#Black Hat 2026
21 stories taggedBlack Hat 2026.

AI Agents That Go Rogue Are Now an Insider Threat, Security Expert Warns
A breach involving AI systems at a major machine-learning platform has exposed a problem companies weren't expecting: the AI tools they deploy to protect themselves can turn against them.

When AI Agents Go Rogue: What the Hugging Face Incident Tells Us About Securing AI Systems
Security researcher Adam Shostack watched OpenAI's Black Hat presentation on AI models that started secretly passing messages to each other during training. His verdict: the real problem isn't the AI. It's the missing guardrails around it.

Your GitHub activity logs are a smoke detector you forgot to switch on
Two researchers showed at Black Hat USA 2026 that the evidence needed to catch software supply-chain attacks has been sitting inside GitHub all along. Their open-source tool turns that evidence into working alerts.

Two iPhone Exploit Tools Once Owned by Governments Are Now in the Hands of Ordinary Criminals
Coruna and DarkSword, sophisticated iPhone attack kits that began as nation-state spy tools, are spreading fast. Security researchers have found roughly 17,000 websites hosting them, and criminals are already making them worse.

NatJack: New Attack Hijacks TCP Sessions by Abusing Network Address Translation
Researcher Malcolm Stagg showed at Black Hat USA 2026 how to twist NAT tables to steal live connections, fake DNS answers, and unmask hidden users.

NatJack: A New Way to Hijack Internet Traffic by Poisoning Router Memory
Researcher Malcolm Stagg says routers from Microsoft to Linux mishandle connection tracking in ways that let attackers steal live sessions and forge DNS replies.

Cybercriminals Now Run Like Franchises. Law Enforcement Still Fights Like It's 2015.
At Black Hat 2026, a former White House cybersecurity adviser laid out why coordinated ransomware gangs and scam networks are winning, and what it would take to actually slow them down.

Researcher Claims He Built a Secret Communications Channel Inside ChatGPT's Locked-Down Sandbox
A Palo Alto Networks security researcher showed at Black Hat 2026 how an attacker could trick ChatGPT into running malicious code, steal data from connected accounts, and relay that data out through a backdoor built from failed login messages. OpenAI says the key components have been removed.

Bobmojis, Bobbleheads, and Hardware Keys: How the Democratic National Committee Rebuilt Its Security After a Russian Hack
Two security chiefs who ran the DNC's defences back-to-back told Black Hat 2026 how they turned a politically focused, budget-constrained organisation into one where the chair personally called staff who skipped security enrolment.

AI Browsers Can Be Hijacked by Hidden Instructions in Emails and Web Pages, Researchers Warn
A new attack class called 'PleaseFix' lets criminals slip fake commands into ordinary content, and the AI does the rest, using your own accounts against you.

AI Browsers Can Be Tricked Into Stealing Your Data, and Nobody Has a Fix Yet
A security researcher at Black Hat tested three major AI-powered browsers and found every single one could be manipulated by hidden instructions on a webpage. The people building these tools say there is no perfect solution.

Your Email's Design Layer Can Steal Your Password. No Suspicious Attachment Required.
Security researcher Gareth Heyes found that CSS, the code responsible for how emails look on screen, can be turned into a data-theft tool inside popular webmail services. No malicious files. No links to click.

15 Flaws in TP-Link Kit Put Automatic Network Setup at Risk
Security researchers found 15 vulnerabilities in TP-Link's Omada networking system and warn that the convenient "zero-touch" setup process that millions of organisations rely on could hand criminals the keys to an entire network.

Airlock Digital Wants to Watch What Your AI Assistant Actually Does, Not Just Whether It's Allowed to Run
A new product layer from Airlock Digital aims to track AI agents command by command, in real time, on the devices where they do their work.

Black Hat 2026: Every Major Security Product Launch You Need to Know
Fifteen vendors dropped new tools at Las Vegas this week. Here is what they actually do, why it matters, and what the pattern of announcements tells us about where the industry thinks the next wave of attacks is coming from.