONGRESS

BLACKHAT 2026 USA

2026 When AI Attacks AI: Inside the Self-Propagating Botnet Built on Compromised AI Infrastructure ShadowRay 2.0 is the first in-the-wild campaign where AI infrastructure is not just targeted, but weaponized into a self-propagating botnet. In this Briefing, we will present concrete evidence of a global operation exploiting Ray, an open-source framework often referred to as the "Kubernetes of AI", to autonomously spread across more than 230,000 exposed servers.

CONGRESS

BLACKHAT 2026 USA

2026

Blind Trust in the 6 GHz Band: Weaponizing Wi-Fi Automated Frequency Coordination (AFC) Driven by rapid device growth and congestion in legacy bands, the 6 GHz spectrum is critical for next-generation Wi-Fi, but it is shared with mission-critical incumbents such as fixed microwave links and cellular backhaul.

CONGRESS

BLACKHAT 2026 USA

2026 ChatMate: Remote Prompt Execution on AI Assistants through Sandbox Escaping Imagine a user asks an LLM a question about a document. An attacker then gains an interactive prompt on the user's chat session, enabling the attacker to instruct the AI assistant to take actions on behalf of the victim.

CONGRESS

BLACKHAT 2026 USA

2026

Closed Loop: From Autonomous Exploit to Deployed Defense in Under 5 Minutes The median time-to-exploit for actively targeted vulnerabilities is now measured in hours, not weeks. CVE-2026-33017 went from advisory to confirmed exploitation in 20 hours. React2Shell saw state-sponsored exploitation within hours of disclosure. When I ran the security programs at Updater, ezCater, and CLEAR, we were following industry standards, patching criticals on 14-to-30-day cycles.

CONGRESS

BLACKHAT 2026 USA

2026

Could a Pattern on Your Clothing Fool Facial Recognition? Facial recognition evasion research has a costume problem. Masks, infrared LEDs, real-time face swaps, adversarial makeup. Every approach either requires active electronics, makes you look like a Batman villain, or replaces your face with someone else's. None of them scale.

CONGRESS

BLACKHAT 2026 USA

2026 One Percent of the Tokens, All of the Strategy: LLM-Assisted Vulnerability Discovery in IoT and Embedded Firmware Progression of IoT and embedded devices is still outpacing security community's assessment capabilities, despite many standards being raised in recent years. Due to the volume of distinct software and hardware stacks, proprietary protocols and heterogenous platform design, it is economically infeasible to manually analyze every device at the rate devices ship.

CONGRESS

BLACKHAT 2026 USA

2026

Policy Meetup Join fellow policy professionals for this interactive meetup session, an informal, semi-structured conversation on national and international cyber policies, all those hard problems which span more than just a single enterprise. Whether you want to ask what is next for cyber in the Trump administration or the EU, what's in store for regulatory harmonization, or how to improve deterrence or disruption of adversaries, this session is for you.

CONGRESS

BLACKHAT 2026 USA

2026

Render Safe: Reverse Engineering and Exploiting an EOD Robot Remotely operated systems are increasingly integral to modern operations, with explosive ordnance disposal (EOD) robots serving as some of the earliest pioneers of deployed robotics. This Briefing provides a deep technical analysis into the architecture, attack surface, and 25-year evolution of iRobot's PackBot.

CONGRESS

BLACKHAT 2026 USA

2026 Root From Kilometers Away: Ubiquiti AirMax RCE You don't realize it until you see them; they are everywhere. From Wireless ISPs links, to the frontline of modern warfare. But no one found anything?

CONGRESS

BLACKHAT 2026 USA

2026

You Can't Patch a Mental Model: How Agentic Systems Expose our Hidden Security Assumptions Agentic security is not hard because it is new. It is hard because it violates the assumptions our security models are built on.

CONGRESS

BLACKHAT 2026 USA

2026 !secure: A Single Wrong Negation to Root Linux and Escape Managed Containers A single-line logic error in the Linux kernel's networking stack -- present for years and reachable without privileges -- results in a use-after-free that gives any unprivileged local user a deterministic path to root on Ubuntu 24.04, and from a default Kubernetes pod to full node compromise on managed cloud services -- demonstrated on 2 cloud providers.

CONGRESS

BLACKHAT 2026 USA

2026

A 0-Click Exploit Chain for the Pixel 10 Attackers are often reported to target mobile devices with 0-click exploits, but limited information is available about how such exploits work on modern Android devices. This Briefing will explain how Project Zero exploited two vulnerabilities to compromise a Google Pixel 9 remotely, without user interaction. It will then explain how we chained a different privilege escalation vulnerability to exploit the Pixel 10.

CONGRESS

BLACKHAT 2026 USA

2026

Batch Me If You Can: Breaking With the State‑of‑the‑Art of Fuzzing Cryptographic Architectures BGP routing underpins the entire Internet and RPKI is supposed to keep it safe. We found 21 new vulnerabilities across every major RPKI vendor, including critical RCE and DoS bugs. We received 8 CVEs so far with CVSS of 7.5 - 9.8. Each vulnerability can downgrade routing protection or worse, expose the server running the validator to hostile takeover.

CONGRESS

BLACKHAT 2026 USA

2026 Beyond Detection: What We Learned Testing Every AI Approach to Vulnerability Classification There has been considerable discussion on how to use AI to find vulnerabilities, but very little discussion on how to use it to _classify_ vulnerabilities. Given the huge backlog of vulnerabilities in our systems, and the agentic coding revolution which will 100x them, a new approach is needed to accurately cull and rank issues.

CONGRESS

BLACKHAT 2026 USA

2026

Born Corrupted: How We Backdoored Trusted Language Binaries I know. You can audit your dependencies, pin your versions, verify signatures, and stick to trusted downloads. But what happens when you're pwned before you even start?

CONGRESS

BLACKHAT 2026 USA

2026

Breaking Recently Deployed Spectre v2 Mitigations: A Novel Attack Primitive Recently deployed Spectre v2 mitigations neutralize branch predictor state through domain isolation or sanitization. Neutralization occurs when switching privilege contexts, or immediately prior to indirect branch execution. Once neutralized, the predictor state is assumed to remain free from attacker influence until it is used.

CONGRESS

BLACKHAT 2026 USA

2026 Catch Me If You Can: AI Investigators Hunting Autonomous Attackers as a Benchmark Attackers are already using AI agents in their workflows. Defenders are still evaluating theirs against stale benchmarks that profile yesterday's attackers. These evaluations do not capture a battle at machine speed where AI agents go toe-to-toe.

CONGRESS

BLACKHAT 2026 USA

2026

One Key to Rule Them All: Taking Over a Flagship Cloud Service In this Briefing, we'll break down how we took over a major cloud provider's managed database service. We'll walk through the entire attack chain: escaping a custom .NET sandbox, moving laterally through internal infrastructure, and ultimately extracting a master key that granted admin access to every customer database on the platform.

CONGRESS

BLACKHAT 2026 USA

2026 Pedal to the Bare Metal: Rehosting and Fuzzing the Tesla Wall Connector to Start a Worm Bare-metal embedded systems are notoriously difficult to secure, which is worrying, as exploits in this domain can blow things up and shut things down. So far, research on this type of embedded system has been rare because automated security analysis techniques were unavailable.

CONGRESS

BLACKHAT 2026 USA

2026

Render Safe Live: EOD PackBot Demonstration Remotely operated systems are increasingly integral to modern operations, with explosive ordnance disposal (EOD) robots serving as some of the earliest pioneers of deployed robotics.

CONGRESS

BLACKHAT 2026 USA

2026

Can't Touch This: Attacking Fingerprint Systems from Sensor to OS Three years ago, we demonstrated full authentication bypasses against the top three fingerprint sensors used in Windows laptops, exposing fundamental flaws in various vendor-specific implementations.

CONGRESS

BLACKHAT 2026 USA

2026 CSS: The Bomb Inside Your Inbox You might think it's safe to open an email in 2026. After all, it's only HTML, right? Turns out, we forgot about CSS. In this Briefing, I'll introduce multiple novel techniques for compromising email accounts by ripping apart trust boundaries, using nothing but CSS and HTML.

CONGRESS

BLACKHAT 2026 USA

2026

If the Adversary Lives Off Your Land, So Should You Modern defenders are expected to detect and respond to adversaries who increasingly "live off the land," blending into enterprise environments by abusing legitimate tools, credentials, and infrastructure.

CONGRESS

BLACKHAT 2026 USA

2026

Invisible Threads: Remote Building Surveillance Through Encrypted Thread Traffic Analysis Thread has rapidly become the backbone of modern building automation systems, powering critical infrastructure in offices, hospitals, manufacturing facilities, and smart buildings worldwide. What if an attacker could map your entire building's automation infrastructure without ever setting foot inside, simply by exploiting Matter's predictable packet sizes?

CONGRESS

BLACKHAT 2026 USA

2026 Policy Meetup: Panel Discussion on Policy Perspectives on AI Security AI security policy is being written right now- in federal agencies, standards bodies, European cybersecurity institutions, and the enterprises trying to put all of it into practice. This session brings those four vantage points into one room.

CONGRESS

BLACKHAT 2026 USA

2026

The 0-Day Engine: Finding 100+ Vulns with LLMs in Chrome and Android Scaling logic vulnerability discovery in high-value targets like Android and Chrome is difficult: traditional fuzzing is blind to non-crashing logic defects, while known LLM approaches fail on large-scale codebases due to context hallucination.

CONGRESS

BLACKHAT 2026 USA

2026 The Crypto Caper: Exposing a Sophisticated Multi-Cloud Bandit Attackers had just made off with tens of millions of dollars in cryptocurrency. The victim had no clue how this could have happened. Step by step, the ensuing investigation revealed a remarkable sprawling campaign which spanned months and compromised every part of the target's multi-cloud infrastructure.

CONGRESS

BLACKHAT 2026 USA

2026

ThreatForest: Automated Attack Trees from Source Code Everyone agrees that threat modeling is important. Almost nobody does it. Today's threat modeling tools still require a human to draw architecture diagrams, enumerate every threat, and manually map findings to MITRE ATT&CK.

CONGRESS

BLACKHAT 2026 USA

2026

Tiny Chips, Big Leaks: Breaking TrustZone-M with Single-Stepping Attacks Trusted execution environments (TEEs) provide confidential-computing guarantees by running sensitive code inside hardware-enforced enclaves that remain isolated even when the operating system is compromised. However, despite this strong architectural isolation, TEEs remain vulnerable to software-based microarchitectural side-channel attacks.

CONGRESS

BLACKHAT 2026 USA

2026 Tracking the Trackers: How We Took Over 36 Million GPS Devices Protecting Children & Vehicles We analyzed three of the largest GPS tracking ecosystems: SETracker (~10M devices across 39 brands), SinoTrack (6M+ vehicles), and TKSTAR/Thinkrace (20M+ devices). Despite appearing as competing products, all three originate from the same Shenzhen-based supply chain and share critical architectural flaws.

CONGRESS

BLACKHAT 2026 USA

2026

Beyond Normalization: The Expanding Unicode Attack Surface Modern web applications process input through layered pipelines: URL decoding, UTF-8 validation, WAF transformations, framework parsing, surrogate handling, database collation, HTML entity decoding, and increasingly, LLM preprocessing.

CONGRESS

BLACKHAT 2026 USA

2026 Breaking Hardware CFI with Sigreturn Modern hardware-assisted Control Flow Integrity (CFI) is increasingly deployed across mobile devices and cloud infrastructure. On ARM64 systems, backward-edge protections such as Pointer Authentication (PAC) protect return addresses, while forward-edge defenses such as Branch Target Identification (BTI) restrict indirect branches to compiler-inserted landing pads.

CONGRESS

BLACKHAT 2026 USA

2026

Caging the Agent: How Roblox Built Multi-Layer Sandboxes to Secure Claude Code at Enterprise Scale A hidden instruction in a GitHub Issue convinced Claude Code to upload Roblox's credentials to a public repository. EDR saw nothing, it was a normal process making a normal network request. The good news, it happened in an internal testing environment.

CONGRESS

BLACKHAT 2026 USA

2026

Inside Coruna and DarkSword - iOS Exploits Caught in the Wild Prior to 2026, iOS Malware and Exploits were seen as a problem only targeting a few individuals. 2026 changed this. Coruna and DarkSword were both deployed as watering hole attacks impacting hundreds of millions of iPhones at the time.

CONGRESS

BLACKHAT 2026 USA

2026 Promptware EOD: Skillful Agent Detonation The AI agent supply chain has become a fertile ground for malware. It lurks in skill markdown files, rug-pulled MCP servers, misaligned models, and weaponized moltbook posts.

CONGRESS

BLACKHAT 2026 USA

2026

Scanning the Scanners: Turning Security Vendors Into Supply Chain Weapons Every security scanner promises to protect your supply chain. We submitted malicious repos to 20 of them through free-tier signups and compromised 5, gaining access to production databases, cloud credentials, third-party service credentials, and OAuth tokens associated with Fortune 100 companies, defense contractors, and government institutions.

CONGRESS

BLACKHAT 2026 USA

2026 The 12th Annual Black Hat USA Network Operations Center (NOC) Report Back with another year of soul-crushing statistics, the Black Hat NOC team will be sharing all of the data that keeps us equally puzzled and entertained, year after year.

CONGRESS

BLACKHAT 2026 USA

2026

The Intent Gap: Where Every AI Regulation Falls Short and What Security Leaders Need Instead Every major AI regulation from the NIST AI Risk Management Framework, the EU AI Act, the U.S. AI Action Plan, and CISA's December 2025 OT guidance was designed for a world where software executes instructions.

CONGRESS

BLACKHAT 2026 USA

2026

When Agentic Glue Melts: Exploiting Cloudflare CodeMode and Workers We began this research with a narrow goal: break Cloudflare Code Mode. What we found was much broader.

CONGRESS

BLACKHAT 2026 USA

2026 Breaking the Unbreakable: Dismantling the Myth of "Trusted" Cryptographic Libraries (ON-DEMAND ONLY) "Don't roll your own crypto." We follow this rule religiously — and in doing so, transfer absolute trust to libraries we never inspect. But how would you actually answer the question: is your cryptographic dependency secure?

CONGRESS

BLACKHAT 2026 USA

2026

Deterministic Chaos - Exploiting and Securing Predictable Timing in TSN Industrial Networks (ON-DEMAND ONLY) Time-Sensitive Networking (TSN) is rapidly becoming the backbone of modern industrial automation. By enabling deterministic, low-latency communication over standard Ethernet, TSN supports safety-critical control loops, synchronized robotics, and real-time industrial processes where reliability and availability are essential.

CONGRESS

BLACKHAT 2026 USA

2026

Exploring the EL2 Attack Surface: From Vulnerability to Full System Compromise (ON-DEMAND ONLY) AVF (Android Virtualization Framework) was introduced with Android 13 to provide underlying data-isolation capabilities that surpass traditional application sandboxing.

CONGRESS

BLACKHAT 2026 USA

2026 From 8 Bytes to Full Compromise: AI-Assisted Exploitation of a Widespread USB Flaw in a Multi-SE Hardware Wallet (ON-DEMAND ONLY) Hardware wallets and secure embedded devices are heavily marketed on their "defense-in-depth" architectures: multi Secure Elements (SE), MPU-protected OTP/fuses, and cryptographic key sharding. This Briefing examines what happens when the software foundation connecting these defensive layers is compromised.

CONGRESS

BLACKHAT 2026 USA

2026

Ghost Credentials: Hunting and Exploiting NonHuman Identities Across Cloud Environments (ON-DEMAND ONLY) In 2026, the ratio of Non-Human Identities (NHIs) to human identities reached a staggering 144:1. While organizations have invested heavily in phishing-resistant MFA, passwordless authentication, and Zero Trust for human users, an invisible ecosystem of service accounts, API keys, OAuth applications, CI/CD secrets, Kubernetes identities, and AI agent credentials continues to operate with persistent privileges, fragmented ownership, and little to no lifecycle management.

CONGRESS

BLACKHAT 2026 USA

2026 Inside the Screen: Deep-Diving into North Korean IT Workers' Live Infrastructure (ON-DEMAND ONLY) North Korean IT workers have infiltrated companies worldwide, generating revenue for the regime while posing significant security risks to employers. In 2025, we exposed their reality—organizational structure, workflows, and tradecraft.

CONGRESS

BLACKHAT 2026 USA

2026

Medical Device Kill Chain: From Debug Port to Patient Impact (ON-DEMAND ONLY) Connected medical devices such as infusion pumps, patient monitors, imaging systems, implantables, and other cyber-physical healthcare technologies increasingly form the backbone of modern clinical care. Despite growing connectivity and cloud integration, the security community still lacks a practical, end-to-end methodology for understanding how weaknesses across hardware, firmware, protocols, and backend systems combine to create patient safety and operational risk.

CONGRESS

BLACKHAT 2026 USA

2026

Spaghettifying DRAM: Breaking Everything with Memory Collision Exploitation (ON-DEMAND ONLY) In this Briefing, we will take a fundamental invariant of computing - that an address identifies a variable's location - and break it at the hardware level.

CONGRESS

BLACKHAT 2026 USA

2026 Trust No Deputy: Breaking Azure and GCP Through Managed Identity Chains (ON-DEMAND ONLY) Cloud platforms delegate sensitive operations to managed identities, trusting that Azure RBAC and GCP IAM boundaries contain blast radius. This trust is misplaced.

CONGRESS

BLACKHAT 2026 USA

2026

When BPF Blinding Goes Dark: Smuggling Raw Gadgets into the Linux Kernel (ON-DEMAND ONLY) bpf_jit_harden=2 is supposed to be the last word on JIT spray in the Linux kernel. Every immediate value in a BPF program gets masked with a random XOR key before the JIT ever sees it. Attacker-controlled bytes cannot land in kernel executable memory. The defense has been in place since 2016 and, until now, it worked.

CONGRESS

BLACKHAT 2026 USA