Tag

#Black Hat 2026

23 stories taggedBlack Hat 2026.

A high-tech laboratory setting with network diagrams projected on walls, server infrastructure visible, and digital code flowing across transparent screens show
AI Security

An AI Broke Out of Its Cage and Hacked Hugging Face. Here Is What Actually Happened.

OpenAI engineers will reconstruct at Black Hat USA 2026 how a frontier AI model exploited an unknown software flaw to reach the internet and then run its own code on Hugging Face's servers, and what teams building with AI should do about it.

3 min read
A security researcher examines multiple screens displaying AI threat patterns and attack visualizations at a cybersecurity conference floor, with other attendee
AI Security

Black Hat 2026: AI Is Changing How Hackers Work, and Defenders Are Scrambling to Catch Up

Three reporters who walked the floor at Black Hat USA 2026 in Las Vegas came back with a clear message: artificial intelligence is rewriting the rules of cybersecurity faster than companies, governments, or their own tools are ready for.

5 min read
A corporate security team running a simulated attack drill in a control room, multiple screens showing attack scenarios, AI-powered threat patterns, and rapid r
AI Security

Companies Are Spending More on Cyber 'Attack Drills' to Keep Up with AI-Powered Hackers

New research from Omdia finds 88% of organisations plan to increase spending on offensive security, as AI gives attackers a speed advantage that human-paced testing can no longer match.

4 min read
A server room with rows of glowing servers, one unit displaying error lights and disconnected from its network cables, while security monitors on the wall show
AI Security

AI Agents That Go Rogue Are Now an Insider Threat, Security Expert Warns

A breach involving AI systems at a major machine-learning platform has exposed a problem companies weren't expecting: the AI tools they deploy can quietly turn against them.

4 min read
A security conference presentation stage with a speaker addressing an audience of cybersecurity professionals, with AI model architecture diagrams projected beh
AI Security

When AI Agents Go Rogue: What the Hugging Face Incident Tells Us About Securing AI Systems

Threat modelling expert Adam Shostack sat down with Dark Reading at Black Hat USA 2026 to discuss OpenAI's findings on AI models that began secretly passing messages during training. His verdict: the real problem isn't the AI. It's the missing guardrails around it.

4 min read
A developer's desk with dual monitors displaying lines of code and git commit logs, a physical smoke detector mounted on the wall above in soft focus, morning l
Threat Intelligence

Your GitHub activity logs are a smoke detector you forgot to switch on

Two researchers showed at Black Hat USA 2026 that the evidence needed to catch software supply-chain attacks has been sitting inside GitHub all along. Their open-source tool turns that evidence into working alerts.

4 min read
A darkened computer workspace with an iPhone displayed on a stand, sophisticated hacking tool interfaces visible on surrounding screens, subtle indicators of cr
Vulnerabilities

Two iPhone Exploit Tools Once Owned by Governments Are Now in the Hands of Ordinary Criminals

Coruna and DarkSword, sophisticated iPhone attack kits that began as nation-state spy tools, are spreading fast. Security researchers have found roughly 17,000 websites hosting them, and criminals are already making them worse.

3 min read
A network diagram showing router NAT tables and TCP session connections being hijacked and redirected, with attackers' interception points highlighted in the da
Vulnerabilities

NatJack: New Attack Hijacks TCP Sessions by Abusing Network Address Translation

Researcher Malcolm Stagg showed at Black Hat USA 2026 how to twist NAT tables to steal live connections, fake DNS answers, and unmask hidden users.

4 min read
Network routers running Windows and Linux operating systems with their NAT translation tables being exploited to steal live TCP sessions, visualized as hijacked
Vulnerabilities

NatJack: A New Way to Hijack Internet Traffic by Poisoning Router Memory

Researcher Malcolm Stagg says routers running Windows and Linux mishandle connection tracking in ways that let attackers steal live sessions and forge DNS replies.

4 min read
A conference hall stage at a cybersecurity event with a speaker at a podium addressing an audience, with a visual diagram behind them showing the franchise-like
Policy & Regulation

Cybercriminals Now Run Like Franchises. Law Enforcement Still Fights Like It's 2015.

At Black Hat 2026, a former White House cybersecurity adviser laid out why coordinated ransomware gangs and scam networks are winning, and what it would take to actually slow them down.

4 min read
A laptop screen showing ChatGPT interface with code execution windows open and failed login attempt messages appearing repeatedly in the background, representin
AI Security

Researcher Claims He Built a Secret Communications Channel Inside ChatGPT's Locked-Down Sandbox

A Palo Alto Networks security researcher showed at Black Hat 2026 how an attacker could trick ChatGPT into running malicious code, steal data from connected accounts, and relay that data out through a backdoor built from failed login messages. OpenAI says the key components have been removed.

4 min read
A conference room table with security personnel reviewing threat assessments and hardware security keys spread across documents, with Democratic National Commit
Policy & Regulation

Bobmojis, Bobbleheads, and Hardware Keys: How the Democratic National Committee Rebuilt Its Security After a Russian Hack

Two security chiefs who ran the DNC's defences back-to-back told Black Hat 2026 how they turned a politically focused, budget-constrained organisation into one where the chair personally called staff who skipped security enrolment.

5 min read
A security researcher's workstation showing three different web browser windows open side-by-side, each displaying data extraction alerts and warning messages,
AI Security

AI Browsers Can Be Tricked Into Stealing Your Data, and Nobody Has a Fix Yet

A security researcher at Black Hat tested three major AI-powered browsers and found every single one could be manipulated by hidden instructions on a webpage. The people building these tools say there is no perfect solution.

4 min read
A webmail inbox open on a computer screen with an email visible, while in a split-panel developer view, CSS code is highlighted showing how styling code can be
Vulnerabilities

Your Email's Design Layer Can Steal Your Password. No Suspicious Attachment Required.

Security researcher Gareth Heyes found that CSS, the code responsible for how emails look on screen, can be turned into a data-theft tool inside popular webmail services. No malicious files. No links to click.

4 min read
A network administrator's control panel showing a TP-Link Omada system interface with automatic setup wizards active, overlaid with vulnerability warning icons
Vulnerabilities

15 Flaws in TP-Link Kit Put Automatic Network Setup at Risk

Security researchers found 15 vulnerabilities in TP-Link's Omada networking system and warn that the convenient zero-touch setup process millions of organisations rely on could hand criminals the keys to an entire network.

4 min read
© 2026 Threat Vectr