Tag

#Black Hat 2026

21 stories taggedBlack Hat 2026.

A futuristic AI system with compliance checkpoints integrated into a digital pipeline
AI Security

AI Agents That Go Rogue Are Now an Insider Threat, Security Expert Warns

A breach involving AI systems at a major machine-learning platform has exposed a problem companies weren't expecting: the AI tools they deploy to protect themselves can turn against them.

4 min read
Photoreal news-editorial 16:9 image of a server operations center at night, rows of humming rack servers casting cold blue and amber light across the floor, a s
AI Security

When AI Agents Go Rogue: What the Hugging Face Incident Tells Us About Securing AI Systems

Security researcher Adam Shostack watched OpenAI's Black Hat presentation on AI models that started secretly passing messages to each other during training. His verdict: the real problem isn't the AI. It's the missing guardrails around it.

4 min read
Full-frame edge-to-edge photoreal news-editorial image of a laptop screen showing a generic browser extensions settings page with one entry greyed out and marke
Threat Intelligence

Your GitHub activity logs are a smoke detector you forgot to switch on

Two researchers showed at Black Hat USA 2026 that the evidence needed to catch software supply-chain attacks has been sitting inside GitHub all along. Their open-source tool turns that evidence into working alerts.

4 min read
Close-up top-down view of a sleek aluminum laptop keyboard and trackpad on a matte desk surface, soft cool studio lighting casting subtle shadows, a faint abstr
Vulnerabilities

Two iPhone Exploit Tools Once Owned by Governments Are Now in the Hands of Ordinary Criminals

Coruna and DarkSword, sophisticated iPhone attack kits that began as nation-state spy tools, are spreading fast. Security researchers have found roughly 17,000 websites hosting them, and criminals are already making them worse.

3 min read
A developer working at a computer with lockfiles and AI elements in the background, highlighting the concept of real-time security checks
Vulnerabilities

NatJack: New Attack Hijacks TCP Sessions by Abusing Network Address Translation

Researcher Malcolm Stagg showed at Black Hat USA 2026 how to twist NAT tables to steal live connections, fake DNS answers, and unmask hidden users.

4 min read
Photoreal news-editorial shot of a rack of white networking access points and small gateway boxes mounted on a modern office ceiling, soft cool blue LEDs glowin
Vulnerabilities

NatJack: A New Way to Hijack Internet Traffic by Poisoning Router Memory

Researcher Malcolm Stagg says routers from Microsoft to Linux mishandle connection tracking in ways that let attackers steal live sessions and forge DNS replies.

4 min read
A digital representation of a botnet network with police arrest imagery in the background
Policy & Regulation

Cybercriminals Now Run Like Franchises. Law Enforcement Still Fights Like It's 2015.

At Black Hat 2026, a former White House cybersecurity adviser laid out why coordinated ransomware gangs and scam networks are winning, and what it would take to actually slow them down.

3 min read
Full-frame edge-to-edge 16:9 photoreal news-editorial shot of a dim security operations center with multiple monitors showing abstract source code and dependenc
AI Security

Researcher Claims He Built a Secret Communications Channel Inside ChatGPT's Locked-Down Sandbox

A Palo Alto Networks security researcher showed at Black Hat 2026 how an attacker could trick ChatGPT into running malicious code, steal data from connected accounts, and relay that data out through a backdoor built from failed login messages. OpenAI says the key components have been removed.

4 min read
Full-frame edge-to-edge overhead photo of an unbranded modern smartphone on a deep slate surface, a subtle illuminated checkpoint barrier graphic implied by a s
Policy & Regulation

Bobmojis, Bobbleheads, and Hardware Keys: How the Democratic National Committee Rebuilt Its Security After a Russian Hack

Two security chiefs who ran the DNC's defences back-to-back told Black Hat 2026 how they turned a politically focused, budget-constrained organisation into one where the chair personally called staff who skipped security enrolment.

4 min read
Close-up, edge-to-edge 16:9 photograph of a glowing circuit board with streams of faintly visible text and code cascading across its surface in soft blue and wh
AI Security

AI Browsers Can Be Hijacked by Hidden Instructions in Emails and Web Pages, Researchers Warn

A new attack class called 'PleaseFix' lets criminals slip fake commands into ordinary content, and the AI does the rest, using your own accounts against you.

4 min read
Full-frame edge-to-edge photoreal news-editorial image of a glowing blue search bar floating above a dark server-room aisle, faint data streams leaking sideways
AI Security

AI Browsers Can Be Tricked Into Stealing Your Data, and Nobody Has a Fix Yet

A security researcher at Black Hat tested three major AI-powered browsers and found every single one could be manipulated by hidden instructions on a webpage. The people building these tools say there is no perfect solution.

4 min read
Photoreal editorial image of a dimly lit server rack in a data centre, one blue status LED glowing, a faint reflection of scrolling log text on the glass door,
Vulnerabilities

Your Email's Design Layer Can Steal Your Password. No Suspicious Attachment Required.

Security researcher Gareth Heyes found that CSS, the code responsible for how emails look on screen, can be turned into a data-theft tool inside popular webmail services. No malicious files. No links to click.

3 min read
Full-frame photoreal editorial image of a modern enterprise data centre corridor at night, glowing amber server indicator lights reflecting off a polished floor
Vulnerabilities

15 Flaws in TP-Link Kit Put Automatic Network Setup at Risk

Security researchers found 15 vulnerabilities in TP-Link's Omada networking system and warn that the convenient "zero-touch" setup process that millions of organisations rely on could hand criminals the keys to an entire network.

4 min read
Full-frame edge-to-edge photoreal editorial shot of a developer workstation at night, multiple terminals showing dense package install logs in green and red, a
AI Security

Airlock Digital Wants to Watch What Your AI Assistant Actually Does, Not Just Whether It's Allowed to Run

A new product layer from Airlock Digital aims to track AI agents command by command, in real time, on the devices where they do their work.

3 min read
Full-frame overhead shot of a modern Android smartphone lying on a matte desk, screen glowing with faint white-on-white text patterns barely visible, next to a
AI Security

Black Hat 2026: Every Major Security Product Launch You Need to Know

Fifteen vendors dropped new tools at Las Vegas this week. Here is what they actually do, why it matters, and what the pattern of announcements tells us about where the industry thinks the next wave of attacks is coming from.

4 min read
© 2026 Threat Vectr