Things You Won’t Want to Miss at Black Hat USA 2026
If you thought AI was a focus last year, buckle up
- Black Hat 2026 isn’t just talking about AI, it’s fully immersed in it, with AI dominating keynotes, briefings, and discussions on everything from offensive tradecraft to cyber resilience and compliance.
- The expo floor will be awash in AI claims and demos, but the real challenge for attendees is separating buzz from capabilities that genuinely help defenders move faster and make better decisions.
- Don’t forget to stop at Booth 4727, where Symantec and Carbon Black are showcasing AI-powered protections, predictive security capabilities, and cross-domain correlation via Symantec® CBX, its unified XDR platform that protects endpoints, networks, and data. You can also pick up a signed copy of Allie Mellen’s new book Code War, and instantly become a music lesson within the infamous AI photo booth.
Last year, everyone was talking about AI at Black Hat USA, DefCon, and B-Sides. That’s because AI overall was still just taking shape as a tool to help defenders to do their jobs better, and threat actors were just learning how to harness the power of AI to automate attacks, create more convincing phishing attacks, and just go about their dark business with less hassle.
This year, you’d be safe in calling Black Hat AI-obsessed. It’s gonna be everywhere—and I’m there for it.
AI everywhere in Vegas
Let’s start with the keynotes. Every Black Hat keynote this year is focused on AI—the defenses it enables, the threats it assists, and the prospect of it assisting in vulnerability research, which thanks to the emergence of frontier AI models has become a hot topic from the SOC to the C-Suite.
The AI tsunami is washing over the conference portion of the event as well.
- Why build stealthy malware or chain together complex evasion techniques when you can simply turn the security product off? Bring Your Own Vulnerable Driver (BYOVD) has become a staple of the modern attacker’s toolkit, with AI helping bad guys execute tasks like building custom EDR-killer tools, write operational drop scripts, and hasten reconnaissance. Always one of the smartest guys in any room, Symantec and Carbon Black Threat Intelligence Analyst Marc Elias will break down how adversaries exploit signed but vulnerable drivers to disable endpoint security. Expect to learn why current protections often fall short and discover practical strategies and tools to keep your defenses alert and resilient. Check out Marc from 10:15 to 11 am on Thursday, Aug. 6 for Lights Out: How Attackers are Weaponizing Vulnerable Drivers.
- If you’re ready for a different perspective—one likely to examine the belief systems and incentive structures that underpin our approach to cybersecurity and AI—then Peiter "Mudge" Zatko is your guy. Equipped with one of the brightest minds out there, Mudge is certain to get you thinking about how taking an unconventional approach to solving problems can help us all spot weaknesses, hacks, and opportunities we’d otherwise might overlook. Thinking Beyond the Code: Contrarian Thinking to AI and Lessons From a Life in Discovery takes place from 10:15 to 10:45 am Wednesday, Aug. 5.
- One interesting thing about all this AI talk is that we’re finally getting to the point where compliance is getting the attention it deserves. Policy Meetup: Government Panel Discussion on AI and the New Era of Cyber Resilience promises to be a terrific panel discussing the challenge of governing AI and predicting where this is all heading for business. With cybersecurity leaders from three countries taking on a topic that impacts us all, this should be gripping. Alas, this 90-minute sesh starts at 10:15 am Wednesday, Aug. 5 (along with two of my other faves), but it’s only available to Briefings pass holders. So if that’s not you, choose one of the other options here.
- Okay, this one is less about AI explicitly and more about an immediate security threat that you need to know about: how attackers are using ad networks to target users and the environments they rely on, and in many cases it’s a completely overlooked vector of initial access. The threat receiving the focus in this session is LANJack, an advanced zero-click malvertising campaign that uses programmatic ads to silently map local home networks, target routers, and exploit IoT devices. Not cool! Moriya Pedael of GeoEdge, the firm that discovered LANJack, gives up the goods in LANJack: Turning Ads into IoT Recon Tools. It’s the same time as Mudge’s talk and overlaps with half the compliance panel (10:15 to 10:45 am Wednesday, Aug. 5), so I recommend you and your colleagues divide and conquer.
The AI force will be strong with vendors
Virtually every vendor is touting some kind of AI assistance in their offerings at this point, and you will see it everywhere you look.
You’ll also be hearing from them. AI vendors, in fact, are getting their own vendor stage. The AI Zone, where the stage is located, gives attendees the opportunity to test tools, examine emerging threats, and see defensive strategies in action. And the Black Hat Startup Spotlight Competition (11:05 am Tuesday, Aug. 4) is bound to give AI-forward innovators their own stage in this annual pitch competition. (So far, what I’ve tended to see are new AI companies that have launched a product on a single feature, but hey, that’s often what beginnings look like.)
The expo in general, however, will have you swimming in an ocean of AI. It will be all over signage and on demo screens. How all that translates into capabilities that offer meaningful help to cybersecurity practitioners, well, that’s for you to decide. I can tell you one booth is definitely worth visiting because I have firsthand experience with how AI is making life a lot easier for the humans at the helm.
New breakthroughs from an AI pioneer
Most folks don’t realize that back in 1982, Symantec was founded in part to develop solutions around—wait for it—artificial intelligence and natural language processing. Symantec has deep roots in AI, and those roots have helped Symantec introduce AI-powered capabilities that simply aren’t available elsewhere. Consider these breakthroughs:
- Adaptive Protection, which shuts down attempted living off the land (LOTL) attacks by blocking anomalous use of legitimate software
- Incident Prediction, which predicts an attacker’s next four to five moves so security teams can prevent lateral movement and the damage it could cause
- Investigation Summaries, which help analysts at all levels of expertise to gain immediate and clear understanding of incidents while offering specific guidance on next steps and mitigation
- Threat Tracer, which visually and dynamically illustrates the blast radius of an attack, which speeds investigations by allowing any analyst to understand the path the attacker took and the assets that were leveraged or compromised
- Cross-domain correlation, which gathers and correlates telemetry across endpoints, networks, SaaS applications, and data to present an extensive view of the full environment while delivering insights, not just noise
That last one is a unique feature of Symantec® CBX, a unified, cloud-based XDR platform that brings endpoint protection, data security, and web security together in a single solution. Built for organizations whose security teams are under-resourced and forever under pressure, Symantec CBX incorporates all these AI breakthroughs into a single platform.
One thing I find impressive about CBX is that it uses attack-trained AI to help security analysts work faster and more efficiently, delivering AI features that support people, not replace them. To my mind, this is AI that stands to make a meaningful difference in analysts’ lives while protecting them with defenses developed by the folks who not only helped pioneer AI, but who also pioneered EDR. Talk about a legendary pedigree.
You can see Symantec CBX in action at Booth 4727. Be sure to get your signed copy of Code War, the new book by Forrester cybersecurity analyst Allie Mellen (she’ll be appearing from 2 to 3 pm Wednesday, Aug. 5). And be sure to transform from Black Hat attendee to music industry icon with Symantec and Carbon Black’s infamous AI photo booth. And when things get serious, you can talk to experts from Leaf Platform, who throughout North America support defenders from discovery and quoting through onboarding, support, and beyond. (You can also book a 1:1 sit-down with Leaf Platform pros right now.)
A good week
Black Hat week is always a good week. I learn a lot, meet smart people, share war stories with fellow defenders, and return home with at least a few new ideas about how best to stop what’s coming next. That’s what Black Hat is, after all: a community gathering for cybersecurity practitioners.
Look for me in some of those sessions or, better yet, come by and see me in Booth 4727. You won’t want to miss what’s happening there.
Safe travels to you and your friends.



