LAS VEGAS — Bring comfortable shoes, a backup battery and, apparently, a butter knife.
Black Hat USA arrives at Mandalay Bay this week with the security industry confronting a threat environment that is faster, more automated and increasingly difficult to separate from legitimate activity.
Trainings run through Tuesday, the main Briefings are Wednesday and Thursday, BSides Las Vegas is underway nearby, and DEF CON begins Thursday.
The conference agenda is heavy with AI agents, cloud identities, browser trust, credential theft and attacks that move too quickly for a human analyst to calmly finish a cup of coffee. The central message is familiar but newly urgent: Trust less, verify more and assume every identity – human or machine – may eventually become an attack path.
The opening keynote panel brings together the White House’s National Cyber Director Sean Cairncross, CISA’s Nick Andersen, the FBI’s Brett Leatherman and the Department of War’s Katherine Sutton, while Microsoft’s David Weston warns of the urgent need for “agentic security.”
Behind that warning is a rapidly expanding identity problem: The machines are multiplying faster than the controls built to govern them.
The Bots Have Better Credentials
Palo Alto Networks’ 2026 Identity Security Landscape report says enterprises now manage 109 machine identities for every human, up from 82 to 1 a year ago. Okta, citing Gravitee research, says 88% of organizations have experienced a confirmed or suspected AI-agent security incident, yet only 22% govern agents as distinct identities.
That identity gap will be hard to miss at Black Hat. Palo Alto Networks is presenting “Every Identity Is Privileged: Securing the Workforce of the AI Enterprise.” Rubrik asks, “Your Agents Are Now Enterprise Actors With Their Own Identity. Who Controls Them?” Silverfort will demonstrate how AI can attack Active Directory in minutes, while Semperis researcher Shai Laron will detail Kerberos flaws that can lead to full domain takeover.
The problem is not merely that the bots have credentials. It is that neither they nor the attackers controlling them are inclined to dawdle.
CrowdStrike offers the week’s most unnerving stopwatch.
Its 2026 Global Threat Report says the average eCrime breakout time — the interval from initial compromise to lateral movement — fell to 29 minutes in 2025. The fastest observed breakout took 27 seconds.
And that was before the newest frontier models — GPT-5.6 Sol, Claude Opus 4.7 and Claude Mythos 5 — began demonstrating how quickly autonomous systems can hunt for vulnerabilities, operate tools and occasionally slip their leashes. Add zero-day machines that can string together CVEs like charms on a friendship bracelet, and 29 minutes begins to sound almost leisurely.
Brave New Frontier Model World
That is the daytime mood at Hacker Summer Camp: The machines are multiplying, attackers are accelerating and established trust boundaries are starting to look more like dotted lines.
Black Hat’s official program is hardly ignoring the frontier. The AI Summit will examine the risks of agentic systems and frontier-model deployments, while the Briefings include researchers building frontier-grade AI agents for exploitation and asking whether autonomous systems can invent entirely new attack techniques. The scheduled conversation is about what these models can do, how attackers can use them and whether defenders can keep them inside the lines.
The hallway conversation is likely to be less tidy. And the timing could scarcely be more Black Hat.
Realtime World of Black Hat Intervenes
While AI-powered offense and defense is very much on Black Hat’s official keynote menu this year, models quietly going off-script during evaluations is not. And that’s exactly why it will be the most talked-about topic not on the agenda.
Washington and the frontier labs are supplying Black Hat’s unofficial hallway track. As the conference opens, OpenAI, Anthropic, Google and Meta have been invited to the White House to discuss a new voluntary testing framework, ordered in June, for deciding when a model’s cyber capabilities cross into “covered frontier” territory. Which raises the most Black Hat question imaginable: Who tests the testers?
OpenAI says GPT-5.6 Sol and a pre-release model escaped a sandbox and compromised Hugging Face; Anthropic says Opus 4.7, Mythos 5 and an internal model reached three real organizations during evaluations. Meanwhile, Hugging Face says commercial guardrails blocked parts of its forensic investigation, forcing responders to turn to open-weight GLM-5.2. The model with fewer constraints helped investigate the models that ignored theirs.
When does cocktail hour begin?
The Research Is Not Subtle
The most anticipated Black Hat sessions do not exactly promise reassurance.
PortSwigger researcher James Kettle is scheduled to debut “Can AI Do Novel Security Research? Meet the HTTP Terminator”, work built around an autonomous system that he says invented new HTTP attack techniques and used them against banks, security products and government infrastructure.
The question is no longer merely whether AI can find familiar classes of flaws. It is whether a machine can devise attack methods researchers have not previously documented — and then open-source the machine.
The humans, meanwhile, are not taking the week off.
In “Anatomy of a Takedown: Inside the Operation That Broke LockBit”, the FBI’s Brett Leatherman and Paul Foster of Britain’s National Crime Agency will unpack Operation Cronos, the international effort that seized LockBit infrastructure and attacked the trust holding its ransomware affiliate economy together.
Servers can be rebuilt. A criminal brand that can no longer promise anonymity is harder to patch.
Trust also runs through the software-supply-chain research. “Scanning the Scanners: Turning Security Vendors Into Supply Chain Weapons” asks what happens when the products hired to inspect software become delivery systems themselves. Microsoft will separately examine ongoing npm attacks in “Poisoned at the Source”.
Apparently, the software supply chain has decided that being a metaphor was not sufficiently alarming.
For those who prefer their unease hands-on, Arsenal returns with open-source security tools, the new Drone Zone lets attendees hack and fly autonomous systems, and the NOC Outpost puts the conference network — and the people defending it — on display in real time.
Nothing says confidence like inviting thousands of hackers to inspect the plumbing.
This is serious material. By late afternoon, however, the threat model acquires a dress code, a guest list and an RSVP link.
Zero Trust Until the Open Bar
At roughly 4 p.m., the doctrine changes.
The same industry that spends all day preaching least privilege and verified identity begins sorting through Black Hat’s official networking calendar, HackerParties, Conference Parties and DEFCON Parties. The directories are useful, and the parties are real. The contradiction s simply too delicious to ignore.
No zero-day is required. A plausible RSVP page promising access to Cyera’s “Blazers, Bourbon & Bubbles” Four Seasons penthouse reception – or any sufficiently exclusive happy hour – could coax corporate email addresses, job titles and phone numbers from people who spent the morning warning everyone else not to click unexpected links.
We have spent decades building layered defenses and machines capable of hunting machines. Yet Black Hat’s most reliable authentication bypass remains entirely social. A scarce invitation, a good view and a plate of sliders.
Then someone texts: “I have the RSVP link.”
Zero trust gives way to infinite vibes.
See you at the bar.
Image Courtesy of Informa PLC