Skip to content
Black Hat 2026: Key news, takeaways and security trends

Black Hat 2026: Key news, takeaways and security trends

Searchsecurity.Techtarget • August 11, 2026

Company employees said their industry should rethink how it balances capabilities and safeguards. Read Now

Black Hat USA 2026 returns for its 29th year, covering the latest in infosec for CISOs, technical experts, thought leaders, innovative vendors and cybersecurity pros. The two-day main event, taking place August 5-6 at Mandalay Bay in Las Vegas, features more than 200 sessions on topics from cyber-resilience and malware to detection engineering, security culture, privacy, supply chain security and cryptography. And, of course, AI security, LLMs, prompt engineering, promptware, autonomous exploits and AI agents. Four days of specialized trainings, August 1-4, will cover incident response, third-party risk management, AI security for executives, red teaming, adversary tactics and more. This year also marks the return of the CISO Summit, Financial Threat Summit, Innovators & Investors Summit, Omdia Analyst Summit and AI Summit, as well as the inaugural Healthcare Summit, in partnership with HIMSS. Informa TechTarget's editorial team will be on-site, reporting from the conference floor. This guide gathers articles from our reports on TechTarget Cybersecurity, Dark Reading and Cybersecurity Dive.

Black Hat USA 2026 returns for its 29th year, covering the latest in infosec for CISOs, technical experts, thought leaders, innovative vendors and cybersecurity pros.

The two-day main event, taking place August 5-6 at Mandalay Bay in Las Vegas, features more than 200 sessions on topics from cyber-resilience and malware to detection engineering, security culture, privacy, supply chain security and cryptography. And, of course, AI security, LLMs, prompt engineering, promptware, autonomous exploits and AI agents.

Four days of specialized trainings, August 1-4, will cover incident response, third-party risk management, AI security for executives, red teaming, adversary tactics and more. This year also marks the return of the CISO Summit, Financial Threat Summit, Innovators & Investors Summit, Omdia Analyst Summit and AI Summit, as well as the inaugural Healthcare Summit, in partnership with HIMSS.

Informa TechTarget's editorial team will be on-site, reporting from the conference floor. This guide gathers articles from our reports on TechTarget Cybersecurity, Dark Reading and Cybersecurity Dive.

Black Hat presenters divulged the latest attacks and sounded warning bells on what could be coming .

Attackers can take control of agents through malicious instructions hidden in content supplied to AI browsers, and there's no simple fix for the threat. Read Now

AI browsers from top vendors remain vulnerable to prompt injection attacks despite multiple security guardrails, according to new research. Read Now

National Cyber Director Sean Cairncross said the administration wants to work collaboratively with the private sector. Read Now

U.S. and allied officials said companies should start preparing now for a cyberattack that changes how they provide essential services. Read Now

Researchers are calling attention to the risks inherent in automated network device provisioning, using a world-leading device manufacturer as a case study. Read Now

The agency has been focused on helping secure systems at drinking and wastewater utilities in recent weeks. Read Now

CSS was once just design. Now researchers warn it's powerful enough to exfiltrate data from webmail -- and some vendors aren't prepared. Read Now

Organized crime is convincingly scamming at scale, making billions thanks to AI-enabled voice cloning, deepfake real-time video overlays, LLM-driven persona management and automated translation. Read Now

We got a sneak peek at some of the show's presentations -- take a look at what you'll see at the show.

Researchers propose focusing on identification of certain cognitive elements in LLMs that indicate when AI systems may take an unwanted action. Read Now

Dormant nonhuman identities can create security blind spots, says security researcher Aleksandr Krasnov, who plans to release an open source tool week at Black Hat USA 2026 that sniffs out trust paths. Read Now

PleaseFix class of flaws makes it easy to socially engineer agentic browsers and highlights weaknesses in how they handle cross-origin requests. Read Now

New research shows how security scanners embedded in the software supply chain can be attacked to serve as a foothold for downstream attacks. Read Now

The agentic AI playing field was heavily tilted toward offense, so researchers began using red team agents to help teach their blue counterparts. Read Now

A myriad of software makes up the typical AI harness, and trust issues between the components can create concerning attack vectors. Read Now

Black Hat 2026 keynotes and presentations will look at a variety of topics. Check out our pre-show coverage here.

This category of vulnerabilities allows an attacker to easily acquire administrative-level permissions and bypass cloud providers' access controls. Read Now

An FBI agent explains how the multinational law-enforcement Operation Cronos was successful in disrupting the largest ransomware group of its time. Read Now

Microsoft addresses a public-by-default configuration and chain of code flaws in Azure Automation that could have let attackers seize another tenant's identity and access others' data, credentials and cloud workloads. Read Now

Ahead of Black Hat USA, researchers find exploitable flaws in how Microsoft handles passkeys that could allow attackers to impersonate privileged users. Read Now

The latest large language models have high false-positive rates and fail to take into account the context of scans, leading to more work for AppSec professionals. Read Now

Agentic AI is creating enough risks for organizations to demand a security reframe. Read Now

Automated Frequency Coordination systems by default trust client-side data, which could lead to location spoofing and other attacks that disrupt traffic. Read Now

An open source, AI-driven system adopts victim personas to engage with phishing attackers, allowing organizations and law enforcement to gather relevant data on cybercriminal operations. Read Now

Organizations, and possibly ATMs, are at risk of compromise, thanks to holes in a Microsoft BitLocker security wrapper. Read Now

Does life feel Orwellian sometimes? One researcher has a solution for you: graphic tees that confuse the neural networks in surveillance cameras. Read Now

Last year's Black Hat USA conference covered a range of essential topics. Here is an array of highlights to get you up to speed and prepare for this year's event.

Read the identity and data security happenings at Black Hat 2025, including advancements that enable AI adoption and products that help prepare for a post-quantum world. Read Now

Passwordless authentication is becoming more common, but account recovery poses increased risks that can lead to account takeovers. It's especially dangerous because even low-skilled attackers can achieve success. Read Now

Experts from Zenity Labs demonstrated how attackers could exploit widely deployed AI technologies for data theft and manipulation. Read Now

Organizations supporting the security vulnerability program said it needed changes to improve stability and rebuild trust. Read Now

Security startups of all stripes submitted applications for Black Hat USA's Startup Spotlight. Prime Security won with its AI security architect platform. Read Now