Black Hat 2026: Five Security Findings Every Organisation Should Know About

From fake AI tools downloaded 1.7 million times to a flaw that lets attackers hijack internet connections through network devices, this year's hacker conference in Las Vegas carried some practical warnings for businesses of every size.

ThreatVectr NewsdeskUpdated · Editor: Lee Brown· 4 min read
The Las Vegas convention center during Black Hat conference with security professionals examining booth displays of attack tools and vulnerability demonstration
Share

Key points

  • Malicious fake AI tools impersonating popular software were downloaded more than 1.7 million times in under a month, researchers from Zenity disclosed at Black Hat.
  • Every one of the 32 network devices or configurations tested by researcher Malcolm Stagg was vulnerable to a newly disclosed class of connection-hijacking attacks called NatJack.
  • Microsoft and Linux maintainers have both issued patches in response to the NatJack findings.
  • A Microsoft executive argued at Black Hat that monthly patching cycles are too slow for the pace at which AI now helps criminals find and exploit security flaws.
  • An open-source detection tool called GitHub Threat Detector, released at the conference, offers 30 built-in rules for spotting software supply-chain attacks.

Black Hat and DEFCON, held in Las Vegas each summer, drew researchers, corporate defenders and officials last week. Two themes dominated: AI as both a defensive tool and a fresh criminal target, and the fragility of security assumptions organisations have trusted for years.

How did criminals use AI tools against ordinary users?

Researchers at security firm Zenity uncovered a campaign in which criminals uploaded booby-trapped AI "skills" to a public marketplace called skills.sh. AI skills are small instruction files that tell AI assistants how to interact with other software; think of them as plug-ins for AI systems.

The fake skills impersonated two legitimate tools: Paperclip and Browser Use. Users who downloaded them got malicious software instead. More than 1.7 million downloads happened in less than a month.

Zenity described this as part of a broader pattern they call AI software supply-chain attacks, where criminals slip poisoned components into the digital shelves that developers and businesses browse when building AI-powered products. It's a delivery method that scales fast, because the marketplace does the distribution for the attacker.

If your organisation uses AI tools built from third-party components, ask your technology team which marketplaces those components come from and whether any vetting process exists before installation.

Should businesses be worried about their network devices?

Yes, particularly if they haven't applied recent patches. Malcolm Stagg, an independent researcher working with the Synack Red Team, disclosed a new family of attacks he named NatJack. We've covered the technical detail in two dedicated pieces published on 7 August: NatJack: New Attack Hijacks TCP Sessions by Abusing Network Address Translation and NatJack: A New Way to Hijack Internet Traffic by Poisoning Router Memory.

The target is a technology called Network Address Translation, or NAT, which almost every office router and firewall uses. NAT was originally built to conserve internet addresses, not to act as a security barrier, but many organisations rely on it as an invisible shield that keeps internal devices off the public internet.

NatJack can punch through that shield. An attacker could hijack active connections, feed poisoned responses to DNS lookups (DNS is the system that translates website names into addresses your computer can reach), or knock devices offline entirely. No special access to the target network is required.

Scope Detail
Products tested 32 devices or configurations across multiple vendors
Vulnerable products All 32, to at least some NatJack techniques
Patches issued Microsoft and Linux maintainers, following Stagg's disclosure
Attack capability Connection hijacking, DNS poisoning, denial of service

Both Microsoft and the maintainers of Linux, the operating system running the majority of the world's servers, have released patches. Applying those updates promptly is the most direct response available.

How did AI change the picture for security defenders?

Two talks offered complementary answers. Microsoft's David Weston argued that AI now lets criminals find software flaws and build attack tools faster and more cheaply than before, meaning defenders can no longer count on having weeks to respond after a flaw surfaces. He called for software written in languages such as Rust that are harder to exploit, and for automated patching rather than monthly update schedules.

Separately, PortSwigger researcher James Kettle demonstrated that AI can do genuinely original security research, finding hundreds of real HTTP request smuggling vulnerabilities (a technique where criminals send confusing instructions to web servers to intercept other users' traffic). His finding: AI works best when a human expert designs the methodology and filters weak outputs. Left fully autonomous, it underperforms.

For defenders, that's a practical boundary. These tools are worth using, but they need a human hand on the wheel.

Common questions

Do I need to do anything right now?

If your organisation uses Microsoft products or Linux-based servers, check with your IT team that the latest patches covering the NatJack flaw have been applied. For any AI-powered tools assembled from third-party components, find out where those components originate.

Could employees accidentally install something harmful?

Yes. The 1.7 million downloads of malicious AI skills show that users often can't tell a fake tool from a genuine one when both appear on the same marketplace. Brief your staff on checking with IT before installing any new AI tool or plug-in, however legitimate it appears.

© 2026 Threat Vectr