| 2026 | BLACKHAT 2026 | Black Hat Briefings (běžně označované jako Black Hat ) je konference o počítačové bezpečnosti , která poskytuje bezpečnostní konzultace, školení a instruktáže hackerům, korporacím a vládním agenturám po celém světě. |
DATE |
NAME |
INFO |
CATEGORY |
SUBCATE |
|
2026 |
Beyond Seccomp: Breaking and Rebuilding Syscall Filtering for Microservices |
In cloud-native environments, system calls serve as both the primary attack surface and the last line of defense for containers. However, widely deployed commercial container security tools still inherit structural design limitations that create critical blind spots when protecting microservices. |
CONGRESS |
|
| 2026 | Bye Bye AI: How We Hacked the AI Shopping Assistant of a Top 3 US Retailer | AI agents have become powerful digital touchpoints in retail, guiding product discovery, influencing purchases, and acting as the front door to the customer experience. For major retailers, these assistants are a core marketing and sales channel used by millions of shoppers daily. Unfortunately, they are also far easier to compromise than most organizations realize. |
CONGRESS |
|
|
2026 |
Detection Engineering Beyond the Inbox | Email gateways fail to detect 63% of targeted phishing in operationally-constrained environments, from our 18-month deployment processing 2.3M+ daily emails. Every industry has structural operational requirements creating email security blind spots gateways cannot solve. |
CONGRESS |
|
| 2026 | GitHub Can Tell You're Being Hacked. You're Just Not Listening: Building EDR for GitHub from Its Own Event Stream | Open-source repositories are critical infrastructure, yet GitHub - where supply chain attacks often originate - remains largely unmonitored. We studied dozens of real-world supply chain attacks spanning 2018–2026 and built a behavioral anomaly scoring model to determine what defenders can detect from GitHub platform telemetry combined with direct Git object-level inspection. |
CONGRESS |
|
|
2026 |
Hunting LANDFALL: From Overlooked Images to State-Linked Mobile Spyware | In mid-2024, a set of malformed DNG image files carrying a fully-featured Android spyware were uploaded to VirusTotal from Iraq, Iran, and Morocco. They sat there, undetected, for over a year. Inside was LANDFALL, a previously unknown commercial-grade Android spyware framework exploiting a zero-day in Samsung's image processing library, to achieve zero-click compromise of Galaxy devices, likely via weaponized images delivered through WhatsApp. |
CONGRESS |
|
| 2026 | LANJack: Turning Ads into IoT Recon Tools | You visit a legitimate website. A trusted brand advertisement loads. Nothing looks suspicious. No phishing page, no exploit kit, no visible signs of an attack. Meanwhile, your browser is silently scanning your internal network, mapping your LAN and identifying connected devices. |
CONGRESS |
|
|
2026 |
Policy Meetup: Government Panel Discussion on AI and the New Era of Cyber Resilience | Agentic AI has moved the security conversation past scale and speed. These systems reason across multiple steps, write and execute code, and take consequential actions in live environments. A failure, a manipulation, or a compromise no longer stays a model problem. It becomes an operational security incident. Governments are weighing that risk as they connect agentic systems to networks supporting critical national functions. |
CONGRESS |
|
| 2026 | Thinking Beyond the Code: Contrarian Thinking to AI and Lessons From a Life in Discovery | In an era increasingly defined by the algorithmic logic of Large Language Models, the true frontier of security isn't just about better code—it's about seeing the world differently. |
CONGRESS |
|
|
2026 |
Turning Enterprise Update Servers Into Backdoor Factories (0_o) | Windows Server Update Services (WSUS) sits at the heart of enterprise patch management, responsible for distributing updates across thousands of endpoints. Its privileged position in the network makes it a high-value target. A compromised WSUS server enables lateral movement, persistent footholds, and organization-wide implant deployment at scale. |
CONGRESS |
|
| 2026 | When Queues Become Vulnerabilities: Reverse Engineering GCD, XPC Races, and macOS Detection Engineering | While many macOS services rely on Grand Central Dispatch (GCD) for concurrency, the underlying kernel integration is often treated as a black box, even by experienced engineers. This Briefing opens that box. From the perspective of a detection engineer and macOS security researcher, this Briefing will map how libdispatch interfaces with the XNU kernel's scheduling infrastructure, focusing on pthread work queues, Mach ports, and quality of service (QoS) propagation. |
CONGRESS |
|
|
2026 |
A Front-Row Seat to APT Operations: How OPSEC Failures Exposed a Malware Supplier | We have spent years tracking adversaries across the Asia-Pacific region. This Briefing presents what may be our most revealing case: a single OPSEC failure by a malware supplier that didn't just expose one campaign — it exposed an entire ecosystem. |
CONGRESS |
|
| 2026 | AI and the Future of Cyber Defense Panel | AI and Cyber from Frontier AI models are crossing capability thresholds that reshape both the offensive and defensive sides of cybersecurity. They can now meaningfully accelerate vulnerability discovery, exploit development, and attack execution — compressing timelines for attackers targeting critical infrastructure. At the same time, these capabilities offer defenders an asymmetric advantage if deployed responsibly and at scale. |
CONGRESS |
|
|
2026 |
Burning Tears of PHP's Memory Hardening | PHP introduced new heap hardening measures for its heap allocator, ZendMM, in April 2024. This Briefing asks a simple question: how much protection do these latest mitigations really buy against a determined attacker? |
CONGRESS |
|
| 2026 | C and Its Consequences: The Source Is Just a Suggestion | int x = k; if (x == 1 && x == 2) { printf("this is possible"); } Modern compilers don't mindlessly translate your code - they entirely rewrite it. By the time C reaches machine code, it's been reshaped by frontend lowering, IR optimizations, register allocation, and backend codegen - a deep, multi-stage pipeline making decisions you can't see. |
CONGRESS |
|
|
2026 |
Defensive V Offensive? - How Do We Balance The Needs Of The Many | The UK like many countries must balance the offensive and the defensive. Since 2016, the NCSC has worked to make the UK the safest place to live and work online, where we counter cyber threats from adversaries planning to do us harm. |
CONGRESS |
|
| 2026 | From Prompts to Pipelines: Building Agentic Detection Engineering and Threat Hunting | Detection engineering and threat hunting remain bottlenecked by the gap between threat intelligence and deployed defenses. |
CONGRESS |
|
|
2026 |
Managing Security Culture Half Life | This Briefing pairs two consecutive CSOs from the same high-profile organization — the Democratic National Committee, breached by two Russian intelligence services in 2016 — to examine what the security industry almost never gets to see: an honest succession. |
CONGRESS |
|
| 2026 | Pre-auth RCE in Enterprise Java: When Middleware Becomes the Exploit | Enterprise Java platforms still expose critical pre-authentication attack paths through middleware features that were never designed to handle untrusted input. |
CONGRESS |
|
|
2026 |
Threat Modeling LLMs: The PHANTOM-B model | Security engineers shipping LLM products face a painful mismatch: the threat landscape is complex and evolving, the boss wants it deployed yesterday, and existing resources — MITRE ATLAS, NIST AI RMF, hundreds of academic papers — are built for thoroughness, not speed. |
CONGRESS |
|
| 2026 | Attacking and Defending AI Browsers | Implementing Kubernetes namespace-based multi-tenancy is challenging, and its isolation is generally considered less effective than control-plane isolation. That's why the latter is often recommended ... and also implemented? Not really, as workloads such as machine learning, pipelines, and scripting capabilities are increasingly common in enterprise environments. And they can introduce unobvious multi-tenancy in clusters. |
CONGRESS |
|
|
2026 |
BTR Reforged: Weaponizing Defender's Remediation Driver as a Kernel Operation Primitive | What if a trusted security component could be repurposed into an attacker-controlled kernel primitive? What if a signed Microsoft remediation driver could be instructed to execute arbitrary file and registry operations from Ring 0—without exploits, vulnerabilities, or memory corruption? |
CONGRESS |
|
| 2026 | Can AI Do Novel Security Research? Meet the HTTP Terminator | We all know AI can find bugs. After a decade of research, I asked a harder question: can an autonomous system invent new attack techniques, and use them to hack live websites at scale? Building this sounded like a bad idea, so I did it. |
CONGRESS |
|
|
2026 |
GPUBreach: Privilege Escalation Attacks on GPUs Using Rowhammer | Rowhammer attacks have been extensively studied on CPUs, where they have enabled powerful exploits, including privilege escalation. In contrast, Rowhammer on NVIDIA GPUs, despite recently demonstrated by GPUHammer attacks, has largely been viewed as low impact, limited to inducing random bit flips that merely degrade machine learning accuracy. In this Briefing, we will overturn that assumption and show that GPU Rowhammer can be weaponized into a full-system compromise. |
CONGRESS |
|
| 2026 | One Click to System: Exploiting Bixby's Trust Model for Full Device Compromise | During the 2025 Mobile Pwn2Own competition, we identified a series of vulnerabilities affecting Samsung devices. Chained together, these issues resulted in remote system-level compromise triggered by a single user interaction. |
CONGRESS |
|
|
2026 |
Scambuster: Social Engineering Scammers at Scale | Most security teams get a scam email and delete it. That's the standard move. Block it, move on, forget it. |
CONGRESS |
|
|
2026 |
The CoreBreak Attack: Turning AI Agents into Credentials Exfiltration Vectors |
Building an AI agent? We all do.Struggling to figure out how to make it secure? You're not alone. Counting on your cloud provider's AI agent platform to handle security for you? It's time to think again. |
CONGRESS |
|
| 2026 | The Good, the Bad, and the Ugly of AI Security | Artificial intelligence is fundamentally reshaping cybersecurity for both attackers and defenders, but the uplifts in capabilities are asymmetrical. Our research presents a comprehensive analysis of how AI is removing long-standing operational bottlenecks across offensive and defensive cyber operations, revealing where the resulting capability gains are greatest and why they are inherently asymmetric. |
CONGRESS |
|
| 2026 | The 'Breaking' News: The OpenAI–Hugging Face Incident - A Technical Reconstruction and Its Implications for AI | In this talk, OpenAI security engineers and researchers will reconstruct the OpenAI-Hugging Face incident and examine its implications for AI security, cyber resilience, and alignment. |
CONGRESS |
|
|
2026 |
Anatomy of a Takedown: Inside the Operation That Broke LockBit | LockBit was the most prolific ransomware-as-a-service operation the world has seen. For four years, it operated as if law enforcement could not touch it. It accounted for one in four ransomware attacks globally, victimized over 2,500 organizations across 120 countries, collected more than $500 million in ransom payments, and built a 194-affiliate operation whose leader went out of his way to project invincibility. |
CONGRESS |
|
| 2026 | Apple macOS Kernel Exploitation with MIE: Building on the Ashes of 100 Vulnerabilities | On modern Apple systems, the AI-powered flood of vulnerabilities does not immediately lead to a flood of Apple exploits. This Briefing walks through a modern XNU kernel chain targeting macOS with MIE, showing how kalloc_type, MTE, PAC, and SPTM reshape every step from memory disclosure to read/write to privilege escalation. |
CONGRESS |
|
|
2026 |
gpwn: Wiretapping Fiber ISP Deployments From the Comfort of Your Home | GPON is the fiber-to-home protocol that carries traffic for hundreds of millions of subscribers worldwide (and climbing). Although actively updated, the threat model in the ITU-T's Recommendation has remained nearly unchanged since original publication in 2004, and no longer reflects the realities of real world deployment by ISPs. |
CONGRESS |
|
| 2026 | No Tools Required: Post-Injection Exploitation Across AI Agent Frameworks | Prompt injection was first understood as a behavioral problem: make the agent misbehave, leak hidden context, or bypass guardrails. Then came tool abuse, where injected content caused agents to misuse APIs, shells, browsers, databases, and file systems. |
CONGRESS |
|
|
2026 |
Privacy at Scale: Roblox's Infrastructure for Honoring User Privacy Rights | Modern online platforms operate complex distributed systems that store user data across hundreds of services and datastores. At the scale of platforms such as Roblox, serving over 100 million daily active users, honoring user privacy rights under regulations requires infrastructure capable of orchestrating data access and erasure requests across highly heterogeneous storages and service layers. |
CONGRESS |
|
|
2026 |
Rules for Neural Traffic: A New Defensive Layer for LLMs | For decades, defenders have used rule-based systems like Snort and YARA to express, share, and enforce precise security logic over network and file activity. LLM security, by contrast, is still dominated by opaque safeguards such as RLHF, moderation APIs, and judge models that monitor mostly surface-level text and are brittle against obfuscation, jailbreaks, and prompt injection. |
CONGRESS |
|
| 2026 | The Cost of Obscurity: Exploiting the ATM Supply Chain | ATMs represent a critical, high-stakes target within the global financial infrastructure. While manufacturers like Diebold Nixdorf employ security measures, their reliance on a proprietary software supply chain introduces systemic risk that remains an under examined attack surface. |
CONGRESS |
|
| 2026 | Transformers: Dark Side of the Type - Weaponizing the Conversion Layer | In 2017, we presented "Friday the 13th: JSON Attacks" and forced the industry to confront Insecure Deserialization. We demonstrated that Java and .NET serialization libraries are vulnerable to Remote Code Execution (RCE) when an attacker can control the type of object being instantiated. |
CONGRESS |
|
|
2026 |
Zero-Day Provisioning: Chaining TP-Link ZTP Vulnerabilities for Infiltrating Networks | An increasing number of network vendors offer Zero-Touch Provisioning (ZTP) to conveniently provision and configure devices with little-to-no manual intervention. A ZTP ecosystem includes provisioning servers (local or cloud-based controllers) that push configurations and updates to client devices: routers, switches, gateways and wireless access points. |
CONGRESS |
|
| 2026 | A Billion-User Blast Radius: Owning ChatGPT's Secure Sandbox | OpenAI designed ChatGPT's container sandbox as a secure runtime environment, enforcing full network isolation, strict execution timeouts, and an AI supervisor to filter every command. Under this model, owning the container and extracting sensitive data seemed impossible. |
CONGRESS |
|
|
2026 |
Breaking the Seal: Static Deobfuscation of Compiled V8 JavaScript Bytecode Malware | Compiled V8 JavaScript bytecode (.jsc) is an emerging format that gives attackers an unusual advantage. Threat actors can assemble capable malware using the rich Node.js ecosystem, apply an off-the-shelf JavaScript obfuscator, and then compile the prepared code. While the payload is relatively easy to build, it is much harder to analyze. From the defender's perspective, it falls in an uncomfortable gap: above the native-level instrumentation, but below the standard JavaScript analysis tooling. |
CONGRESS |
|
| 2026 | Identity Crisis: Novel Vulnerabilities Leading to Kerberos Downgrade, DoS, and Full Domain Takeover | Active Directory remains the crown jewel of enterprise infrastructure, and for threat actors, the holy grail is clear: gaining Domain Admin privileges. This level of privilege effectively grants full control over the environment. |
CONGRESS |
|
|
2026 |
Lights Out: BMCs Are Still Broken and Now We Have the Receipts | Baseboard management controllers (BMCs) are embedded into every modern enterprise server. These devices run their own OS, have their own network interfaces, and are network-reachable even when the server is powered off. The devices speak a protocol called IPMI that was thoroughly trashed by Dan Farmer's ground-breaking research in 2013. |
CONGRESS |
|
|
2026 |
Pass-the-Passkey Family of Attacks | Coming from the field of enterprise security, performing privilege escalation and lateral movement by attacking Windows Integrated Authentication is our bread and butter. But as more and more companies are adopting cloud services, we decided to shift our attention to Passkeys, which are slowly but steadily becoming the norm. |
CONGRESS |
|
| 2026 | Policy Meetup: Fireside Chat with Kirsten Davies, CIO at DOW | This exclusive fireside chat with the Hon. Kirsten Davies, the Department of War CIO, explores the military's shifting IT landscape, efforts to create an enduring digital foundation, hardened cybersecurity capabilities, and essential partnerships. The session provides firsthand insights into tackling legacy technical debt, accelerating modern software delivery, and operationalizing systems for warfighter dominance. |
CONGRESS |
|
|
2026 |
Surveillance as a Service: LightSpy's 72 Servers, Router Implants, and Operators Eating Out for Fried Chicken Forensics | LightSpy is an actively developed surveillance framework with 70+ plugins targeting iOS, Android, macOS, Windows, Linux, and routers. While previous reporting focused on individual platform variants, no research has mapped the full operational scope of LightSpy's infrastructure, its live operator workflows, or its router infection capabilities. |
CONGRESS |
|
|
2026 |
Time for ACKrobatics: Abusing TCP Timestamps to Improve Remote Timing Attacks | Exploiting timing side-channel leaks over the Internet is known to be challenging due to variations in the round-trip time, i.e., network jitter. Timing attacks have become especially challenging as processors become faster, resulting in smaller timing differences, systems become more complex, making it more difficult to collect consistent measurements, and networks become more congested, amplifying the network jitter. |
CONGRESS |
|
| 2026 | Trusted Enough to Run: Breaking AI Agents in Official Workflows | Official AI-agent workflows increasingly run as trusted, unattended automation. These workflows are not a single decision point: they are built from internal stages that decide what is approved, sanitized, and safe to reuse during execution. Our research identifies a distinct failure class inside those official workflow paths: the product marks state as safe, and a later component in the same workflow interprets or consumes that state more powerfully than the earlier decision accounted for. |
CONGRESS |
|
| 2026 | Vulnerabilities Assembled! The Vulnerability Factory Inside the Windows Kernel | As a fundamental part of the Windows networking stack, AFD (Ancillary Function Driver) has undergone years of security hardening and is often considered a well-investigated target whose attack surface would be expected to steadily reduce over time. But is that actually true? Actually, vulnerabilities are not just found, but assembled. |
CONGRESS |
|
|
2026 |
Beam Me Up, Luke: A Review of Teleport Attack Scenarios | Traditional network perimeters are disappearing with the increased adoption of cloud infrastructure, SaaS applications, and remote workforces. As a result, solutions such as Teleport have emerged to provide secure access to distributed infrastructure and services, including emerging AI-driven access patterns. But what happens when a threat actor targets the very technology responsible for guarding remote access? |
CONGRESS |
|
|
2026 |
CRLF-Powered Desync Attacks: Beheading HTTP Streams | Have you ever discovered a header injection vulnerability and settled for little more than an open redirect or XSS? In this Briefing, we will introduce a battle-tested "header injection" powered desync methodology, enabling you to perform HTTP request smuggling attacks against even strictly RFC-compliant proxy chains. |
CONGRESS |
|
| 2026 | Deny. Disrupt. Dismantle. Breaking the Business Model of Cybercrime in the Gray Zone | Ransomware networks and cyber-enabled fraud syndicates, from ransomware-as-a-service (RaaS) ecosystems to pig-butchering scam compounds - are not separate problems requiring separate policy responses. |
CONGRESS |
|
|
2026 |
Forgotten but Not Gone: Unauthenticated RCEs and LPEs in Legacy Linux Services | The cybersecurity industry constantly chases the greatest risks in the latest tech, while old components developed with outdated security principles gather dust. Companies rush to secure their latest AI-based product, while their network remains the same. |
CONGRESS |
|
|
2026 |
Handle With Care: Chaining Azure Automation Flaws for Cross-Tenant Identity Takeover | In modern cloud architecture, the integrity of tenant isolation is the ultimate safeguard. However, when the very logic intended to manage identity and automation is flawed, those boundaries become transparent. |
CONGRESS |
|
| 2026 | PLaTypus: Eliminating Code-Reuse at the Module Boundary | Numerous techniques have been proposed to thwart code reuse attacks, yet practical adoption remains limited due to compatibility and deployment challenges. In the current and foreseeable Intel architecture landscape, the main line of defense against such attacks is Intel CET, a hardware-enforced control-flow integrity (CFI) mechanism integrated into recent Intel x86-64 CPUs. |
CONGRESS |
|
|
2026 |
Prompt2Own: Real-World Kernel Exploit Development with LLMs | Operating system kernel exploit development is a high-effort, expert-driven process: beyond identifying a memory corruption flaw, developers must build a bug-triggering proof-of-concept (PoC), tame non-determinism from races and allocator noise, determine which exploit primitives are available from the crash context, and compose them into an end-to-end exploit, achieving local privilege escalation (LPE) while overcoming modern mitigations. |
CONGRESS |
|
|
2026 |
Pwning Agentic Browsers with PleaseFix: A New Vulnerability Class for 0-Click Takeover | Atlas breaks Same-Origin Policy (SOP). Gemini and Edge add untethered localhost access. Comet opens up your filesystem. Claude executes scripts on any website, giving you XSS as a service. Their main mitigation is model safety training. These are design choices, not vulnerabilities. Subsequently, XSS, sandbox escapes, and drive-by exploitation are making a comeback! |
CONGRESS |
|
| 2026 | Running Untrusted Code: An Empirical Study of Developer Compromise and Its Blast Radius | Developer-targeted attacks, particularly those using trojanized coding assessments, are a known threat vector. What has been missing is empirical data on what these attacks actually yield at scale, and how far downstream the impact extends. |
CONGRESS |
|
|
2026 |
Breaking Trust Boundaries: Exploiting Design Assumptions in Network Infrastructure | Most modern network infrastructure relies on design assumptions that have remained unchallenged for decades since their original development. While these assumptions historically held under cooperative network environments, some no longer withstand adversarial conditions. |
CONGRESS |
|
|
2026 |
Cracking the Chains: Accelerating Ransomware Recovery via LLM-Assisted Engineering and Verification | In the high-stakes world of ransomware incident response, organizations are often forced into a binary choice: pay the ransom or face permanent data loss. However, even the most aggressive threat actors make fatal implementation errors. |
CONGRESS |
|
|
2026 |
Bring Your Own COM - Session Pivoting and Lateral Movement via Ephemeral COM Registration | Modern Endpoint Detection and Response (EDR) systems heavily rely on process lineage and telemetry tracking to identify malicious behavior. To bypass these checks, advanced threat actors have historically turned to Component Object Model (COM) hijacking — specifically Living off the Land (LotL) techniques that abuse known, trusted binaries like MMC20.Application. |
CONGRESS |
|
| 2026 | Cost-Effective, Private, Frontier-Grade: AI Agent Exploitation with a Fine-Tuned OSS Model | Large Language Models (LLMs) have transitioned from isolated chat interfaces to autonomous agents, shifting the attack surface from output generation to active, multi-step execution. |
CONGRESS |
|
|
2026 |
Cracking the Chains: Accelerating Ransomware Recovery via LLM-Assisted Engineering and Verification | In the high-stakes world of ransomware incident response, organizations are often forced into a binary choice: pay the ransom or face permanent data loss. However, even the most aggressive threat actors make fatal implementation errors. |
CONGRESS |
|
|
2026 |
Cyberspace Pirates: Outsourcing Cyberwar in the Age of AI and Ransomware | Four days ago, the White House publicly declared it is "not interested in fighting pirates with pirates." Congress disagrees. H.R. 4988 - the Scam Farms Marque and Reprisal Authorization Act - would invoke one of the Constitution's oldest war powers to deputize private actors to hack foreign criminal enterprises, disrupt infrastructure, and seize illicit cryptocurrency. |
CONGRESS |
|
| 2026 | Kinetic Prompt Injection: Agent Compromise With a Physical Blast Radius | Prompt injection is usually treated as a text problem contained on a screen: a bad output, leaked data, a rogue tool call. This one isn't. A live jailbreak of a stock Unitree Go2 robot dog running Gemini Robotics-ER 1.6, reached through its own camera and mic and driven to physical movement, no human in the loop. |
CONGRESS |
|
|
2026 |
Sift or Get Off the PoC: Applying Information Retrieval to Vulnerability Research | You bought an IoT device, extracted the firmware, and dropped the main runtime binary into your favorite reverse engineering tool. Now you're staring at thousands of decompiled functions with no source, no symbols, and no obvious place to start bug hunting. |
CONGRESS |
|
|
2026 |
Tractor ECU RE: When a Noise Triggered Recall is Also a Security Patch | Tractor brake controllers are assumed to be isolated from the trailer's noisy powerline network. This research proves that assumption false. In 2024, a major North American recall was issued for Bendix EC80 brake controllers, citing "memory corruption from power-line noise" as the cause. |
CONGRESS |
|
| 2026 | When AI Attacks AI: Inside the Self-Propagating Botnet Built on Compromised AI Infrastructure | ShadowRay 2.0 is the first in-the-wild campaign where AI infrastructure is not just targeted, but weaponized into a self-propagating botnet. In this Briefing, we will present concrete evidence of a global operation exploiting Ray, an open-source framework often referred to as the "Kubernetes of AI", to autonomously spread across more than 230,000 exposed servers. |
CONGRESS |
|
|
2026 |
Blind Trust in the 6 GHz Band: Weaponizing Wi-Fi Automated Frequency Coordination (AFC) | Driven by rapid device growth and congestion in legacy bands, the 6 GHz spectrum is critical for next-generation Wi-Fi, but it is shared with mission-critical incumbents such as fixed microwave links and cellular backhaul. |
CONGRESS |
|
| 2026 | ChatMate: Remote Prompt Execution on AI Assistants through Sandbox Escaping | Imagine a user asks an LLM a question about a document. An attacker then gains an interactive prompt on the user's chat session, enabling the attacker to instruct the AI assistant to take actions on behalf of the victim. |
CONGRESS |
|
|
2026 |
Closed Loop: From Autonomous Exploit to Deployed Defense in Under 5 Minutes | The median time-to-exploit for actively targeted vulnerabilities is now measured in hours, not weeks. CVE-2026-33017 went from advisory to confirmed exploitation in 20 hours. React2Shell saw state-sponsored exploitation within hours of disclosure. When I ran the security programs at Updater, ezCater, and CLEAR, we were following industry standards, patching criticals on 14-to-30-day cycles. |
CONGRESS |
|
|
2026 |
Could a Pattern on Your Clothing Fool Facial Recognition? | Facial recognition evasion research has a costume problem. Masks, infrared LEDs, real-time face swaps, adversarial makeup. Every approach either requires active electronics, makes you look like a Batman villain, or replaces your face with someone else's. None of them scale. |
CONGRESS |
|
| 2026 | One Percent of the Tokens, All of the Strategy: LLM-Assisted Vulnerability Discovery in IoT and Embedded Firmware | Progression of IoT and embedded devices is still outpacing security community's assessment capabilities, despite many standards being raised in recent years. Due to the volume of distinct software and hardware stacks, proprietary protocols and heterogenous platform design, it is economically infeasible to manually analyze every device at the rate devices ship. |
CONGRESS |
|
|
2026 |
Policy Meetup | Join fellow policy professionals for this interactive meetup session, an informal, semi-structured conversation on national and international cyber policies, all those hard problems which span more than just a single enterprise. Whether you want to ask what is next for cyber in the Trump administration or the EU, what's in store for regulatory harmonization, or how to improve deterrence or disruption of adversaries, this session is for you. |
CONGRESS |
|
|
2026 |
Render Safe: Reverse Engineering and Exploiting an EOD Robot | Remotely operated systems are increasingly integral to modern operations, with explosive ordnance disposal (EOD) robots serving as some of the earliest pioneers of deployed robotics. This Briefing provides a deep technical analysis into the architecture, attack surface, and 25-year evolution of iRobot's PackBot. |
CONGRESS |
|
| 2026 | Root From Kilometers Away: Ubiquiti AirMax RCE | You don't realize it until you see them; they are everywhere. From Wireless ISPs links, to the frontline of modern warfare. But no one found anything? |
CONGRESS |
|
|
2026 |
You Can't Patch a Mental Model: How Agentic Systems Expose our Hidden Security Assumptions | Agentic security is not hard because it is new. It is hard because it violates the assumptions our security models are built on. |
CONGRESS |
|
| 2026 | !secure: A Single Wrong Negation to Root Linux and Escape Managed Containers | A single-line logic error in the Linux kernel's networking stack -- present for years and reachable without privileges -- results in a use-after-free that gives any unprivileged local user a deterministic path to root on Ubuntu 24.04, and from a default Kubernetes pod to full node compromise on managed cloud services -- demonstrated on 2 cloud providers. |
CONGRESS |
|
|
2026 |
A 0-Click Exploit Chain for the Pixel 10 | Attackers are often reported to target mobile devices with 0-click exploits, but limited information is available about how such exploits work on modern Android devices. This Briefing will explain how Project Zero exploited two vulnerabilities to compromise a Google Pixel 9 remotely, without user interaction. It will then explain how we chained a different privilege escalation vulnerability to exploit the Pixel 10. |
CONGRESS |
|
|
2026 |
Batch Me If You Can: Breaking With the State‑of‑the‑Art of Fuzzing Cryptographic Architectures | BGP routing underpins the entire Internet and RPKI is supposed to keep it safe. We found 21 new vulnerabilities across every major RPKI vendor, including critical RCE and DoS bugs. We received 8 CVEs so far with CVSS of 7.5 - 9.8. Each vulnerability can downgrade routing protection or worse, expose the server running the validator to hostile takeover. |
CONGRESS |
|
| 2026 | Beyond Detection: What We Learned Testing Every AI Approach to Vulnerability Classification | There has been considerable discussion on how to use AI to find vulnerabilities, but very little discussion on how to use it to _classify_ vulnerabilities. Given the huge backlog of vulnerabilities in our systems, and the agentic coding revolution which will 100x them, a new approach is needed to accurately cull and rank issues. |
CONGRESS |
|
|
2026 |
Born Corrupted: How We Backdoored Trusted Language Binaries | I know. You can audit your dependencies, pin your versions, verify signatures, and stick to trusted downloads. But what happens when you're pwned before you even start? |
CONGRESS |
|
|
2026 |
Breaking Recently Deployed Spectre v2 Mitigations: A Novel Attack Primitive | Recently deployed Spectre v2 mitigations neutralize branch predictor state through domain isolation or sanitization. Neutralization occurs when switching privilege contexts, or immediately prior to indirect branch execution. Once neutralized, the predictor state is assumed to remain free from attacker influence until it is used. |
CONGRESS |
|
| 2026 | Catch Me If You Can: AI Investigators Hunting Autonomous Attackers as a Benchmark | Attackers are already using AI agents in their workflows. Defenders are still evaluating theirs against stale benchmarks that profile yesterday's attackers. These evaluations do not capture a battle at machine speed where AI agents go toe-to-toe. |
CONGRESS |
|
|
2026 |
One Key to Rule Them All: Taking Over a Flagship Cloud Service | In this Briefing, we'll break down how we took over a major cloud provider's managed database service. We'll walk through the entire attack chain: escaping a custom .NET sandbox, moving laterally through internal infrastructure, and ultimately extracting a master key that granted admin access to every customer database on the platform. |
CONGRESS |
|
| 2026 | Pedal to the Bare Metal: Rehosting and Fuzzing the Tesla Wall Connector to Start a Worm | Bare-metal embedded systems are notoriously difficult to secure, which is worrying, as exploits in this domain can blow things up and shut things down. So far, research on this type of embedded system has been rare because automated security analysis techniques were unavailable. |
CONGRESS |
|
|
2026 |
Render Safe Live: EOD PackBot Demonstration | Remotely operated systems are increasingly integral to modern operations, with explosive ordnance disposal (EOD) robots serving as some of the earliest pioneers of deployed robotics. |
CONGRESS |
|
|
2026 |
Can't Touch This: Attacking Fingerprint Systems from Sensor to OS | Three years ago, we demonstrated full authentication bypasses against the top three fingerprint sensors used in Windows laptops, exposing fundamental flaws in various vendor-specific implementations. |
CONGRESS |
|
| 2026 | CSS: The Bomb Inside Your Inbox | You might think it's safe to open an email in 2026. After all, it's only HTML, right? Turns out, we forgot about CSS. In this Briefing, I'll introduce multiple novel techniques for compromising email accounts by ripping apart trust boundaries, using nothing but CSS and HTML. |
CONGRESS |
|
|
2026 |
If the Adversary Lives Off Your Land, So Should You | Modern defenders are expected to detect and respond to adversaries who increasingly "live off the land," blending into enterprise environments by abusing legitimate tools, credentials, and infrastructure. |
CONGRESS |
|
|
2026 |
Invisible Threads: Remote Building Surveillance Through Encrypted Thread Traffic Analysis | Thread has rapidly become the backbone of modern building automation systems, powering critical infrastructure in offices, hospitals, manufacturing facilities, and smart buildings worldwide. What if an attacker could map your entire building's automation infrastructure without ever setting foot inside, simply by exploiting Matter's predictable packet sizes? |
CONGRESS |
|
| 2026 | Policy Meetup: Panel Discussion on Policy Perspectives on AI Security | AI security policy is being written right now- in federal agencies, standards bodies, European cybersecurity institutions, and the enterprises trying to put all of it into practice. This session brings those four vantage points into one room. |
CONGRESS |
|
|
2026 |
The 0-Day Engine: Finding 100+ Vulns with LLMs in Chrome and Android | Scaling logic vulnerability discovery in high-value targets like Android and Chrome is difficult: traditional fuzzing is blind to non-crashing logic defects, while known LLM approaches fail on large-scale codebases due to context hallucination. |
CONGRESS |
|
| 2026 | The Crypto Caper: Exposing a Sophisticated Multi-Cloud Bandit | Attackers had just made off with tens of millions of dollars in cryptocurrency. The victim had no clue how this could have happened. Step by step, the ensuing investigation revealed a remarkable sprawling campaign which spanned months and compromised every part of the target's multi-cloud infrastructure. |
CONGRESS |
|
|
2026 |
ThreatForest: Automated Attack Trees from Source Code | Everyone agrees that threat modeling is important. Almost nobody does it. Today's threat modeling tools still require a human to draw architecture diagrams, enumerate every threat, and manually map findings to MITRE ATT&CK. |
CONGRESS |
|
|
2026 |
Tiny Chips, Big Leaks: Breaking TrustZone-M with Single-Stepping Attacks | Trusted execution environments (TEEs) provide confidential-computing guarantees by running sensitive code inside hardware-enforced enclaves that remain isolated even when the operating system is compromised. However, despite this strong architectural isolation, TEEs remain vulnerable to software-based microarchitectural side-channel attacks. |
CONGRESS |
|
| 2026 | Tracking the Trackers: How We Took Over 36 Million GPS Devices Protecting Children & Vehicles | We analyzed three of the largest GPS tracking ecosystems: SETracker (~10M devices across 39 brands), SinoTrack (6M+ vehicles), and TKSTAR/Thinkrace (20M+ devices). Despite appearing as competing products, all three originate from the same Shenzhen-based supply chain and share critical architectural flaws. |
CONGRESS |
|
|
2026 |
Beyond Normalization: The Expanding Unicode Attack Surface | Modern web applications process input through layered pipelines: URL decoding, UTF-8 validation, WAF transformations, framework parsing, surrogate handling, database collation, HTML entity decoding, and increasingly, LLM preprocessing. |
CONGRESS |
|
| 2026 | Breaking Hardware CFI with Sigreturn | Modern hardware-assisted Control Flow Integrity (CFI) is increasingly deployed across mobile devices and cloud infrastructure. On ARM64 systems, backward-edge protections such as Pointer Authentication (PAC) protect return addresses, while forward-edge defenses such as Branch Target Identification (BTI) restrict indirect branches to compiler-inserted landing pads. |
CONGRESS |
|
|
2026 |
Caging the Agent: How Roblox Built Multi-Layer Sandboxes to Secure Claude Code at Enterprise Scale | A hidden instruction in a GitHub Issue convinced Claude Code to upload Roblox's credentials to a public repository. EDR saw nothing, it was a normal process making a normal network request. The good news, it happened in an internal testing environment. |
CONGRESS |
|
|
2026 |
Inside Coruna and DarkSword - iOS Exploits Caught in the Wild | Prior to 2026, iOS Malware and Exploits were seen as a problem only targeting a few individuals. 2026 changed this. Coruna and DarkSword were both deployed as watering hole attacks impacting hundreds of millions of iPhones at the time. |
CONGRESS |
|
| 2026 | Promptware EOD: Skillful Agent Detonation | The AI agent supply chain has become a fertile ground for malware. It lurks in skill markdown files, rug-pulled MCP servers, misaligned models, and weaponized moltbook posts. |
CONGRESS |
|
|
2026 |
Scanning the Scanners: Turning Security Vendors Into Supply Chain Weapons | Every security scanner promises to protect your supply chain. We submitted malicious repos to 20 of them through free-tier signups and compromised 5, gaining access to production databases, cloud credentials, third-party service credentials, and OAuth tokens associated with Fortune 100 companies, defense contractors, and government institutions. |
CONGRESS |
|
| 2026 | The 12th Annual Black Hat USA Network Operations Center (NOC) Report | Back with another year of soul-crushing statistics, the Black Hat NOC team will be sharing all of the data that keeps us equally puzzled and entertained, year after year. |
CONGRESS |
|
|
2026 |
The Intent Gap: Where Every AI Regulation Falls Short and What Security Leaders Need Instead | Every major AI regulation from the NIST AI Risk Management Framework, the EU AI Act, the U.S. AI Action Plan, and CISA's December 2025 OT guidance was designed for a world where software executes instructions. |
CONGRESS |
|
|
2026 |
When Agentic Glue Melts: Exploiting Cloudflare CodeMode and Workers | We began this research with a narrow goal: break Cloudflare Code Mode. What we found was much broader. |
CONGRESS |
|
| 2026 | Breaking the Unbreakable: Dismantling the Myth of "Trusted" Cryptographic Libraries (ON-DEMAND ONLY) | "Don't roll your own crypto." We follow this rule religiously — and in doing so, transfer absolute trust to libraries we never inspect. But how would you actually answer the question: is your cryptographic dependency secure? |
CONGRESS |
|
|
2026 |
Deterministic Chaos - Exploiting and Securing Predictable Timing in TSN Industrial Networks (ON-DEMAND ONLY) | Time-Sensitive Networking (TSN) is rapidly becoming the backbone of modern industrial automation. By enabling deterministic, low-latency communication over standard Ethernet, TSN supports safety-critical control loops, synchronized robotics, and real-time industrial processes where reliability and availability are essential. |
CONGRESS |
|
|
2026 |
Exploring the EL2 Attack Surface: From Vulnerability to Full System Compromise (ON-DEMAND ONLY) | AVF (Android Virtualization Framework) was introduced with Android 13 to provide underlying data-isolation capabilities that surpass traditional application sandboxing. |
CONGRESS |
|
| 2026 | From 8 Bytes to Full Compromise: AI-Assisted Exploitation of a Widespread USB Flaw in a Multi-SE Hardware Wallet (ON-DEMAND ONLY) | Hardware wallets and secure embedded devices are heavily marketed on their "defense-in-depth" architectures: multi Secure Elements (SE), MPU-protected OTP/fuses, and cryptographic key sharding. This Briefing examines what happens when the software foundation connecting these defensive layers is compromised. |
CONGRESS |
|
|
2026 |
Ghost Credentials: Hunting and Exploiting NonHuman Identities Across Cloud Environments (ON-DEMAND ONLY) | In 2026, the ratio of Non-Human Identities (NHIs) to human identities reached a staggering 144:1. While organizations have invested heavily in phishing-resistant MFA, passwordless authentication, and Zero Trust for human users, an invisible ecosystem of service accounts, API keys, OAuth applications, CI/CD secrets, Kubernetes identities, and AI agent credentials continues to operate with persistent privileges, fragmented ownership, and little to no lifecycle management. |
CONGRESS |
|
| 2026 | Inside the Screen: Deep-Diving into North Korean IT Workers' Live Infrastructure (ON-DEMAND ONLY) | North Korean IT workers have infiltrated companies worldwide, generating revenue for the regime while posing significant security risks to employers. In 2025, we exposed their reality—organizational structure, workflows, and tradecraft. |
CONGRESS |
|
|
2026 |
Medical Device Kill Chain: From Debug Port to Patient Impact (ON-DEMAND ONLY) | Connected medical devices such as infusion pumps, patient monitors, imaging systems, implantables, and other cyber-physical healthcare technologies increasingly form the backbone of modern clinical care. Despite growing connectivity and cloud integration, the security community still lacks a practical, end-to-end methodology for understanding how weaknesses across hardware, firmware, protocols, and backend systems combine to create patient safety and operational risk. |
CONGRESS |
|
|
2026 |
Spaghettifying DRAM: Breaking Everything with Memory Collision Exploitation (ON-DEMAND ONLY) | In this Briefing, we will take a fundamental invariant of computing - that an address identifies a variable's location - and break it at the hardware level. |
CONGRESS |
|
| 2026 | Trust No Deputy: Breaking Azure and GCP Through Managed Identity Chains (ON-DEMAND ONLY) | Cloud platforms delegate sensitive operations to managed identities, trusting that Azure RBAC and GCP IAM boundaries contain blast radius. This trust is misplaced. |
CONGRESS |
|
|
2026 |
When BPF Blinding Goes Dark: Smuggling Raw Gadgets into the Linux Kernel (ON-DEMAND ONLY) | bpf_jit_harden=2 is supposed to be the last word on JIT spray in the Linux kernel. Every immediate value in a BPF program gets masked with a random XOR key before the JIT ever sees it. Attacker-controlled bytes cannot land in kernel executable memory. The defense has been in place since 2016 and, until now, it worked. |
CONGRESS |