Black Hat 2025: Five things worth your time, and the traps to avoid
The Las Vegas conference still produces genuinely useful research. Getting to it means ignoring a lot of expensive noise.

Key points
- Black Hat was founded in 1997 as a more corporate spin-off of DEF CON, then sold to CMP Media (now Informa) in 2005 for $14 million.
- RSA Conference attracted nearly 44,000 attendees this year, a figure that shows how large enterprise security events have grown since RSA launched in 1991.
- Five research areas dominate the 2025 Black Hat agenda: AI agent attacks, state-sponsored hacker infrastructure, AI-powered exploit tools, threat hunting in the AI era, and criminal use of AI.
- Skip the themed cocktail parties and vendor pitches; the researcher-led sessions are where the useful material sits.
- The gap between a flaw being discovered and criminals weaponising it has shrunk to near-zero, a shift we've tracked closely in recent months.
Black Hat began in 1997 as a practical fix to an awkward problem. DEF CON, the long-running hacker gathering, was too rough-edged for corporate attendees. So its founders created a tamer version: same technical depth, fewer theatrical stunts. For years it worked.
Then in 2005 the conference sold to CMP Media (since absorbed into Informa) for $14 million. The money brought scale and an identity problem that, according to CSO Online, Informa is now paying a New York branding agency to help resolve.
The tension is simple. Researchers and threat analysts still show up with genuinely important findings. Vendors also show up, paying premium rates for floor space and themed cocktail parties. The two crowds want different things from the same event. Book the research sessions first and treat the exhibition floor as optional.
What research actually matters this year?
Five topic areas are worth a security professional's time.
| Topic | Why it matters now |
|---|---|
| Agentic AI exploitation | Organisations are giving AI agents (software that takes actions automatically, without a human approving each step) access to databases and internal systems. Criminals are studying how to hijack those agents. |
| APT infrastructure | APT stands for Advanced Persistent Threat: well-funded attackers, often state-sponsored, who stay inside a network for months. Their methods now include hijacking home routers and stealing login sessions. |
| AI-powered exploit tools | The gap between a flaw being discovered and criminals weaponising it has shrunk to near-zero. Our 23 July story "Can You Still Patch Your Way to Safety?" found that AI can now turn a published vulnerability description into a working attack in under a day. Automated patching pipelines are no longer optional. |
| AI-era threat hunting | Static watchlists of known bad IP addresses aren't enough. Defenders need continuous behaviour monitoring that flags unusual patterns rather than known signatures. |
| Criminal use of AI | Attackers use AI to write malware on demand, scrub their digital footprints, and build convincing fake identities. Understanding the full attack chain is the prerequisite for choosing any defensive tool. |
These five areas connect. Criminals are using AI to move faster, hide more effectively, and target newer automated systems that defenders have only just started deploying. The sessions addressing each area are where substantive answers sit.
Should ordinary workers care about any of this?
Yes, concretely. Criminals using AI to generate fake personas means phishing emails (fraudulent messages designed to trick recipients into handing over passwords or clicking malicious links) are harder to spot. They're better written, better targeted, arriving faster than before.
For anyone who uses work email or handles customer data, the baseline habit stays the same: treat unexpected requests for credentials or payments with scepticism, regardless of how plausible they look, and report anything odd to your IT team.
Black Hat's real value, buried under the sales pitches, is that it surfaces the specific techniques criminals are refining right now. The professionals who extract that knowledge are building the defences that protect everyone else. The triads and the branding crisis are noise; the sessions on AI-driven attack chains are not.



